Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

171–180 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#171
post #158

Earlier quoted context omitted.

> don't want to serve as an oracle for the people whose malware they are trying to block Those people don't have a registered business; The people contacting Microsoft do. There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any ne…

> Those people don't have a registered business; The people contacting Microsoft do. I don't think you understand how sophisticated malware distribution can be. There's absolutely nothing stopping a "legitimate business" from distributing malware.

He's not saying there is. He's saying that it's pretty unlikely that the malware authors are going to phone Microsoft and ask why their site is flagged, so putting in some reasonable road blocks that a legitimate business would definitely jump over (e.g. talking to real people) would be plenty to remove the oracle issue.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#172
post #54

I'm so sick and tired of businesses abusing my trust and/or not publishing their security breaches that I'm using plus ('+') email addresses everywhere, i.e.: my_account+site_address@example.org for regular interactions, or: my_account+site_address-current_date@example.org for one-off interactions. Won't help with historical abuses/data breaches but it'll certainly be invaluable in the future.

I started doing the same years ago and nothing came out of it. Most spam I got subscribed to, seemed to get my details some other way (or sanitised my email).

Re: Ask HN: Microsoft SmartScreen is destroying our business

#174

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Hijacking for tangentially related question: > It might be wise to engage a security firm to conduct an investigation if you don't have in-house expertise in this area. Any good security firms you recommend for a small to midsize website?

Do you practice know your customer (are you required to)? Is this shared hosting? Who runs the site? Who is responsible for security? What are your assets? Any other way(s) for them to be compromised? Where are your backups; did someone get ahold of those?

What about all of the garbage that people pull in from the webs (and into their customer's browsers)? Do you know why fonts.google.com is controversial? Is some ad network participating in a watering hole attack? Got a chatbot on your payment page?

Once you have a handle on that, you can start looking for answers. If that's too much to ask, then the time to start paring down your attack surface is before there are questions.

Use hosting that provides such guarantees. Use an MxP. Don't keep customer information you don't need. What you quote is facile.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#175

Earlier quoted context omitted.

Well, when you're driving and you get pulled over, you show your driver's license to the police and they don't arrest you for driving without a license. It seems like asking to run code on other people's machines is a privilege, too. Unfortunately the World Wide Web has trained consumers to grant that privilege willy-nilly to every web page they visit. I am thankful that code signing and validation is ending the part…

Yes, but quis custodiet ipsos custodes? With the driver's license, the police officer can usually easily see if you've been behaving like someone who found their license in a packet of chips or not. Does the certificate issuer perform any kind of due diligence to determine if the certificate should be given to this program? Racket protection's determining characteristic is that the outfit can't care less what you do…

The code-signing certificate says nothing about whether the program is worthy. The code-signing certificate authenticates the publisher. That's how it's supposed to be used. The due diligence for code security is up to the publisher, because they're staking their reputation by certifying it.

The certificate authorities are separately run, by the way. I don't know how you could say Microsoft has a protection racket when they accept certificates from disparate authorities.

Code-signing certificates enable users to discern reputation. A certificate confers a reputation and not holding a certificate means an unknown reputation.

If I drive a car without a license, I can probably drive that car for years as long as I'm obeying laws and not causing trouble. A police officer who pulls me over may perhaps not ask for a license after all, but he doesn't know my reputation of obeying traffic laws; he's got to check my privilege. A driver's license in my jurisdiction carries reputation beyond just the driving privilege: infractions will rack up points.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#176
post #134

Earlier quoted context omitted.

IR is incident response, it means you find out everything the bad guys did and how it was compromised and fix it all. You should contact a security company or professional to help you if you don't know. I have used the webshells of compromised sites where the owner tries to cleanup but the webshell is still there hosting different campaigns. You should secure your site better and have someone who knows what they are…

> It's like someone messed with your car tank and tires and the police stop you from driving it because it is unsafe to other drivers, they are not punishing you but protecting other people from being hurt by your property. The police says why they stopped you though! Which implies what you have to change in order to be able to drive again. They will not say "you have to figure it out on your own or the guys who mess…

Yes, because the police serve you but MS serves its customers and even the police will not diagnose your car for you, they might say "we see gas leaking, stop driving" but they won't tell you if the fuel line, tank, injector,etc are responsible. MS's block is for MS customers not the public, MS also is not the only vendor that does this, there are dozens of vendors that provide domain reputation services like this to their customers. MS can block random sites and is their right, if you disagree stop using edge and use firefox maybe.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#177

Earlier quoted context omitted.

Yes that worked out well last time. Microsoft was broken up and they were forced to unbundled their browser from Windows. Also, politicians never go after companies for biased reasons and we can count on the government with more power not to abuse it.

It made Microsoft sweat pretty good in the late-90s. They had to behave a little better, but not doing anything too anti-competitive, during a critical juncture of the internet's growth and adoption, while the anti-trust proceedings dragged on. Just because there was no AT&T style divestiture at the end, doesn't mean there were no positive externalities.

And because of that, a million flowers bloomed and now we have dozens of browsers engines and not one dominant player controlled by a large tech company…

Re: Ask HN: Microsoft SmartScreen is destroying our business

#178

Earlier quoted context omitted.

It made Microsoft sweat pretty good in the late-90s. They had to behave a little better, but not doing anything too anti-competitive, during a critical juncture of the internet's growth and adoption, while the anti-trust proceedings dragged on. Just because there was no AT&T style divestiture at the end, doesn't mean there were no positive externalities.

And because of that, a million flowers bloomed and now we have dozens of browsers engines and not one dominant player controlled by a large tech company…

Without that pressure, they could have pursued a more aggressive strategy with IIS and server technologies. Outlook was only mildly annoying. They could have been much more aggressive there. Microsoft did and does a lot more than Windows and Internet Browsers.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#179

Earlier quoted context omitted.

Yes that worked out well last time. Microsoft was broken up and they were forced to unbundled their browser from Windows. Also, politicians never go after companies for biased reasons and we can count on the government with more power not to abuse it.

It made Microsoft sweat pretty good in the late-90s. They had to behave a little better, but not doing anything too anti-competitive, during a critical juncture of the internet's growth and adoption, while the anti-trust proceedings dragged on. Just because there was no AT&T style divestiture at the end, doesn't mean there were no positive externalities.

I think the biggest thing that came out of that anti-trust case is the publishing of specs for various file formats and protocols used by Microsoft software.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#180
post #75

Earlier quoted context omitted.

That's not actually slander/libel. Truth is an absolute defence, and that does not require you to disclose details up front. You'd only need to demonstrate truth to defend yourself if sued. In this case I also expect it's all very carefully worded ("Be careful! This site might be trying to harm your computer") to be legal even in cases when they accidentally (and inevitably) miscategorize a site.

> Truth is an absolute defence Depends on jurisdiction, although I am presuming OP is from the USA due to their spelling.

Yes, sorry! Only trying to talk about my (non-professional) understanding of US libel law
Post reply on HN