Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

121–130 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#121
post #73
post #50

Earlier quoted context omitted.

I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances. With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you ap…

I have no idea what your post is about but from MS's perspective it isn't the site owners but MS's users around the world that are victims of thr threat actor that need protection. If it truly is a compromised site then the site owner is also a victim but as owners it is also their duty to secure and cleanup their site that is currently endangering the public.

Microsoft is not the Guardian of the World. If they take it upon themselves to act as such without being a responsible Netizen (cooperating with other site operators to provide a higher quality Net) then they are more interested in cementing their own position rather than being a part of a civilized Net.

Imagine if I just suddenly started spreading around rumors of your malfeasance and shadyness, and untrustworthyness.

It's a big deal.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#122
post #91
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

No, because they would cause the following scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.

In the specific scenario where they're running multiple kinds of malware on the same site, they won't know which one got detected.

Is that really something to worry about so strongly that we screw over legitimate websites?

A malicious actor can already know exactly what's detected if they run one malware at a time per site.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#123

Earlier quoted context omitted.

Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue. Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our…

TXT DNS records are used by Google, Microsoft and LE exactly for this purpose.

[deleted]

Re: Ask HN: Microsoft SmartScreen is destroying our business

#124
post #25
post #18

Earlier quoted context omitted.

No it doesn't. It simply tells that the detection system _has_ worked.

Imagine that MS replies "we detected malware spreading from your site" without any other details. What is OP supposed to do then? Won't they be just as frustrated, if not more, than before?

There is a 0% chance that a site could be spreading malware and there's not a single thing MS could point to to help out the owners find it that wouldn't leak Super Secret Advanced Mega-Genius Malware Detection Methods.

They just don't want to because that costs more money than being a huge piece of shit does.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#126
post #22

Do you allow user generated content at all that is internet accessible? Have you looked up your domain and IPS in virustotal and other similar services? Can users host any type of file that can be accessed without authentication? Yes/no/yes to the above questions means that is where you should look.

We’re a web analytics product. We don’t show any user generated content. All pages (except login/signup/etc..) are behind an authwall.

I recommend two things as a minimum then:

1) Check your DNS registrar and make sure there are no new subdomains. dnsdumpster can also help a bit.

2) Check for any new files in the directory tree of public facing sites.

If you're sure all is good you just have to keep escalating with microsoft and creating new requests to remove your domain multiple times a day from different IPs and emails so you can land in the right queue eventually. Squeaky wheel and all (don't forget social media noise).

Re: Ask HN: Microsoft SmartScreen is destroying our business

#127
post #118

Earlier quoted context omitted.

Yes that worked out well last time. Microsoft was broken up and they were forced to unbundled their browser from Windows. Also, politicians never go after companies for biased reasons and we can count on the government with more power not to abuse it.

Also I suppose companies never go after politicians for biased reasons, with legalized bribery of campaign contributions as the tool.

Yes, but no company has a “monopoly on violence” - the government does. Given a choice, a powerful government can do far more damage than Microsoft.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#128
post #90
post #70

Earlier quoted context omitted.

That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.

Easy. Scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.

That's exactly what I am saying...

Re: Ask HN: Microsoft SmartScreen is destroying our business

#129
post #70

Earlier quoted context omitted.

That's not what is being said here, the domain is blacklistes and my comment was about MS not the bad guy telling the site owner the malicious URL. If you tell them the URL, they will change it and claim it was a compromise so they can increase campaign lifetime.

... MS is telling everyone that the root domain is on a black list. A malicious actor doesn't need more than that, they already know the exact URL that malware resides at. A non-malicious actor doesn't know, so telling them the exact URL at least tells them where the compromised asset might be.

Yes a malicious actor needs more than that because compromised domains are valuable and keeping them alive longer means more money...

A non-malicious actor who needs the URL isn't monitoring or responding to the incident properly. Threat actors do take advantage of this and simulate a fake cleanup. Actually they exclude certain ips and asns on phishing kits so that visiting the url gives you a 404 or a webhosts "cleanup" page.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#130
post #71

Earlier quoted context omitted.

They don't need one but having one maximizes campaign life.

How on earth does it do that? If I put malware at xyz.com/mybadpage and MS starts flagging xyz.com, how on earth do I "maximize campaign life" by being told xyz.com/mybadpage has malware?

You move it to xyz.com/anotherbadpage and tell MS it has been cleaned up. They do this all the time. Speaking from first hand experience. This is a very simple topic, why are there so many people not understanding this?!
Post reply on HN