Do you run programs without valid digital signatures?

Do you run programs without valid digital signatures?

  • No, I only run programs that are digitally signed.

    Votes: 3 15.8%
  • Yes, only if I know they are safe.

    Votes: 13 68.4%
  • Yes, I never pay attention to Windows digital file warnings.

    Votes: 2 10.5%
  • Other (please list)

    Votes: 1 5.3%

  • Total voters
    19

Littlebits

Retired Staff
Thread author
May 3, 2011
3,893
1gr8k7c.png


Do you run programs without valid digital signatures??
 
D

Deleted member 178

yes after i test-ran them in a virtual environment ^^
 

Littlebits

Retired Staff
Thread author
May 3, 2011
3,893
I use a lot of free open-source software and most of them don't have enough funds to digitally sign all of their files but I make sure I get the installers from the developer's site or Softpedia. If I'm in doubt, I will run the installers in Sandboxie and check them with VirusTotal right click menu before installing these to my system.

Thanks. :D
 

Ink

Administrator
Verified
Staff Member
Well-known
Jan 8, 2011
22,361
Yes, only if I know they are safe and if it's something I've downloaded.

Littlebits, you can remove that warning if you unblock it, correct?

XgTQo5H.png
 

Littlebits

Retired Staff
Thread author
May 3, 2011
3,893
Earth said:
Yes, only if I know they are safe and if it's something I've downloaded.

Littlebits, you can remove that warning if you unblock it, correct?

XgTQo5H.png

Yes you can unblock a program and bypass the Windows digital file warnings but UAC will still block it, you will have to approve it.

Of coarse EagleGet setup is a safe program but not digitally signed.

Thanks. :D
 

Littlebits

Retired Staff
Thread author
May 3, 2011
3,893
MalwareCenter said:
Yes, I never pay attention to Windows digital file warnings.

Most users who get infections don't pay attention either.

Usually Windows first line of security is ignored by most users.

Thanks. :D
 

souhrid

Level 5
Jun 29, 2012
226
I depends upon my mood sometimes i take great care and sometimes just ignore it...
 

McLovin

Level 76
Verified
Honorary Member
Malware Hunter
Apr 17, 2011
9,224
I would have to go with MC, I just run the program. :-/
 

MrXidus

Super Moderator (Leave of absence)
Apr 17, 2011
2,503
My personal 3-3 rule. 3 download websites, 3 ways of checking.

I only download programs that are from FileHippo, Softpedia and MajorGeeks. CNET is avoided like the black plague for its CNET adware installer.

Since not all software developers get their software digitally signed I have a few options at hand, Right click VirusTotal option in Windows Explorer, Anubis, Run unknown program inside VM and use a tracer to monitor what the program does. If it appears safe I'll use it on my main OS.

I collect small helpful utilities for my toolkit USB, They are often very small in file size (<1000kb) and don't have valid signatures, By following the 3-3 rule and by using them personally to know they don't do anything fishy. All goes well.

Since I am in Windows 8 the SmartScreen will often pop up for these little utilities but I allow since I know they're safe.

If you see a weakness in my 3-3 rule let me know what and I will certainly do something about it if needed.

Thanks.

2p1BOrP.png

 
 

Overkill

Level 31
Verified
Honorary Member
Feb 15, 2012
2,128
MrXidus said:
Since not all software developers get their software digitally signed I have a few options at hand, Right click VirusTotal option in Windows Explorer, Anubis, Run unknown program inside VM and use a tracer to monitor what the program does. If it appears safe I'll use it on my main OS.

Where can I dl tracer?
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top