Microsoft Defender was flagging Tor browser as a trojan and removing it
deform.co
deform.co
First, what is malware? It’s actually very hard to define in such a way that makes everyone happy. The line gets really blurry on the border of nuisance vs malicious, and on security tools, which might do things in the name of privacy that malicious software might do to hide its tracks.
The other issue is false positives. We tried really hard to avoid false positives; we ran tests with known good binaries to see if they were inappropriately detected, etc. We feared false positives more than false negatives.
I am sure that the MS antimalware team is having a bad day and not acting in bad faith.
But... they are very clearly publishing info claiming my site is malicious, and it's not. It seems like a super clear case of libel, which I won't pursue because it's personal sites and I'm not losing revenue or anything, but it seems open and shut.
It's not even exempt due to general section 230 clauses. It's not user content. It's just them.
I didn't do any downvoting, but I suspect it could be a reaction to the fact that treating this as libel would make operating any security company or service effectively impossible by requiring zero false positives. That seems like an obviously unworkable standard even if getting incorrectly flagged as malicious admittedly does suck.
To their credit - Mozilla pulled it from their copy of the safebrowsing list and no longer reports it as malicious. Google does though.
Google also has no contact in place to appeal, and I've provided written contact information if they have any actual evidence of abuse that I can prevent.
They have had these reports for more than 10 months now, and I resubmit roughly once every week or so.
The software does have disclaimer of warranties and limits on liability to the purchase price as part of the terms of use [2]
[1] https://www.prnewswire.com/news-releases/consumers-file-clas...
[2] https://www.microsoft.com/en-us/legal/terms-of-use [note: I am not 100% certain that this is the TOU specifically applicable to MS AM but most TOU look similar]
> Microsoft Defender is detecting the latest version of Tor Browser as malware because it is using a new heuristic detection method that is designed to identify Trojans that use Tor to hide their activity. However, the heuristic method is too broad and also flags the Tor Browser itself as malware.
The lack of consideration for the impact is what makes it bad faith; they clearly didn't care to properly test it, or did and didn't care that they were also flagging the browser itself. I'm sure quite a few people thing the Tor browser doesn't have a legitimate use.
If it’s so easy that only incompetence or malice could explain it, why don’t you go work for them and fix it? I’m sure that people who have spent decades in the field would appreciate your wisdom.
This fruit could only be lower-hanging if it shipped with Windows.
If they can't be bothered to look for the single most obvious non-malicious use of the thing they are trying to detect, it says very concerning things. Things like "we beta test our file removal tool in production", except "production" is "millions of unwitting people's PCs" rather than some website.
Not that poster, but I'll answer your question and challenge happily.
>why don’t you go work for them and fix it?
Because it wouldn't be mine and would never be in any way, and I don't trust those businesses and the executives that end up running them, either as responsible stewards, or fundamentally speaking based on their incentive structure.
>I’m sure that people who have spent decades in the field would appreciate your wisdom.
You mean corporations/orgs, or actually people? The people almost universally do. The corps/orgs on the other hand have liberally demonstrated their appreciation by acquiring the largest shared repositories of code and craftsmanship humanity has hitherto generated, and used that corpus in order to do everything possible to decrease their reliance on hiring people they might have to actually pay, or who might tell them no when they demand someone build something unethical.
So again, comes down to trust. Pretty sure you were setting up a sarcasm burn, but I figured I'd take you at face value, and threw in rendering the elephant in the room.
I know. I'm spouting anathema to the business peeps in the room, but I'm pretty sure the makers in the room know where I'm coming from.
The people doing that are shaving bytes, fitting music and 3D graphics in self-contained executables smaller than many HN posts. Having enough space for malware after that would be insane.
The reason these are often flagged as malware is that they are typically using runtime compression and a variety of tricks to save space, these techniques are unusual in legitimate programs and common in malware. Malware scanners could add support for the likes of crinkler and kkrunchy, but these are probably too niche to care.
Scanners could discriminate. These productions are often compressed with well known packers. It would be a "simple" matter of unpacking the file and scanning the result executable, which is often just a bunch of graphics and sound calls. But that's significant work for such a niche application. These tiny packers are also way more resource hungry than their size would suggest.
I wonder if that might also expose some attack-surface, like with "zip bombs".
win32 shellcode for downloading the real malware could very easily fit even in a 4k intro.
There's an easy definition: does it give value to the user, or act against the user's interests? The former isn't, the latter is.
Of course, by that definition, Windows itself would be considered malware.
I suspect the other comment here referencing libel is why "potentially unwanted" is another category that they often use.
Here's Microsoft's definition: https://learn.microsoft.com/en-us/microsoft-365/security/int...
Next time you propose a definition, try to break it as an adversary as a test.
It is not the first time they do this.
https://forum.torproject.org/t/torbrowser-12-5-6-no-longer-f...
"With the latest signature database (1.397.1910.0), tor.exe is no longer considered a trojan by Windows Defender."
Reportedly, mass removal of Tor Browser happened, and damage is done: a lot of privacy/security stuff disabled, couldn't be used, some won't be reinstalled, there's extra vulnerability at reinstallation time, etc.
And the demonstration that Microsoft can easily do this is of interest to people tho don't want that kind of thing to happen, as well as to people who would like that capability.
Also, this is Microsoft actively removing a competing Web browser (after long ago being put on notice about sneakiness around competing browsers specifically).
Responding to the call to flag the post, I gave examples of impact, and why it's newsworthy and the post shouldn't be flagged just because Microsoft stopped the behavior after the damage had been done.
That's pre-established as major industry and business news, so it's an additional reason not to flag the post.
Please tell me how, good sir. Not replace, not turn off temporarily until the next day or the next restart when it turns on again automatically. Tell me, how do I turn off Windows Defender real time protection in a way that I can turn it on when I need it and turn it off when I don't.
As far as I know, It's not possible without 3rd party tools AND in a way that will persist (even after Windows updates).
turning it off is temporary
if you disable the service it gets re-enabled, if you delete the service it comes back, if you delete the executable it comes back
what does seem to work is removing all permissions to it in safe mode
Pretty much every platform with hash-based antivirus can do this. It's bad, but so is the fact that Tor on iPhone can't use the same browser engine and privacy patches as Android/Desktop does. The average user is far-removed from caring about their OS vendor's power, apparently.
Linux offers the opposite: I’ll just do what you want.
Windows has a fun alternative: you can customize things but I’ll also change things, we’ll handle conflicts by rolling the dice.
Which would be a good feature request for Defender, make it automatically do that in the event of a legitimate EXE whose detection status changes after it has been quarantined.
I see no malice here.
Third-party AVs are a crapfest of dark patterns and false positives and resource hogging, if you install one and it does something bad that's kind of on you.
But Windows Defender is built into the OS and enabled by default.
Tor.exe should certainly be in a list of top 1000 common software packages that any tester would want to ensure don't get flagged and quarantined/deleted in a new virus definitions database. An update candidate that went out to a fraction of a percent of installs or to Microsoft's own employees, scanned without taking action, and posted to a dashboard reviewed by the Defender team that a file called "tor.exe" would be flagged if they continued the rollout would have stopped this. I can think of a dozen ways that a testing process would catch this. The fact that it happens proves there's either a lot of incompetence, or malice that was able to subvert a testing process.
1. You are up to 1-2 hours behind on every update
2. If your job fails for whatever reason you're now N hours behind until an engineer fixes it.
3. Are you going to write one of these jobs for literally every good binary?
4. What happens if TOR changes any aspect of how it's packaged? Today it's a tar, tomorrow it could be a zip.
It depends on how they got here, but if they literally had a heuristic to detect use of tor and didn't think about how it would affect tor.exe then that's really bad.
See also this helpful list (getting out of date unfortunately): https://github.com/hankhank10/false-positive-malware-reporti...
My little hobby projects that I write end up getting flagged by all these ML AV systems and I don't seem to have any recourse against it as a developer.
It causes issues and general confusion by my albeit small communiy of users.
Anyhow, it turned out that apparently my hand-coded base64-decoder was sufficiently similar to a base64-decoder used in some trojan out there (which was apparently built with the same version of MSVC): removing/sufficiently rewriting my decode_base64 function made the detection go away reliably. So yeah, I believe now that those virus signatures are quite arbitrary in nature.
It’s bizarre. I built an app and it was flagged by numerous AVs, and many of them had a “submit false positive” thing which eventually removed them. There’s no way that involved manual review so I assume bad actors can do the same.
Apparently these misclassifications are extremely common, and affect certain devs more than others. For instance, I had a Go binary which was flagged for a certain Trojan/worm and it was apparently common with other Go projects on GitHub.
Heuristic detection has been a thing for literally decades, and cloud-based antivirus which uses aggregate detection has been around for almost as long. It's notable that NIST does not seem to distinguish between these and just lumps them under endpoint protection.
A corporate-enforced inscrutable system that uses cryptography and OCSP to potentially remotely approve and deny what users run on their machines would be coveted by leaders who want to crackdown on their constituents.
I submitted the build to Microsoft for verification and it reports totally clean. Gee, thanks.
We also get Defender warnings for anything that isn't signed. We also get Defender warnings for things that are signed. Apparently we have to pay an extra couple hundred dollars a month for the "real" signing certificate. The one we already pay for apparently isn't secure enough to disable Defender warnings?
Sounds like an absolute racket to me
[1] - https://www.virustotal.com/gui/file/88c33af6f1963eb94683be1f...
To no one's surprise it was hacked, but what was quite amusing is what the hacker wannabe installed... RDPGuard to protect 'his' machine from other hacker wannabees.
Also years ago mIRC was a popular component of the Windows 'rootkits' because it has control and communications built-in.
Yes, Tor is used by malware to securely communicate so it's no wonder it can trigger AV. Refer to [0] for details.
I think this was, at worst, a temporary issue that was resolved.
This led to a situation where it decided to delete all of the shortcuts to apps, leading end users to believe all of their apps were removed.
If there is malware on a machine, it's already compromised and needs to be reimaged rather than selectively, haphazardly repaired through so-called "remediations". There should be no malware on a machine to begin with by disallowing running random software from untrusted sources. Signature-based anti-malware is a last line of defense, reactive security often unable to prevent a machine from being compromised as it already happened.
Another issue is that only a fraction of malware ever has signatures for them by either being too new or not widely seen.
A final problem is mis-categorizing things as "malware" when they do no harm but do things certain factions of people don't like: remote control, recover passwords, and pirate keygens.
About 2 months ago, Microsoft Defender's Enterprise web filter started blocking all requests to the Brave browser domain including their search.
I've brought this up in a couple places and I've only gotten vague responses about how Brave supposedly had "malware" a couple years ago. That still does little to explain the recent addition to the blocklist, however.
> Microsoft Defender is detecting the latest version of Tor Browser as malware because it is using a new heuristic detection method that is designed to identify Trojans that use Tor to hide their activity. However, the heuristic method is too broad and also flags the Tor Browser itself as malware.
TLDR: Microsoft Defender is identifying any app trying to connect over Tor. The idea is malware sometimes uses Tor network to phone home, so detecting that would be a signal of potential malware.
Obviously a false positive for the Tor Browser itself.
(Which is why you set your AV to quarantine, not delete items, so you can overrule it immediately, make it put the data it flagged back where it belongs, and send a false positive report so the next update, which can be as soon as the next day, won't repeat the mistake)
Yes malware was written in Delphi for much the same reasons regular programs were[1], but had low enough exposure that none of the major scanner developers bothered including reference exe's to avoid flagging harmless run-time library code.
[1]: https://en.wikipedia.org/wiki/Rapid_application_development
After I caught Windows Defender uploading my places.sqlite in my FF profile "for analysis", I permanently disabled automatic sample submission, auto-remediation, etc via group policies.
I still won't use any other AV though because they are generally even worse about making decisions without user input and don't respect group policies at all unless you are an actual enterprise customer.
I used to be work on a remote IT administration product. To be completely fair it is a foreign systems component that updated over the Internet with a goofy looking binary if you're expecting MSVC to build everything since that code was written in Go.
On the other hand, it was signed properly, and the AV vendors couldn't give two shits about not flagging it despite their customers loudly complaining. It was really rough because when AV would flag this component, IT in a lot of cases couldn't get back in to mend the pieces left.
(Yes, obviously it would be difficult at best to quantify that benefit.)
The stories are out there, they're just not delivered to your doorstep because there's no sensationalism in them with which to sell clicks and ad impressions.
You just keep updating your obfuscator/packer tool and constantly deploy new, undetected binaries.
There’s online “crypter” services which are quite cheap that will do this for you - give you a constant stream of new, unique, undetected versions of your malware executable.
AV is basically very good at blocking yesterdays threats - the shit it knows about.
Professional blackhats just factor constant evasion into their operating costs (which includes other costs like new C&C domains, VPS’s, buying traffic for installs. etc) anyway.
If the cost is more than the reward, we get less malware. This is good.
A few months ago I did some maintenance on my Dad's old laptop, found it was running one of the old spammy AVs which feel the need to install browser addons and tons of other garbage. The AV was bogging down the system hard, uninstalling it helped a lot, but then a few days later it came back begging you to reinstall it. That one left me baffled as to how anyone thought that wasn't blatant malware-style behavior intending to bypass maintenance to dupe people who are less caught up on the state of computing.
A Python script creating 10000 empty files takes 1.2s on C:, but only 0.5s on D:. Both are NTFS partitions on the same SSD, both partitions are using the default settings. (but the defaults differ: on the system drive Windows enables compatibility features such as 8dot3names, on additional partitions it does not)
There's a bigger problem, right there.
Tor Browser running on especially untrustworthy platforms should warn the user.
Are there other things affected by this?