Pirate sites have reputations the same as anybody. The more reputable ones actively remove spam and malware.
So it's kind of like saying, I don't understand how people dare to run executables downloaded through the internet. Depends a lot on where on the internet you downloaded it.
I have no idea what the landscape looks like today, and I’d be reluctant to run anything outside a vm, since I no longer know where the reputable sources are, but I’m sure there are still private trackers and discord servers where you could trust every link.
They happily ban users for sharing the wrong links, and have banned entire instances for discussing anticheating technology.
The unpaid WinZip still works great though.
Online proprietary software sells you to advertisers for money, or locks you into an ecosystem so they can sell you to other third parties, and they use some of that money to fund development.
With free software you either have to improve it yourself (the source code is on the internet) or give them money so they can hire someone to do it (they all have donation links). If you're dissatisfied with the user interface, have you tried doing the things that cause it to be improved?
Rome wasn't built in a day, as they say.
Great looking software existed long before the rise of everything being always online.
Only if by "nothing to do with" you ignore that it is the method by which development is funded.
> Great looking software existed long before the rise of everything being always online.
At which time you had to pay a lot of money for it. If everybody gave the same money to free software developers, they'd have plenty of resources to build interfaces that are more to your satisfaction.
>If everybody gave the same money to free software developers, they'd have plenty of resources to build interfaces that are more to your satisfaction.
You're just arguing to pay for software, but in a more roundabout way. And again, great looking software existed far before the popularity rise in always-online.
I mean just look at these instructions
https://help.libreoffice.org/Common/Using_the_notebook_bar/v...
I can't make heads or tails of this...first I gotta switch layouts?? Then I gotta go to view and turn notebook bar mode on? Then i've gotta choose between tabbed, contextual groups or contextual single bar...nope no siree this is why piracy's just not for me.
These knockoffs are always so complicated, why can't they be simple like the official certified word? And shiny and jazzy lookin'? I know ya get what ya pay for, but how hard would it be to slap some bezels and rounded edges on there? Maybe some 3d transitions?
And being open source, the project won't have the same luxuries in terms of user-testing and iterative improvement of things as trivial as a 'shiny' UI. Again, if you have the time, you could help them out.
Ah well: play stupid games, win stupid prizes.
This is just one example of a basic feature, used on a regular basis, which has obviously been tested thoroughly by the Office 97 developers, but has seemingly barely received any attention from LibreOffice.
I use a very basic laptop, and through the wonders of virtualization have a Windows ME VM with Office 97 on it, and it runs just as fast as LibreOffice does natively, if not faster. In a VM, being used for an hour or two at a time, Win ME has no stability issues.
Win ME came with IE 5.5, and I eventually upgraded it to 6.0. Because I built my site to be compatible with both, I can easily copy and paste what I wrote into my blog. Office 97 and IE 6.0 support Unicode well enough that I can do all this in two different character sets.
I rarely print anything, and I'd probably still use LibreOffice for that. But if I really wanted to, I could probably figure out how to print, too.
The Win 9x series is remembered for being unstable and crashy, but I think it's also a marvel of engineering and UI design. And when you take away malware, random utilities, registry decay, hardware malfunctions, and so on, it's a comfortable, almost typewriter-like experience.
About the Ctrl-s thing, maybe it's specific to windows, I use libre office on linux and have for years and Ctrl-s on a new document has always brought up the save-as dialog for me.
Either way, I'd rather use an older version of word or libreoffice over new versions of office.
I grew up using older windows, I don't really remember it being overly good or bad, it just kind of was. I remember lots of crashes, but used to do a lot of things I probably shouldn't have been and I do remember it working for everything I tried to do so I don't really have any complaints really. I don't really have any fond nostalgia either though to be honest.
I stopped using windows entirely outside work over a decade ago so none of it really matters all that much to me.
I'm using LibreOffice on Fedora, and I've used it on Mac and Windows too.
Yes, it brings up the Save As dialog, but the name is not pre-filled with an intelligent choice.
In Office 97, it typically pre-fills the suggested file name with the first line of the file. If that's not available, it tries to think of something else.
But never does it ever suggest a file name that is either invalid or would overwrite an existing file.
It ensures that the suggested filename is not too long, and doesn't contain unacceptable characters.
If there's already a file with the first name it thinks of, it appends a number, so that you don't accidentally overwrite an existing file.
In case you don't care about the filename, and just want to save the document, you are never forced to change the default, and it always works.
Many of my files begin with "I'm ..." and sometimes the best that Word 97 can come up with is "I7.doc".
Well, that "I7.doc" is a whole lot better than LibreOffice's "Untitled 1", which will overwrite the last "Untitled 1" it already had me save.
After how many years of development is LibreOffice still not smart enough to do any of these things?
Surely, LibreOffice today has been in development longer and by more people than Office 97 had been in '97?
What is the cause of this unfortunate circumstance?
No, but it's usually helpfully preselected so a single keystroke, changes the name.
>Many of my files begin with "I'm ..." and sometimes the best that Word 97 can come up with is "I7.doc".
>Well, that "I7.doc" is a whole lot better than LibreOffice's "Untitled 1", which will overwrite the last "Untitled 1" it already had me save.
Personally, I dislike that feature of word because typically I do not want my files saved by the first thing i've written and yes I care about file names and take the time to name things sensibly and even put them in related folders.
Also, it should automatically detect an untitled1 and enumerate to untitled2 if untitled1 exists, again this is how it's always worked for me. So your file overwriting example seems a tad dubious to me.
I have to be honest, of all the gripes i've heard, this one's just a bit ridiculous. The save feature works exactly as it should. A program should allow me to choose a name for a file or choose a reasonable generic default, not decide what it thinks I want.
If I see an untitled1.doc around, I know I forgot to rename a file and I investigate, if I see I7.doc or a my name is.doc, I dunno what the hell it is. Maybe it's something I forgot to rename, maybe it's something I wrote before and forgot about, who knows?
Then you can rename it?
>Also, it should automatically detect an untitled1 and enumerate to untitled2 if untitled1 exists, again this is how it's always worked for me. So your file overwriting example seems a tad dubious to me.
But it doesn't! That's what my complaint is about! Do you think I'm just making it up?
>I have to be honest, of all the gripes i've heard, this one's just a bit ridiculous. The save feature works exactly as it should. A program should allow me to choose a name for a file or choose a reasonable generic default, not decide what it thinks I want.
To me, this reads as, "I read your text, but I don't think your problem is real, because I think it should work differently."
I think you should do a deep examination into how you relate and communicate with people, because you spent this whole thread invalidating what I'm saying and telling me the problems I'm describing in detail are not real problems.
You've given me the impression of being an insensitive and careless person.
Free, open-source, and much faster.
You're unlikely to get a direct answer because... Well you don't talk about fight club. But if you watch the subreddits a bit you'll get a much better idea of where to start, how to get invites to private trackers, etc.
Or use Vagrant if you want better security.
Do you have an alternative to trusting them?
I don't remember when PirateBay or other Warez sites first appeared, but they have been around for at least 20 years. I remember people were even using Blogspot to promote their wares/z with links to RG, FS, DF, etc.
I know and trust(?) the results of Virustotal, and I tell all my clients that when in doubt, drop that bad (?) boy in VT and let it scan it.
Not running pirate software is the only valid path for security.
Way back when, we had usenet, telnet and gopher, and local BBS's would sometimes have a private stash of cough shareware.
Prior to usenet etc being easily accessible to people outside of educational institutions (the majority of the 80s), it was more common to share programs via "sneakernet" on floppy disk as well, these would often contain a text document that would say what other programs were available and some clues on how to obtain them, but usually it was just a viral spread among friends and acquaintances.
Cracked software would often include intro screens and trainers, the intros sometimes included animations and catchy music to showcase the elite skills of the cracking crew and build reputation, and often they improved the software so it would load more quickly, unlock hidden functionality, or give you infinite lives etc. This spawned the DemoScene, which still exists today unrelated to piracy but historically rooted in the 80s cracking scene.
Here's a compilation of crack intros from 86 to 89 - https://www.youtube.com/watch?v=SFqBkSJOYOQ (skip to 11:40 and you'll see an advert for "cleveland cracking service" with a phone number for an example of how stuff got around before internet was common)
Essentially even back in the 80s and 90s there were the serious crews trying to demonstrate their awesomeness and generate rep, and dumb kids like me naively sharing "free stuff" we were given on disks because we had no idea what things like copyright and licensing even were, let alone stopping to consider whether the stuff we were loading onto our machines had any malicious intentions.
So I'd say that the idea of building reputation and trust in regards to piracy "crews" has a long history going back even further than 20 years, well before the web was common in homes, and I'm at least aware of early to mid 80s cracktro / intro scene materials so perhaps ~35-40 years is a good guess?
Who are your clients? Are you aware that everything that's uploaded to VT becomes public? As in full file contents, not just metadata & scan results. There's no harm in uploading .exe's there, but you should at least warn them not to upload private documents.
Also, VT results are trash for anything new so "all green" doesn't necessarily mean you're safe to run stuff if it also happens to be the first time VT has seen the file. It's not even the VT's fault, AV's suck and everybody knows it. The value of VT is that once something gets detected people can go back in time and look for other incidents that had flown under the radar previously.
...that aren't there own.
rutracker isn't some fly-by-night random tracker, it's a well established site in Russia, and the admins have been extremely communicative with users throughout virtually every governmental upset.
To add some context, try to imagine if the classic western trackers had prominent links like this, for example, what.cd.
Looking at the thread, the early posts correctly identified it as malware before the malwarebytes report, and even noted that the link itself violated the application post rules.
It's good for malwarebytes to report that this exists, but they're focusing on the wrong parts, imho.
The hash files to identify the affected file should have been the first part, then the explanation. A bit of google translate would have shown that already, rutracker users are calling to delete the thread.
AV/anti-"malware" has always meant "pro-corporations/pro-copyright/pro-establishment", ever since they started detecting completely clean keygens and cracks as well as "hacking tools" and demoscene productions.
There is sometimes truth, like this article, but there is also a lot of FUD --- IMHO to herd users into giving up personal discretion and instead adopting centralised trust.
AFAIK this is usually a side effect of self-unpacking compressed executables, as produced by EXE packers. They have a property that's been useful to malware authors: they obfuscate the code. To de-obfuscate, you have to unpack, which some anti-virus vendors actually do for executables produced by common compression tools like UPX. For certain types of demoscene productions, however, a popular tool like UPX won't do if you can shave another few bytes using a more obscure packer that AV software are unlikely to have unpackers for. Once malware authors start using those same packers you'll get false positives based on signatures that are likely common to all software using them.
Little angel gone too soon.
But do you understand people who dare to run executables from 'proper-company' site? It's closed source, you have no idea what you are running, isn't it? As long as it's not free software in terms of FSF there is not guarantee what so ever that it's not harmful or even worse intentionally harmful.
How about this one from SONY, that didn't even ask user to run? https://en.wikipedia.org/wiki/Sony_BMG_copy_protection_rootk...
or this one Amazon remotely deletes book from kindle: https://www.nytimes.com/2009/07/18/technology/companies/18am...
The set of computer users who a) have the knowledge to do security code review and b) have the time to review the programs they run is, I would expect, fairly small.
Obligatory reference to Reflections on trusting trust [1]
Even a small number of those who understands can make a huge noise, because if comment is well grounded, it spreads exponentially by people who do not need to understand all the details.
And frankly how much those who understand you really need for each project? The thing is, if you are worried you can always look, which is not the case if you have nowhere to look.
Also expert is not always required just to see there is no brutal obvious harm intent, which covers a lot of cases
Then you have the fact that if it's deliberately malicious things can be hidden such that even experienced code reviewers (who are not plentiful) could be fooled. A good example of this is the underhanded C contest http://www.underhanded-c.org/_page_id_2.html .
Sure an open source user may catch malicious behaviour, but then security researchers find malicious behaviour in closed source software pretty regularly via reverse engineering or binary analysis.
This isn't an anti-open source thing, it's a reflection that open source often isn't much of a signal of safety, unless further work has been done and continues to be done on a regular basis.
I have also never seen anybody who made this argument verify their free software by looking at sources before compiling.
You'll have to trust somebody at some point.
Do you trust the company who designed your Ethernet chip? Do you trust the person who wrote the firmware for it? If not, go and design your own network chip. Otherwise, there's no guarantee it won't spy on you.
You'll also want to write your own compiler that you'll then use to build the operating system you intend to run. You won't just go download some Linux .iso to install, would you? After all, there's no guarantee it's not been manipulated by those who offer it on their website.
No, I do not have to. I can choose to, but I don't have to! That is the core of the issue.If I 'have to' then I don't. I prefer checking and facts, not delusions.
>Do you trust the company who designed your Ethernet chip?
No, I don't and we shouldn't. I evaluate chances and we should track network activity with diff. hardware on diff. chipsets from diff. manufacturers.
>Do you trust the person who wrote the firmware for it?
No, I don't and we shouldn't as it's insane to do so.
>If not, go and design your own network chip.
There are other means to overcome this: encryption. But yes, you right, we should make open source network chip. Agree. I certainly plan to design it.
>Otherwise, there's no guarantee it won't spy on you. That is correct, I agree with you.
>You'll also want to write your own compiler.
Yes, that is correct. I want and I am writing it right now. There is also an option of GNU c/c++ compiler available (GCC) https://gcc.gnu.org
>that you'll then use to build the operating system you intend to run.
This is how you build a proper GNU/Linux system worth some degree of your trust.
>You won't just go download some Linux .iso to install, would you? After all, there's no guarantee it's not been manipulated by those who offer it on their website.
Exactly. Or it can be modified on the way, while you download it. For the later you can check hash sums published by a site who respects user freedom and cares about own reputation.
>You'll have to trust somebody at some point.
Again I do not have to, but I can choose to trust with some degree to Richard Stallman and people sharing his views. https://www.youtube.com/watch?v=n9YDz-Iwgyw
I have some trouble trusting FSF since he was removed from the position due to false accusations for saying (!) just saying things, which he actually didn't say if you read carefully. Speak about respect of freedom of speech.
https://www.youtube.com/watch?v=7UbQ1kc1vQU
To trust the system we should have trust worthy components with open sourced designs starting from CPU and every chip installed and ending with each software running. That is the only way!
For pirated software the incentive structures are also clear, and usually point towards "yeah if given the chance they'll take everything from my HDD and make a run for it."
I'm all for FOSS everything, but running a company-distributed binaries is very different from pirated ones, and I agree with GP that it baffles me someone would do the latter.
It also depends on what company means by "not screw everyone over" Right now many companies consider practices as 'OK' while I am coming from the times when most of those modern activities considered to be virus or malware. So for me it doesn't really matter whether you have malware installed by a virus or it's hidden deeply in EULA which you can't reject partially anyway.
Pirating and re-packaging software for torrent is also a non-negligible amount of work, and with no revenue stream besides bundling the apps with malware. So it's quite a different incentive structure still.
Let's take a File System for a second as example. If you wrote your personal data on some disk drive and then to read this drive you need let's say Mac/Win because it's a closed format. And Mac/Win cost money. How it differs from ransomware then? Sure you have more time to decide, usually more than 3 days and it costs a bit less, but is it much of a difference there? Probaly a choice to start using it, but is it really a choice? In many cases it's not really. So back to your point, I understand it, but do you?
Anyhow, I know that much of my early software license transgressions resulted in actual software licenses.
...and now you know why Adobe products are so easy to pirate. Young pirates turn into loyal product users and customers.
Adobe doesn't spend copyright enforcement time on individuals much.
Check with your university. This shall includes hundreds of software, all editions of Windows both 32 bits and 64bits, as well as all editions of Visual Studio Ultimate, plus databases and other tools.
After that they really cracked down on piracy, and at the same time offer the CC subscription decently cheap (50$ a month) that honestly the risk of malware isn't worth it any more.
Yes, digital responsibility is ignored by those using cracked software, but really you can't ignore factual constraints and the economic situation, when talking about who's to blame.
It's a cost/benefit analysis... Billions of people in the developing world rely on pirated software, for one...
Heck, even in large parts of Europe, at some point there would be much fewer graphic designers today e.g. if they couldn't pirate Photoshop when they were young and non-pro (and no, Gimp wouldn't be of much use, they want to learn on the industry standard)...
But for students Adobe was basically giving it away :) I remember getting a CD for 15 guilders at the time at the university. Which was around 5 euros.
To be honest, when I had to upgrade my Windows machine last year, I really regretted the fact that I've gone fully legit with VST plugins. It took me more than a week to deregister and reregister all the horrible proprietary DRM schemes those companies are using. That would have taken less than a day if I had used cracked versions.
Is there something like a "steam for VST"? Maybe it should exist, to ease the DRM pain for legitimate customers.
Nobody really cares if you use the same presets. There were countless top-10 hits with the same handful of DX7, M1, JV-1080, etc presets.
Nowadays, there are so many VSTs and they have so many presets, that nobody can keep track anyway, even if you do use their presets.
And of course you can always program your own patches on most VSTs, alter presets with layers of effects, etc...
Although there are a few larger DRM "alliances", for some reason manufacturers have not yet been able to agree on a common DRM and package management system. Currently every larger company and a number of smaller ones want to push their own plugin management system.
VSTs are a mess anyway, there are only few hosts who are able to scan all of them correctly without crashing (and these do it by separating the process that crashes from the rest of the host).
And it shows in their systems. I know a few people with extensive travel experience in Africa and most of them, despite being decidedly non-technical, came back with essentially the same story: "if you absolutely have to bring a laptop, don't ever connect it to something that has a data line"
No one knows what they are doing. Unless you are decompiling and reverse engineering the whole thing you are mostly just blindly trusting its safe. Even on trusted sites people share stuff from other sites not knowing its infected.
Obviously those can be repacked and faked so you'd have to check multiple sources to ensure you get a genuine release, but yeah the scene groups are as usual way ahead of everyone else.
I think the scene groups are a traditional bunch that in some respects are years behind because of it. I remember in maybe 2005 I'd still download releases that were split into floppy sized RAR files. Possibly, this tradition carried on for so long because the scene was so keen to shame groups that didn't package like everyone else. I don't know how it is now but I'm hoping they got over splitting releases.
Like the OP, back in the day I used to have plenty of pirated software (mostly games) and never had a problem with viruses (at least, not that I knew or had any noticeable effects). The threat complexity is probably way worse these days and I wouldn't risk it. Plus, of course, I support games by paying for them :)
Isn’t that why things like heartbleed took two years before being found out? I presume some people using the vulnerable OpenSSL versions felt similar to you.
The worst I have seen is xscreensaver embedding a message in the code to complain about the old version a year after release.
I used to swear by Outpost Firewall as it was able to do things like detect applications adding to startup, injecting into other processes, gaining raw disk access, reading your browser profile for passwords, communicating with any unexpected hosts, etc. This is enough to rapidly identify most malware packaged with pirated software immediately. This isn't some advanced targeted attack, it's a script kiddie packing ransomware, password dumpers like iStealer, RATs like DarkComet, etc. The kind of thing these tools are designed to detect.
I’m on my phone so can’t search better, but couldn’t find it at rutracker from a quick search. Not sure if it will be available via some archive.
Sony has a root kit included, Zoom had a web server that could be exploited (at least) to then on your camera.
That’s just off the top of my head.
I don’t remember malware on Debian, Ubuntu, Fedora or Arch’s repository (put there by maintainers like the examples I gave above, or by a hack). And definitely not Gentoo.
But you are right. The bottom line is, you shouldn’t trust that which you cannot verify; but with open source, you have much more ability to verify (but it’s not a panacea - you run to many lines of code to verify yourself, it’s not clear anyone trustworthy verified it all, and there also the “reflections on trusting trust” argument)
The damage malware can do now is so much deeper - encrypting all your files, which then gets synchronised out through the tool you were using for backups automatically, before holding them to ransom. Then it turns your light bulbs into DDoS nodes to spread that to people across the internet, and probably you won't notice because you're on a fast enough connection for that to fly under the radar.
There is a de-drm tool that I used to use which packages some other open source. For whatever reason, I always assume people who package up software are careful about what they're packaging up, but no, as it turned out this project is not careful at all. It shouldn't have been surprising but it was.
(I ended up writing my own tool. I de-drm on principle; I don't mind buying stuff, I am deeply offended when that stuff vanishes out from under me because of deliberate obsolescence and/or shutdown. Buying DRM-free is not always an option.)
edit: fix the autocorrect
Mac has the sandbox runner, with a configuration file. However it’s deprecated, and difficult to create.
Also, not even Facebook signs all their apps.
It’s funny, bc everybody is kicking and yelling against the AppStore, and the process. But it’s the only thing protecting everybody from misuse
It was and is a small number of people regardless. I’m not sure if that’s going to be the “reason” nothing happened. If so, it doesn’t seem like that can conclude protection from misuse.
Adobe and Microsoft are the most targeted by malware writers unsurprisingly.
Ive done similar on mac too.
In Big Sur, it might be.
> AFAIK it is always safe to open an app you download from the web (although the app may not respect your privacy).
Apps can still encrypt your disk this way.
https://nektony.com/wp-content/uploads/2019/11/grant-acces-d...
I could be wrong, maybe it's only for certain kinds of apps.
This is separate from the older sandboxing feature that’s designed to fully isolate apps from the rest of the system, which is mandatory for Mac App Store apps but opt-in for other apps.
No its not various ways to break out of sandboxes exist.
Now everything is subscription based fully you have to replace the license system within most major software.
So I'm told.