Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

41–50 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#41
post #6

I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.

The government desperately needs to step in and regulate these automated "destroy your business" practices.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#42
post #10

Earlier quoted context omitted.

See: spam blacklists

My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".

> "my voice didn't sound like my age"

Wow, hello marginalization! I wonder where their training data set came from.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#43

Earlier quoted context omitted.

Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

No post body was provided.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#44
Similar thing happen to me. My OneDrive links that I share with clients end in their email spam folder. It took mi few weeks before I realized that few clients was still waiting for my work, because they did not have it in inbox.

I know that it is problem of email providers, but still I would like to leave OneDrive, but I cannot find alternative that is in similar price range as OneDrive (about 2 USD/month for 1TB).

Re: Ask HN: Microsoft SmartScreen is destroying our business

#47
post #16
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

If you're hosting it on purpose, then you already know that it's the culprit and would've tried to change it anyways. I don't really see a scenario where telling the person who opened the ticket what the issue is would weaken the security measures or detection strategy.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#48

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

This!

I worked with a very well-known university that unknowingly had been compromised and was being flagged for malware by various protective services.

They, assuming it was just a false positive, put up a banner at the top of their webpages that said they were falsely being flagged and that visitors should ignore any warnings and essentially shut off any protections for their website.

Meanwhile their site was compromised and attempting to dump payloads onto visitors.

Have you ensured you are not compromised?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#49
post #18

Earlier quoted context omitted.

No it doesn't. It simply tells that the detection system _has_ worked.

If they tell you the steps you have to take to get off the shit list then its not hard to reverse engineer how to avoid being on the shit list.

Yes, that's how it should work.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#50
post #16
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances.

With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you applied for credit with them. No funds are stolen. You demand they show proof. They say nope, because TTPs. So: how do I know it's a one-off, and not data theft by fraud at scale? Off goes a letter to the FTC...

Do you think like a muppet? Here is satirical example (http://athena.m3047.net/temporizing.html):

    TEMPORIZING FOUND NOT TO BE A FORM OF LYING
    
    "Temporizing", which is speculating from what we know now as to the
    motives of actors in the past and presenting that as historical fact,
    has been found not to be a form of lying. "Social proof demonstrates
    that temporizing is not lying" said a social commentator.
    
    The news was greeted optimistically as a good day for humanists and
    levels the playing field because "now the standards of proof we need
    to meet for the existence of society are the same as for religion".
    
    "People must have known about this in the past because it seems
    like they should have" said a man in the street. "Everybody who
    believes in science trusts society" said another.
Post reply on HN