Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

11–20 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#11
post #3

Have you considered that your service, unbeknownst to you, may have been compromised at some point in time, and the source of some phishing page or other malicious material? Besides that possibility, if your business is truly being "destroyed," have you contemplated retaining counsel to escalate things with Microsoft?

Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material?

Ye, it tells bad actors how the detection system works.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#12
post #3

Have you considered that your service, unbeknownst to you, may have been compromised at some point in time, and the source of some phishing page or other malicious material? Besides that possibility, if your business is truly being "destroyed," have you contemplated retaining counsel to escalate things with Microsoft?

Yea, the first thing I would do is rigorously determine whether the problem is actually a false positive (note: not a "false flag" which is something entirely different). Seems a bit early to jump straight to "it must be a competitor."

Re: Ask HN: Microsoft SmartScreen is destroying our business

#14

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Should they then not just reply with "You're on the list because of the malware payload at "?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#16
post #14

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Should they then not just reply with "You're on the list because of the malware payload at "?

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#17
post #10
post #6

I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.

See: spam blacklists

My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".

Re: Ask HN: Microsoft SmartScreen is destroying our business

#18

Earlier quoted context omitted.

Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

No it doesn't. It simply tells that the detection system _has_ worked.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#19
post #14

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Should they then not just reply with "You're on the list because of the malware payload at "?

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block.

Not saying that isn't shit or frustrating.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#20

Earlier quoted context omitted.

Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

The Catch-22 enabling "corporate responsibility shirking".
Post reply on HN