https://forum.torproject.org/t/torbrowser-12-5-6-no-longer-f...
"With the latest signature database (1.397.1910.0), tor.exe is no longer considered a trojan by Windows Defender."
https://forum.torproject.org/t/torbrowser-12-5-6-no-longer-f...
"With the latest signature database (1.397.1910.0), tor.exe is no longer considered a trojan by Windows Defender."
Reportedly, mass removal of Tor Browser happened, and damage is done: a lot of privacy/security stuff disabled, couldn't be used, some won't be reinstalled, there's extra vulnerability at reinstallation time, etc.
And the demonstration that Microsoft can easily do this is of interest to people tho don't want that kind of thing to happen, as well as to people who would like that capability.
Also, this is Microsoft actively removing a competing Web browser (after long ago being put on notice about sneakiness around competing browsers specifically).
Responding to the call to flag the post, I gave examples of impact, and why it's newsworthy and the post shouldn't be flagged just because Microsoft stopped the behavior after the damage had been done.
That's pre-established as major industry and business news, so it's an additional reason not to flag the post.
Please tell me how, good sir. Not replace, not turn off temporarily until the next day or the next restart when it turns on again automatically. Tell me, how do I turn off Windows Defender real time protection in a way that I can turn it on when I need it and turn it off when I don't.
As far as I know, It's not possible without 3rd party tools AND in a way that will persist (even after Windows updates).
turning it off is temporary
if you disable the service it gets re-enabled, if you delete the service it comes back, if you delete the executable it comes back
what does seem to work is removing all permissions to it in safe mode
Pretty much every platform with hash-based antivirus can do this. It's bad, but so is the fact that Tor on iPhone can't use the same browser engine and privacy patches as Android/Desktop does. The average user is far-removed from caring about their OS vendor's power, apparently.
Linux offers the opposite: I’ll just do what you want.
Windows has a fun alternative: you can customize things but I’ll also change things, we’ll handle conflicts by rolling the dice.
Which would be a good feature request for Defender, make it automatically do that in the event of a legitimate EXE whose detection status changes after it has been quarantined.
I see no malice here.
Third-party AVs are a crapfest of dark patterns and false positives and resource hogging, if you install one and it does something bad that's kind of on you.
But Windows Defender is built into the OS and enabled by default.
Tor.exe should certainly be in a list of top 1000 common software packages that any tester would want to ensure don't get flagged and quarantined/deleted in a new virus definitions database. An update candidate that went out to a fraction of a percent of installs or to Microsoft's own employees, scanned without taking action, and posted to a dashboard reviewed by the Defender team that a file called "tor.exe" would be flagged if they continued the rollout would have stopped this. I can think of a dozen ways that a testing process would catch this. The fact that it happens proves there's either a lot of incompetence, or malice that was able to subvert a testing process.
1. You are up to 1-2 hours behind on every update
2. If your job fails for whatever reason you're now N hours behind until an engineer fixes it.
3. Are you going to write one of these jobs for literally every good binary?
4. What happens if TOR changes any aspect of how it's packaged? Today it's a tar, tomorrow it could be a zip.
It depends on how they got here, but if they literally had a heuristic to detect use of tor and didn't think about how it would affect tor.exe then that's really bad.