Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

31–40 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#31

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

In this case, Microsoft "SmartScreen" is a big culprit. Just google "microsoft smartscreen false positive". Tons of support forums on this including even some product companies explaining to their users on how to unblock because of false positives. It happened to some of our customers as well and it is very difficult to explain why we cannot do much except them asking to whitelist somehow or turning off this stupid thing.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#32
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

should ? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take th…

They're already checking where the malware is when reviewing a report or unlisting request. The email template would need exactly one value: the URL they found.

Likely they already store this info somewhere so that the next time anyone reviews the domain, the reviewer cannot overlook it. In that case, the system could be completely automated, sending the info to the hostmaster or tech-c of the domain or something.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#33
post #22

Do you allow user generated content at all that is internet accessible? Have you looked up your domain and IPS in virustotal and other similar services? Can users host any type of file that can be accessed without authentication? Yes/no/yes to the above questions means that is where you should look.

We’re a web analytics product. We don’t show any user generated content. All pages (except login/signup/etc..) are behind an authwall.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#34
post #6

I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.

I am currently in a 3 day Facebook ban because I posted an NIH (National Institute of Health, peak legitimacy right here) link which was meant to help someone understand something.

Unfortunately, the medical procedure it covered thumbnailed down (in the generated preview) to a fairly graphic photo of a woman's private parts being operated on... and that resulted in an uncontestable instaban. No humans can be reached about it, of course.

I hate automated flagging. Not only can I now not help that person on the platform in question, but I am now discouraged from even using that product further (probably not a bad thing in FB's case!)

Re: Ask HN: Microsoft SmartScreen is destroying our business

#36
post #3

Have you considered that your service, unbeknownst to you, may have been compromised at some point in time, and the source of some phishing page or other malicious material? Besides that possibility, if your business is truly being "destroyed," have you contemplated retaining counsel to escalate things with Microsoft?

This. Also: magecart for TTPs.

OTOH it might not be. LinkedIn flagged a domain I own as malware and pointed fingers at Spamhaus. Spamhaus had it flagged, but removed the flag when I objected. Their management claimed sites which they flag did something to deserve it on LinkedIn, but never said what. (There is no malware. It's just cranky, especially to bots.) I doubt that Spamhaus' intent was that someone should publicly mark it as malware for other parties though.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#37
post #25
post #18

Earlier quoted context omitted.

No it doesn't. It simply tells that the detection system _has_ worked.

Imagine that MS replies "we detected malware spreading from your site" without any other details. What is OP supposed to do then? Won't they be just as frustrated, if not more, than before?

Just "we detected malware spreading from your site" would sure narrow things down a lot. Time to inspect the web server access logs, 'diff' the site contents with a month-old backup, etc.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#38
post #18

Earlier quoted context omitted.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

No it doesn't. It simply tells that the detection system _has_ worked.

If they tell you the steps you have to take to get off the shit list then its not hard to reverse engineer how to avoid being on the shit list.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#39
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

should ? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take th…

If they provided proof they wouldn't get "we swear our website is actually fine" tickets. Or if they did, it would be easy to resolve them: Post the proof.

If you launch a product that targets other businesses and has the capability of destroying them, you better take responsibility for that.

Post reply on HN