9 ms·
We ship Microsoft-signed Go binaries on Windows (via Windows Update) and have never, to date, had any issues with false positives. This smells like clickbait fo
by daviddever23box 4y ago
We ship Microsoft-signed Go binaries on Windows (via Windows Update) and have never, to date, had any issues with false positives. This smells like clickbait for someone unfamiliar with Windows application release and delivery.
- hdjjhhvvhga 4y agoHave you read the linked page? It clearly shows many people have been affected.
- pjerem 4y ago> We ship Microsoft-signed Go binaries Cool. So we just all need to politely ask Microsoft to sign our binaries. What a bright future where Microsoft have the power to decide who lives and who dies. I know that you'll answer that Apple also does it. Well, it's also an issue. Who needs courts and laws when you have good corporations :)
- tgv 4y agoIdk how Windows does it, but under macOS, you can change a setting and it'll let you run any binary, but you have to approve it before running it the first time. It's not based on malware detection.
- Semaphor 4y agoIt’s the same in Windows. Well, mostly. You have to click 2 buttons to allow it. This thread is about AV software, sadly the horrible headline ("on Windows") makes everyone who stopped with the headline comment about unrelated things.
- daviddever23box 4y agoThat's what consenting adults do in lieu of 'bcdedit /set testsigning on' via an admin prompt. Alternately, one can call off the antivirus dogs and get on with it.
- IceWreck 4y ago> Microsoft-signed Go binaries on Windows (via Windows Update) There is your answer.
- cowl 4y agoIt doesn't matter if it's signed or not. It's the AV heuristics that trip on the way the new executables from these languages are build. I have had The AV trigger even on simple Hello world programs while developing. THere is no "sign" option while developing.
- int_19h 4y agoWe ship Microsoft-signed Win32 binaries via PyPI, and I regularly have to go and deal with new releases being reported as malware. This kind of thing is why release pipelines normally do an automatic submission to a scanning service that checks it across all major anti-malware vendors. Granted, this is a debugger, which among other things contains code to inject threads into running processes - which, of course, trips any decent heuristic scanner. But there are many broadly legitimate patterns that are also useful to malware and so get falsely reported as such, e.g. https://github.com/nim-lang/Nim/pull/19767 https://github.com/nim-lang/Nim/pull/19767