I also dispute "It's a tautological false-positive, by the very definition of the term, _everything_ is potentially unwanted."
That's not the definition. Here is a definition in line with what just about everyone means by the term:
"A potentially unwanted program (PUP) is a piece of software that is also downloaded when a user downloads a specific program or application. PUP is similar to malware in that it will cause problems when it is downloaded and installed."[0]
Or my own shorter definition: "Software that nobody would want on their computer if they knew what it is and does."
It sounds like that's exactly what was detected.
I don't dispute, but I'm curious about his claim that AV vendors maliciously flag their competitors' legitimate software. I wouldn't be the least bit surprised if that's true, but it's the first time I've heard of it.
[0] https://www.techopedia.com/definition/4061/potentially-unwan...
https://web.archive.org/web/20140816230250/http://blog.glust...
Back then, they were doing it as part of the (previous incarnation of) SourceForge's "DevShare" offering. eg malware authors got SourceForge to bundle crapware with popular Win installers, and gave the developers a cut of the take.
It seems like the FileZilla people didn't like that revenue stream being cut off, and went to the source directly afterwards. :(
Do you really truly think they did an adequate job responding to the complaints/criticisms/questions? Seriously?
>The lack of actual rebuttal — a tonne of valid points were made about the bundled binary, the dats, the phoning home, the unsigned executables, etc. None of them were addressed.
https://forum.filezilla-project.org/viewtopic.php?p=161493#p...
Maybe the dude didn't go into excruciating detail but I understood the reply. Which part of the reply was factually incorrect?
>3) the nonsense about digital signatures
Could you link to the comment ?
>Do you really truly think they did an adequate job responding to the complaints/criticisms/questions? Seriously?
I don't know which complaints you're referring to. Some are reasonable, and others are just wild accusations. But just to give you an answer that you will be happy with, No, they didn't.
Your reactions to this post deeply concern me. I do believe this is a serious problem you should at least entertain investigating whomever you have an agreement with in regards to bundling their stuff into your installer.
Those domains its communicating with have several hits on known malware/RATs reports. For instance, https://www.maltiverse.com/sample/a98b1 ... 38233c50b7.
Here is another that spawns the same type of .exe which turns out to be NJRAT malware -> https://www.hybrid-analysis.com/sample/ ... mentId=120
Your defensive attitude is what alarms me the most. Almost as if you might care more about your bundle agreement profits than your users security/safety.
Hole in one. I wouldn’t trust those admins to make me a cup of tea, and I agree that their attitude reeks of deception for selfish reasons. Nobody should ever trust their software again, full stop.
They earned their reputation as untrustworthy.
Whoever wrote these replies would probably do well in politics.
I do so because I hope other people will listen and stop doing business with them leading to a decrease in profit and THEN changed behaviour from the culprit.
There is lots of factual information. They are factually doing a lot of malware like behaviour in their installer and bundling software from questionable sources they have no control over. At best they are putting their customers at risk.
The only facts that can possible emerge is that its actually worse and customers are getting their identities stolen or some such.
Rabble rousing is literally the only way anything gets fixed.
>They are factually doing a lot of malware like behaviour in their installer and bundling software from questionable sources they have no control over.
Their explanation was that AV vendors flag their competitors, so now in the 'arms race', competitors have resorted to downloading individual bits from random URLs and then merging them together. While this would be a technique that malware software would use to possibly defeat security software, but hey, its also how torrents work. Tools can be used for good or bad.
https://www.howtogeek.com/207692/yes-every-freeware-download...
Of course there is trustworthy freeware. You can get it using Apt, Yum, Ninite, Chocolatey, Homebrew, or just by going to the actual site of a trustworthy software product.
The fact that the people who run most download sites are scum isn't a problem with the software. It's a problem with those sites.
ksk - many hn readers build using free software for places like google, amazon etc, that are trusted all the way up to places like the CIA. Seriously, please troll somewhere else. Basically no one working in almost any open source project wants to be working with an author that bundles in crapware, ESPECIALLY if the author doesn't actually even control the crapware. If you don't get why this is a bad idea you'll have to trust folks who use open source software regularly that this is a bad thing.