Browsing the posts from the main page makes Bitdefender go crazy. Why?

OrangeCorvus@lemmy.world to Lemmy.World Announcements@lemmy.world – 12 points –

I was just browsing the main page and looking at threads, any idea why Bitdefender thinks some pages are suspicious?

The first one with the infected, I think it was a post and it had some pictures, didn't click on anything, just loaded the post.

4

I think Lemmy fetches a lot of thumbnails/embeds from the instance where the user who posted the post lives.

And a lot of Lemmy instances are on domains registered like yesterday, in TLDs that are rarely used by companies, and are extremely unpopular websites. You might be the first Bitdefender user to query them.

So Bitdefender sees that you went to one site and immediately started requesting a bunch of weird stuff from a domain you didn't visit, which nobody else has ever visited as far as they know, and which was registered yesterday out in the boonies of .space or whatever, and decides it must be evil since it's so dang weird and is exactly what would happen if you were being attacked via some kind of cross-site scripting hole.

It is a worrying trend nowdays to have security software decide that anything it doesn't know about must be evil. Even Windows will block you from running programs you download that it thinks nobody else has ever downloaded.

Honestly, lots of reasons. Malware links, new sites, it's a bit of the wild west, I use Jerboa on mobile, with RethinkDNS and Orbot (mobile Android), my logs are an absolute shitfight, with what to block, and what to allow. Give it time, it will settle. New sites (instances) may, or may not be malicious. I do not know what ,if any, protection Lemmy provides against malware. Good luck, we're all counting on you you