Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Releases page flagged as Unwanted Software by Google Safe Browsing #160

Closed
makuhlmann opened this issue Jul 31, 2022 · 52 comments
Closed

Releases page flagged as Unwanted Software by Google Safe Browsing #160

makuhlmann opened this issue Jul 31, 2022 · 52 comments
Assignees
Labels
critical Fix Immediately, Literally Destroying the Project as we type enhancement New feature or request

Comments

@makuhlmann
Copy link

Describe the request
The releases page of this repo has been flagged as malicious by Google, resulting in a big red warning in Chrome and Firefox (possibly other browsers too). As a result downloads are blocked as well and need to be allowed manually.

Screenshots
Unbenannt

Desktop (please complete the following information):

  • OS: Any
  • Build Any

Additional context
Related:
https://geekflare.com/tools/tests/3o910hetl
https://twitter.com/christitustech/status/1553445177221586947

@makuhlmann makuhlmann added the enhancement New feature or request label Jul 31, 2022
@SpaghettDev
Copy link

Can confirm. I had to update and this error popped up, after clicking "ignore the risk", and downloading the exe, Firefox flagged it (the exe) as harmful and may contain viruses or whatever.

@rcmaehl

This comment was marked as off-topic.

@rcmaehl rcmaehl pinned this issue Aug 1, 2022
rcmaehl added a commit that referenced this issue Aug 1, 2022
@rcmaehl
Copy link
Owner

rcmaehl commented Aug 1, 2022

https://github.com/rcmaehl/MSEdgeRedirect/releases is blocked
https://github.com/rcmaehl/MSEdgeRedirect/releases/ is not

I honestly don't know what to make of this

@ChrisTitusTech I've already replied to twitter but sorry that you got caught in the crossfire.

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 1, 2022

Looks like @isaak654 and Sandboxie-Plus had the same issue a while ago. I'm going to review the install/uninstall process to see if that can improve things.

@rcmaehl rcmaehl self-assigned this Aug 1, 2022
@rcmaehl rcmaehl added the critical Fix Immediately, Literally Destroying the Project as we type label Aug 1, 2022
@ChrisTitusTech
Copy link

I was able to bombard youtube via Twitter, and the strike was reversed. Still a bit a bummer for an awesome project. It's not the creators fault, just googles algo go wonky.

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 1, 2022

TODO:

  • Improve installing, updating, repair, and other changes #65.
    Pretty sure the installer/uninstaller leaves behind some registry entries. Lets get those cleaned up
  • Discontinue directly offering x86 builds.
    Will still be availabe in the .zip.
    x86 has been ~5% of total downloads (5,845 of 110k)
    Generally receives 2-4x the AV false positive rate of x64
  • Archive old releases
    Especially pre-0.5.0.1 due to security advisory.
    The less number of AV false positives on the releases page, the better.
  • Swap to own logo
    Stop using a modified Microsoft Edge logo to prevent any Intellectual Property issues
  • Add Webdriver option
    Mix between IEFO and Service Mode.
    https://github.com/Danp2/au3WebDriver
    https://msedgedriver.azureedge.net/<version>/edgedriver_win<arch>.zip
  • Code Signing Cert
    While an EV code signing cert would be preferred. It is a large chunk of change. A regular $100ish/yr cert will do fine in the meantime.

@rcmaehl rcmaehl closed this as completed Aug 1, 2022
@rcmaehl rcmaehl reopened this Aug 1, 2022
@rcmaehl rcmaehl changed the title Releases page flagged as malicious (Unwanted Software) by Google Safe Browsing Releases page flagged as Unwanted Software by Google Safe Browsing Aug 2, 2022
rcmaehl added a commit that referenced this issue Aug 3, 2022
@rcmaehl
Copy link
Owner

rcmaehl commented Aug 3, 2022

Actions taken so far:

  • Jul 31: Updated all internal links to use /releases/
  • Jul 31: Filled out the Safe Browsing False Positive form. Although this seems to be only for phishing.
  • Aug 1: Discontinued direct x86 build links for releases.
  • Aug 1: Contacted Github Support to see if they could file a review for Security Issues. Github support ticket #1726178
  • Aug 1: Contacted Google through the Report A Security Issue form Sandboxie Plus found. Case ID [5-8504000032703]
  • Aug 1: Contacted Graphic Artist for new logo design
  • Aug 1: Received preliminary draft for new logo design
  • Aug 2: Received response Google could not verify ownership. Responded with proof of ownership and advised further on the content.
  • Aug 3: Cleaned up leftover registry key if no other software created by me is installed
  • Aug 4: Google directed me to Github Support as well as Search Central Community.
  • Aug 4: Uploaded New Logo base to github. Working on new logo using base, along with other assets.
  • Aug 5: Continued drafts for updated Logo with Graphic Artist
  • Aug 6: Removed old assets from Releases
  • Aug 6: Removed nightly.link from Releases page
  • Aug ?: Submitted Web False Positive to Avira per Virustotal Detection
  • Aug 16: Fixed issue with WinGet keeping old packages
  • Aug 16: Added option to installer to Submit False Positive
  • Aug 18: Avira removed Releases page from their Blacklist per Virustotal
  • Sep 11: Removed from Google Safe Browsing Blacklist

Continuation:

  • Oct 27(ish): Entire repo added to Google Safe Browsing Blacklist
  • Oct 27: Filled out the Safe Browsing False Positive form.
  • Oct 27: Re-added the option to quick submit the project as a false positive after installation to release 0.7.2.0, deselected by default.
  • Oct 31: Filed False Positive with Fortinet
  • Nov 1: Removed from Fortinet Blacklist
  • Nov 1: Removed from Google Safe Browsing Blacklist!

@gnpaone
Copy link
Collaborator

gnpaone commented Aug 4, 2022

I think it may be probably due to this issue plaguing GitHub recently https://www.bleepingcomputer.com/news/security/35-000-code-repos-not-hacked-but-clones-flood-github-to-serve-malware/

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 6, 2022

@micwoj92 Any way to have a new release remove assets from old releases during github actions CI?

@micwoj92
Copy link
Collaborator

micwoj92 commented Aug 7, 2022

No idea. I have quickly looked and there are couple "delete assets" actions on github marketplace with various degrees of feature richness and configurability.

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 7, 2022

No idea. I have quickly looked and there are couple "delete assets" actions on github marketplace with various degrees of feature richness and configurability.

Yeah, saw those. Just wanted your opinion since a lot of them don't show a lot of usage.

@t0rzz
Copy link

t0rzz commented Aug 9, 2022

Same problem with Firefox, both when opening page and when opening the .exe file.

@justadudeongithub
Copy link

Reported a false positive and thank you. This so works. I can finally use search.

@AgainPsychoX
Copy link

Can we get new release soon? The old file is still flagged, making it unable to install on business hardware :C

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 12, 2022

Can we get new release soon? The old file is still flagged, making it unable to install on business hardware :C

Yep. Will be prioritizing getting a new Webdriver based mode added this weekend and hopefully have 0.7.1.0/0.8.0.0 out.

@farcepest
Copy link

Webroot also reports this as a threat.

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 18, 2022

Webroot also reports this as a threat.

Submitted a support ticket

@AveYo
Copy link

AveYo commented Aug 20, 2022

It's like security and AVs are going backwards, to the 90's whitelist by hand trash.
Ain't a low number of FPs equally important to detection rates?!
Cause I can block everything myself without their cloud, AI, heuristics, ATP and dozens more buzzwords

Yesterday Defender started FP my scripts. FFS!
I went powershell-less once, now vbs-less. Relevant part is now just cmd. And flashing window 👎
Frankly, it's unacceptable. "Smart Screen", "Safe Browsing" are nothing but corporate bully tools.
Good luck to you!

@rcmaehl
Copy link
Owner

rcmaehl commented Aug 20, 2022

Frankly, it's unacceptable. "Smart Screen", "Safe Browsing" are nothing but corporate bully tools.
Good luck to you!

Yep, you as well!

@Eden7600
Copy link

This issue is popping back up again with the latest version.

@ElitePheonix2009
Copy link

It's popping back up again when downloading the .exe file and the .zip file.

@rcmaehl rcmaehl unpinned this issue Oct 27, 2022
@rcmaehl rcmaehl reopened this Oct 27, 2022
@rcmaehl rcmaehl pinned this issue Oct 27, 2022
@rcmaehl
Copy link
Owner

rcmaehl commented Oct 27, 2022

Looks like they flagged the entire repo this time... Woooo

@t0rzz
Copy link

t0rzz commented Oct 27, 2022

Someone asks Mozilla why they flagged the exe file as potentially unsafe. They must provide an answer. This is unacceptable.

@rcmaehl
Copy link
Owner

rcmaehl commented Oct 27, 2022

Someone asks Mozilla why they flagged the exe file as potentially unsafe. They must provide an answer. This is unacceptable.

Mozilla uses Google's safe browsing list unfortunately.

@Masamune3210
Copy link

Someone asks Mozilla why they flagged the exe file as potentially unsafe. They must provide an answer. This is unacceptable.

Unfortunately, they neither have to, nor do they usually, provide a reason. They are a private company. Also, usually, they DONT KNOW why its been tagged as malicious. Heuristics are usually black boxes rather intentionally to keep actual malware manufacturers from knowing what to do to avoid detection

@Sensu0
Copy link

Sensu0 commented Oct 31, 2022

I wouldn't be surprised if someone else suggested this in the past;

I think the best way to ultimately resolve this issue is by the developer providing a signature which could then be bundled with the installer.

After all, a lot of viruses out there is being released without a known publisher, but if it's a signed piece of software, then that would most likely help with making this software trusted by big tech. Unless of course, Microsoft is actively paying to have this software flagged as a PUP. Or they would try using the "Embrace, Extend, Extinguish" tactic. Then again, Microsoft owns Github...

@Masamune3210
Copy link

Code Signing Certs arent cheap, and even that isn't guaranteed to fix the issue. Google just shouldn't label something as malicious without a due process that actually works to remove that label should it be (and it often is) incorrect, and the rest of the industry shouldn't allow them to get away with having as much control as they do

@MoiraPrime
Copy link

Someone I know had connections to google and was able to get this escalated and fixed.

@Masamune3210
Copy link

We shall see how long it lasts this time, I prophesize not long

@rcmaehl
Copy link
Owner

rcmaehl commented Nov 1, 2022

Someone I know had connections to google and was able to get this escalated and fixed.

Yep. It's showing as resolved. Well damn. Big thank you!

@rcmaehl rcmaehl closed this as completed Nov 1, 2022
@androidacy-user
Copy link

Page is no longer blocked; however the downloads still are and smartscreen blocks the executable, fyi

@rcmaehl
Copy link
Owner

rcmaehl commented Mar 7, 2023

Page is no longer blocked; however the downloads still are and smartscreen blocks the executable, fyi

Interesting...

@rcmaehl rcmaehl reopened this Mar 7, 2023
@BlackSparowYT
Copy link

Had no more issues when downloading, went through smoothly. No blocked page, no smartscreen and not even a warning when downloading (maybe my settings but idk)

@rcmaehl rcmaehl closed this as completed May 28, 2023
@Glinte
Copy link

Glinte commented Sep 3, 2023

Maybe remove the "help us get off google's blacklist" option in installation since this is resolved?

@rcmaehl
Copy link
Owner

rcmaehl commented Sep 3, 2023

Maybe remove the "help us get off google's blacklist" option in installation since this is resolved?

Possibly

@sguergachi
Copy link

Chrome download blocks it with standard security enabled :/
image

@Masamune3210
Copy link

Chrome also blocks downloads from the official psn servers, its not very smart lol. Honestly, probably not much that can be done about it, as even if they are convinced to remove it, it will just creep back in at some point either way

@vonDubenshire
Copy link

Chrome download blocks it with standard security enabled :/ image

This is actually normal behavior for a .EXE file. If you go to some scam site they'll initiate a download of an exe that poor Grandma will install without thinking.

It's the flag on the web that sucks

@trlkly
Copy link

trlkly commented Mar 26, 2024

@vonDubenshire It doesn't seem to be for every EXE or ZIP file. It seems you can talk with Google to get them to change it. Squarespace did this for their customers, and there's no inherent reason that a file from a Squarespace site would necessarily be virus free.

@sguergachi That said, Chrome isn't completely blocking the file. There is a workaround while staying in Standard Safe Browsing. Rather than deleting the file from the list when prompted, close the dialog and then click on the Download button, and then click Full Download History.

There you will be given the option to keep the file.

@rcmaehl
Copy link
Owner

rcmaehl commented Mar 29, 2024

Actions taken so far:

  • Jul 31: Updated all internal links to use /releases/
  • Jul 31: Filled out the Safe Browsing False Positive form. Although this seems to be only for phishing.
  • Aug 1: Discontinued direct x86 build links for releases.
  • Aug 1: Contacted Github Support to see if they could file a review for Security Issues. Github support ticket #1726178
  • Aug 1: Contacted Google through the Report A Security Issue form Sandboxie Plus found. Case ID [5-8504000032703]
  • Aug 1: Contacted Graphic Artist for new logo design
  • Aug 1: Received preliminary draft for new logo design
  • Aug 2: Received response Google could not verify ownership. Responded with proof of ownership and advised further on the content.
  • Aug 3: Cleaned up leftover registry key if no other software created by me is installed
  • Aug 4: Google directed me to Github Support as well as Search Central Community.
  • Aug 4: Uploaded New Logo base to github. Working on new logo using base, along with other assets.
  • Aug 5: Continued drafts for updated Logo with Graphic Artist
  • Aug 6: Removed old assets from Releases
  • Aug 6: Removed nightly.link from Releases page
  • Aug ?: Submitted Web False Positive to Avira per Virustotal Detection
  • Aug 16: Fixed issue with WinGet keeping old packages
  • Aug 16: Added option to installer to Submit False Positive
  • Aug 18: Avira removed Releases page from their Blacklist per Virustotal
  • Sep 11: Removed from Google Safe Browsing Blacklist

Continuation:

  • Oct 27(ish): Entire repo added to Google Safe Browsing Blacklist
  • Oct 27: Filled out the Safe Browsing False Positive form.
  • Oct 27: Re-added the option to quick submit the project as a false positive after installation to release 0.7.2.0, deselected by default.
  • Oct 31: Filed False Positive with Fortinet
  • Nov 1: Removed from Fortinet Blacklist
  • Nov 1: Removed from Google Safe Browsing Blacklist!
  • ???: Direct link for release page of 0.7.5.3 added to Google Safe Browsing Blacklist
  • Mar 26: Filled out the Safe Browsing False Positive form
  • Mar 26: Started investigating hosting releases elsewhere
  • Mar 29: 0.7.5.3 releases page no longer marked, .zip file still marked however. Considering dropping 32-bit builds from .zip

@rcmaehl rcmaehl unpinned this issue Apr 8, 2024
@rcmaehl rcmaehl pinned this issue Apr 8, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
critical Fix Immediately, Literally Destroying the Project as we type enhancement New feature or request
Projects
None yet
Development

No branches or pull requests