Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

51–60 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#51
post #10

Earlier quoted context omitted.

See: spam blacklists

My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".

I hate being demanded to set up voice verification. Even more annoying when the representative suggests that you active your voice despite you saying no. Voice verification is such a weak security system.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#52

Earlier quoted context omitted.

Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

Yeah, I don't buy this one. "Your site is participating in a phishing campaign, here is an example: $URL" doesn't tell a malicious party anything they didn't already know from the original MS warning.

In fact, I'll go further. MS owns we an explanation why they are warning on any random site. Not only the site's owner.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#54
I'm so sick and tired of businesses abusing my trust and/or not publishing their security breaches that I'm using plus ('+') email addresses everywhere, i.e.:

my_account+site_address@example.org

for regular interactions, or:

my_account+site_address-current_date@example.org

for one-off interactions.

Won't help with historical abuses/data breaches but it'll certainly be invaluable in the future.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#55
post #28

Get a lawyer. Ask for an injunction by a court. Make smartscreen liable for the damage they do to you.

Yes, poster needs to talk with a lawyer. Ideally, a company would do this on Day One of the situation.

And keep all the data you can (from Web, marketing, ads, etc.), to try to figure out and show how much this is costing you. "And here's where the hockey stick snapped in half."

Re: Ask HN: Microsoft SmartScreen is destroying our business

#56
As has already been said, there's a chance that you are compromised and don't know. Obviously keep trying to contact MS, but in the mean time I'd make as much sure as you can that they don't have a legitimate beef.

If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals with breach detection," though that is good advice.

For what it's worth I went through something similar to this not too long ago, so I know how maddening it is. My client never found any breach (though I did find some PHP library CVE's that could have conceivably been chained together to wreak some havoc), but I ended up rebuilding their prod environment clean and the flag went away on it's own after a couple days, probably because whatever malware was in there had disappeared.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#57

Earlier quoted context omitted.

Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.

> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.

This is why well-regarded justice systems don't disclose anything about why they arrested someone and are jailing them indefinitely. It'd give criminals too much of an edge otherwise, and would surely be unworkable and lead to violent anarchy in short order.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#58
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

Saying they detected malware already does that.

Being slightly more specific shouldn't be a problem.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#59
post #6

I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.

The government desperately needs to step in and regulate these automated "destroy your business" practices.

Totally. It should be illegal for Edge, Chrome and other browsers to take any measures, such as a little warning, in an attempt protect users from malware. I see no way that getting the government involved in this could go badly.
Post reply on HN