BlackFog Privacy

Discussion in 'other anti-malware software' started by liba, Feb 2, 2018.

  1. Krusty

    Krusty Registered Member

    Joined:
    Feb 3, 2012
    Posts:
    10,239
    Location:
    Among the gum trees
    It looks like we're up to 4.2.3 already
     
  2. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Yes small change for a very specific set of customers running legacy 32 bit system apps on a 64 bit machine.
     
  3. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Yes, my client updated 3 hrs 20 mins later (South Africa).
     
  4. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    so you have the geofencing in blackfog and that's great
    but could you add information in events tab (recent blocks) of what country has been blocked, should be easy enough tweak to add 1 column with country info
    this way I don't have to turn off geofencing alltoghter to visit a particular website and compromise security in that layer
     
  5. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @lucd We do provide that in the actual Event itself, the button on the Events section. I assume you mean the one on that page with the icons?
     
  6. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    @Darren , Could you explain exactly what the execution tab does when enabled. Does this block the execution of malware in the system etc (fileless malware for instance) Under what circumstances should it be enabled and disabled for instance. I assume this would not block the activation of an .exe from the desktop.
     
  7. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Great question @DarkStar. So the execution option provides a new technique for preventing malware execution. The old technique used a fairly draconian whitelisting approach, which while effective, tended to cause more trouble than it was worth for legitimate applications. Unfortunately, not everyone follows the rules when it comes to development and a lot fo apps (including those from MS) used these reserved locations to execute files. This meant you had to whitelist a lot of apps and it was simply too much effort for the average user.

    So we eliminated this in favor of process monitoring and application validation generally. This is a behavioral technique for detecting malicious activity. The concept is that malware masquerades as other applications, or spawns from system processes to attack the user. In these scenarios we introspect all the processes to see if they are being hijacked, replicated or simply spoofed. Now like the networking rules, this is done in real-time as well. The infrastructure was all part of the 4.0 release but we delayed implementation to ensure the core functions were stable and then added it into the 4.2 release.

    Ultimately this will lead to less false positives and ensure more accurate protection than the previous technique as well and we are continuing to add more functionality to this switch in 4.3 which we expect to release before Christmas.
     
  8. Dark Star 72

    Dark Star 72 Registered Member

    Joined:
    May 27, 2007
    Posts:
    778
    Many thanks Darren, that's exactly what I wanted to know.
     
  9. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    FYI, just noticed that post 4.3 yesterday, I did have the following threat detections - in short succession ...
    but must say I can't remember what I did to prompt these, nor did I notice any Windows notifications, nor any ill-effect:

    Attempted illegal process execution: explorer.exe (PID:8524) Parent: winlogon.exe (PID:1300)
    Attempted illegal process execution: explorer.exe (PID:19320) Parent: taskhostw.exe (PID:19576)
    Attempted illegal process execution: explorer.exe (PID:14472) Parent: taskmgr.exe (PID:20392)
     
  10. lucd

    lucd Registered Member

    Joined:
    Jan 30, 2018
    Posts:
    782
    Location:
    Island of Woman
    I think you can achieve better results with better GUI management to make specific country visible directly in the events section (whithout clicking the second events button) by adding a 5th column, e.g. 1) Date 2) Hostname 3) Process, 4) Port 5) Country (new column), there is too much noise (from privacy clean) in the second (last) events button in my opinion, or add some filters to the second events button, to filter out geofencing
    the second button event section cannot be checked against the first event button, because there are spammy privacy clean events and other junk...
    not a big problem but please take it into consideration so I or some other user don't waste precious time
    best
     

    Attached Files:

    Last edited: Dec 18, 2019
  11. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Good feedback @lucd we will look at that for the roadmap.

    @paulderdash We will be removing that message in the next release. These are just transient spawns of explorer by the system.
     
    Last edited: Dec 18, 2019
  12. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    :thumb: Due to the new behavioural technique, no doubt - thanks for clarifying.
     
  13. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We have a beta of 4.3 available later today with changes to the events if anyone wants to try it. We have enlarged the area, provided excel export and new filters for the events. PM me and I can provide the link to try it.
     
  14. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We have now released 4.3 with a number of changes related to events filtering and optimized messaging and performance across the board. Please see our web site for the release notes here: https://www.blackfog.com/changelog-privacy-win/
     
  15. Antarctica

    Antarctica Registered Member

    Joined:
    Feb 25, 2003
    Posts:
    2,180
    Location:
    Canada
    Thank you Darren and Merry Christmas!
     
  16. paulderdash

    paulderdash Registered Member

    Joined:
    Dec 27, 2013
    Posts:
    4,644
    Location:
    Under a bushel ...
    Updated to 4.3 (b475) overnight here. :thumb:
     
  17. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    Thanks and Merry Christmas to all.
     
  18. X9X

    X9X Registered Member

    Joined:
    Apr 8, 2019
    Posts:
    32
    Location:
    Europe
    Looks like iOS version was updated to 4.0.0.

    What features work if i don't buy license to it? Because i really hate paying twice for apps that change to in-app purchases after release, when i already bought it when it was released initially..
     
  19. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    @X9X As an existing user it is free for life on iOS. If you already purchased it prior to 4.0 then as a thank you we have grandfathered in all existing users. The app should recognize that you are an existing user and just lock it in. So you get all the new filters and regular updates forever.
     
  20. X9X

    X9X Registered Member

    Joined:
    Apr 8, 2019
    Posts:
    32
    Location:
    Europe
    For me it says unlicensed in the app. And it's not blocking anything..

    https://abload.de/img/f54a7f88-70e3-467f-b29jd5.jpeg
     
    Last edited: Jan 18, 2020
  21. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    You should be able to click restore purchase in the settings to enable the license. We will validate that for you Monday if that isn't the case for you.
     
  22. X9X

    X9X Registered Member

    Joined:
    Apr 8, 2019
    Posts:
    32
    Location:
    Europe
    Tried restore button, but it doesn't seem to do anything. Also tried to uninstall and reinstall the app, but no luck with the license working.

    Let me know if you need the receipt from app store that i got when i purchased Blackfog.
     
  23. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
    We have just submitted a quick update with 4.0.1 which fixes the grandfather code. Apparently it has to compare the build numbers rather than the version numbers which we were doing. Hopefully that gets pushed through quickly from Apple.
     
    Last edited: Jan 19, 2020
  24. X9X

    X9X Registered Member

    Joined:
    Apr 8, 2019
    Posts:
    32
    Location:
    Europe
    Updated and now it's working.
     
  25. Darren Williams

    Darren Williams Developer

    Joined:
    Feb 4, 2018
    Posts:
    418
    Location:
    California
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.