Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

61–70 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#61

I encountered this, I had a cloud service that I had spun up services on with some DNS records pointing to, and then abandoned. The IP address was then used by malware, but because my DNS pointed to it, my whole domain got blacklisted.

This is a good point, to properly "offline" your old hostnames and IPs. I've seen many of these cases where stale DNS started pointing to $BAD_THING

Re: Ask HN: Microsoft SmartScreen is destroying our business

#62
post #29

Quoted post unavailable.

> Too many Microsoft shills here. Can you quote one of the shills? I see people saying that OP should verify that it's a false flag. Are those the shills to whom you're referring?

Given the second sentence of 'Microsoft should be able to state exactly what is wrong.', then they probably mean these:

https://news.ycombinator.com/item?id=33037323

https://news.ycombinator.com/item?id=33037211

And these ones showed up right after they posted:

https://news.ycombinator.com/item?id=33037364

https://news.ycombinator.com/item?id=33037349

Edit: actually that first one was after they posted too? So their comment may not have been accurate the second they made it, but three comments defending microsoft's secrecy showed up in the next five minutes.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#66

Earlier quoted context omitted.

The government desperately needs to step in and regulate these automated "destroy your business" practices.

Totally. It should be illegal for Edge, Chrome and other browsers to take any measures, such as a little warning, in an attempt protect users from malware. I see no way that getting the government involved in this could go badly.

Another anti-trust suit perhaps.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#67
post #54

I'm so sick and tired of businesses abusing my trust and/or not publishing their security breaches that I'm using plus ('+') email addresses everywhere, i.e.: my_account+site_address@example.org for regular interactions, or: my_account+site_address-current_date@example.org for one-off interactions. Won't help with historical abuses/data breaches but it'll certainly be invaluable in the future.

About 10% of sites don't allow you to use a plus sign in your email address.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#68

As has already been said, there's a chance that you are compromised and don't know. Obviously keep trying to contact MS, but in the mean time I'd make as much sure as you can that they don't have a legitimate beef. If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals w…

If MS have found a compromise they should share it. Making the allegation but not disclosing any reason is just slander.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#69

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

In this case, Microsoft "SmartScreen" is a big culprit. Just google "microsoft smartscreen false positive". Tons of support forums on this including even some product companies explaining to their users on how to unblock because of false positives. It happened to some of our customers as well and it is very difficult to explain why we cannot do much except them asking to whitelist somehow or turning off this stupid t…

Both can be true.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#70
post #16

Earlier quoted context omitted.

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

If you're hosting it on purpose, then you already know that it's the culprit and would've tried to change it anyways. I don't really see a scenario where telling the person who opened the ticket what the issue is would weaken the security measures or detection strategy.

That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.
Post reply on HN