6 ms·
In a way, this has already happened. Microsoft has chosen to classify qBittorrent, Transmission, and Deluge as PUA (potentially unsafe application). As a conseq
by e2le 4y ago
In a way, this has already happened. Microsoft has chosen to classify qBittorrent, Transmission, and Deluge as PUA (potentially unsafe application). As a consequence, Defender will block their installation and remove existing copies.
https://github.com/qbittorrent/qBittorrent/issues/14489 https://github.com/qbittorrent/qBittorrent/issues/14489
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?name=PUA%3AWin32%2FQBitTorrent&threatid=292801 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=PUA:Win32/TransmissionTorrent&threatId=292809 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...
https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=PUA:Win32/Deluge&threatId=292802 https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo...
- namlem 4y agoHuh, I haven't experienced any problems with qBittorrent in Windows.
- IceWreck 4y agoStop using Windows then. Linux is the way.
- toastal 4y agoHaving used a torrent client to download a Linux ISO from Windows, I agree
- e40 4y agoIt's trivial to setup Docker on Windows to run a torrent client.
- fsflover 4y agoIt's trivial to run Linux and not needing any workarounds for simple actions.
- skazazes 4y agoAs someone who uses Linux daily, when will this stop being parroted. Your average person, your average BitTorrent user even, does not have the skill set required for the running of Linux to be anything near trivial...
- netr0ute 4y agoWhat site are we on again?
- fartcannon 4y agoAt what point do you ask yourself if perhaps your opinion of the average user is out of date?
- skazazes 4y agoProbably around the time a Microsoft product does not appear in the top 100 torrents by seeds across all of the major public trackers
- unlaxedneurotic 4y agoProbably when my <50yo dad stops asking me to change the font size on his phone everytime he changes it. The thing is, technology is just a tool for most people and except software engineers almost no one wants to spend any time dealing with anything that they would have to configure. Until the day linux based OSes come pre-installed with sane defaults that work out of box on laptops, the average person won't use it.
- LordDragonfang 4y agoPoint of clarification, "PUA" actually stands for "Potentially Unwanted Application" (not "unsafe"), which makes this an even more transparently bad faith classification. https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/detect-block-potentially-unwanted-apps-microsoft-defender-antivirus?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/security/defe...
- godelski 4y agoDoesn't Microsoft use torrents to update their software? I thought they enabled P2P downloading to reduce their server overhead in windows 10. That's a bit hypocritical if you ask me.
- jaywalk 4y agoNo, they don't use torrents. The technology is called BITS (Background Intelligent Transfer Service): https://docs.microsoft.com/en-us/windows/win32/bits/about-bits https://docs.microsoft.com/en-us/windows/win32/bits/about-bi...
- iggldiggl 4y agoActually BITS is the old thing by now (it's been present in Windows since Windows XP), which only tries to download things in the background by using spare network bandwidth. I've never actively tested how well this "spare bandwidth detection" actually works, but on the other hand I've also never negatively noticed it, so I guess it might actually be doing its job quite well. On the other hand there is in fact a newer (relatively speaking, given that it's a few years old by now, too) thingy specifically for Windows Update which also tries to use P2P distribution – that one is called DOS. Officially that stands for "Delivery Optimization Service", though personally I rather prefer "Denial of Service service", because when I first encountered I immediately noticed it in a negative way: Even without any P2P features enabled, it spammed literally dozens of TCP connections to download stuff, and would thereby effectively monopolise the whole bandwidth of my internet connection. Until I figured out what was happening and disabled it (you can disable it and switch back to using BITS for downloading updates), every time my new (at the time) laptop was downloading updates, it would dramatically slow down Internet speeds for everything else in my whole home. Maybe by now that kind of issues have been fixed, but I've never tried it myself because BITS is, as I said, working perfectly fine and unobtrusively.
- jonathanlydall 4y agoI have a few Windows machines at home and BITS is so good that I’ve never really noticed it in action. By comparison, macOS App Store downloads and updates can hog bandwidth horribly. It was just my wife and I on our at the time 25mb/s line, and Netflix dropped to like 240p and was still struggling while I was doing an XCode update.
- mike_hearn 4y agoWell, no, not really. The GitHub thread is based on a mis-understanding of what Windows is doing and how Windows AV works. Windows uses a system very similar to those used for spam filters, except for binaries. That system is "reputation". It tries to learn over time to classify software into wanted and malware. Just like with email, to build binary reputation you need to cooperate by using cryptography. With email you sign your mail using DKIM and publish your DKIM keys in DNS. This lets spam filters associate the mails you send together and learn that a stream of mails, even though they may all be very different, are in fact all "good". With Windows programs you have to sign your software. This lets Windows know that different versions of your program are actually all "good". Authenticode certificates cost money. QBitTorrent is open source. Unsurprisingly they'd rather not pay for a code signing certificate, so their installers are unsigned. From Windows' perspective every new version resets the clock and is "unknown" because the binaries have different hashes. It then has to start learning reputation all over again. New binaries are described as "potentially unwanted" rather than explicitly as malware because malware is polymorphic, exactly to evade blacklisting, so binaries that haven't accumulated any reputation yet might or might not be malicious. Windows just doesn't know yet. That's why some users report it happens and others don't. This isn't QBitTorrent's fault exactly but they're experiencing the same problem you'd get if you tried to run a popular mailing list off a site that didn't use SPF or DKIM. You aren't signing, so, you get lumped in with all the other people who don't sign and many of them are malicious. tl;dr It's got nothing to do with being a BitTorrent client.
- e2le 4y ago> tl;dr It's got nothing to do with being a BitTorrent client. That's simply not true. It's got everything to do with it being a BitTorrent client. > Microsoft uses specific categories and the category definitions to classify software as a PUA. > Torrent software (Enterprise only): Software that is used to create or download torrents or other files specifically used with peer-to-peer file-sharing technologies. https://docs.microsoft.com/en-us/microsoft-365/security/intelligence/criteria?view=o365-worldwide https://docs.microsoft.com/en-us/microsoft-365/security/inte... Microsoft explicitly include "Torrent software" in their article for what's considered by them to be PUA. > In a background article on what’s considered unwanted software, torrent clients are specifically mentioned, along with advertising software and cryptominers. The article suggests that it applies to “enterprise” only, but the complaints we have seen apply to other Windows versions as well. https://torrentfreak.com/utorrent-continues-to-be-flagged-as-severe-threat-and-its-not-alone-210318/ https://torrentfreak.com/utorrent-continues-to-be-flagged-as... As pointed out by TorrentFreak, the Microsoft article suggests that it only applies to the "enterprise" version of Windows however as we've seen this doesn't appear to be true. It at least explains why some experience this user hostile behaviour while others don't.
- searchableguy 4y agoI built an API to flag pirated content last year. I shared the progress on HN: https://news.ycombinator.com/item?id=26748724 https://news.ycombinator.com/item?id=26748724 Maybe I can find customers if this passes. :P
- e2le 4y agoMake it a Windows kernel driver for scanning process memory and I'm sure you'll have enterprise customers lining up to buy it. With or without this new legislation. A new tool for spying on their users (students, employees, etc) wont go ignored.
- vkou 4y agoAn employee of a company is not a user of the company, they are an employee.
- Asooka 4y agoThat doesn't remove their right to basic human decency. Like not being spied on.
- vkou 4y agoAs an employee, you trade time and some basic human decency in exchange for money. How much decency you trade is debatable, but I assure you, there are millions of people working in industries where losing far more decency is considered normal. Call centers, retail, food all immediately spring to mind.