Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…
Ask HN: Microsoft SmartScreen is destroying our business
31–40 of 206 posts
Re: Ask HN: Microsoft SmartScreen is destroying our business
#32Earlier quoted context omitted.
Should they then not just reply with "You're on the list because of the malware payload at "?
should ? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take th…
Likely they already store this info somewhere so that the next time anyone reviews the domain, the reviewer cannot overlook it. In that case, the system could be completely automated, sending the info to the hostmaster or tech-c of the domain or something.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#33Do you allow user generated content at all that is internet accessible? Have you looked up your domain and IPS in virustotal and other similar services? Can users host any type of file that can be accessed without authentication? Yes/no/yes to the above questions means that is where you should look.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#34I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.
Unfortunately, the medical procedure it covered thumbnailed down (in the generated preview) to a fairly graphic photo of a woman's private parts being operated on... and that resulted in an uncontestable instaban. No humans can be reached about it, of course.
I hate automated flagging. Not only can I now not help that person on the platform in question, but I am now discouraged from even using that product further (probably not a bad thing in FB's case!)
Re: Ask HN: Microsoft SmartScreen is destroying our business
#35Re: Ask HN: Microsoft SmartScreen is destroying our business
#36Have you considered that your service, unbeknownst to you, may have been compromised at some point in time, and the source of some phishing page or other malicious material? Besides that possibility, if your business is truly being "destroyed," have you contemplated retaining counsel to escalate things with Microsoft?
OTOH it might not be. LinkedIn flagged a domain I own as malware and pointed fingers at Spamhaus. Spamhaus had it flagged, but removed the flag when I objected. Their management claimed sites which they flag did something to deserve it on LinkedIn, but never said what. (There is no malware. It's just cranky, especially to bots.) I doubt that Spamhaus' intent was that someone should publicly mark it as malware for other parties though.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#37Earlier quoted context omitted.
No it doesn't. It simply tells that the detection system _has_ worked.
Imagine that MS replies "we detected malware spreading from your site" without any other details. What is OP supposed to do then? Won't they be just as frustrated, if not more, than before?
Re: Ask HN: Microsoft SmartScreen is destroying our business
#38Earlier quoted context omitted.
> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.
No it doesn't. It simply tells that the detection system _has_ worked.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#39Earlier quoted context omitted.
Should they then not just reply with "You're on the list because of the malware payload at "?
should ? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take th…
If you launch a product that targets other businesses and has the capability of destroying them, you better take responsibility for that.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#40Not sure if they solved it, but might be helpful asking them.