Author Topic: Download process is not safe anymore  (Read 7583 times)

0 Members and 1 Guest are viewing this topic.

Offline moneymaker0886

  • Jr. Member
  • **
  • Posts: 28
Re: Download process is not safe anymore
« Reply #15 on: April 17, 2020, 02:12:05 AM »
first, I am not using Avast antivirus anymore, I use window defender. Second, if a new virus or malware force install on my pc, because it's new, no matter what antivirus you on, it wont be stopped. I've seen it before and this is still going on. The only way to avoid problems would be to let owners control what files can download on the PC.

Since secure browser download files before you tell him to, this is unsafe. You could get a popup that force download stuff with no option to avoid the download. It's really really bad.

« Last Edit: April 17, 2020, 02:17:00 AM by moneymaker0886 »

Offline Libor Šlechta

  • Browser QA Team
  • Avast team
  • Jr. Member
  • *
  • Posts: 44
Re: Download process is not safe anymore
« Reply #16 on: April 22, 2020, 04:05:15 PM »
Hello moneymaker0886,

I have discussed this with one of our security experts that focuses on browsers and we ended up in agreement that the download itself is not dangerous. Executing the malicious code is.

So therefore pre-downloading the data before you click save is not security vulnerability and also it is the reason why other major browsers (Chrome, Firefox) behaves the same and why most of the browsers are by default set to not ask where to download the file and automatically download it to Downloads folder. Downloading does not mean installing/executing.

And you were not right about Chrome pre-downloading only trusted files. I just checked with our malware samples that are on internal network (private ip range) and Chrome pre-downloaded them without worry.

However, we are not saying we can’t be wrong. If you know about any existing exploit or you have some proper research about how this attack would work from technical point of view (like what exact steps would need the attacker achieve to infect the machine) then please properly describe the vulnerability and contact us via our bug bounty program https://www.avast.com/bug-bounty. As this would be massive security flaw, that would basically be affecting every online user, the reward from the bug bounty program would be for sure financially really rewarding. Please read the programs instruction first, before submitting your report.

To your question about Avast team staff. You can identify us on forum by "Avast team" info under the profile icon. "Avast Überevangelist" are recognized community users that have deep knowledge about our products.
« Last Edit: April 22, 2020, 04:12:32 PM by Libor Šlechta »