The internet would have be believe the 2 AUR attacks this year are EVEN WORSE. Even though it barely affected less than 1% of users. The web is just nothing but constant rage bait, it sucks now =/
Better title: "make sure you're on the official website when you're trying to download software, even if you've used it before".
The list includes widely used tools like PowerToys, CrystalDiskMark, EasyBCD, Lively Wallpaper, and Wintoys, all cloned onto lookalike domains that in most cases rank above the real project pages on Google.
Off the top of my head, I wouldn't know the right domain to download CrystalDiskMark or EasyBCD, for example. It doesn't sound like these clones are perfect replicas, but a convincingly close enough domain name with the same page contents might fool a ton of people
Off the top of my head, I wouldn’t know the right domain to download CrystalDiskMark or EasyBCD, for example.
The way to find out the correct domain is to go to the Wikipedia page about the software.
But actually, the right way to do it is to install software using your Linux distro's package manager.
70??
Those are rookie numbers.
That's a load-bearing "plus" there.
70++
70#
Holy shit, when you unpack that mofo there are at least four +s there.
I believe I've seen the face of god, and it is the big 70.
Nothing new here. This has been the case forever.
Yeah, this "similar enough sounding domain name" tactic is far from new, and they must just be using new SEO tricks to get their sites to surface to users, that or illegitimate ad services promoting them.
They’re actually usually optimized to get AI to serve you the download link… or in the case of agentic browsers, just find, download and run it for you.
Step 1: Degoogle
Step 2: Demicrosoft
Step 3: Demi Lovato
Step 4: Demilitarize
The wikipedia search method to find the official sites has never failed me.
Windows users get what they deserve here. Windows gave you an app store, and you spat on it. maybe it was a bad implementation, but signed apps exist for a reason.
Free Software package managers are good, because having somebody who knows what they're doing curate the apps for you is helpful. "App stores" are evil, because you've replaced that expert with a salesperson with a vested interest in exploiting you.
again, why do you hate yourself? do you think using Windows and holding it wrong is empowering? i don’t get it.
trust is required somewhere. if you don’t trust Microsoft, why would you use Windows in the first place?
I use Linux and have done exclusively for almost a decade, dipshit. Get some reading comprehension skills.
Boy oh boy, was it ever a bad implementation. Whoooo nelly was (is) that.
I use PPAs in Linux and I stay clear of the AUR. Entire open source projects have added such things to Windows but Microslop still rejects doing it properly themselves. Torches and pitchforks for Redmond one day!
Winget is the equivalent to AUR
Wait Winget is a user repository- as-in it's completely unpoliced? Hahah I stand corrected
According to MS there are various validation steps when app is added to repository, including virus checks:
Each submission to the Windows Package Manager Repository is run through several antivirus programs. These programs all have different virus detection algorithms for identifying potentially unwanted applications (PUA) and malware.
https://learn.microsoft.com/en-us/windows/package-manager/package/repository#validation-process
So I guess it's safer to install apps trough winget, at least as much as much You trust Microslop doing good job.
at least as much as much You trust Microslop doing good job.
In my case that's not at all, but I learned something today, thanks
why work on a feature that your users categorically reject? this isn’t me projecting, i literally have this conversation with a buddy all the time. he’s a programmer and talks about all the problems with Windows like there aren’t options. use the OS the way the devs designed it, pick a different one, or stfu
Kind of a bad take. "Windows fits my use case best. But it would be even better if the package management was improved." "Stfu, pick a different OS"
You say that like malware can't be signed
Or that perfectly legitimate software can't be used in nefarious ways. Teamviewer, for example.
you say that like that makes it not worth doing
It can be, but the certificate would be quickly revoked and signing ones aren't exactly cheap. Also app store does a little bit of app checking I'd say.
woof these downvotes. Windows users will never stop hating themselves
Technology
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related news or articles.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.