Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Try again. The page has been updated with a direct link (CDN).

Here is the direct link to executable just in case. [1]

[1] - http://download.windowsupdate.com/c/msdownload/update/softwa...



Then it turns out parent is the ransomware vendor and the linked file turns out to contain the ransomware, with a few letters in the URL substituted for Unicode lookalikes so it appears to be a legitimate Windows update.

I'm not saying that's truly what's happening, but it's easy to imagine. I'd verify I'm connecting to the right domain and double-check with e.g. VirusTotal if I were you.


It doesn't take voodoo to figure out if something is ascii or not.



What's your point? If I put the non-punycode version in my ascii checker it immediately tells me it isn't ascii.

Having to check because registrars are dumb has nothing to do with the fact that doing the check is easy.


That's very true. Such attacks are predicated on an ignorant and/or lazy target demographic, I guess.

Incidentally, when I copied the link out of Chrome (57) it pasted the punycode link even though it showed "apple.com" in the omnibox. So then I carefully copy-pasted just the domain and TLD to work around Chrome's link-copying magic, submitted, and... discovered that Arc punycode-ifies Unicode domains.

So that was interesting, but it kind of killed the impact of the point I was making.


It doesn't, but you do have to do a manual check and remember to do that.


Wait - a critical security update distributed via plain HTTP instead of HTTPS...? I checked all the links provided for my computers, too - they're all http://


Probably because some windows xp boxes can't connect to https servers running TLS 1.2 so the patches are available under http as well.


No issue as long as the updates are properly signed. Distributing updates via HTTP/FTP is normal in Linux land.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: