Bitcoin Forum
November 09, 2024, 05:04:06 AM *
News: Latest Bitcoin Core release: 28.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: #BitcoinIsSafe & #WasabiIsSafe | false positives campaigns  (Read 244 times)
hugeblack (OP)
Legendary
*
Offline Offline

Activity: 2688
Merit: 3969



View Profile WWW
January 14, 2020, 10:13:32 AM
Merited by TryNinja (1), Chikito (1)
 #1

I saw this tag spread on Twitter so I liked to share it here.
Many of Wasabi's wallet users have reported that computer security algorithms for Avira, Bitdefender, and Kaspersky confuse Bitcoin full nodes with unwanted mining software (that runs in the background and steals processing power) hence Wasabi and Bitcoin core is known as "system infections."
Consequently, this campaign began to encourage members to report anti-virus software to regard BitcoinCore and Wasabi as "false positives."


Read more ----> https://bitcoinmagazine.com/articles/wasabi-wallet-launches-bitcoinissafe-campaign-to-counter-erroneous-antivirus-detections
Report using ---> https://docs.wasabiwallet.io/building-wasabi/FalsePositive.html#email-template

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
pooya87
Legendary
*
Offline Offline

Activity: 3626
Merit: 11020


Crypto Swap Exchange


View Profile
January 15, 2020, 04:16:51 AM
Merited by mk4 (1), hugeblack (1), o_e_l_e_o (1)
 #2

i don't want to be a wet blanket but this doesn't seem like a useful move to me. people shouldn't rely on their anti viruses in first place. as they have false positives, they also have the opposite (not recognize malicious software). example is all the fake Electrums that have been stealing users money over the past year.

a much better campaign would have been to encourage users to verify not trust. whether their anti virus tells them something they've downloaded is a malware or not they should not trust that thing until they verify it. AV is there as a suggestion, that is why they all have an option to whitelist files.

both bitcoin core and wassabi wallet have PGP signatures that could be verified for those who download the binaries and want to trust the developers + others who have verified the binaries' hashes. and they both support deterministic builds which means anybody can compile the code and verify if the hash of their build matches the hash of what the team released. and being open source means the source has been looked at and the more popular the project the less the chance of having anything malicious inside.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
hugeblack (OP)
Legendary
*
Offline Offline

Activity: 2688
Merit: 3969



View Profile WWW
January 15, 2020, 06:20:24 AM
Merited by ABCbits (1)
 #3

both bitcoin core and wassabi wallet have PGP signatures that could be verified for those who download the binaries and want to trust the developers + others who have verified the binaries' hashes.

Your words are true, but the reality is different.
I think it depends on who receives such news.
If you are a beginner, it is difficult for you to choose who you trust and therefore the default trust in antivirus programs as a first step for these beginners, "it is easier to setup and check."
Getting a negative feedback from these applications is a negative indicator for anyone who wants to use Bitcoin.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pmalek
Legendary
*
Offline Offline

Activity: 2940
Merit: 7547


Playgram - The Telegram Casino


View Profile
January 15, 2020, 09:52:31 AM
 #4

example is all the fake Electrums that have been stealing users money over the past year.
My guess would be that the same Anti Virus vectors that flag the official Electrum software as malicious would also flag the fake versions.
My systems have never flagged Electrum as a malware and I wonder what would happen if I downloaded one of the fake wallets.

It is not really a malicious software when you think about it. it is used to send Bitcoin transactions just like the original Electrum releases. The only malicious part of it is the clipboard hijacker. I don't know if some of the fake Electrum wallets also come with additional malware like password stealers, keyloggers etc.

▄▄███████▄▄███████
▄███████████████▄▄▄▄▄
▄████████████████████▀░
▄█████████████████████▄░
▄█████████▀▀████████████▄
██████████████▀▀█████████
████████████████████████
██████████████▄▄█████████
▀█████████▄▄████████████▀
▀█████████████████████▀░
▀████████████████████▄░
▀███████████████▀▀▀▀▀
▀▀███████▀▀███████

▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
 
Playgram.io
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀

▄▄▄░░
▀▄







▄▀
▀▀▀░░
▄▄▄███████▄▄▄
▄▄███████████████▄▄
▄███████████████████▄
▄██████████████▀▀█████▄
▄██████████▀▀█████▐████▄
██████▀▀████▄▄▀▀█████████
████▄▄███▄██▀█████▐██████
█████████▀██████████████
▀███████▌▐██████▐██████▀
▀███████▄▄███▄████████▀
▀███████████████████▀
▀▀███████████████▀▀
▀▀▀███████▀▀▀
██████▄▄███████▄▄████████
███▄███████████████▄░░▀█▀
███████████░█████████░░
░█████▀██▄▄░▄▄██▀█████░
█████▄░▄███▄███▄░▄█████
███████████████████████
███████████████████████
██░▄▄▄░██░▄▄▄░██░▄▄▄░██
██░░░░██░░░░██░░░░████
██░░░░██░░░░██░░░░████
██▄▄▄▄▄██▄▄▄▄▄██▄▄▄▄▄████
███████████████████████
███████████████████████
 
PLAY NOW

on Telegram
[/
o_e_l_e_o
In memoriam
Legendary
*
Offline Offline

Activity: 2268
Merit: 18746


View Profile
January 15, 2020, 03:36:05 PM
Merited by ABCbits (1), Pmalek (1)
 #5

If you are a beginner, it is difficult for you to choose who you trust and therefore the default trust in antivirus programs
I agree with you, but perhaps we need to educate newbies a little bit about this. People think antivirus programs are completely trustworthy, based on nothing. If you believe your anti-virus or you believe your bitcoin wallet is down to trust. Both are being developed by people you (presumably) don't know personally, and don't know if you can trust. The former is likely closed source; the latter should be open source, and in the case of Bitcoin Core, Electrum, or any of the other major wallets, will have had its code widely reviewed. Even if you don't or can't review the code yourself, I'd be picking the latter.

The only malicious part of it is the clipboard hijacker.
The fake 4.0.0 Electrum wasn't a clipboard hijacker. Instead, as soon as you opened it, it would attempt to sweep your wallet to the attacker's address. Anyone who used Electrum stand-alone (as in, not paired with a hardware wallet) had all their coins lost instantly. They didn't need to copy and paste anything for this to happen.
mk4
Legendary
*
Offline Offline

Activity: 2926
Merit: 3881


📟 t3rminal.xyz


View Profile WWW
January 15, 2020, 04:48:18 PM
 #6

i don't want to be a wet blanket but this doesn't seem like a useful move to me. people shouldn't rely on their anti viruses in first place. as they have false positives, they also have the opposite (not recognize malicious software). example is all the fake Electrums that have been stealing users money over the past year.

a much better campaign would have been to encourage users to verify not trust. whether their anti virus tells them something they've downloaded is a malware or not they should not trust that thing until they verify it. AV is there as a suggestion, that is why they all have an option to whitelist files.

both bitcoin core and wassabi wallet have PGP signatures that could be verified for those who download the binaries and want to trust the developers + others who have verified the binaries' hashes. and they both support deterministic builds which means anybody can compile the code and verify if the hash of their build matches the hash of what the team released. and being open source means the source has been looked at and the more popular the project the less the chance of having anything malicious inside.

I'm for users verifying what they download and install on their computer, but I can guarantee it's going to be a difficult move to convince everyone, especially the older crowd, and the less tech-savvy crowd. You're probably underestimating how much people don't even know how to navigate computers that much, but instead rely too much on their iPhones. Having an antivirus put's their minds at peace I guess, even though I personally don't use antiviruses either. I'd say giving publicity to these false positives for both of these wallets is a decent temporary solution.

» t3rminal.xyz «
Telegram Alert Bots for Traders
Wind_FURY
Legendary
*
Offline Offline

Activity: 3094
Merit: 1930



View Profile
January 28, 2020, 09:45:22 AM
 #7

i don't want to be a wet blanket but this doesn't seem like a useful move to me. people shouldn't rely on their anti viruses in first place. as they have false positives, they also have the opposite (not recognize malicious software). example is all the fake Electrums that have been stealing users money over the past year.


But the movement is not only for experienced users like you. It's for the newbies, which the false-positives might discourage/scare from running harmless open source software "because their anti-virus said so". It's a hindrance.

██████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
██████████████████████
.SHUFFLE.COM..███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
█████████████████████
████████████████████
██████████████████████
████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
██████████████████████
██████████████████████
██████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
███████████████████████
.
...Next Generation Crypto Casino...
pooya87
Legendary
*
Offline Offline

Activity: 3626
Merit: 11020


Crypto Swap Exchange


View Profile
January 29, 2020, 05:24:04 AM
 #8

i don't want to be a wet blanket but this doesn't seem like a useful move to me. people shouldn't rely on their anti viruses in first place. as they have false positives, they also have the opposite (not recognize malicious software). example is all the fake Electrums that have been stealing users money over the past year.

But the movement is not only for experienced users like you. It's for the newbies, which the false-positives might discourage/scare from running harmless open source software "because their anti-virus said so". It's a hindrance.

i get that and hugeblack already pointed this out too.
all i was saying is that we should be trying to educate "newbies" correctly so instead of saying "lets fix the false positive of AVs and continue trusting them" say "don't trust anything, verify everything". i've already included an example of how trusting an AV could cut both ways.

█▀▀▀











█▄▄▄
▀▀▀▀▀▀▀▀▀▀▀
e
▄▄▄▄▄▄▄▄▄▄▄
█████████████
████████████▄███
██▐███████▄█████▀
█████████▄████▀
███▐████▄███▀
████▐██████▀
█████▀█████
███████████▄
████████████▄
██▄█████▀█████▄
▄█████████▀█████▀
███████████▀██▀
████▀█████████
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
c.h.
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀█











▄▄▄█
▄██████▄▄▄
█████████████▄▄
███████████████
███████████████
███████████████
███████████████
███░░█████████
███▌▐█████████
█████████████
███████████▀
██████████▀
████████▀
▀██▀▀
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!