Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

161–170 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#161
post #73
post #50

Earlier quoted context omitted.

I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances. With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you ap…

I have no idea what your post is about but from MS's perspective it isn't the site owners but MS's users around the world that are victims of thr threat actor that need protection. If it truly is a compromised site then the site owner is also a victim but as owners it is also their duty to secure and cleanup their site that is currently endangering the public.

If it truly is a compromised site then the site owner needs to clean it up; but starting the sentence with "If.." doesn't make it so.

Alex Pinto's classic research into the (lack of) overlap among threat indicator feeds should be a shot across the bow; I worked with threat indicators for a decade. To fend off muppet thinking I would like to remind everybody that they're selling threat indicator feeds; nobody that I know of sells not-a-threat feeds. A false positive means a site was falsely reported as a threat [sp]; a false negative does not mean that it is good, it simply means it is omitted from the list of threats.

In my experience vendors are a lot more worred about false positives than dropping something which is a threat on the floor (false negatives in context). However, moral hazard pushes them to publish things which turn out to be false positives anyway, because at the end of the day they're selling FUD.

My network, my rules. Something doesn't have to be a threat for it to be blocked from a private network in my opinion; there are lots of reasons for that, including minimizing potential threats. Something could be hosted on stinky infrastructure, but it's unknown or hasn't been demonstrated to be a threat. Profiles for operational security vary, and so does the appetite for proactively blocking (and whitelisting necessary resources): just because it's legal doesn't mean it doesn't put me at a competitive disadvantage if people know what I'm doing. I have no problem with people sharing and discussing such indicators, but there has to be attribution to the sharer: they have a reputation to be considered with equal concern as that of the indicators they publish.

If you're going to do something public with such information, you can't point fingers at "AI" and indicators you found in a paper bag on the bus: you do that, then you own it. Saying the victim deserves it is something you'd better be prepared to defend in court.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#162
post #134
post #93

Earlier quoted context omitted.

What are you even talking about? What is IR? What happens is a website is blocked and the site operator has no idea why. The defense of "we can't share any information as to why you got punished as it might help bad actors avoid punishment" should not be an acceptable stance. It's the equivalent of being thrown to prison without due process and just ignoring false positives. It's a very "natural" way of acting, but t…

IR is incident response, it means you find out everything the bad guys did and how it was compromised and fix it all. You should contact a security company or professional to help you if you don't know. I have used the webshells of compromised sites where the owner tries to cleanup but the webshell is still there hosting different campaigns. You should secure your site better and have someone who knows what they are…

> It's like someone messed with your car tank and tires and the police stop you from driving it because it is unsafe to other drivers, they are not punishing you but protecting other people from being hurt by your property.

The police says why they stopped you though! Which implies what you have to change in order to be able to drive again. They will not say "you have to figure it out on your own or the guys who messed with your car would have it more easy."

Re: Ask HN: Microsoft SmartScreen is destroying our business

#163
post #158

Earlier quoted context omitted.

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

> don't want to serve as an oracle for the people whose malware they are trying to block Those people don't have a registered business; The people contacting Microsoft do. There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any ne…

[deleted]

Re: Ask HN: Microsoft SmartScreen is destroying our business

#166
post #158

Earlier quoted context omitted.

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

> don't want to serve as an oracle for the people whose malware they are trying to block Those people don't have a registered business; The people contacting Microsoft do. There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any ne…

> Those people don't have a registered business; The people contacting Microsoft do.

I don't think you understand how sophisticated malware distribution can be.

There's absolutely nothing stopping a "legitimate business" from distributing malware.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#167

Earlier quoted context omitted.

Another anti-trust suit perhaps.

Yes that worked out well last time. Microsoft was broken up and they were forced to unbundled their browser from Windows. Also, politicians never go after companies for biased reasons and we can count on the government with more power not to abuse it.

Who knew that the browser should have been separated fully anyway because it was a security issue?

They weren't broken up but they were anti-competitive asswipes.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#168

Earlier quoted context omitted.

How on earth does it do that? If I put malware at xyz.com/mybadpage and MS starts flagging xyz.com, how on earth do I "maximize campaign life" by being told xyz.com/mybadpage has malware?

Imagine that you have put malware in xyz.com/mybadpage1, xyz.com/mybadpage2, and xyz.com/mybadpage3 pages. MS flags you, and you query MS. They tell you they see malware on the first two urls. Now you gained information about their blindspots. You can capitalise on this multiple ways. You can remove the first two and hope they remove the flag. You can design your next attack better so it is more like mybadpage3. Etc

Except if you're a malicious actor you can also do:

msscanninghoneypot1.com

msscanninghoneypot2.com

msscanninghoneypot3.com

You're pigeonholing a bad actor's actions into good actor behavior, it doesn't work like that...

edit: missed that multiple replies cover this

Re: Ask HN: Microsoft SmartScreen is destroying our business

#169

Earlier quoted context omitted.

Looks like protection racket.

Well, when you're driving and you get pulled over, you show your driver's license to the police and they don't arrest you for driving without a license. It seems like asking to run code on other people's machines is a privilege, too. Unfortunately the World Wide Web has trained consumers to grant that privilege willy-nilly to every web page they visit. I am thankful that code signing and validation is ending the part…

Yes, but quis custodiet ipsos custodes?

With the driver's license, the police officer can usually easily see if you've been behaving like someone who found their license in a packet of chips or not.

Does the certificate issuer perform any kind of due diligence to determine if the certificate should be given to this program?

Racket protection's determining characteristic is that the outfit can't care less what you do as long as you pay your dues and don't cross them. And if you don't, it doesn't matter how upright a citizen you are or how paranoid about safety you are, your shop will burn.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#170

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

This is a good suggestion to check your system carefully.

I have seen and investigated cases where malware runs for everyone except in certain locations or even excluding only the site operators.

Look for weird scripts, includes, base64 decode and exec calls in your codebase/site.

Post reply on HN