heb12 / heb12-electron

A simple Electron app for reading the Bible
https://heb12.github.io/desktop
GNU General Public License v3.0
8 stars 7 forks source link

.exe compilation looks suspicious #6

Closed AmazingMech2418 closed 5 years ago

AmazingMech2418 commented 6 years ago

Edit by MasterOfTheTiger: Old title ".exe compilation contains virus based on McAfee"

MasterOfTheTiger commented 6 years ago

You beat me to making this issue :P. I noticed this when installing it on my grandma’s computer. I could not even get it to install. I don’t know how to fix it. Do you have any ideas?

MasterOfTheTiger commented 6 years ago

I could not find anything on McAfee's website that would help us. I could not even find an email address that would help.

ed6767 commented 6 years ago

See https://kc.mcafee.com/corporate/index?page=content&id=KB85567

MasterOfTheTiger commented 6 years ago

@edxtech Thanks! I will look into it.

EDIT: This does not seem to be the right answer. It talks about business and login to an account...

ed6767 commented 6 years ago

It's the same email for both, I think..?

MasterOfTheTiger commented 6 years ago

I don't have McAfee, so I can't login or anything. We need to find an email.

ed6767 commented 6 years ago

I did a Scan, McAffee does say it is vulnerable software. due to it running an older, more vulnerable version of electron. I guess you need to check out this: https://github.com/electron/electron/blob/master/docs/tutorial/security.md

MasterOfTheTiger commented 6 years ago

I guess I can see about updating it. It should not be hard at all. Hopefully that fixes it.

MasterOfTheTiger commented 6 years ago

I set the new version of Electron to 1.8.4 (the newest besides the 2.0.0 betas). Can someone make an exe file and test it?

MasterOfTheTiger commented 6 years ago

Here are some of the things I have run into when downloading and installing the .exe:

  1. Chrome says that it has not been downloaded often and could be dangerous
  2. Windows asks you if you are sure you want to run the file because it looks suspicious.
  3. If you are using McAfee then shortly after you install it a notice from then will pop up saying that the file looks malicious and has been quarantined
ed6767 commented 6 years ago

This is the same with any file. They are reported as suspicious until they have been downloaded and ran enough times.

MasterOfTheTiger commented 6 years ago

@edxtech So we make a bot that downloads it over and over and over again. Great idea.

So, what do we actually do about it?

MasterOfTheTiger commented 6 years ago

I checked it out on virustotal.com and only one antivirus tripped up on it, and it was not McAfee.

MasterOfTheTiger commented 6 years ago

Confirmed for version 0.2.0 and over.

MasterOfTheTiger commented 6 years ago

I think the best way to fix this is to sign the code. It is expensive, but when this project gets bigger, we will need it.

MasterOfTheTiger commented 5 years ago

Any news on this @amazinigmech2418?

AmazingMech2418 commented 5 years ago

No news currently. I haven't actually had much time to work on this lately.

MasterOfTheTiger commented 5 years ago

No news currently. I haven't actually had much time to work on this lately.

I know, but would you mind re-testing this with Heb12 Desktop 0.3.0?

AmazingMech2418 commented 5 years ago

All good!

MasterOfTheTiger commented 5 years ago

@amazinigmech2418 Do you think we can close it then?

AmazingMech2418 commented 5 years ago

I think so.