186
top 32 comments
sorted by: hot top controversial new old
[-] Scotty_Trees@lemmy.world 5 points 7 hours ago

The internet would have be believe the 2 AUR attacks this year are EVEN WORSE. Even though it barely affected less than 1% of users. The web is just nothing but constant rage bait, it sucks now =/

[-] XLE@piefed.social 48 points 2 days ago

Better title: "make sure you're on the official website when you're trying to download software, even if you've used it before".

The list includes widely used tools like PowerToys, CrystalDiskMark, EasyBCD, Lively Wallpaper, and Wintoys, all cloned onto lookalike domains that in most cases rank above the real project pages on Google.

Off the top of my head, I wouldn't know the right domain to download CrystalDiskMark or EasyBCD, for example. It doesn't sound like these clones are perfect replicas, but a convincingly close enough domain name with the same page contents might fool a ton of people

[-] grue@lemmy.world 17 points 2 days ago

Off the top of my head, I wouldn’t know the right domain to download CrystalDiskMark or EasyBCD, for example.

The way to find out the correct domain is to go to the Wikipedia page about the software.

But actually, the right way to do it is to install software using your Linux distro's package manager.

[-] IWW4@lemmy.zip 33 points 2 days ago

70??

Those are rookie numbers.

[-] XLE@piefed.social 25 points 2 days ago

That's a load-bearing "plus" there.

[-] 01189998819991197253@infosec.pub 2 points 19 hours ago

Holy shit, when you unpack that mofo there are at least four +s there.

I believe I've seen the face of god, and it is the big 70.

[-] FrostyPolicy@suppo.fi 22 points 2 days ago

Nothing new here. This has been the case forever.

[-] SnotFlickerman 7 points 2 days ago

Yeah, this "similar enough sounding domain name" tactic is far from new, and they must just be using new SEO tricks to get their sites to surface to users, that or illegitimate ad services promoting them.

[-] adespoton@lemmy.ca 2 points 2 days ago

They’re actually usually optimized to get AI to serve you the download link… or in the case of agentic browsers, just find, download and run it for you.

[-] Bishma@discuss.tchncs.de 13 points 2 days ago
[-] Sidyctism2@discuss.tchncs.de 1 points 8 hours ago
[-] m8052@lemmy.world 2 points 7 hours ago

Step 4: Demilitarize

[-] Truscape 8 points 2 days ago

The wikipedia search method to find the official sites has never failed me.

[-] chrash0@lemmy.world 2 points 2 days ago

Windows users get what they deserve here. Windows gave you an app store, and you spat on it. maybe it was a bad implementation, but signed apps exist for a reason.

[-] grue@lemmy.world 14 points 2 days ago

Free Software package managers are good, because having somebody who knows what they're doing curate the apps for you is helpful. "App stores" are evil, because you've replaced that expert with a salesperson with a vested interest in exploiting you.

[-] chrash0@lemmy.world 1 points 2 days ago

again, why do you hate yourself? do you think using Windows and holding it wrong is empowering? i don’t get it.

trust is required somewhere. if you don’t trust Microsoft, why would you use Windows in the first place?

[-] grue@lemmy.world 11 points 2 days ago

I use Linux and have done exclusively for almost a decade, dipshit. Get some reading comprehension skills.

[-] Reygle@lemmy.world 9 points 2 days ago

Boy oh boy, was it ever a bad implementation. Whoooo nelly was (is) that.
I use PPAs in Linux and I stay clear of the AUR. Entire open source projects have added such things to Windows but Microslop still rejects doing it properly themselves. Torches and pitchforks for Redmond one day!

[-] frongt@lemmy.zip 3 points 2 days ago

Winget is the equivalent to AUR

[-] Reygle@lemmy.world 1 points 2 days ago

Wait Winget is a user repository- as-in it's completely unpoliced? Hahah I stand corrected

[-] Sinirlan@lemmy.world 4 points 2 days ago* (last edited 2 days ago)

According to MS there are various validation steps when app is added to repository, including virus checks:

Each submission to the Windows Package Manager Repository is run through several antivirus programs. These programs all have different virus detection algorithms for identifying potentially unwanted applications (PUA) and malware.

https://learn.microsoft.com/en-us/windows/package-manager/package/repository#validation-process

So I guess it's safer to install apps trough winget, at least as much as much You trust Microslop doing good job.

[-] Reygle@lemmy.world 3 points 2 days ago

at least as much as much You trust Microslop doing good job.

In my case that's not at all, but I learned something today, thanks

[-] chrash0@lemmy.world 2 points 2 days ago

why work on a feature that your users categorically reject? this isn’t me projecting, i literally have this conversation with a buddy all the time. he’s a programmer and talks about all the problems with Windows like there aren’t options. use the OS the way the devs designed it, pick a different one, or stfu

[-] Paulemeister@feddit.org 1 points 5 hours ago

Kind of a bad take. "Windows fits my use case best. But it would be even better if the package management was improved." "Stfu, pick a different OS"

[-] frongt@lemmy.zip 6 points 2 days ago

You say that like malware can't be signed

[-] T156@lemmy.world 1 points 18 hours ago

Or that perfectly legitimate software can't be used in nefarious ways. Teamviewer, for example.

[-] chrash0@lemmy.world 1 points 2 days ago

you say that like that makes it not worth doing

[-] Mihies@programming.dev 1 points 2 days ago

It can be, but the certificate would be quickly revoked and signing ones aren't exactly cheap. Also app store does a little bit of app checking I'd say.

[-] chrash0@lemmy.world 1 points 2 days ago

woof these downvotes. Windows users will never stop hating themselves

this post was submitted on 30 Jul 2026
186 points (100.0% liked)

Technology

86760 readers
3545 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 3 years ago
MODERATORS