TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Ask HN: I'm a pro; still harmed by CCleaner's malware. What could I have done?

11 点作者 oferzelig超过 7 年前
Frustrating.<p>I&#x27;m a pro user (or at least that&#x27;s how I consider myself, unless I suffer from the Imposter Syndrome).<p>I don&#x27;t click links just because. I just don&#x27;t. Not once in a million, not by mistake. I just don&#x27;t.<p>I don&#x27;t install software that comes from an &quot;Unknown Publisher&quot;, even if I have to have it. I just don&#x27;t.<p>I use CCleaner for a long time, as it&#x27;s considered trusted, reliable and crap-free.<p>I did install the dodgy CCleaner 5.33. It was digitally signed by Piriform: https:&#x2F;&#x2F;i.imgur.com&#x2F;GlDiEJM.png<p>And yet, it contains malware that was injected to the build process, thus got it to be as part of the &quot;normal&quot; program files and signed.<p>The trust model has broken.<p>What could I have done differently?

7 条评论

bob33212超过 7 年前
There was not much you could have done. Personally I never used CCCleaner even though folks on my team did. I just didn&#x27;t have a use for it because I wanted to make sure I understood chrome&#x27;s caching logic. SO maybe I am slightly more &quot;Pro&quot; than you. But I install lots of software that could have had their deployment process hacked without me knowing.
TurboHaskal超过 7 年前
Think twice before installing a new application. Try to use the OS default applications as much as you can tolerate them.<p>I don&#x27;t think you need CCleaner in 2017.<p>Recommended reading: <a href="https:&#x2F;&#x2F;usesthis.com&#x2F;interviews&#x2F;marius.eriksen&#x2F;" rel="nofollow">https:&#x2F;&#x2F;usesthis.com&#x2F;interviews&#x2F;marius.eriksen&#x2F;</a>
peruvian超过 7 年前
It&#x27;s not like CCleaner was out to get you - they got hacked. It&#x27;s like if your bank got hacked and your stuff got stolen. The bank didn&#x27;t trick you.<p>What should you do now? Never update an app automatically. Wait at least a day and see if there are any issues.
评论 #15289140 未加载
codegladiator超过 7 年前
Think twice before installing a &quot;Anti- (virus&#x2F;malware)&quot; software. I havent installed one in either windows&#x2F;linux&#x2F;mac for the last 10 years ( because norton&#x2F;mcafee&#x2F;avg and others used to mess up the speed ).<p>- use ad blocker<p>- dont auto update
senoraptget超过 7 年前
Don&#x27;t do all tasks on one computer. Computers dropped in price so there&#x27;s no reason to do that.<p>You can use a livecd for surfing the web. The web is one of the biggest sources of badware.
thiagooffm超过 7 年前
not using CCleaner would be a start.<p>pay attention to the version of what you are using and avoid using things on auto-update or on a version which haven&#x27;t been battleproof.<p>use linux and check the source code of everything you run... but it&#x27;s a lot of work<p>so basically I don&#x27;t think you could&#x27;ve done much, nor most of the people can unless you would accept living in a very walled and time-consuming computer setup
评论 #15283514 未加载
romanovcode超过 7 年前
I don&#x27;t get how can you be a pro yet use this kind of crapware.