Author Topic: On download "xLights64_2020_46.exe was blocked because it could harm your device  (Read 656 times)

Offline johnpucci@comcast.net

  • Newbie
  • *
  • Posts: 2
    • View Profile
Tried a number of times to download xLights and always fails with the message "xLights64_2020_46.exe was blocked because it could harm your device."

Offline Ebuechner

  • Hero Member
  • *****
  • Posts: 750
    • View Profile
That's normal. I have to turn off my virus software every time I download.
Windows will also try to block the install you have to tell it to run anyway.

Offline johnpucci@comcast.net

  • Newbie
  • *
  • Posts: 2
    • View Profile
Ok thanks, will try that.

Offline Henry

  • Newbie
  • *
  • Posts: 12
    • View Profile
I hit this also.  I went ahead and actually submitted (for an earlier version) the file for analysis to Microsoft, and they indicated that particular one I uploaded had no known virus/etc. 

However, this problem will continue to occur with each and every release, until the release binaries are digitally signed.

For now, I download xLights (bypassing these warnings), but leave the file alone for a few weeks, before running it through an online virus scanners a few weeks later.

I really hope adding digitally signed releases is on on the xLight roadmap.

Offline Gilrock

  • Supporting Member
  • Hero Member
  • *
  • Posts: 6946
    • View Profile
Its like child safety locks...eventually you learn how to deal with them...lol

Offline Henry

  • Newbie
  • *
  • Posts: 12
    • View Profile
Sure, when you've never experienced the need for anti-malware, it all seems like an annoyance.  Similarly, once you've experienced the pain and frustration of malware, and the time it takes to rebuild, then suddenly security becomes important.

xLights HAS a solution to making the releases trustable ... and it's a well understood process.  Releases must be digitally signed, to provide a digital identity for the software and provide evidence that the software is what the author intended to provide.  This also allows some level of trust to "carry over" between versions, because it's tied to the same identity.  The digital signature also provides users with the ability to know that the software hasn't been changed since it was signed (including after download), which provides additional protection.  Digital signing of releases is a strong indication of a software's maturity.

I do wish that the process of securely signing software (both the binaries and the installers) was much easier, and especially wish that popular open-source programs had available a way to digitally size at zero/low cost.



Offline Gilrock

  • Supporting Member
  • Hero Member
  • *
  • Posts: 6946
    • View Profile
You're probably sitting in your house alone wearing a mask aren't you.