Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

21–30 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#21
post #14

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Should they then not just reply with "You're on the list because of the malware payload at "?

should? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take the view, and I don't totally blame them, that securing your website is your problem, and they aren't going to offer security consulting for free.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#22
Do you allow user generated content at all that is internet accessible? Have you looked up your domain and IPS in virustotal and other similar services? Can users host any type of file that can be accessed without authentication?

Yes/no/yes to the above questions means that is where you should look.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#23
post #14

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Should they then not just reply with "You're on the list because of the malware payload at "?

In this case, that sure would be helpful. Now imagine that you're running a website that is intentionally trying to trick people into installing malware. You've successfully evaded tools like Smart Screen but now you've ended up on the list.

You're not sure which one of your virus payloads set off their screen so you open a ticket. And Microsoft is supposed to tell you exactly how to get off their list again?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#25
post #18

Earlier quoted context omitted.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

No it doesn't. It simply tells that the detection system _has_ worked.

Imagine that MS replies "we detected malware spreading from your site" without any other details. What is OP supposed to do then? Won't they be just as frustrated, if not more, than before?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#27
post #16
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

Actual bad guys, hosting $Evil on purpose, are extremely unlikely to need any "change the URL" hints.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#30
post #16
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

I considered that but it didn't seem logical. If it's on purpose, it would be trivial to change the URL and then go "ok it's clean now please remove the flag"

How does keeping secret (from the bad guys) where the malware is thwart the bad guys?

Post reply on HN