jpillora / jpillora/chisel

Today Microsoft Security Essentials started to flag all chisel versions as a hacking tool

Open
#279 19 comments 20 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

duplicate help wanted
Dominant language
Go
Stars
16.6k
Forks
1.6k
PR merge metrics
No merged PRs in 30d

Description

Today Microsoft updated the database for security essentials and Windows Defender. Therefore, all software using chisel on Microsoft will be prevented from running because it is considered a "hack tool".
The argument is that "Hacktools can be used to patch or "crack" some software so it will run without a valid license or genuine product key."

I strongly disagree with the fact that Microsoft can just blacklist an open source tcp tunnel software library without blacklisting all such tunnels. If a software misuses an open source library the software doing so should be banned, not the underlying library providing a technical means.

The solution is to whitelist this but this is not very elegant.

This has also been discussed previously here #229 for another anti-virus vendor and is flagged as won't fix. I guess this will end up as won't / can't fix as well? But maybe we should address this with Microsoft?

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the Microsoft Security Essentials and Windows Defender detection linked in the issue, then review the prior discussion in #229. Determine whether the chisel project has an actionable change or whether resolution requires Microsoft to adjust its classification; done means documenting a decided, feasible resolution.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
networking, security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
20/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.