Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

181–190 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#181
post #75

Earlier quoted context omitted.

If MS have found a compromise they should share it. Making the allegation but not disclosing any reason is just slander.

That's not actually slander/libel. Truth is an absolute defence, and that does not require you to disclose details up front. You'd only need to demonstrate truth to defend yourself if sued. In this case I also expect it's all very carefully worded ("Be careful! This site might be trying to harm your computer") to be legal even in cases when they accidentally (and inevitably) miscategorize a site.

Whether "truth is an absolute defence" depends on the jurisdicton. In Canada and Britain proof of truth is an absolute defence, but mere truth is no defence at all. Think about it - how much of what you say could you actually prove in a court of law?

In court and parliament, this is relaxed somewhat. But just 'cause you - say - saw a murder by X in broad daylight, doesn't mean you get to say you did anywhere you like, in Canada and Britain.

PS, yes defence is really spelled with a c in Canada. This was deliberately done historically in order to distinguish ourselves from the US long before the internet and spell-checkers.

IANAL - but then a lot of lawyers aren't much good at their game either.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#182

Earlier quoted context omitted.

Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue. Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our…

TXT DNS records are used by Google, Microsoft and LE exactly for this purpose.

Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc.

Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforcement do with this info?

Re: Ask HN: Microsoft SmartScreen is destroying our business

#183

Earlier quoted context omitted.

It made Microsoft sweat pretty good in the late-90s. They had to behave a little better, but not doing anything too anti-competitive, during a critical juncture of the internet's growth and adoption, while the anti-trust proceedings dragged on. Just because there was no AT&T style divestiture at the end, doesn't mean there were no positive externalities.

I think the biggest thing that came out of that anti-trust case is the publishing of specs for various file formats and protocols used by Microsoft software.

Not really

http://moglen.law.columbia.edu/publications/lu-18.pdf

Re: Ask HN: Microsoft SmartScreen is destroying our business

#184

Earlier quoted context omitted.

I think the biggest thing that came out of that anti-trust case is the publishing of specs for various file formats and protocols used by Microsoft software.

Not really http://moglen.law.columbia.edu/publications/lu-18.pdf

This mostly talks about APIs, and only briefly mentions protocols.

I don't know about the specifics of what is legally required vs what the Microsoft legal team decided to do to avoid further scrutiny. But the fact is that there's a lot of docs that were published in the aftermath of that ruling:

https://learn.microsoft.com/en-us/openspecs/protocols/ms-pro...

https://learn.microsoft.com/en-us/openspecs/data_portability...

Re: Ask HN: Microsoft SmartScreen is destroying our business

#185
post #157

Earlier quoted context omitted.

Bad actors know 1. It's detected (because Microsoft told everyone) 2. What was detected and where it was (because they put it there) Good Actors only know 1. So by telling someone 2 they are giving bad actors no new information, and good actors valuable information.

This assumes the bad actor only put one thing there. If they put multiple things there they don't know what was detected unless told.

But if a bad actor wants to know what's detectable they can just put each malware on separate domains.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#186

Earlier quoted context omitted.

TXT DNS records are used by Google, Microsoft and LE exactly for this purpose.

Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc. Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforc…

No post body was provided.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#188
post #89

Earlier quoted context omitted.

I am currently in a 3 day Facebook ban because I posted an NIH (National Institute of Health, peak legitimacy right here) link which was meant to help someone understand something. Unfortunately, the medical procedure it covered thumbnailed down (in the generated preview) to a fairly graphic photo of a woman's private parts being operated on... and that resulted in an uncontestable instaban. No humans can be reached…

After the post, there is a button to remove the preview. Is that available before posting? Or would immediately removing the preview avoid the ban? Just wondering...

Why’d you get banned over a preview that Facebook decides to show? Apparently they’re aware it’s graphic enough that they can ban you for it.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#190

I encountered this, I had a cloud service that I had spun up services on with some DNS records pointing to, and then abandoned. The IP address was then used by malware, but because my DNS pointed to it, my whole domain got blacklisted.

how exactly does this work? I had to request that one of my server's IP address reverse mapped to the domain name. In that circumstance i could see "abandoning" that ip, and maybe it gets reused by someone i can't send a nasty letter to, but other than that, how would some subdomain on my domain pointing to an AWS IP i haven't used in a decade remotely trace back to me or my domain?

Maybe i am too tired and am missing some feature in whois or something.

Post reply on HN