this post was submitted on 02 Oct 2023
1280 points (98.4% liked)

Technology

68495 readers
4817 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] [email protected] 284 points 2 years ago (4 children)

similarly, I've removed Microsoft from my system.

[–] [email protected] 70 points 2 years ago (31 children)

Probably a good move on your part. When they try to force windows 11 on me, that's when I will be moving to Linux.

[–] [email protected] 34 points 2 years ago (35 children)

Why wait, do it now.

I jumped ship to Linux when Win 7 died, cause I'd rather be fucked by a rusty fencepost than be forced to use 10, and 11 is right out.

[–] [email protected] 11 points 2 years ago (7 children)

Looking to move an older Windows 7 laptop to Linux this week, any suggestions? Feels like there’s so much.

[–] [email protected] 18 points 2 years ago* (last edited 2 weeks ago) (2 children)
load more comments (2 replies)
[–] [email protected] 9 points 2 years ago (5 children)

If you just need a general purpose desktop and it's your your first time, I would suggest just picking a popular and stable one with lots of documentation like Debian, Mint or Ubuntu.

load more comments (5 replies)
[–] [email protected] 7 points 2 years ago

Fedora saved my old Windows laptop and it was a pretty smooth switch from Windows for me (though I had a bit of Linux experience). That thing became quicker than when I first bought it haha.

load more comments (4 replies)
load more comments (34 replies)
load more comments (30 replies)
[–] [email protected] 10 points 2 years ago

That's the real trojan.

load more comments (2 replies)
[–] [email protected] 192 points 2 years ago (3 children)

I’m not sure about the browser, but a lot of malware used to ship with the tor binary and used it to connect to the CNC. I can totally see it ending up in the indicator list.

I love bashing MS as much as the next guy, but this is not completely indefensible behavior given typical user use cases and needs. As long as it’s easy to add an exception of you installed it on purpose.

[–] [email protected] 79 points 2 years ago (15 children)

Yeah I'm guessing this is a false positive based on heuristic analysis, i.e. the TOR program has a lot of the same behaviors as malicious programs. Of course it is more accurate to say that the malicious programs are copying TOR behavior or just straight using TOR code, whatever the case may be.

My main issue is that it kind of shows a lack of due diligence. I assume the official TOR binaries are signed, so the official TOR binaries should be exempted from these heuristic positives. If the binaries are unsigned/have no valid certificates, then I can totally understand the false positive. At that point, the user should know they are installing software that cannot be automatically verified as being safe, and antivirus should never assume that something is safe otherwise. Like you said, for typical users this should be the expected behavior. Users can always undo Windows Defender actions and add exemptions.

load more comments (15 replies)
[–] [email protected] 10 points 2 years ago (2 children)

Oh god I hate that spelling of C2 lol

load more comments (2 replies)
[–] [email protected] 8 points 2 years ago

It's defensible only from the perspective that it's safer to flag many innocent apps than to miss something harmful. That said, it heavily punishes many legitimate developers and creators, as documented here. I was personally affected on many occasions and there hasn't been a single one where Microsoft wouldn't admit to false-flagging upon a manual review.

[–] [email protected] 126 points 2 years ago (14 children)

At this point, Microsoft Windows itself can basically be classified as malware

[–] [email protected] 9 points 2 years ago

If we define malware as something having functions to harm the user and not only things build soley for this purpose, then of course Windows is malware.

https://www.gnu.org/proprietary/malware-microsoft.html

load more comments (13 replies)
[–] [email protected] 89 points 2 years ago (5 children)

Dude ms defender used to delete my "Hello World" executables built using visual studio just because they were made by an unknown publisher.

[–] [email protected] 24 points 2 years ago

Well maybe you should have become a known publisher before writing any programs.

/s

[–] [email protected] 7 points 2 years ago

It flagged your program for being dissident propaganda.

load more comments (3 replies)
[–] [email protected] 69 points 2 years ago (2 children)

I've run into antiviruses blocking code I've written just because I pulled in certain cryptographic libs. Literally pulling in some Microsoft cryptography libraries in c# made it think I was writing a crypto locker.

[–] [email protected] 21 points 2 years ago

Imo, compared to how prevalent viruses were on older versions of windows, this type paranoia seems to be working

load more comments (1 replies)
[–] [email protected] 65 points 2 years ago

Classic Microsoft

[–] [email protected] 47 points 2 years ago (5 children)

Fucking microsoft doing microsoft things.

load more comments (5 replies)
[–] [email protected] 36 points 2 years ago* (last edited 2 years ago) (1 children)

A little context, one of the larger exit nodes was compromised and would send malware to your computer. The behavior shield probably caught this and correctly marked the program as a trojan, since, by definition, that's literally what it was acting as when connected to that node. More advanced AVs (like malwarebytes) will instead block the malicious connection rather than blanket-banning the entire program.

load more comments (1 replies)
[–] [email protected] 22 points 2 years ago (4 children)

This only happens in the latest version btw.

You can still download previous version and replace tor.exe and it works.

load more comments (3 replies)
[–] [email protected] 15 points 2 years ago

Windows Defender sucks compared to the original Williams version.

[–] [email protected] 14 points 2 years ago

How dare they use a non-Edge browser for this!

load more comments
view more: next ›