Hey to everyone that can not download or install Vital, please turn off Windows Security, Vital is 100% safe, its just a new app and it takes a bit of time for windows to recognize them as safe
I’m going to respectfully disagree. A few days ago, the installer didn’t trigger this warning (I bought early access). Now it is. I am 100% certain Matt isn’t doing anything nefarious, but I don’t know for sure that somebody didn’t manage to hack into his AWS account and inject malware into his binary.
It’s unlikely, yes, but considering the risk of borking my Windows laptop, I’m going to wait. I have been following this issue since last night, and I still don’t see an official response from Matt.
chill out dude, it’s either a false positive or someone has compromised the installer in some way which is just as shitty for *Matt, if not more so, than for you or anyone else.
To hopefully ease everyone’s mind, I’m not a hacker and have a long history of making music software (working at Cakewalk + Harmonix, Helm before Vital, etc). I would be ruining my reputation and business model by packaging a virus in Vital.
For those of you concerned about a hacker getting into my servers. I just verified the builds on S3 where the builds are stored and everything matches what I uploaded and signed.
As for why Vital is getting marked as a virus, there could be a few reasons why.
There are two types of code signing signatures to, there’s a ‘regular’ version and an ‘extended validation’. I opted for the regular version because I thought at minimum it would take care of this issue. After talking with more audio plugin developers I’ve come to the conclusion that validating using this ‘regular’ code signing certificate is pretty much useless.
There have been a massive number of downloads in a single day. Massive download numbers + my brand new code signing certificate makes Vital look like a Trojan to auto malware detectors. I probably tripped some auto protection mechanism in Windows and/or Chrome after a certain number.
I’m actively trying to fix this but it may take some time to get through to these companies and switch over to an ‘extended validation’ code signing certificate. Thanks for you’re understanding and patience!
Thanks for the good information, @Tytel! Sucks that this is happening, hopefully it’s resolved sooner rather than later. In the meantime, I’ve just manually allowed it within SmartScreen.