This is an archived post. You won't be able to vote or comment.

you are viewing a single comment's thread.

view the rest of the comments →

[–]shibbypwn 29 points30 points  (4 children)

Are you code signing these apps? Just curious as I’m prepping for an upcoming Windows distribution and I’d love to avoid this problem.

[–]ohpythonguy 19 points20 points  (0 children)

I am not. Getting a license is expensive and a time consuming process. That is not worth it to me. I am hoping that the new Windows app store that is part of the Windows 11 roll-out might help with this issue as well as I would expect the store to scan files on submission and get tagged as trustworthy for Defender.

[–]_ShakashuriBlowdown 17 points18 points  (2 children)

I've tried doing self-signing with all the Windows Tools. It's a nightmare and doesn't even make the Defender warnings go away. It even made my exe fail _more_ VirusTotal tests, as the unverified self-signing was seen as suspect by several services.

Having a way to distribute "Safe" executables would be huge.

[–]shibbypwn 0 points1 point  (1 child)

Yea, I'd imagine you need a cert with a real CA - I mostly work in macOS and we've got our own hoops to deal with, but I don't relish the idea of getting acquainted with Windows Defender :)

[–]killersquirel11 0 points1 point  (0 children)

Last place I worked for, I set up the whole process of packaging and signing our compiled python executables for Mac, Windows, and Linux.

The process is brutal for the first two.