SRWare Iron Homepage

Discuss anything related to portable freeware here.
Post Reply
Message
Author
TP109
Posts: 571
Joined: Sat Apr 08, 2006 7:12 pm
Location: Midwestern US

SRWare Iron Homepage

#1 Post by TP109 »

Probably has been discussed before. Anyway, from http://portableapps.com/apps/internet/iron_portable.
Homepage Warning: It is highly recommended you switch to something besides the default Iron homepage. It may contain ads or links to fake adware-containing downloads.
Maybe the download link on TPFC should be be changed or the same warning included? I do need to add a certificate exception for the SRWare homepage at https://www.srware.net/en/software_srware_iron.php.

User avatar
joby_toss
Posts: 2971
Joined: Sat Feb 09, 2008 9:57 am
Location: Romania
Contact:

Re: SRWare Iron Homepage

#2 Post by joby_toss »

I don't understand... so, the homepage is evil, but the app is not?

Image

TP109
Posts: 571
Joined: Sat Apr 08, 2006 7:12 pm
Location: Midwestern US

Re: SRWare Iron Homepage

#3 Post by TP109 »

I'm not sure. Why the warning on Portableapps? Also, it's possible Portableapps has made some mods, since users use another link to download. Why the precautions? I'm not making any judgements, just pointing this out. Anyway, WOT gives the SRIron site an excellent rating, so it's kind of confusing.

User avatar
SYSTEM
Posts: 2043
Joined: Sat Jul 31, 2010 1:19 am
Location: Helsinki, Finland

Re: SRWare Iron Homepage

#4 Post by SYSTEM »

The warning on PortableApps.com is about the default homepage of SRWare Iron, http://iron-start.com/, not about the download page. I copied the warning, with slightly different wording, to the entry.
joby_toss wrote:I don't understand... so, the homepage is evil, but the app is not?
The download page is not "evil". Srware.net only has an outdated TLS certificate, which means (with some simplifying) that the browser can't guarantee that it's actually connecting to the right website. The browser is not 100 % sure that a man-in-the-middle attack such as DNS spoofing isn't going on. No reason to panic: it's the same situation as with regular HTTP sites, as HTTP doesn't have endpoint authentication. Most of the time, the website is correct even when there are authentication problems. However, web browsers give these scary warnings when a website can't be authenticated because it might be an important site such as a bank. If the warnings were less scary, clueless users would just add security exceptions when they are, in fact, being attacked.
TP109 wrote:Also, it's possible Portableapps has made some mods, since users use another link to download.
Yes, PortableApps.com does "modify" programs. It bundles them with the PortableApps.com Launcher which portablizes them.
My YouTube channel | Release date of my 13th playlist: August 24, 2020

TP109
Posts: 571
Joined: Sat Apr 08, 2006 7:12 pm
Location: Midwestern US

Re: SRWare Iron Homepage

#5 Post by TP109 »

SYSTEM wrote: Yes, PortableApps.com does "modify" programs. It bundles them with the PortableApps.com Launcher which portablizes them.
I meant modify as for the default homepage settings or for eliminating malware. The portableapps.com page does state "ads and fake adware-containing downloads." If the home page is infected, possibly the the app itself could also be infected? Anyway, that statement combined with the certificate warning was suspicious. In any case, adding the warning to the entry is a good precaution even if it there really isn't anything to worry about.

User avatar
JohnTHaller
Posts: 716
Joined: Wed Feb 10, 2010 4:44 pm
Location: New York, NY
Contact:

Re: SRWare Iron Homepage

#6 Post by JohnTHaller »

Last I checked, the iron-start page routinely showed ads with fake 'download' buttons that are designed just to download rather nasty stuff. I added that note to let users know about it. We also have notes for apps where the local versions or the publisher's own 'portable installer' have particularly tricky bundleware that is either difficult not to install or will install even when you select not to install. Only DVD Styler has fallen afoul of the latter and it was corrected a few versions after it happened. It doesn't affect our packaged versions, of course, but sometimes a user will go and install a local version of a given app after seeing it on our site.

As a general rule, we don't modify app settings except as they affect portability and performance from flash media (though the latter is less likely now that more and more of our users use our apps locally). Homepage settings in an app are usually how the publisher makes money. Many times, we are contractually obligated to leave these unchanged (Firefox, Opera, etc). Other times, we could easily change them for our packaged versions but we leave them as is so the developer continues making money to fund development (Iron, QupZilla, etc).
PortableApps.com - The open standard for portable software | Support Net Neutrality

TP109
Posts: 571
Joined: Sat Apr 08, 2006 7:12 pm
Location: Midwestern US

Re: SRWare Iron Homepage

#7 Post by TP109 »

JohnTHaller wrote:Last I checked, the iron-start page routinely showed ads with fake 'download' buttons that are designed just to download rather nasty stuff....
Rather scary scenario. Good to know that this stuff doesn't go on unchecked. I downloaded the portableapps.com version of SRWare Iron after becoming suspicious.

User avatar
Midas
Posts: 6726
Joined: Mon Dec 07, 2009 7:09 am
Location: Sol3

Re: SRWare Iron Homepage

#8 Post by Midas »

JohnTHaller wrote:Last I checked, the iron-start page routinely showed ads with fake 'download' buttons that are designed just to download rather nasty stuff.
  • The way I see it, with very few exceptions, most one-click file hosters display similar adds right along their downloads nowadays, making a good adblocker a must have. :!:

    What's particularly unfortunate in Iron's case is this coupling with the certificate issue, which screams malware from the get go...

    Iron's prestige with the vocal majority of the net literati crowd never really amounted to anything -- this episode sure won't help it. :?

Post Reply