Results 1 to 14 of 14

Thread: The Story Behind the OpenCandy Adware Debacle

  1. #1
    Registered User Hawk-NGO's Avatar
    Join Date
    Apr 2010
    Posts
    63

    The Story Behind the OpenCandy Adware Debacle

    Remember the story of ESET and Microsoft OpenCandy mass false positive alerts we published a few days ago? OpenCandy's CEO has made the following statement: "I’d like to take a moment to update our partners, consumers and other interested parties on a situation that has consumed the vast majority of our small company’s attention lately.

    A few weeks ago, on February 12, the Microsoft Malware Protection Center (MMPC) classified OpenCandy’s software as “Low (threat level) Adware.” This prompted Microsoft security products (such as Microsoft Security Essentials and Windows Defender) to alert consumers downloading any of the hundreds of high-quality, trusted applications that use OpenCandy to make software recommendations in their installers.

    We believe we have identified the cause of this misunderstanding and taken action to resolve it, so it should not affect any new OpenCandy software distribution going forward. However, there still remains an issue that Microsoft is falsely alerting potentially hundreds of millions of consumers (who have downloaded or are downloading, previous versions of OpenCandy software)."
    Read more: http://www.ngohq.com/news/19519-the-...e-debacle.html

  2. #2
    c[_]
    Join Date
    Nov 2002
    Location
    Alberta, Canada
    Posts
    18,728
    Despite the lack of clarity or direction from the MMPC, our team worked day and night to decode the nuances of the policies and procedures we were presented with and in time isolated what we believe to be the source of the issue. Namely, one individual OpenCandy partner (out of hundreds) appears to have been mistakenly missing an End User License Agreement (EULA) in their installer. This means that any consumer installing this specific partner’s software did not agree to OpenCandy’s transmission and collection of anonymous information (used for purposes of making a software recommendation).

    Ok, a mistake. A mistake on the part of our partner and a mistake by us for not having the right process in place to catch that the EULA had been removed after it had passed our compliance process. The partner has since added their EULA.

    So, why would a missing EULA cause such a ruckus? We asked MMPC and ourselves the same, and we believe it may be linked to one of our software features that enables us to place and access an OpenCandy specific “cookie” (unique, non-personally identifiable registry entry) on a consumer’s machine. In reality, we’ve never used this “cookie” feature but the intent behind building it in was to lower the chances that a recommendation previously declined would be shown again. We believe that MMPC was concerned with the possibility of utilizing a cookie that may have been placed without consent during the install of that specific partner’s software that was missing a EULA.

    Note to self: dont install opencandy software. Cant be very anonymous or unique if they're sending YOU software recommendations and calling a registry setting a cookie.
    Last edited by STEvil; 03-05-2011 at 05:14 PM.

    All along the watchtower the watchmen watch the eternal return.

  3. #3
    Xtreme Member
    Join Date
    Jun 2005
    Posts
    442
    Microsoft didn't make the mistake. It's OpenCandy who made the mistake by collecting personal information and placing a cookie designed for selling stuff.

    Good job Microsoft. Makes me glad I've got MSE on my computer.
    PII 965BE @ 3.8Ghz /|\ TRUE 120 w/ Scythe Gentle Typhoon 120mm fan /|\ XFX HD 5870 /|\ 4GB G.Skill 1600mhz DDR3 /|\ Gigabyte 790GPT-UD3H /|\ Two lovely 24" monitors (1920x1200) /|\ and a nice leather chair.

  4. #4
    Registered User Hawk-NGO's Avatar
    Join Date
    Apr 2010
    Posts
    63
    Dont forgot.. software developers need to eat too. :P

  5. #5
    c[_]
    Join Date
    Nov 2002
    Location
    Alberta, Canada
    Posts
    18,728
    Quote Originally Posted by Hawk-NGO View Post
    Dont forgot.. software developers need to eat too. :P
    Then make software people will buy

    All along the watchtower the watchmen watch the eternal return.

  6. #6
    Xtreme Member
    Join Date
    Jun 2005
    Posts
    442
    Quote Originally Posted by Hawk-NGO View Post
    Dont forgot.. software developers need to eat too. :P
    Couldn't agree more. Shady tactics = empty plates.
    PII 965BE @ 3.8Ghz /|\ TRUE 120 w/ Scythe Gentle Typhoon 120mm fan /|\ XFX HD 5870 /|\ 4GB G.Skill 1600mhz DDR3 /|\ Gigabyte 790GPT-UD3H /|\ Two lovely 24" monitors (1920x1200) /|\ and a nice leather chair.

  7. #7
    Xtreme Enthusiast
    Join Date
    Sep 2006
    Location
    Nordschleife!
    Posts
    705
    Don't this rule apply in this thread?

    4. We do not permit advertising of any kind.
    This includes offering items for sale or trade (other than in the Classifieds). Posting to your homepage, an eBay URL, a URL to another site, or announcements of new sites. This applies equally to commercial and private sites/ads. This is also not to happen within user signatures. Links to deals available online are to be posted only in Online Deals & Sales. The only allowed links in a signature will be links directly related to XtremeSystems, Xtreme D2OL, Xtreme Folding@Home and XtremeSystems affiliated website or organization. If you wish to link to your site, you may do so in your usercp which links in every post you make.
    Murray Walker: "And there are flames coming from the back of Prost's McLaren as he enters the Swimming Pool."

    James Hunt: "Well, that should put them out then."

  8. #8
    XS - Extra Strong
    Join Date
    Aug 2003
    Location
    Toronto, Canada
    Posts
    2,070
    Quote Originally Posted by Caparroz View Post
    Don't this rule apply in this thread?
    Considering that the suggestion is not to buy the product, its kind of hard to draw the conclusion that the op is trying to advertise something...
    -Phenom2 x6 1055 @stock
    -8gb ddr3
    -Gigabyte UD3
    -Geforce 7900Gt 755/1863 1.562v vgpu
    -OCZ Powersupply 600w

  9. #9
    Xtreme Addict
    Join Date
    Apr 2007
    Posts
    2,128
    Quote Originally Posted by lalPOOO View Post
    Considering that the suggestion is not to buy the product, its kind of hard to draw the conclusion that the op is trying to advertise something...
    I think it has more to do with linking to ngohq, with which I myself see no problem with though.

  10. #10
    Xtreme Member
    Join Date
    Jun 2005
    Posts
    442
    Quote Originally Posted by lalPOOO View Post
    Considering that the suggestion is not to buy the product, its kind of hard to draw the conclusion that the op is trying to advertise something...
    Look at his name and the site he linked, then read the rule.

    It's a gray area.
    PII 965BE @ 3.8Ghz /|\ TRUE 120 w/ Scythe Gentle Typhoon 120mm fan /|\ XFX HD 5870 /|\ 4GB G.Skill 1600mhz DDR3 /|\ Gigabyte 790GPT-UD3H /|\ Two lovely 24" monitors (1920x1200) /|\ and a nice leather chair.

  11. #11
    Xtreme Addict
    Join Date
    Aug 2005
    Location
    Germany
    Posts
    2,247
    Quote Originally Posted by Mad Pistol View Post
    Look at his name and the site he linked, then read the rule.

    It's a gray area.
    i don't see what's wrong about it. others are doing this all the time as well, no matter if they're posting news, reviews or whatever.

    there has to be a source. if the source is the OP himself - well, fine?!
    1. Asus P5Q-E / Intel Core 2 Quad Q9550 @~3612 MHz (8,5x425) / 2x2GB OCZ Platinum XTC (PC2-8000U, CL5) / EVGA GeForce GTX 570 / Crucial M4 128GB, WD Caviar Blue 640GB, WD Caviar SE16 320GB, WD Caviar SE 160GB / be quiet! Dark Power Pro P7 550W / Thermaltake Tsunami VA3000BWA / LG L227WT / Teufel Concept E Magnum 5.1 // SysProfile


    2. Asus A8N-SLI / AMD Athlon 64 4000+ @~2640 MHz (12x220) / 1024 MB Corsair CMX TwinX 3200C2, 2.5-3-3-6 1T / Club3D GeForce 7800GT @463/1120 MHz / Crucial M4 64GB, Hitachi Deskstar 40GB / be quiet! Blackline P5 470W

  12. #12
    Xtreme Enthusiast
    Join Date
    Sep 2006
    Location
    Nordschleife!
    Posts
    705
    Quote Originally Posted by lalPOOO View Post
    Considering that the suggestion is not to buy the product, its kind of hard to draw the conclusion that the op is trying to advertise something...
    Quote Originally Posted by RaZz! View Post
    i don't see what's wrong about it. others are doing this all the time as well, no matter if they're posting news, reviews or whatever.

    there has to be a source. if the source is the OP himself - well, fine?!
    Maybe I was a bit vague but looking at his/her (brief) post history all he/she does is post links to the ngohq website...
    Murray Walker: "And there are flames coming from the back of Prost's McLaren as he enters the Swimming Pool."

    James Hunt: "Well, that should put them out then."

  13. #13
    YouTube Addict
    Join Date
    Aug 2005
    Location
    Klaatu barada nikto
    Posts
    17,574
    Quote Originally Posted by STEvil View Post
    Note to self: dont install opencandy software. Cant be very anonymous or unique if they're sending YOU software recommendations and calling a registry setting a cookie.
    Here is a far better idea, don't install software unless you have the source code.
    Fast computers breed slow, lazy programmers
    The price of reliability is the pursuit of the utmost simplicity. It is a price which the very rich find most hard to pay.
    http://www.lighterra.com/papers/modernmicroprocessors/
    Modern Ram, makes an old overclocker miss BH-5 and the fun it was

  14. #14
    Xtreme Member
    Join Date
    May 2005
    Posts
    196
    This seems pretty mild, have you guys seen all the permissions that are granted to Android apps?
    i5 750 @ 4.2ghz
    EVGA P55 FTW
    8gig G.Skill Ripjaw @ 1055mhz
    Gigabyte 6950 modded
    Seasonic X-650
    Antec P180 modded and watercooled
    Thermochill PA160
    Apogee XT
    MCP350

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •