Bonum Certa Men Certa

Windows Defender Flags Tor Browser as “Trojan Horse” Malware

posted by Roy Schestowitz on Oct 04, 2023

High Tor Vintage Comedy Poster

Reprinted with permission from Ryan Farmer.

Windows Defender Flags Tor Browser as “Trojan Horse” Malware.

Anti-virus software is terrible, and Microsoft’s is obviously no exception.

The fact that it flags a lot of Free and Open Source software makes me wonder if this is worse than the usual “it’s only guessing” that usually lead to false positives in anti-virus programs.

I’ve seen it flag LibreOffice, qBittorrent, PeaZip, and many other FOSS programs, but it also has flagged the latest Tor Browser.

This doesn’t surprise me. What does surprise me is that anyone wanting privacy would use Tor Browser on Windows, where on top of the spyware Microsoft builds into the OS, you have millions of other pieces of spyware, ranging from ransomware, to “Pegasus-like” government-backed malware. And since Windows has so many security problems, it has no trouble getting in.

The United States has committed cyberwarfare using Windows, to sabotage the Iranian nuclear program, with malware like Flame and Stuxnet, which set up on millions of Windows computers and completely eluded anti-virus programs for years.

China and Russia target Windows. Lots of governments do things like this.

Why do these go undetected for years? Are the government attackers really that good at hiding it, or do the anti-virus companies suck that much, or are they told not to do anything? Some of each?

On Debian, on most Linux distributions, you can just install Tor Browser Launcher and forget about it. It automatically downloads the Tor Browser and installs it and checks the signature to make sure it’s really from them and hasn’t been tampered with.

If you don’t want to persistently install a Linux system, you should at least consider running Tails in a live environment.

Again, who is even running Tor Browser on a Windows machine?

A lot of people use Tor criminally, like the multi-national band of criminals, crazies, and derelicts who attacked Techrights’ IRC server and briefly caused an outage of the site.

Tor was part of their harassment mechanism.

But other people use Tor because they need to be safe from actual government oppression or bypass the censors, and if they get caught using it, it could mean prison or death.

Even in America, which is no longer a free country, or a democracy, even looking up an abortion using a normal Web browser with Google can be used later to send you to prison, in some States.

It’s not safe to browse the Web as an American anymore. Even if you have done nothing wrong. Using it on Windows and without a reliable VPN and non-US server, and maybe Tor as well sometimes, is a serious mistake.

But Windows completely undermines the privacy of Tor. The software itself may work, but everything you do gets uploaded to Microsoft. If you download a file, Windows Defender (the same one that flagged Tor Browser as malware) can send them the file or a hash value so they know what you have. If you browse with it at all, Windows sends your keystrokes to Microsoft…..”For Spell Checking”.

If Tor Browser crashes, Windows will send an error report, including a crash dump of what was in the Tor Browser while it was in memory, leading up to the crash.

This is all stated in the Windows EULA. It’s possible it’s worse than we even know.

Even if you think you’ve “Disabled Telemetry” or something, it is still Windows.

Don’t trust it.

Other Recent Techrights' Posts

What EPO Staff, the Staff Union of the European Patent Office (SUEPO), and Europe Want and Need
Who should be served by patents?
 
EPO Cocainegate Escalates - Part I - Cocaine Abuse in Family of Campinos (President’s Office)
at the EPO's management you can do illegal drugs and still represent Europe's second-largest institution
Gemini Links 19/04/2026: Big Brother and the Telescreen, Syncing Gemini Capsule With a Makefile
Links for the day
Links 19/04/2026: Introducing “Fighting Fascism” Podcast and Kyiv Mass Shooting
Links for the day
Links 19/04/2026: Mass Layoffs at GAFAM Again (10% Laid Off), Azure Capacity Problems (Enshittification)
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, April 18, 2026
IRC logs for Saturday, April 18, 2026
GAFAM Decided to Stop 'Old' Formats From Working, Format-Shifting Treadmills Resemble the Certificate Cartel Keeping Everybody Forever Chasing Rotations
Lots of extra chores because those who control the browsers decided that "too much choice" is bad, so they'll break "old" sites and make multimedia that's "old" not work anymore (not playable)
Nothing But Vapourware Since XBox Leadership Ousted and Mass Layoffs Will Come Soon
We just don't know the exact date/s... yet
Gemini Links 18/04/2026: Guix and WikiReader
Links for the day
Network Maintenance Next Friday
We must be doing a terrific job so far given how much money gets spent trying to silence us
"The Work-to-rule is Having Effect" at the European Patent Office (EPO)
The media knows how to contact SUEPO, but it's clearly not doing it
Improving the Sites, Not Bloating Them
Sites need to evolve over time. Many conflate evolution with bloat (as if more complexity is desirable).
SLAPP Censorship - Part 50 Out of 200: The Time Staff of Law Firm Burgess Mee Was Showing Up in Letters Sent for a Serial Strangler From Microsoft
Family-friendly? No.
Next Week the Star of the "EPO Reality TV Show" Will Likely be Absent (Absconding the Tough Reality of Widespread Unrest)
He tarnishes the legacy of that surname and the country's image by spouting out lies and hurling abusive insults (lots of the "f word") at staff
Speculations That IBM's CEO is on His Way Out
IBM has mass layoffs, but the media is not covering this [...] IBM is a company in the loo, a firm in a state of rapid disintegration
Slopwatch Was Deprecated, It's Not Coming Back
LLMs that produce many words very fast (and waste a lot of energy in the process) cannot compete with authentic news sites
WELCOME to The Cyber|Show @ Geminispace!
Andy set things up this past week
Links 18/04/2026: Microsoft's PR Department (Waggener Edstrom) and CEO's Wife Buys NPR (BillPR, Now BallmerPR) as Independent/Public Service Media Dims Down
Links for the day
Gemini Links 18/04/2026: Chronic Pain and CodingFont Game
Links for the day
Links 17/04/2026: "I Hate the Internet" and Fake Wallet in Apple App Store
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, April 17, 2026
IRC logs for Friday, April 17, 2026
European Patent Office (EPO) Strikes and Other Industrial Actions Are Working: Patent Application Grants Have Collapsed
Even before the strikes happened any day of the week
SLAPP Censorship - Part 49 Out of 200: Two Americans, One Case, Recycled for Low Budget at Brett Wilson LLP and 5RB Barristers
Change one character, bill the client tens or hundreds of thousands of US dollars
Pension Contribution Increases as Another Attack on Compensation for EPO Staff (Mostly Patent Examiners)
Pension contribution increases!
Almost 1,000 IBM Layoffs Not Newsworthy (Nobody Covers It), Unlike When Snap Does It and Mentions a Celebrated - or Reviled - Buzzword
not a word regarding IBM layoffs
Behind the Scenes With Richard Stallman
If you support his ideas, even if you dislike him as a person, then you'll welcome his ability to speak about those ideas
Gemini Links 17/04/2026: "Many Problems and Inequities in the Legal System", "No Place to Hide"
Links for the day
Links 17/04/2026: SRA Breaks Its Own Rules as Solicitor Attempts Suicide, IPv6 Barely Hits 50% After 20+ Years
Links for the day
ActBlue former IT boss disappearance: Decklin Foster & Debian, Harvard suicide lab, Chris Gleason is wife, whistleblower or both?
Reprinted with permission from Daniel Pocock
Gemini Links 17/04/2026: Getting competent in NixOS and Alhena 5.5.6 Released
Links for the day
Links 17/04/2026: "We Cannot Lose Sight of Ukraine" and "When Leaders Should Resign"
Links for the day
GizChina Appears to Have Become a Slopfarm, I.e. Fake News Site With Fake Text
Don't waste a moment reading LLM slop, as at the very least it rewards plagiarism [...] Deemed to be slop also by two human beings, not just two scanners
Massive, Cross-Site Strike at the EPO Today
There's coordination across sites for maximal pressure
Dr. Andy Farnell Says "AI" is "Only a Marketing Term" for Things That Exist for "Entertainment Purposes Only"
distortion or misuse of the term (now buzzword/s) "AI"
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Thursday, April 16, 2026
IRC logs for Thursday, April 16, 2026