Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

151–160 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#151
post #55
post #28

Get a lawyer. Ask for an injunction by a court. Make smartscreen liable for the damage they do to you.

Yes, poster needs to talk with a lawyer. Ideally, a company would do this on Day One of the situation. And keep all the data you can (from Web, marketing, ads, etc.), to try to figure out and show how much this is costing you. "And here's where the hockey stick snapped in half."

Of course. As an outside party, you're not bound by Microsoft's EULA. You can go after them for defamation, tortuous interference with contract, etc. You're in a much better legal position than a customer.

This is when you have a lawyer send a letter. That's cheap. That gets your lawyer talking to Microsoft's lawyers. Most commercial disputes are, in practice, resolved that way.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#152

Earlier quoted context omitted.

Facebook + Google hold similar levels of power as governments over our lives, and so should adopt similar structures. An independent judiciary, review bodies, ombudsmen, aldermen, etc.

No they shouldn't, they should be broken up so they don't have that power.

"Thus solving the problem, once and for all!"

Re: Ask HN: Microsoft SmartScreen is destroying our business

#153
post #91

Earlier quoted context omitted.

No, because they would cause the following scenario: Malicious attacker looks for exactly what Microsoft detected, and fixes each specific detection while keep operating the undetected ones. The end result would be operational malicious site, without being detected.

So what? Just leave legit users in the dark because assholes exist? This type of logic needs to die. Assholes continue to exist because we enable them to by not raising the bar high enough that compromise is impractical, and no longer easy money.

People underestimate the extent to which a bunch of opaque "anti-abuse" algorithms control things. Everyone is given a risk score and if you exceed an internal threshold they will never respond to your support requests until your complaint gets on the HN frontpage. Then as justification to continue their pointless cat and mouse game the abuse department types will come in and say "well if we told you why we arbitrarily decided to then the real criminals would know how we detected them!"

Re: Ask HN: Microsoft SmartScreen is destroying our business

#154

Earlier quoted context omitted.

The government desperately needs to step in and regulate these automated "destroy your business" practices.

Totally. It should be illegal for Edge, Chrome and other browsers to take any measures, such as a little warning, in an attempt protect users from malware. I see no way that getting the government involved in this could go badly.

I should have some way to resolve the issue outside of the automation. Barring that, I should be able to sue them libel.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#155

Earlier quoted context omitted.

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

Saying they detected malware already does that. Being slightly more specific shouldn't be a problem.

Except that it could help attackers beefen up their tools. A certain amount of obscurity is good to keep the attackers from having too much information.

I've been in the situation where a company kinda 'ghosts' me before. And found out I was indeed the bad player (unintentionally, of course).

Re: Ask HN: Microsoft SmartScreen is destroying our business

#156

Earlier quoted context omitted.

Looks like protection racket.

Well, when you're driving and you get pulled over, you show your driver's license to the police and they don't arrest you for driving without a license. It seems like asking to run code on other people's machines is a privilege, too. Unfortunately the World Wide Web has trained consumers to grant that privilege willy-nilly to every web page they visit. I am thankful that code signing and validation is ending the part…

Sure, but "Pay $502 for the privilege of running code on other people's machines" doesn't seem like a big improvement?

At least to get a driver's license you need to pass a driving test, and return periodically to update the photo and pass an eye exam.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#157
post #130

Earlier quoted context omitted.

You move it to xyz.com/anotherbadpage and tell MS it has been cleaned up. They do this all the time. Speaking from first hand experience. This is a very simple topic, why are there so many people not understanding this?!

Bad actors know 1. It's detected (because Microsoft told everyone) 2. What was detected and where it was (because they put it there) Good Actors only know 1. So by telling someone 2 they are giving bad actors no new information, and good actors valuable information.

This assumes the bad actor only put one thing there. If they put multiple things there they don't know what was detected unless told.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#158
post #14

Earlier quoted context omitted.

Should they then not just reply with "You're on the list because of the malware payload at "?

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

> don't want to serve as an oracle for the people whose malware they are trying to block

Those people don't have a registered business; The people contacting Microsoft do.

There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any negative effects their services might have on others, at least not until someone big enough makes a fuss or lawyers get involved.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#159
post #89

Earlier quoted context omitted.

I am currently in a 3 day Facebook ban because I posted an NIH (National Institute of Health, peak legitimacy right here) link which was meant to help someone understand something. Unfortunately, the medical procedure it covered thumbnailed down (in the generated preview) to a fairly graphic photo of a woman's private parts being operated on... and that resulted in an uncontestable instaban. No humans can be reached…

After the post, there is a button to remove the preview. Is that available before posting? Or would immediately removing the preview avoid the ban? Just wondering...

On Discord you can wrap the link in to prevent a preview.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#160
post #130

Earlier quoted context omitted.

You move it to xyz.com/anotherbadpage and tell MS it has been cleaned up. They do this all the time. Speaking from first hand experience. This is a very simple topic, why are there so many people not understanding this?!

Bad actors know 1. It's detected (because Microsoft told everyone) 2. What was detected and where it was (because they put it there) Good Actors only know 1. So by telling someone 2 they are giving bad actors no new information, and good actors valuable information.

1 is for domain only.

2, MS only knows some information that shows the site is malicious, it cannot tell if it is a compromise or just a malicious site unless it perhaps looks at reputation but even then the site owner should be able to tell new or malicious files on their webserver withour MS telling them, if they can't even do that they have bigger problems and threat actors do abuse anti-abuse systems like this all the time and they do deploy multiple things on your site as well as use it to attack other sites and monitor the reputation of their infrastructure.

Post reply on HN