Ngrok.exe Flagged as PUA
Hyporeal opened this issue ยท 1 comments
This is not inherently your problem, but I thought I would mention that several well-known security suites, including Microsoft Defender, flag ngrok.exe as a Potentially Unwanted Application (PUA). This is because Ngrok is a tool which is sometimes exploited for unauthorized access (https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=PUA:MacOS/Ngrok!MTB) (microsoft/botframework-sdk#6654).
If there aren't alternatives, I would at least suggest mentioning this on the description page, noting that this is normal and generally safe to allow in this instance. I would also note why this happens, possibly linking to resources that explain the security implications (https://news.sophos.com/en-us/2022/07/14/rapid-response-the-ngrok-incident-guide/).
It might be worth looking into alternatives like PageKite or Localtunnel, which could offer similar functionality with potentially fewer security flags, though I understand they may have other trade-offs in terms of ease of use and features.