3 ms·
This is funny to me in an admittedly schadenfreude kind of way, as I've had to deal with their false positive system before, and it was an exercise in frustrati
by chops 14y ago
This is funny to me in an admittedly schadenfreude kind of way, as I've had to deal with their false positive system before, and it was an exercise in frustration.
In short, one of my products is a guild hosting system for games like WoW. One of my tools offer is a profile harvesting and uploading system in the form of an executable that simply uploaded the Lua files generated by my WoW Profiling Mod (collecting things like character level, name, class, professions, skills, etc - nothing personal or potentially dangerous). After getting a few customer emails about Sophos detecting it as a virus, I contacted Sophos to let them know about it.
After verifying that it did indeed not contain a virus, they decided to still flag it as a supposed "PUA (Potentially Unwanted Software) or Adware". I protested, saying that no one would ever accidentally install this (it's not bundled with anything, it's a direct download), nor does it generate ads, nor does it do anything the user doesn't expect it to do, which is exclusively uploading character profile information to their website. In no way should be classified alongside Adware.
They responded with something of the order "Sophos is for business computers, and because this is for games, it potentially unwanted on the business machine." They refused to remove the flag.
So my Sophos users just have to accept that Sophos basically tells them that my app contains malware - since who's going to see "PUA/Adware" and think anything other than "This is adware? Screw this, not worth it. BRB cancelling this scam of a service."
So I have absolutely no sympathy for Sophos, and it's funny to me that a company supposedly dedicated to keeping malware and viruses off business computers is riddled with security vulnerabilities, and then tries to brush them under the table because they have not yet been detected to have been exploited. Stay classy, Sophos.