Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

If your users get used to clicking "yeah, whatever" on any and all software update pop-ups, this will almost certainly become an attack vector. Adobe Reader, Flash and Oracle's Java each have their own nuisance updaters that are constantly pestering you for attention.

That software-updates-as-a-service is now a thing is really a sad state of affairs, but if Ninite can make a go of it, right on.



Adobe Flash updates are already an attack vector for some malware. My wife was presented with a "FlashPlus" installer to "update to the latest version of Flash" that looked exactly like Adobe's with the exception of the name. I'm still not sure what good fortune intervened to show me that particular installer before she hit "install".


Before we talk about your fortune, how many phony installers did you miss?


I wonder why the creators of such an installer even bothered changing the name? Virus/malware authors shouldn't care about the possibility of trademark violations; They usually take care to ensure the software can't be traced back to their identities regardless.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: