Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

Linux is obsolete (Andrew Tanenbaum)


computers / alt.windows7.general / The Dollar Inspired B.S. For Trashing Sandboxes Never Ends

SubjectAuthor
o The Dollar Inspired B.S. For Trashing Sandboxes Never EndsNomen Nescio

1
The Dollar Inspired B.S. For Trashing Sandboxes Never Ends

<9a4527c9936f0314b394403afe7d9e3a@dizum.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=5309&group=alt.windows7.general#5309

  copy link   Newsgroups: alt.windows7.general
From: nob...@dizum.com (Nomen Nescio)
Subject: The Dollar Inspired B.S. For Trashing Sandboxes Never Ends
Message-ID: <9a4527c9936f0314b394403afe7d9e3a@dizum.com>
Date: Fri, 11 Nov 2022 02:32:35 +0100 (CET)
Newsgroups: alt.windows7.general
Path: i2pn2.org!i2pn.org!aioe.org!news.mixmin.net!news2.arglkargh.de!sewer!news.dizum.net!not-for-mail
Organization: dizum.com - The Internet Problem Provider
X-Abuse: abuse@dizum.com
Injection-Info: sewer.dizum.com - 2001::1/128
 by: Nomen Nescio - Fri, 11 Nov 2022 01:32 UTC

https://www.forbes.com/sites/forbestechcouncil/2022/03/16/does-sandboxing-have-a-future/?sh=b92b8e87d971

"Sandboxes don�t always work. Sophisticated cyberattacks are known to
detect and evade sandboxing. Even some known and outdated malware
attacks have evolved and reemerged with variants that can circumvent
sandboxing techniques. For instance, a variant of the Emotet malware
masks its file type with a .doc extension. Since sandboxing relies on
true filetypes, it doesn�t consider it an executable and opens it in a
Word document instead."

Are they serious? Sandboxing does not rely on file types to accept
them. On a home computer it's you who must download that file, reboot
without the sandbox starting up with Windows, and then open that file.
If you have not checked the file through VirusTotal, lots of luck. Can
the file still be a bummer, possibly. But the sandbox wasn't
responsible for saving and opening that file. You were.

Yes, to download files to save, use, you have to still use that Safe
Hex stuff. Do a system restore. Do a registry save with a program like
Erunt. And, if you even half suspect there might still be problem, use
a backup program to backup you C: system with all files. My freebie
AOMEI does that in about 15 minutes or so.

If you're too undisciplined and/or lazy to do this, have fun spending
a week or two on Usenet trying to find some software guru to solve the
reason for your busted Windows OS.

Discipline. Period. (And that I find much easier to do than put up
with than all the phoney alerts and real problems caused by using some
costly/worthless AV p.o.s.)

"Modern malware also analyzes the hardware, installed applications,
network connectivity, patterns of mouse clicks and open and saved
files to gauge if it�s in a sandbox environment. The malware will
delay execution if it detects a sandbox. Result? Security analysts
won�t find any malicious file behavior and will deem the malware-laden
files safe."

Bullshite! I've already covered that one more than once.

"Sandboxes are typically useless against phishing attacks that involve
files with no apparent malicious behavior. For instance, a simple PDF
file may contain a link to a phishing site or a fake sign-in form. A
sandbox will not flag the file because it doesn�t exhibit any
malicious activity, and sandboxing doesn�t address malicious intent."

Oh, get real!

Why in world would you download a PDF you never asked for from someone
you've never heard of? And again, a sandbox, or Time Freeze, on a home
computer doesn't "flag" anything by assigning some label as White Hate
or Black Hat or anything else. It does nothing. YOU are the one who
has to download it outside the sandbox and later install it/read it
outside the sandbox.

Oh, yeah, Forbes may not be selling a "Security Suite" of their own,
but they damn well make their dollars off those who do through getting
the advertising dollars from such companies. Like all anti sandbox
sites, they, too, eat off the revenue generated by all these so-called
Security Suites/Sites.

All the other "threats" portrayed by these sites pertain to company
sites which have a much different set of problems than do users with
personal home computers. Ain't the same ballgame.

You can't beat a good sandbox for safety. The real enemy of computer
security is yourself.

1
server_pubkey.txt

rocksolid light 0.9.8
clearnet tor