Earlier quoted context omitted.
See: spam blacklists
My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".
Ask HN: Microsoft SmartScreen is destroying our business
51–60 of 206 posts
Re: Ask HN: Microsoft SmartScreen is destroying our business
#52Earlier quoted context omitted.
Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.
> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.
In fact, I'll go further. MS owns we an explanation why they are warning on any random site. Not only the site's owner.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#53Re: Ask HN: Microsoft SmartScreen is destroying our business
#54my_account+site_address@example.org
for regular interactions, or:
my_account+site_address-current_date@example.org
for one-off interactions.
Won't help with historical abuses/data breaches but it'll certainly be invaluable in the future.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#55Get a lawyer. Ask for an injunction by a court. Make smartscreen liable for the damage they do to you.
And keep all the data you can (from Web, marketing, ads, etc.), to try to figure out and show how much this is costing you. "And here's where the hockey stick snapped in half."
Re: Ask HN: Microsoft SmartScreen is destroying our business
#56If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals with breach detection," though that is good advice.
For what it's worth I went through something similar to this not too long ago, so I know how maddening it is. My client never found any breach (though I did find some PHP library CVE's that could have conceivably been chained together to wreak some havoc), but I ended up rebuilding their prod environment clean and the flag went away on it's own after a couple days, probably because whatever malware was in there had disappeared.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#57Earlier quoted context omitted.
Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.
> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#58Earlier quoted context omitted.
Should they then not just reply with "You're on the list because of the malware payload at "?
Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.
Being slightly more specific shouldn't be a problem.
Re: Ask HN: Microsoft SmartScreen is destroying our business
#59I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.
The government desperately needs to step in and regulate these automated "destroy your business" practices.