------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

OpenGD77CPS
VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sat Sep 09, 2023 10:41 pm

Someone or something has reported the OpenGD77 CPS to Google as malware. This may be a bot or possibly an individual who doesn't like the project

Anyway.

Simple solution, is to move this location.

The new location is currently

downloads/PC_CPS/Latest

but this may need to be changed.


Its possible that someone could attempt to completely get this entire site marked as malware, in which case we'll need to move to an encrypted messaging group e.g. Telegram

I'll investigate setting up a Telegram group as a precaution in case someone is trying prevent people from accessing the CPS and firmware

Any suggestions will be welcomed

iz5wga
Posts: 29
Joined: Fri Sep 18, 2020 8:19 am

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by iz5wga » Sat Sep 09, 2023 11:14 pm

Hi Roger,

I'm not a big telegram fan... actually I don't get how a full site can be moved to a chat.
Anyhow, as far as I can understand, whatever site hosted with a domain reachable via browser might fall in trouble.

Anyhow I would have something to propose such as
- selfhosted: nexctloud with authentication
- slefhosted: discourse with authentication
- slefhosted; mattermost, rocketchat
- slefhosted: whatever site, with nginx/apache authentication
- Interplanetary File System (ok, this is far the best and most unusable solution, but I wanted to mention it)
- in cloud: Discord (why not? Even TGIF is on that ;))
- in cloud: jira
If you want a "chat" might we consider matrix instead of telegram? At least it's open source and multi platform (and reachable even trough web, if necessary)

To be honest there are plenty of solutions, we just need a compromise between ease of use and resilience (but really, if you are pro-chat consider Discord over Telegram, at least you can have more rooms for each topic).

If you think, pm or mail me with what you want to achieve (want to move only the download section? The entire site? Want to turn it into chat-style?), I'll try my best to assist this great project (I'm not a coder, but I've been working some decades as unix system administrator).

'73

IZ5WGA

VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sat Sep 09, 2023 11:21 pm

iz5wga wrote:
Sat Sep 09, 2023 11:14 pm
Hi Roger,

I'm not a big telegram fan... actually I don't get how a full site can be moved to a chat.
Anyhow, as far as I can understand, whatever site hosted with a domain reachable via browser might fall in trouble.

Anyhow I would have something to propose such as
- selfhosted: nexctloud with authentication
- slefhosted: discourse with authentication
- slefhosted; mattermost, rocketchat
- slefhosted: whatever site, with nginx/apache authentication
- Interplanetary File System (ok, this is far the best and most unusable solution, but I wanted to mention it)
- in cloud: Discord (why not? Even TGIF is on that ;))
- in cloud: jira
If you want a "chat" might we consider matrix instead of telegram? At least it's open source and multi platform (and reachable even trough web, if necessary)

To be honest there are plenty of solutions, we just need a compromise between ease of use and resilience (but really, if you are pro-chat consider Discord over Telegram, at least you can have more rooms for each topic).

If you think, pm or mail me with what you want to achieve (want to move only the download section? The entire site? Want to turn it into chat-style?), I'll try my best to assist this great project (I'm not a coder, but I've been working some decades as unix system administrator).

'73

IZ5WGA
Moving would be a last resort

Possibly just putting the CPS exe's somewhere else may be enough. I can keep renaming the folder if necessary but if things get worse I'd need to put the file somewhere completely different to prevent the whole forum getting blacklisted

Re: Discord

I hear bad things about them also.

iz5wga
Posts: 29
Joined: Fri Sep 18, 2020 8:19 am

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by iz5wga » Sat Sep 09, 2023 11:24 pm

What about encrypting the exe with a known password?
I assume a bot cannot "understand" it, or at least make it downloadable after a captcha.
Just brain storming

VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sat Sep 09, 2023 11:29 pm

iz5wga wrote:
Sat Sep 09, 2023 11:24 pm
What about encrypting the exe with a known password?
I assume a bot cannot "understand" it, or at least make it downloadable after a captcha.
Just brain storming
This may not be a bot it could be a person.

iz5wga
Posts: 29
Joined: Fri Sep 18, 2020 8:19 am

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by iz5wga » Sat Sep 09, 2023 11:40 pm

Yes I see.
I meant that if the thing that makes Google accept the malware complain is the presence of an "exe" file, making it downloadable only after a captcha or making it unreadable due to encryption, might solve the problem wherever it's hosted (whatever it's in this site, dropbox-like cloud, or telegram).

Anyhow I see that if you upload the .exe to virustotal (that is owned by google, like chrome), some antivirus vendors report the CPS installer as virus.

This won't help.
https://www.virustotal.com/gui/file-ana ... MwMjY4Mw==

VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sat Sep 09, 2023 11:52 pm

Yes. I know about virus total

It seems that some antivirus simply report any files that are not signed by an authentication signature

I just tested with both the installer and only the CPS exe and both fail


Installer
https://www.virustotal.com/gui/file-ana ... MwMzMzNg==

CPS exe

https://www.virustotal.com/gui/file/efd ... ?nocache=1



So basically, Google and probably all the commerical companies are making it increasingly difficult for non commerical applications

VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sat Sep 09, 2023 11:57 pm

I doubt it will help, but I logged into Virus total and commented that its not a virus

https://www.virustotal.com/gui/file/efd ... /community

VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sat Sep 09, 2023 11:58 pm

BTW.

I'll see if I can do something on the new page, so that the download is only triggered when you press a button

i.e have the actual link exe in javascript and attempt to hide that its an exe from the scanners

VK3KYY
Posts: 7590
Joined: Sat Nov 16, 2019 3:25 am
Location: Melbourne, Australia

Re: ------------------ IMPORTANT - DOWNLOAD LOCATION CHANGED ------------------

Post by VK3KYY » Sun Sep 10, 2023 12:24 am

Interestingly Brave is not blocking

downloads/CPS/Latest/

But Firefox has started to block it.

It seems there is no granularity in this option on firefox, which is not good for FireFox as it means they are now very aligned with Google

https://support.mozilla.org/en-US/questions/922449

Post Reply