logoalt Hacker News

belochyesterday at 10:31 PM3 repliesview on HN

I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.

It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.


Replies

spicyjpegyesterday at 11:24 PM

This isn't even the worst payload ever delivered through Windows Update. The prize for that should probably go to chip manufacturer FTDI, which once abused the system to publish a driver that would semi-permanently brick USB serial bridge parts the driver detected as counterfeit [1] by exploiting a command that the genuine parts did not implement correctly (how ironic) [2]. The backlash was large enough that Microsoft ended up pulling the update almost immediately, but that did not stop FTDI from trying again a few years later with another driver update that deliberately corrupted data sent through detected-counterfeit parts.

[1] https://en.wikipedia.org/wiki/FTDI#Driver_controversy

[2] https://github.com/therealdreg/ftdibrick#diving-deep

show 1 reply
ryandraketoday at 2:44 AM

It's about time some company was prosecuted under CFAA for this kind of abuse. This should easily fit the legal definition of "intentional unauthorized computer access."

But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?

godelskitoday at 3:31 AM

  > I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.
I really want to ask, earnestly, how do we communicate these things earlier?

I don't think there's a shortage of HN users that one about this type of bullshit going on. I'm not going to tell you "I told you so", and I'll even attack those that do. But when people who are concerned with these types of issues talk out they get dismissed as being conspiracy theorists or simply too sensitive.

I'll admit that sometimes it can be hard to differentiate, but well respected experts in the tech field have discussed such issues for decades. So I really do want to understand, how do we reach you earlier? Before we get to this point. How do we not just come across as uppity tech nerds screaming "I use arch btw" in furry programmer socks?

I really do think we as a community need to figure out how to reach the public better. We're well past what was considered terrifying in 1984. We aren't a society where big brother could be listening to you at any time, we are living in a society where uncle Mark is watching you all the time. Where uncle Pichai knows who all your friends are. Where uncle Nadella knows when you're awake. They know whose been bad and good but they don't even have the decency to deliver gifts under the Christmas tree. Are we only fighting back because their actions have become so obvious? Or are we fighting is the principle enough?