4 ms·
I wish they would take the antivirus issue on Windows more seriously https://github.com/nim-lang/Nim/issues/17820 https://github.com/nim-lang/Nim/issues/17820
by styeco 4y ago
I wish they would take the antivirus issue on Windows more seriously https://github.com/nim-lang/Nim/issues/17820 https://github.com/nim-lang/Nim/issues/17820
This issue alone means I can't use it at work, and I haven't put much time and thought into Nim as a whole because I could only use it in private toy projects.
I understand it's mostly the AV vendors fault and the devs shouldn't have to worry about a problem they haven't caused, but for me, this grinds real-life adoption of the whole thing to a halt.
- jthrowsitaway 4y agoMS Defender flags binaries that have been compressed by upx. It's really annoying because upx is a great way to shrink binaries.
- PMunch 4y agoWe take it very seriously, but there isn't a whole lot we can do unfortunately. Apart from reporting false positives the only venue we could pursue is applying obfuscation practices used by actual viruses. This of course has its own slew of issues.
- GordonS 4y agoAre Nim Windows binaries signed with Authenticode? If not, it's possible to get reasonably priced code signing certificates.
- guiriduro 4y agoYep, I mean, if the virus defence community took the same blanket, lazy approach with C and C++ compilers because viruses can be written in those, too (shock horror!) they'd be shutdown by some big players very fast.
- nyanpasu64 4y agoI hear (but have not personally seen recently) that MinGW-compiled EXEs are falsely detected as malware by some programs: https://stackoverflow.com/questions/62364507/compiled-c-executable-is-detected-as-a-virus-by-windows-defender https://stackoverflow.com/questions/62364507/compiled-c-exec...
- tyingq 4y agoIt's not clear to me what they could do. In the thread you linked, it's not just the binaries of the various nim executables, but also user generated binaries. And it appears that even signed binaries are getting flagged by some vendors. I'm guessing the issue is that some malware writers started using nim, and the antivirus vendors then decided to make heuristics that detect nim generated binaries and call it malware.
- PMunch 4y agoThis is pretty much it, malware was written in Nim, vendors started fingerprinting those binaries but didn't include any/enough non-malware binaries. This means that the fingerprint is more "this program is written in Nim" and less "this is malware written in Nim".
- styeco 4y agoI hope I didn't come off as too aggressive in my original post, I'm not trying to demand anything, or trying to act like I know anything they don't, I most certainly do not. I just love the language so much, I wish I could use it more. The linked issue doesn't show any traction, and other languages used for malware don't have this problem, so I (probably incorrectly) presumed there was a lack of interest to solve this. I apologize if I came off as demanding.
- GordonS 4y agoYikes, does that mean scumbags could effectively torpedo any new language, like Zig and Hare, for example?
- tyingq 4y agoHard to say, since we have no idea how the antivirus vendors are identifying nim. Maybe there's something about the fact that nim compiles to C which is then usually compiled by mingw? (You can use compilers other than mingw, but it's the default). Mingw might have a higher weight for "this is malware". Then you combine that with nim generating code that's common across most nim binaries (the GC, boilerplate symbols, etc). Then there's perhaps not enough positive signals to offset that, since there's not yet a wildly popular windows app written in nim.