The Internet Shutdown Game
shutdowngame.apc.org
shutdowngame.apc.org
When I download a file of uncertain origin/quality I always upload it there and rest (relatively) easy on what's in it.
How would you prefer they distribute the files?
If we're really going to do this right, then Smoke Signals are the way. We take the 1s and 0s and encrypt them into different 1s and 0s to obfuscate. ;)
The need of downloading anything might be the point of that game, but people spreading viruses also like playing that way.
I might have agreed with you 15 years ago, back in the age of antivirus and such.
The parent commenter is suggesting the random file may be malicious, not that their unzip utility or pdf viewer is untrustworthy.
They are further suggesting that the data contained within the zip could be distributed in a fashion that is less commonly weaponized (PDF is a common attack vector, zip is a common obfuscation method).
>I might have agreed with you 15 years ago, back in the age of antivirus and such.
What does this even mean? You still need antivirus today.
Today's AV has to be more than it was in the past to be a successful shield, hence products like CYNET or CrowdStrike.
I still run AV at home on all systems, because I agree with you. AV is still needed and people without it...well, I wish them success.
An AV is a waste of system resources unless you're a fool that's easily convinced into opening things you shouldn't.
Did Malware write this? lol
Meanwhile, I know plenty of people WITH antivirus and other shit with utterly compromised and slow shit. We can blame the user behavior instead of the antivirus, naturally, but how do we know the AV is protecting the user and not luring them into a sense of security so that they do risky things?
I'm clearly doing something right.
I think that you underestimate the capabilities of modern malware, and overestimate the capabilities of the average lazy person.
Modern malware doesn't need this "download and execute" flow to activate. It exploits vulnerabilities in browsers and browser components to achieve arbitrary code execution. One click required (the one that leads you to the malware) [1].
A malware flow with manual downloading that leaves persistent breadcrumbs on your computer has more opportunities where a "real-time protection" antivirus can detect and stop the threat, so it's no longer the norm outside email attachments.
[1] https://github.blog/2023-09-26-getting-rce-in-chrome-with-in...
It can't provide value to laypeople who're cutoff from the internet if all that's passed around is a URL.
If you really care about "casual usability of things that can spread viruses" in your security model, you would actually prefer documents in PDF format and running them thru Qubes sanitizing conversion appvm.
For the average user, I would say malware running under the browser sandbox within a domain context is game over, assuming for example malware under your webmail or bank page domain.
This XKCD applies to this very well: https://xkcd.com/1200/
> If someone steals my laptop while I'm logged in, they can read my email, take my money, and impersonate me to my friends, but at least they can't install drivers without my permission.
If your webmail provider or bank is serving malware or user generated content under the same origin as the frontend, they have self-owned beyond the browser’s capacity to help.
Technically possible, but the vast majority of sites that can get you infected just by viewing them depend on JS. I'd much sooner trust an HTML document than a PDF file from some random website.