Detroit TAC

  • Subscribe to our RSS feed.
  • Twitter
  • StumbleUpon
  • Reddit
  • Facebook
  • Digg

Thursday, December 8, 2011

FAQ: CNET's "Trojan" installer

Posted on 5:34 AM by Unknown

Popular download site under fire for wrapping open source software in meddlesome packaging

By Tim Greene, 

CNET is under fire for downloading more than just open source software with the open source software that it makes available on its Web site.
It wraps the software in an installer that also alters the browsers on the computers that pull down the open source code, and this has angered many in the open source community as well as others who just don't like having their browsers messed with when they're downloading something for free.
ALSO UNDER THE GUN: Carrier IQ again asserts no user data is logged or sent 
What is CNET up to?
To continue reading, register here to become an Insider. You'll get free access to premium content from CIO, Computerworld, CSO, InfoWorld, and Network World. See more Insider content or sign in.
CNET is under fire for downloading more than just open source software with the open source software that it makes available on its Web site.
It wraps the software in an installer that also alters the browsers on the computers that pull down the open source code, and this has angered many in the open source community as well as others who just don't like having their browsers messed with when they're downloading something for free.


What is CNET up to?

CNET's download site offers a range of open source tools including anti-virus software, anti-malware, Flash players and Nmap, the open source security scanner. The creator of Nmap, Gordon Lyon, wrote a blog post Monday ripping CNET for wrapping its download of Nmap in an installer that also changes the default search engine to Bing, makes Microsoft MSN the homepage and installs a StartNow toolbar with buttons for Facebook, multimedia search and local weather. It also floats an ad for third-party software in the middle of the install process.
What's wrong with that?
According to Lyon, it's a bad thing. He writes: "Then the next time the user opens their browser, they find that their computer is hosed with crappy toolbars, Bing searches, Microsoft as their home page, and whatever other shenanigans the software performs! The worst thing is that users will think we (Nmap Project) did this to them!"
Anything else?
Lyon again: "In addition to the deception and trademark violation, and potential violation of the Computer Fraud and Abuse Act, this clearly violates Nmap's copyright."
What bad things does this do to your computer?
Nothing destructive has been reported.
But there's talk of malware and Trojans. Isn't that bad?
The Web site Virus Total says that 22,524 of its members describe the CNET-wrapped Nmap as malware. Malware scans by security companies including F-Secure, McAfee and Panda identify the installer as a Trojan.
How long has this been going on?
CNET started using the installer in July.
Why is it getting all this attention now?
Mainly because Lyon's bluntly worded blog post caught a lot of attention. "F**k them!" he writes. "If anyone knows a great copyright attorney in the U.S., please send me the details or ask them to get in touch with me."
What can I do to avoid it?
There's an opt-out button on the download page. Part of Lyon's beef is that many people trust CNET's download page and skip right over the opt-out notification.
Why would CNET do this?
On its FAQ page, CNET says: "By downloading with the Download.com Installer the user is guaranteed that the file they install on their system came directly from Download.com. Only software that is tested spyware-free and hosted on Download.com's secure servers may be delivered via the Installer.
"In addition, thanks to the clear steps provided by the Installer, the percentage of users who are able to complete the download process increases significantly when using the Installer for their downloads.
"Finally, Download.com is supported primarily by advertising, and we include offers for additional downloads from advertisers as part of our Installer process. Unlike other download sites that employ similar ad-supported technologies, however, our Installer is limited to a single offer that is carefully screened to ensure compliance with the Download.com Software Policies
Email ThisBlogThis!Share to XShare to FacebookShare to Pinterest
Posted in Tech News Security | No comments
Newer Post Older Post Home

0 comments:

Post a Comment

Subscribe to: Post Comments (Atom)

Popular Posts

  • Rise of the 'maker movement'
    Rise of the 'maker movement' What does 'do-it-yourself' culture mean for the future of development?  ...
  • Quantum Computing Almost Here
    R. Colin Johnson   IBM recently demonstrated the components necessary to build a quantum computer, including superconducting microchips th...
  • How a Baptist pastor in Florida became the go-to IT guy
    NorthRidge Church pastor Terrill Gilley installs security gateways, watches for network attacks By Ellen Messmer   As a Baptist pastor,...
  • When touring the Large Hadron Collider, stay with your group
  • 14 Ways to Take Your IT Career to the Next Level - Network World
    14 Ways to Take Your IT Career to the Next Level - Network World
  • Medical Privacy Secured on Smartphones
    R. Colin Johnson | Anti-cloning encryption technology is being used to secure validated medical data, which can only be accessed by an att...
  • 10 Free Google Chrome Extensions to Increase Your Productivity - Network World
    10 Free Google Chrome Extensions to Increase Your Productivity - Network World
  • The No. 1 place to work in IT: Quicken Loans - Network World
    The No. 1 place to work in IT: Quicken Loans - Network World
  • The ACTEra – WHY YOU SHOULD HAVE BEEN AT THE BDPA 2013 CONFERENCE! | The Aspiring Critical Thinker's Era
    The ACTEra – WHY YOU SHOULD HAVE BEEN AT THE BDPA 2013 CONFERENCE! | The Aspiring Critical Thinker's Era
  • 10 hard-earned lessons of a lifetime in IT - Network World
    10 hard-earned lessons of a lifetime in IT - Network World

Categories

  • Android (1)
  • BDPA (3)
  • BDPA Local Chapter (3)
  • Career Networking (20)
  • Cool Stuff (14)
  • Education Tech (8)
  • Election (1)
  • FoodforThought (32)
  • FreeStuff (2)
  • Funny (2)
  • Green Power (7)
  • Hackerspace (6)
  • Local Tech Events (2)
  • Med Tech News (9)
  • Money (1)
  • MovieTech (1)
  • New Technology (5)
  • Open Source Tech News (7)
  • Personal Achievement (1)
  • personal rant (1)
  • Presidental (2)
  • SocialNetworkTech (1)
  • Space Tech (10)
  • Tech News (35)
  • Tech News Security (12)
  • Tech Tip (5)
  • Tech Tips (1)
  • Tech Toys (2)

Blog Archive

  • ►  2013 (202)
    • ►  September (6)
    • ►  August (21)
    • ►  July (17)
    • ►  June (17)
    • ►  May (26)
    • ►  April (23)
    • ►  March (32)
    • ►  February (28)
    • ►  January (32)
  • ►  2012 (200)
    • ►  December (27)
    • ►  November (31)
    • ►  October (33)
    • ►  September (12)
    • ►  August (14)
    • ►  July (5)
    • ►  June (9)
    • ►  May (13)
    • ►  April (9)
    • ►  March (24)
    • ►  February (10)
    • ►  January (13)
  • ▼  2011 (95)
    • ▼  December (10)
      • Entry-level IT jobs will be plentiful in 2012, exp...
      • Motivational Moment
      • Combining GPS, Cameras and More to Chart Health
      • HP Does The Right Thing In Open Sourcing WebOS
      • FAQ: CNET's "Trojan" installer
      • The Strangest Secret Earl Nightingale 1950's - You...
      • 10 Commandments of Networking by DetroitNet.org
      • Motivational Moment
      • Motivational Moment
      • Is Voice Microblogging the Next Social Media Trend?
    • ►  November (27)
    • ►  October (18)
    • ►  September (11)
    • ►  August (24)
    • ►  July (5)
Powered by Blogger.

About Me

Unknown
View my complete profile