Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

71–80 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#71
post #16

Earlier quoted context omitted.

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

Actual bad guys, hosting $Evil on purpose, are extremely unlikely to need any "change the URL" hints.

They don't need one but having one maximizes campaign life.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#72
post #30
post #16

Earlier quoted context omitted.

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

I considered that but it didn't seem logical. If it's on purpose, it would be trivial to change the URL and then go "ok it's clean now please remove the flag" How does keeping secret (from the bad guys) where the malware is thwart the bad guys?

MS is already stopping the bad guys by blocking the domain. You are supposed to do proper IR and clean up after yourseld including finding out the cause of the compromise which MS can't help with. What happens in the real world is people delete the file or webshell and think the bad guys are gone and if MS unblocks them then the campaign continues.

Or the bad guys themselves do that pretending to be the site owner. MS analysts can only inspect the normal site and the malicious URL that has now been removed in order to unblock it.

This is how abuse and IR works, I am surprised at the naivette of the responses here.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#73
post #50
post #16

Earlier quoted context omitted.

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances. With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you ap…

I have no idea what your post is about but from MS's perspective it isn't the site owners but MS's users around the world that are victims of thr threat actor that need protection. If it truly is a compromised site then the site owner is also a victim but as owners it is also their duty to secure and cleanup their site that is currently endangering the public.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#74
post #10

Earlier quoted context omitted.

See: spam blacklists

My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".

If you can, take your business elsewhere…

Re: Ask HN: Microsoft SmartScreen is destroying our business

#75

As has already been said, there's a chance that you are compromised and don't know. Obviously keep trying to contact MS, but in the mean time I'd make as much sure as you can that they don't have a legitimate beef. If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals w…

If MS have found a compromise they should share it. Making the allegation but not disclosing any reason is just slander.

That's not actually slander/libel. Truth is an absolute defence, and that does not require you to disclose details up front. You'd only need to demonstrate truth to defend yourself if sued.

In this case I also expect it's all very carefully worded ("Be careful! This site might be trying to harm your computer") to be legal even in cases when they accidentally (and inevitably) miscategorize a site.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#77

I encountered this, I had a cloud service that I had spun up services on with some DNS records pointing to, and then abandoned. The IP address was then used by malware, but because my DNS pointed to it, my whole domain got blacklisted.

This is risky for things other than malware blacklisting. For example, the attacker can get a certificate for your domain, and then they can access any HTTPONLY and/or SECURE cookies set at the registrable domain level and impersonate your users just by getting someone to visit their page.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#78

As has already been said, there's a chance that you are compromised and don't know. Obviously keep trying to contact MS, but in the mean time I'd make as much sure as you can that they don't have a legitimate beef. If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals w…

If MS have found a compromise they should share it. Making the allegation but not disclosing any reason is just slander.

Yeah maybe, but the reality is they won't. You can shake fists at MS all day long but it won't get your business up and running. Fixing the breach (if it's not a false positive of course) will. It's not right or fair, but it is reality, and you can only control your own actions.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#79
post #76

People talking about is it a false flag, real flag... Post your SaaS URL and you'll get a free security assessment from a dozen hners.

That's undoubtedly true, but you'll also get a lot of assholes and script kiddies hoping to pwn your site for lulz, and they often don't care who gets hurt along the way. By posting you've just given them an easy legal defense. If it were me, I wouldn't do it. Not worth the risk.

I would however, probably be willing to DM people individually after doing a small amount of due diligence on their comment history. I guess it depends on sensitivity of the site and how desperate they are.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#80
post #25

Earlier quoted context omitted.

Imagine that MS replies "we detected malware spreading from your site" without any other details. What is OP supposed to do then? Won't they be just as frustrated, if not more, than before?

Just "we detected malware spreading from your site" would sure narrow things down a lot. Time to inspect the web server access logs, 'diff' the site contents with a month-old backup, etc.

They should be doing exactly that anyway.
Post reply on HN