logoalt Hacker News

retoxyesterday at 10:13 PM2 repliesview on HN

If the problem is in the installer then this can't be 'fixed', affected installers should be fingerprinted as malware.


Replies

gertlextoday at 4:07 AM

I had that thought of "existing installers are sus..." but didn't connect to "fingerprinting it as malware". Makes sense.

Couple questions as savvy tech person but not working day-to-day in security/IT:

Would a regular home user with an old installer in their Downloads folder need to worry? (is a bad download file going to target looking for these old installers, then moving files around, etc?)

On the other hand, I could see corporate IT having the stronger case of proactively wanting to flag this installer if present on their systems.

pghatedphonesyesterday at 10:20 PM

[dead]