3 ms·
> after the download my Windows Defender instantly detecting a virus. > (because i am often working with programms which triggering the defender i just ignored
by quantummagic 6mo ago
> after the download my Windows Defender instantly detecting a virus.
> (because i am often working with programms which triggering the defender i just ignored that)
This again shows the unfortunate corrosive effect of false-positives. Probably impossible to solve while aggressively detecting viruses though.
- pshirshov 6mo agoBut sorta possible to solve with source-based distribution and totally possible to solve with pure reproducible builds.
- daveguy 6mo agoWhat systems have pure reproducible builds? Does Nix? Any others? From what I understand, it is a very difficult problem.
- pshirshov 6mo agohttps://stal-ix.github.io/ https://stal-ix.github.io/ and Guix, but the definitions of purity are different for them. Yes, a very difficult problem, compilers must be pure functions with thin effectful wrappers.
- gertop 6mo agoIt's entirely possible to ship malware in source form... Just look at the numerous supply chain attacks. Nix is a cute project but entirely irrelevant here.
- miniBill 6mo agoIt is possible but visible, and it means burning an identity, so it's not irrelevant
- Thorrez 6mo agoBurning an identity? Instead of hacking the server that serves the binary, you have to hack the developer's machine and commit a malicious source change. I wouldn't consider either of them to burn an identity.
- eviks 6mo agoIf only there were a great Windows app store or a package manager to help with the impossible...
- vegadw 6mo agoI think to an extent Microsoft is the guilty party here. For may cracks Windows Defender will trip saying "Win32/Keygen" even if there's no actual malware https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=HackTool%3AWin32%2FKeygen https://www.microsoft.com/en-us/wdsi/threats/malware-encyclo... This trains people that do a lot of piracy to be used to turning off their antivirus to let something through, which is fine until it's not. It's like drugs, if we know a subset of the population will do them no matter what, we should make it safe for them to the extent we can. False positives, causing people to ignore actual positives, creates a market for these things.
- ls612 6mo agoI mean this is by design? It makes pirates more likely to get malware, and thus normal people more likely to pay for MS products rather than pirate? You may think its immoral but the incentives line up.
- vegadw 6mo agoI don't think it's some conspiracy to make anyone more likely to get malware. Instead it's that for their business model of mostly being used on business PCs where the same dozen tools are installed all over the world they can be overzelous in protection and it is what most customers want. Really, they should leave the "piracy is malware" thing in defender, it should just be off by default if your PC isn't connected to a domain or setup as "work PC".
- Gigachad 6mo agoSoftware is the one thing I won't pirate since the risk of installing malware is extremely high. For media files, unless you are incredibly unlucky and someone is exploiting a bug in the media player, you are entirely safe. But for software you have no way of knowing how the software has been tampered with, and often there actually is malware in it.
- ziml77 6mo agoSame. I used to pirate software but even way back I kept it limited to very popular software and established downloads (where if they were malware they were almost certain to be in a signature database by that point). And I absolutely never pirated an OS. I thought anyone doing that was out of their freaking mind because any malware there had ultimate access to block its own detection and do whatever else it pleased. Now I don't do it at all. It's not worth the risk when I have the money to pay for the proprietary software that I like and when the ecosystem of open source software is very good.