Skip to content

Comment on Discovered: Botnet Costing Display Advertisers over $6,000,000 per Monthparent

Comments

"The future in personal computing I think lies squarely in an automatically updated (even managed) sandboxed environment."

Until the day where the main server serving the automated updates gets compromised and instead of serving, say, an updated Chrome, it serves a version of Chrome which a) is compromised on the behalf of a botnet master and b) never ever accepts any other update automatically.

Because people have been trained never to update their browser themselves anymore they'll think everything is fine.

Because hundreds of millions --if not billions-- of people are running Chrome suddenly you have the biggest botnet ever out there.

I find it very interesting that you fear extortion, exploits, DDoS, identity theft, invasion of privacy and whatnots as an argument for putting something in place which potentially can be way more destructive.

But of course this shall never happen right? Just as we haven't seen FaceBook getting penetrated and just as we've seen any major bank getting hacked right? And rogue employees also don't exist right?

Be careful about what you wish in the future...

It is really just choosing between lesser of 2 evils.

1.) A million people using $BROWSER, never updating, continually downloading free_ipad.exe

2.) A million people being owned by an intelligent hacker because of a fault of Google, that is relatively quickly patched, and I'm sure someone will figure out something to disable those rouge Chrome installs.

The first scenario is much, much more likely to happen, and while the second could happen I doubt, Google would sit on their hands while it does happen.

I guess the only problem is in the second issue, its not your fault if you got screwed. Its your mom's, and just your mom's, problem if she downloads free_ipad.exe, but if Google is hacked all the sudden all your info is comprised and it wasn't your fault.

Considering these two options however, IMO, I'd rather place my faith in Google overloads keeping us all safe.

How is this different to the status quo of hundreds of millions running old exploitable versions of $BROWSER, infected with malware which hijacks your internet connection? All you've done is swap one delivery mechanism for another.

You don't fix this by switching out automatic updates for manual ones, because users will blindly install an update even if it's a badly-designed 'update dialog' popup on a shady website. You fix it by ensuring users can trust their software, and care enough to do so.

Did the "centralized anything == bad" camp show up or something? This is a surprisingly hyperbolic rant about browser security.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.