NFCGate flagged as malware even after multiple followups saying it isn't
1–10 of 17 posts
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#2Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#3This reminds me of may of one of my favourite piece of software, Mail PassView, which is (AFAIK) considered Malware bei Windows/Defender because it shows you the passwords you entered yourself in Outlook (but forgot to write down somehwere). Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#4This reminds me of may of one of my favourite piece of software, Mail PassView, which is (AFAIK) considered Malware bei Windows/Defender because it shows you the passwords you entered yourself in Outlook (but forgot to write down somehwere). Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
Nirsoft tools? Bam, "virus" and "malware". How dare you!
Tailscale website? Uh-oh, ZScaler thinks that's a "remote access tool" so you're being given a click-through formal warning!
The Framework website? Uh-oh, .work is a bad TLD! Can't browse to that, it could be evil!
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#5Re: NFCGate flagged as malware even after multiple followups saying it isn't
#6This reminds me of may of one of my favourite piece of software, Mail PassView, which is (AFAIK) considered Malware bei Windows/Defender because it shows you the passwords you entered yourself in Outlook (but forgot to write down somehwere). Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
False detection is a nightmare in the corporate world and this IT worker bashes his head every time he runs across it. Nirsoft tools? Bam, "virus" and "malware". How dare you! Tailscale website? Uh-oh, ZScaler thinks that's a "remote access tool" so you're being given a click-through formal warning! The Framework website? Uh-oh, .work is a bad TLD! Can't browse to that, it could be evil!
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#7This reminds me of may of one of my favourite piece of software, Mail PassView, which is (AFAIK) considered Malware bei Windows/Defender because it shows you the passwords you entered yourself in Outlook (but forgot to write down somehwere). Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
False detection is a nightmare in the corporate world and this IT worker bashes his head every time he runs across it. Nirsoft tools? Bam, "virus" and "malware". How dare you! Tailscale website? Uh-oh, ZScaler thinks that's a "remote access tool" so you're being given a click-through formal warning! The Framework website? Uh-oh, .work is a bad TLD! Can't browse to that, it could be evil!
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#8This reminds me of may of one of my favourite piece of software, Mail PassView, which is (AFAIK) considered Malware bei Windows/Defender because it shows you the passwords you entered yourself in Outlook (but forgot to write down somehwere). Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
making an exception for such a heuristic is, in all cases, wrong since it will always be abused.
The actual answer is: Defender needs a PUP category.
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#9This reminds me of may of one of my favourite piece of software, Mail PassView, which is (AFAIK) considered Malware bei Windows/Defender because it shows you the passwords you entered yourself in Outlook (but forgot to write down somehwere). Flagging Malware is hard, and research/dev tools are always behaving at least similar to Malware (because we want to get data/do stuff regular users won't do).
But the main characteristic of malware is that it works for someone other than the user, no? Research software works for the user themselves.
Re: NFCGate flagged as malware even after multiple followups saying it isn't
#10Earlier quoted context omitted.
But the main characteristic of malware is that it works for someone other than the user, no? Research software works for the user themselves.
And something using keystroke injection to abuse the exception?
Like Powershell, or Microsoft Automate or Tosca, who can all run keystroke injection, but aren't flagged.