Author Topic: Avast Download Redirect to CNET - Not concerned with security best practice?  (Read 6749 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Start:  https://www.avast.com/en-us/index
Click on "Download Free Antivirus" copied url is: https://www.avast.com/en-us/download-thank-you.php?product=FAV-ONLINE&locale=en-us
The link redirects here:  http://download.cnet.com/Avast-Free-Antivirus-2015/3001-2239_4-10019223.html?hasJs=n&hlndr=1&part=dl-85737&path=direct&ls=media

Should I worry when the Antivirus software you rely on to protect you from just these maneuvers does not serve its own products and redirects you without notice or permission?

Or the question is, why should I NOT worry?
« Last Edit: November 30, 2017, 05:17:27 AM by scherazades »

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #1 on: November 29, 2017, 09:13:41 AM »
You can also download it from the official Avast server.
-> https://forum.avast.com/index.php?topic=210678.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #2 on: November 29, 2017, 12:54:35 PM »
Thank you for the link to the Avast online installers.  But the linked urls are also http not https and point to an executable file.  So we have to risk malware to get the Antivirus?
« Last Edit: November 29, 2017, 12:58:08 PM by scherazades »

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #3 on: November 29, 2017, 11:48:38 PM »
Thank you for the link to the Avast online installers.  But the linked urls are also http not https and point to an executable file.  So we have to risk malware to get the Antivirus?
No malware just the installation file. :)
If you prefer, get them from here: How to Successfully Install Avast http://goo.gl/VLXde
« Last Edit: November 29, 2017, 11:50:20 PM by bob3160 »
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

REDACTED

  • Guest
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #4 on: November 30, 2017, 12:03:09 AM »
I am surprised that AVAST does not utilize https for software distribution.  Isn't this a basic precaution?  What am I missing?

Offline bob3160

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 48562
  • 64 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #5 on: November 30, 2017, 12:07:30 AM »
Here's the download link I use for the free version:
https://www.avast.com/download-thank-you.php?product=FAV-AVAST&locale=en-ww
Free Security Seminar: https://bit.ly/bobg2023  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v22H2 64bit, 16 Gig Ram, 1TB SSD, Avast Free 23.5.6066, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq -- My Online Activity https://bit.ly/BobGInternet

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #6 on: November 30, 2017, 04:56:55 AM »
I am surprised that AVAST does not utilize https for software distribution.  Isn't this a basic precaution?  What am I missing?
-> https://forum.avast.com/index.php?topic=60523.msg527512#msg527512
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #7 on: November 30, 2017, 05:03:51 AM »
My concern is that Avast itself does not respect customer security enough to permit this.  Following links in a forum does not instill confidence in security practices.  Should be on the main page, secure and transparent.

This url also redirects to CNET without notice or permissions:
https://www.avast.com/en-us/download-thank-you.php?product=FAV-ONLINE&locale=en-us

http://download.cnet.com/Avast-Free-Antivirus-2015/3001-2239_4-10019223.html?hasJs=n&hlndr=1&part=dl-85737&path=direct&ls=media



« Last Edit: November 30, 2017, 05:13:25 AM by scherazades »

Offline mchain

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 5616
  • Spartan Warrior
What you say seems to be correct.  Seems to go along with what you could get for free could also come at a hidden cost.

I'd follow Asyn's advice @ reply # 1.  Furthermore, I'd also strive to download all executable files from original vendor sites only in the future as I've known about this redirect issue for several years now. 

Bitcoin miners is one of the new things in redirects.
Windows 10 Home 64-bit 22H2 Avast Premier Security version 24.1.6099 (build 24.1.88821.762)  UI version 1.0.797
 UI version 1.0.788.  Windows 11 Home 23H2 - Windows 11 Pro 23H2 Avast Premier Security version 24.2.6105 (build 24.1.8918.827) UI version 1.0.801

REDACTED

  • Guest
Asyn's reply - the link is https to the forum (low risk) but the links to the downloads are http (high risk). 

So it seems I am the only one out of 400 million who finds this to be problematic.  In posting the question, I was hoping to be educated on security risks but am just getting more unsecure links.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Asyn's reply - the link is https to the forum (low risk) but the links to the downloads are http (high risk). 
See Reply #6.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

REDACTED

  • Guest
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #11 on: November 30, 2017, 07:45:27 AM »
I am surprised that AVAST does not utilize https for software distribution.  Isn't this a basic precaution?  What am I missing?

I realize where you are coming from and I don’t disagree. However you could download the package from the http site (avast’s not cnet’s) then get the md5 hashes from this page https://support.avast.com/en-us/article/Troubleshoot-Antivirus-corrupted-setup and use a md5 tool to verify the package. IMHO the best you’ll probably get?

REDACTED

  • Guest
OK This one is served from AVAST - https://www.avast.com/en-us/download-thank-you.php?product=FAV-AVAST&locale=en-us

NOTE FAV-AVAST not FAV-ONLINE

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: Avast Download Redirected to CNET - Should I worry?
« Reply #13 on: November 30, 2017, 09:28:53 AM »
I am surprised that AVAST does not utilize https for software distribution.  Isn't this a basic precaution?  What am I missing?

I realize where you are coming from and I don’t disagree. However you could download the package from the http site (avast’s not cnet’s) then get the md5 hashes from this page https://support.avast.com/en-us/article/Troubleshoot-Antivirus-corrupted-setup and use a md5 tool to verify the package. IMHO the best you’ll probably get?

All the Avast installers (and other files) have a digital signature by Avast Software s.r.o.
Verifying that (rightclick --> Properties / Digital Signatures / Details) is the best way (much better than comparing some MD5 hashes, in my opinion).

REDACTED

  • Guest
Good information, Igor.  However once you click on the executable and before the confirmation prompt, if there is malware, it is too late.