ShadowWhisperer / BlockLists

DNS Block Lists
260 stars 32 forks source link

False Positive - start.me #101

Closed nick-elms closed 1 year ago

nick-elms commented 1 year ago

"start.me" is being blocked, but it's a normal homepage/landing page alternative, been using it for years. Virus total results are all clean:

ShadowWhisperer commented 1 year ago

start.me is considered a PUP (Potentially Unwanted Program) - Used to be a Search Engine Hijacker The extension was pulled from the Firefox add-ons page. StartMe requires addition extension in Firefox to even use it.

It appears it was blocked by Malwarebytes at one point.

I see it's available on the Play Store. A little suspicious that it hasn't been updated since 9/15/2020

I do not see a reason to whitelist this extension. I have 100+ of my own businesses users that run this list. Not worth the risk. I recommend whitelisting internally, if you choose to use it.

https://malwarefixes.com/how-to-remove-weknow-start-me-mac/ https://malwaretips.com/blogs/remove-weknow-start-me/ https://support.mozilla.org/en-US/questions/1183215 https://www.myantispyware.com/2017/07/16/how-to-remove-start-me-chrome-firefox-ie-edge/ https://www.pcrisk.com/removal-guides/14437-weknow-start-me-redirect-mac https://www.reddit.com/r/privacytoolsIO/comments/f6w23n/startme_can_we_trust_them/ https://www.reddit.com/r/techsupport/comments/4e17xc/startme_chrome_extension_malware/ https://www.wipersoft.com/remove-start-me-redirect/

spirillen commented 1 year ago

Well I have it for Tracking (https://0xacab.org/my-privacy-dns/matrix/-/issues/67411) as they store and sells all your data

nick-elms commented 1 year ago

Seems like you guys are referring to the browser extension which is fine, do the same concerns exist on just the website as I alluded to?

ShadowWhisperer commented 1 year ago

The website itself is fine. Blocked to prevent users from downloading the extension, and whatever else is done in the background when the extension calls out to it.

nick-elms commented 1 year ago

ah ok makes sense ~the website was the intent behind opening this issue, I've never used the extensions