Worrisome insecure binary install

Have an issue with VPaint or VGC software? Ask your question here.
Post Reply
tdunning
Posts: 1
Joined: Mon Aug 10, 2015 2:07 am

Mon Aug 10, 2015 2:12 am

Installing on OSX, I get a warning about an unauthorized source of a binary.

On investigation, the warning details show sourceforge as the source of the binary. Since sourceforge has such a problematic history of inserting adware (see references below), that made me abort the installation.

Is there any way to get a clean installer not created by sourceforge? Is there a strong reason to host vpaint there at all?

http://arstechnica.com/information-tech ... ng-adware/
https://www.reddit.com/r/technology/com ... ed_adware/
http://www.theregister.co.uk/2015/06/03 ... imp_grump/
http://arstechnica.com/information-tech ... ng-adware/

User avatar
Boris
Site Admin
Posts: 192
Joined: Thu Aug 14, 2014 9:09 pm

Mon Aug 10, 2015 6:04 pm

Thx a lot for raising this point! I didnt know about the SourceForge issue, other people commented on this on HackerNews as well. I'll definitely remove my stuff from there and never touch it again.

But note that it should be safe in this case. I created the binary myself and uploaded it on GitHub first, then exported from GitHub to SourceForge as it seemed to me that SourceForge was a more standard software repository for Windows folks. You can download the binary directly from GitHub, it will be 100% safe. :-)

Post Reply