logoalt Hacker News

belochyesterday at 10:31 PM2 repliesview on HN

I was unaware of these side-loaded malicious apps until now. This is information consumers need to have.

It's very reminiscent of Sony putting rootkits on CD's. Unwanted, dangerous software is being loaded onto your computer by people you paid money to. The companies involved, including MS, should face serious blowback over this, as Sony did.


Replies

ryandraketoday at 2:44 AM

It's about time some company was prosecuted under CFAA for this kind of abuse. This should easily fit the legal definition of "intentional unauthorized computer access."

But we all know, the law is enforced aginst regular people, not corporations. Are corporations ever prosecuted for invoking something on a user's computer without their authorization?

spicyjpegyesterday at 11:24 PM

This isn't even the worst payload ever delivered through Windows Update. The prize for that should probably go to chip manufacturer FTDI, which once abused the system to publish a driver that would semi-permanently brick USB serial bridge parts the driver detected as counterfeit [1] by exploiting a command that the genuine parts did not implement correctly (how ironic) [2]. The backlash was large enough that Microsoft ended up pulling the update almost immediately, but that did not stop FTDI from trying again a few years later with another driver update that deliberately corrupted data sent through detected-counterfeit parts.

[1] https://en.wikipedia.org/wiki/FTDI#Driver_controversy

[2] https://github.com/therealdreg/ftdibrick#diving-deep

show 1 reply