Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It certainly happens with enough regularity to create and maintain a reputation for pirated software often-enough being compromised with malware that it is not worth the risk.

The fact that you have both a low-enough risk profile, and exceptional skills to minimize both the incoming risks and the consequences of a problem, does not mean that it is not or should not be a factor for others who have higher risk profiles and lower skills.

I am an actual case in point. Former CTO of several successful software/SAAS companies, now working in manufacturing, including on DOD projects. I could probably make use of some software that is $6-figures/seat, and it'd be fun to try out pirated copies since my small company can't justify that expense. But probably over a decade ago, I did encounter some malware from a download; handled it without a disaster, but it was a significant waste of time and resources. Since then, my observations of even the regular 'legit' software download services (freeware/shareware/trials, even used as official sites by some software authors), is that they look substantially less-well maintained and more 'scammy' than ever. Even if it isn't outright malware, but merely adware that comes along for the ride, I'm out.

Considering the risk of everything from malware to ransomware, to potential exfiltration of even encrypted-on-disk CUI (Confidential Unclassified Information, a new level of information control), I'm extremely wary about any software download, repeatedly check that it is coming directly from the vendor (certs, keys, checksums, etc.).

Again, I'm someone with a somewhat elevated risk profile, but also the (rusty) skills to deal with it, and I legitimately consider it a non-trivial risk. The vast majority of the user population has negative skills to deal with it despite their lower risk profile.

Stop trying to make pirated downloads look like a legitimate and safe option. They are not.

Although vendors are extremely foolish and shortsighted to not make available extended trials, you are still taking something from the owner without permission, and unless you know of some service that is actually 100% effective at scanning for malware, including 0-days and all the morphing/encrypted/etc. malware techniques, it is still a real risk (and if you do know of such a service, let us know about it, and how you have vetted their reliability).



Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: