{"id":323,"date":"2008-07-09T13:38:00","date_gmt":"2008-07-09T17:38:00","guid":{"rendered":"http:\/\/www.contrapositivediary.com\/?p=323"},"modified":"2009-01-14T17:53:26","modified_gmt":"2009-01-14T21:53:26","slug":"the-conundrum-of-avg-linkscanner","status":"publish","type":"post","link":"http:\/\/www.contrapositivediary.com\/?p=323","title":{"rendered":"The Conundrum of AVG LinkScanner"},"content":{"rendered":"<p>Just before we left Colorado, and after several weeks of furious               nagging by the software, I upgraded version 7.5 of AVG Free Anti-Virus               for the new V8. I did it on Carol&apos;s machine only, as the upgrade               required some damned thing or another that was missing on Win2K               SP4, and I didn&apos;t have time to research it. (Carol uses XP.) With               version 8 came something I had not heard about and did not expect:               AVG LinkScanner.<\/p>\n<p>It&apos;s an interesting idea, and at first glance sounds like something               truly useful: LinkScanner works with Google and Yahoo to prescan               search results for evidence of malware injection. At a rate of 2-20               results per second, LinkScanner visits each displayed search result               link, looks at what&apos;s on the other side, and displays one of three               icons to the right of the search link: Good, questionable, or bad.               I didn&apos;t even know the feature was present until later that day,               when Carol was doing some Google work and asked me what the icons               were. All were a reassuring green, but when I Googled on &#8220;warez&#8221;               almost all of the search results came back with icons of alarming               red.<\/p>\n<p>This seemed reasonable to me, and I was too frantic getting ready               for our trip to think too deeply on it. But a few days later, I               started to run across Web articles <a href=\"http:\/\/www.avg-watch.org\/\">howling               about an avalanche of Web hits spawned by LinkScanner<\/a>. The Register               provides <a href=\"http:\/\/www.theregister.co.uk\/2008\/06\/13\/avg_scanner_skews_web_traffic_numbers\/\">one               of the saner descriptions of the issue<\/a>. Traffic on some smaller               Web sites has spiked by 80%, and Slashdot says that as much as 6%               of its massive clickthrough comes from LinkScanner&apos;s user agents.<\/p>\n<p>LinkScanner, it seems, tries its best to look like an ordinary               user. Well, duhh: If LinkScanner&apos;s probe announced its presence,               malware artists would serve up an innocuous version of their sites,               keeping the malware for ordinary Web surfers who could be discerned               as such. I can understand the logic, but given that AVG has as many               as seventy million users worldwide (few of whom have yet upgraded)               widespread adoption of the technology could make ordinary Web traffic               analysis meaningless. Traffic on duntemann.com started rising about               April 1, but I couldn&apos;t quite figure what was going on. May was               a record month for me, even though my traffic has been fairly steady               since I launched <a href=\"http:\/\/jeff-duntemann.livejournal.com\/\">my               LiveJournal mirror of Contra<\/a> in early 2006. Things leveled out               in June, but given the proportion of my traffic that now reads Contra               on LiveJournal, I would expect aggregate traffic on duntemann.com               to be falling slowly.<\/p>\n<p>Having had a little time to think about this, I can raise a couple               of points:<\/p>\n<ul>\n<li>AVG has not made it entirely clear what its probe looks for                 when it prefetches search results. A site tagged as &#8220;safe&#8221;                 might not actually <i>be<\/i> safe\u2014especially once the bad                 guys reverse-engineer the probe and figure out how to dodge it.                 People might trust the utility a little too much, and assume that                 there is no possible downside to visiting a green-tagged site.<\/li>\n<li>Obviously, AVG actually visits all sites in a search results                 list, even those most users would shun as obviously dicey. If                 the bad guys discover an exploit in AVG&apos;s probe, AVG could unwittingly                 become the world&apos;s largest malware installer.<\/li>\n<li>The probe does not mask or alter the user IP in any way. As                 far as remote site logs are concerned, <i>the local user clicks                 on every link in a search results list<\/i>. Meditate on that for                 a moment, and then read <a href=\"http:\/\/yro.slashdot.org\/article.pl?sid=08\/03\/20\/2323247\">this                 article from Slashdot<\/a>. If you&apos;re not at least a little freaked                 out yet, read it again.<\/li>\n<\/ul>\n<p>I&apos;m going to uninstall the feature on Carol&apos;s machine when we get               home, and may try one of the alternative lightweight AV products               like <a href=\"http:\/\/www.avast.com\/eng\/download-avast-home.html\">Avast<\/a>,               especially since AVG Free V8.0 barfed on my main Win2K machine.<\/p>\n<p>I&apos;ve begun to see indications that AVG is patching V8.0 so that               LinkScanner is not enabled by default, but haven&apos;t gotten anything               crisp enough to link to. Supposedly, the patched version becomes               available today. We&apos;ll see. In the meantime, spidering sites with               some sort of malware-detection probe may not be as good an idea               as it seems on the surface. Better, perhaps to completely sandbox               or virtualize the browser, which would be better protection at a               bandwidth cost of&#8230;zero.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Just before we left Colorado, and after several weeks of furious nagging by the software, I upgraded version 7.5 of AVG Free Anti-Virus for the new V8. I did it on Carol&apos;s machine only, as the upgrade required some damned thing or another that was missing on Win2K SP4, and I didn&apos;t have time to [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[27],"tags":[],"class_list":["post-323","post","type-post","status-publish","format-standard","hentry","category-reviews"],"_links":{"self":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts\/323","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=323"}],"version-history":[{"count":1,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts\/323\/revisions"}],"predecessor-version":[{"id":337,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=\/wp\/v2\/posts\/323\/revisions\/337"}],"wp:attachment":[{"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=323"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=323"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.contrapositivediary.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=323"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}