7 ms·
We can't use Nim at my organization as the binaries it generates are detected as viruses and deleted by CrowdStrike Falcon when I attempt to execute them and re
by mcdermott 5y ago
We can't use Nim at my organization as the binaries it generates are detected as viruses and deleted by CrowdStrike Falcon when I attempt to execute them and results in a visit from our security team. I uploaded one of my binaries to Total Virus for inspection and several AV products mark it as malicious. This was with Nim verson 1.6.2. I created an issue but it was promptly closed as there was already open 6+ month old issue about this. I know it's not the project's fault and that the AV companies need to resolve this, but if this is not resolved it's going to severely limit the viability of Nim, especially in larger companies. I want to use Nim to build tools, but can't until this is resolved.
- Guzba 5y agoIt's interesting. How does one exactly address this? If anyone knows I'm genuinely curious since this seems horrible. (Snark time) Is there someone that gets paid for protection? Maybe a "contribution" to security research efforts at one of these places? Or is there just an "I'm not a virus" flag Nim is forgetting to set.
- skymt 5y agoAV vendors have points of contact to report false positives. They don't always respond quickly, but they're not brick walls. Reliable FPs from a specific toolchain seems like something their team would be especially interested in solving. CrowdStrike's reporting point is an email address on their contact page: https://www.crowdstrike.com/contact-us/ https://www.crowdstrike.com/contact-us/
- Guzba 5y agoOk I sent an email report explaining the issue with additional info. Let's see what happens. Edit: Got a reply: > Thank you for contacting CrowdStrike’s public AV scanner team! If you have not done so yet, please upload a sample of the file in question to Hybrid Analysis at https://www.hybrid-analysis.com/ https://www.hybrid-analysis.com/. Furthermore, please make sure that your request contains the SHA256 hash of the file. I look forward to them no longer flagging one specific Nim binary produced just as an example.
- melony 5y agoTry adding debug symbols or make a fatter binary. Nim (and to a lesser extent Zig) has an emphasis on producing tiny binaries. I suspect some of the same optimization outputs matches the signatures of malware (which often is written in heavily optimised code).
- Guzba 5y agoI realize you are trying to help, but I find this to be a very depressing suggestion. "Make things worse". Fortunately I do not need to care about people captured by these anti-virus cartel members so I will not do this.
- treeform 5y agoI don't think there is anything for Nim people todo. Anti virus companies run a very simple algorithm, they flag everything they have not seen before... At this point anti virus companies are the virus, slowing down peoples computers, mining bitcoin, false advertising, hard to cancel payments etc...
- ensignavenger 5y agoAlternatively, you could tell the security team it is a false positive, and they can, mark it and report it as such to their vendor. Or the company could stop using a defective security tool.
- nooorofe 5y agoSame here, I can use nim.exe on desktop, but nimble.exe is killed SentinelOne. It works on Linux machines. Before they were deleting everything named bash.exe (not anymore).