Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

81–90 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#81

Earlier quoted context omitted.

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

Saying they detected malware already does that. Being slightly more specific shouldn't be a problem.

Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue.

Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our work, would be another thing totally.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#82

As has already been said, there's a chance that you are compromised and don't know. Obviously keep trying to contact MS, but in the mean time I'd make as much sure as you can that they don't have a legitimate beef. If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals w…

I can absolutely confirm that Edge is blocking sites based on spurious signals. One of mine is still getting a similar warning. We were given an explicit reason, namely that a form action was pointing to a different URL that looked suspicious. The URL was an API service that we also operate. I followed up with their support who said they couldn't remove the warning unless I sent a link to a page on that URL they could look at. I replied that it's an API server and does not have any pages which got no reply. Besides the fact that that's a terrible test of authenticity. We could easily apply a DNS TXT record or something but it wasn't offered as an option. MS are definitely in the wrong in my case and the only solution is to change our implementation and cross our fingers.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#83
post #6

I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.

I am currently in a 3 day Facebook ban because I posted an NIH (National Institute of Health, peak legitimacy right here) link which was meant to help someone understand something. Unfortunately, the medical procedure it covered thumbnailed down (in the generated preview) to a fairly graphic photo of a woman's private parts being operated on... and that resulted in an uncontestable instaban. No humans can be reached…

Facebook + Google hold similar levels of power as governments over our lives, and so should adopt similar structures. An independent judiciary, review bodies, ombudsmen, aldermen, etc.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#84

Earlier quoted context omitted.

My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".

If you can, take your business elsewhere…

Who does business with Wells Fargo anymore? [https://www.forbes.com/sites/eriksherman/2021/09/28/wells-fa...]

Re: Ask HN: Microsoft SmartScreen is destroying our business

#85

Earlier quoted context omitted.

The government desperately needs to step in and regulate these automated "destroy your business" practices.

Totally. It should be illegal for Edge, Chrome and other browsers to take any measures, such as a little warning, in an attempt protect users from malware. I see no way that getting the government involved in this could go badly.

?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#86
When this happened to my software product I fixed it by purchasing a Comodo EV code signing certificate. It cost me $502, it was FedExed to me in a USB, and I signed my program. Tens of thousands of installs later, I have never had an issue with smart screen. Note that there are two types of code signing certs, you want the EV Code Signing Certificate. It will instantly give your program reputation that ends the smartscreen filter issue.

Is it a corrupt system? Pay to play? Sure. But this is a guaranteed way to solve the problem. And way cheaper and 1000x faster and less of a headache than contacting an attorney (which a surprising number of people here are recommending!)

Re: Ask HN: Microsoft SmartScreen is destroying our business

#87
post #70

Earlier quoted context omitted.

If you're hosting it on purpose, then you already know that it's the culprit and would've tried to change it anyways. I don't really see a scenario where telling the person who opened the ticket what the issue is would weaken the security measures or detection strategy.

That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.

... MS is telling everyone that the root domain is on a black list. A malicious actor doesn't need more than that, they already know the exact URL that malware resides at.

A non-malicious actor doesn't know, so telling them the exact URL at least tells them where the compromised asset might be.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#88
post #71

Earlier quoted context omitted.

Actual bad guys, hosting $Evil on purpose, are extremely unlikely to need any "change the URL" hints.

They don't need one but having one maximizes campaign life.

How on earth does it do that?

If I put malware at xyz.com/mybadpage and MS starts flagging xyz.com, how on earth do I "maximize campaign life" by being told xyz.com/mybadpage has malware?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#89
post #6

I've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.

I am currently in a 3 day Facebook ban because I posted an NIH (National Institute of Health, peak legitimacy right here) link which was meant to help someone understand something. Unfortunately, the medical procedure it covered thumbnailed down (in the generated preview) to a fairly graphic photo of a woman's private parts being operated on... and that resulted in an uncontestable instaban. No humans can be reached…

After the post, there is a button to remove the preview. Is that available before posting? Or would immediately removing the preview avoid the ban? Just wondering...

Re: Ask HN: Microsoft SmartScreen is destroying our business

#90
post #70

Earlier quoted context omitted.

If you're hosting it on purpose, then you already know that it's the culprit and would've tried to change it anyways. I don't really see a scenario where telling the person who opened the ticket what the issue is would weaken the security measures or detection strategy.

That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.

Easy. Scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.
Post reply on HN