Out of interest, how many packages have you examined and how long did each one take to examine? What was your methodology?
No, the problem is with your use of the English language.
You know them all, personally?
Cite one piexce of malware that uses a priv. escalation in Atguard.
Apart from the entire class of ad-ware. I do not need to cite examples. The fact there is a clas, that you are aware of indicates there is software in this class.
Particularly the one we're discussing. Your solution of 'not using that software' is not a solution. It is risk avoidance vs risk reduction.
Why?
I have a clue. I work in the REAL WORLD. Your posting history suggests you do not. At least you have an unrealistic expectation as to how users will use their systems.
Bogwitch.
Didn't find your answer? Ask the community — no account required.
S
Sebastian G.
Didn't count, but it were many. Ranging from XML Editors over resource management software, network sniffers, scripting language implementation (do you know how many Python implementations are out there?) to computer algebra systems.
Depending on the functionality and the results ranged from seconds till weeks (long term testing).
Well, what do you think? Collecting information, testing on a test machine, careful analysis, and potentially long term testing.
F.e. Wehntrust, and ASLR implementation for Windows, breaks about once in
10000 processes. Now if your shell script is spawning one process for each
500 files, iterating over 2 mio. files...
Doubtful. "the author" is singular, not plural. So why the hell should I care for the author of an ad-ware supported software if other authors write free and better alternatives?
Why should I? It's a matter of definition.
Agobot/Gaobot
Anyway, even without any example it would be generally true.
Ad-ware is not legitimate software. Unless you want to stick with your unreasonable definitions.
Since ad-ware is not legitimate, you can't reasonably expect it to not bypass your filter. In fact, even if you're coming up with your strange redefinition this expectation doesn't change at all (thereby debunking your definition).
Even further, any sane implementation of ad-ware will disable the associated software if it can't download the advertisement.
It is. Trivially.
Because it's entirely different. And, as I told you, "layered security" is a common buzzword for selling an entirely different concept than "defence in depth", but trying to inherit the good fame of the latter by simple confusion.
That's what I should tell to you. But then again, you're a d*****ad. A d*****ad who doesn't even consider to inform himself what defense in depth actually means and how it's different from the buzzword "layered security", even though he has been pointed on his misconception.
Huh? Obviously quite the contrary. I do expect very much that the stupid has done something stupid, does something stupid and will do something stupid. You're suggesting that adding software that actually supports his stupidity would help him. Unless we made a damn huge improvement in AI recently, this is obviously nonsense. At any rate, there's no chance that whatever the stupid user is thinking would be suitable for a reasonable definition, or that redefining his stupid behaviour into reasonable usage criteria would be productive in any way.
Sorry, but if you're running with admin rights and then install malware you're hosed and it's simply your fault.
B
Bogwitch
For you to have tested 'Generally every' package available to any reliable depth would take an inordinate amount of time. You are a liar.
Your definition is wrong.
Bollocks. You know full well that it is not priv. escalation that agobot performs. It simply attempts to disable the software.
My definition os not unreasonable.
Ad-ware is not per-se illegitimate, only in your world.
Not if it provides a function not provided by other software.
It is not entirely different. Layered security is a subset of defence-in-depth.
Resorting to personal insults? Quite sad really.
Yes, but where in the thread was that suggested?
Bogwitch.
S
Sebastian G.
No, you're just stupid. Just like no-one has ever tested every toast with jam on the world, you can still reasonably assume that they all fall down with the jam side on the bottom.
What a nonsense. You want to define a problem that doesn't exist from nowhere, blaming it exactly on those who don't consider it as a problem.
If you don't know what you're talking about, please just shut up. Agobot/Gaobot is an open-source malware with literally thousand of available plugins and the trivial possibility to implement your own plugins. I can assure you that there are multiple plugins available for generic privilege escalation for all kinds of driver bugs, including the one mentioned.
We're talking about common ad-ware supported software. This doesn't even nearby fall into alternative-less software. Your claim is very unplausible.
Bullshit. Layered security doesn't provide defence-in-depth, since breaking one layer is sufficient to break the entire system (and that's why you have to avoid adding unnecessary "layers").
By you. You claimed that common stupidities (like not configuring software correctly, consider bullshit/ad-ware as legitimate) should be regarded as basic parts of reasonable definition. According to that, milk is produced like cola and the world was created about 6000 years ago.
B
Bogwitch
Total s**te, irrelevant and wrong.
Please, alternatives != free alternatives. You're changing the goalposts to fit your flawed arguement.
Each layer addresses a particular issue that other layers do not. In this case, it will block communication from software that is otherwise not configurable. Why is that such a difficult concept for you to grasp?
On the one hand your babbling on about unlikely priv. escalation and on the other your talking about running with admin rights. You continue to twist the realities of the situation to provide fuel for your own arguments.
? Oh, I see. Your mental.
Bogwitch.
S
Sebastian G.
Expect that it's a scientific fact, can be well explained with simply newtonian physic and is just another way I'm trying to tell you that you're talking nonsense, and that reasonable assumptions take place instead of your "test every possible implementation" crap shouting.
No, you're just riding on miniscolous details based on simply shortage.
And defense-in-depth is something completely different. Beside that, even your description is flawed: Layered security typically doesn't involve separation of tasks.
Or it won't, because it can't, since it addresses a non-problem at the wrong place.
Because it's utter nonsense. Just like Web 2.0.
Hm? Isn't it exactly you who has now started mixing these things?
I'm mental because I'm exposing how stupid the things are that *you*'re claiming?
B
Bogwitch
It was you that said you had tested '"Every" as in "generally every, there may be some exceptions, but they're rare."' And the vast majority of toast does not fall jam side down. It depends on so many factors as to make your assertation completely flawed. Where are you getting your science? Mythbusters?
A shortage that is addressed by some ad-ware. Yuo may choose not to run such software but you do not control what software other people run as much as you might like to.
Typically doesn't. But does in this case.
But it does. Witnessed by myself and many others.
Apples and oranges. You keep throwing in irrelevancies to support your flailing argument.
No.
No, you're mental for introducing such unrelated concepts in an attempt to obscure your pathetic argument.
Bogwitch.
Join the Discussion
Have something to add? Share your thoughts — no account required.
Didn't find your answer?
Ask the community — no account required
Report Content
You are reporting this content to the moderators. They will look at it
ASAP.