4 ms·
mmh, so is using MSVC compiler a possible workaround?
by pietroppeter 4y ago
mmh, so is using MSVC compiler a possible workaround?
- badsectoracula 4y agoPossibly, but note that this is a lack of encountering an issue, not that the issue doesn't exist. Also it limits you to MSVC, C/C++ and languages that can transpile to C/C++ via MSVC. This isn't something that, e.g. Free Pascal can do and when i use other C compilers is mainly to avoid MSVC :-P.
- GoblinSlayer 4y agoNo, the workaround is a signed executable.
- noobermin 4y agoIs Nim trying to get a signed compiler?
- mike_hearn 4y agoIt's not the compiler that has to be signed, it's the outputs. Any Windows EXE can be signed. It doesn't matter what compiler you used. The problem here isn't actually anything specific to Nim or Go, it's rather, the underlying UNIX oriented culture in which developers rarely sign their binaries. It'd affect any language with that culture. The Go FAQ on virus detection doesn't even mention signing at all - no wonder they have such problems.
- noobermin 4y agoOk, tell me then, how does a random person sign their binaries without paying through the nose and going through an extensive review process? It's one thing for a developer to get to distribute apps on an app store full hog with no oversight, and even there app stores are onerous. It's another to stop users from running their own software. Calling that a cultural difference is way too much. Heck, teenage Bill Gates made money selling his own software without someone forbidding it running on their own computers, it'd be hard imagining microsoft being what it is if this is the environment we're leaving the next generation of young hackers.
- GoblinSlayer 4y agoCAs want to eat. Also antivirus doesn't prevent users from running a program, it just shows a scary looking message. The whole thing is just a drop in quality as viruses are a thing of the past since Vista and as a result antiviruses don't have enough funding to maintain quality.
- mike_hearn 4y ago"how does a random person sign their binaries without paying through the nose and going through an extensive review process?" You just self sign. Conveyor does it by default, even. You can always run your own software on your own machine. Now, other people's Windows machines out of the box won't treat that as signed of course. Users would have to install your signing certificate. But you certainly can sign code without paying for it, it's just not meaningful to a fresh Windows install. Self signing is useful for distributing software internal to organizations for example. To distribute more widely, well, neither OV nor EV is actually an extensive review process. Even for EV they just verify that you're actually buying a certificate by looking you up in a business directory and calling you via the published contact details. Nothing about your software is reviewed.
- account42 4y agoIf signing actually prevents false positives then it's another problem with the AV tools - bad actors can get signing certificates easily enough, easier than a open source developer with 0 budget in fact.
- mike_hearn 4y agoIt doesn't prevent false positives, it just means that once these tools learn that you're a legit organization you're much less likely to encounter them because it's a strong signal of goodness, especially so for EV keys that are harder to steal.