Live data from Hacker News

Ask HN: Microsoft SmartScreen is destroying our business

news.ycombinator.com

201–206 of 206 posts

Re: Ask HN: Microsoft SmartScreen is destroying our business

#201
post #158

Earlier quoted context omitted.

Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block. Not saying that isn't shit or frustrating.

> don't want to serve as an oracle for the people whose malware they are trying to block Those people don't have a registered business; The people contacting Microsoft do. There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any ne…

They don't? How do you know? Having one seems like it would be a real benefit.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#202

Earlier quoted context omitted.

TXT DNS records are used by Google, Microsoft and LE exactly for this purpose.

Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc. Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforc…

> but if the admins of a domain email you from the same domain as the flagged site

Email domains aren't always match with domains running the web-site (don't forget only ten years ago www. was still expected and people redirected you there from non-www. name).

But having access to DNS zone you can prove 'ownership' (at least technical) of the domain (even if it doesn't have the associated MX records for e-mail), precisely why LE is doing it.

> by copying&pasting whatever the original certbot

> I have no idea what they do, who can read them, when, where, why, etc

Oh my...

> Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance?

More like "to prove you are the one responsible for tailspintoys.com - create a TXT record under that domain with 'dylan604 is admin here'".

> I have no idea what they do

TXT records are just plain text strings (in ASCII), nothing more, nothing less.

> who can read them, when, where, why

Everyone, anytime, anywhere, because it is you who placed it there in a system of Public DNS servers

Re: Ask HN: Microsoft SmartScreen is destroying our business

#203
post #10

Earlier quoted context omitted.

See: spam blacklists

My own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".

[deleted]

Re: Ask HN: Microsoft SmartScreen is destroying our business

#204
post #14

Very important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why…

Should they then not just reply with "You're on the list because of the malware payload at "?

I believe they will if you use their vulnerability management offering it should come up with such details.

We can not expect companies to give free security advice. Secondly, providing such info without consent might result in legal actions from not so smart companies.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#205
post #50
post #16

Earlier quoted context omitted.

How does MS know they aren't hosting it on purpose? That might cause them to just change the malicious URL.

I live in the USA. Victim blaming "they did something to deserve it" is at best unethical. In court theoretically I would have the right to demand to see evidence. "Hold my beer" is not likely to be sufficient except in egregious circumstances. With that said, there is an epidemic of muppet thinking right now. It's not just the intertubes. Suppose a credit card company pulls your credit report because they say you ap…

In many of these extreme cases where it's non-obvious what is wrong, the victim IS often the one responsible.

Example: Viral video shows police pulling unarmed (and allegedly innocent) suspect out of a parked car that sparks outrage. It's later found out that the victim was previously evading police pursuit just minutes before, and was trying to blend in with the other cars in a lot.

Re: Ask HN: Microsoft SmartScreen is destroying our business

#206
post #29

Earlier quoted context omitted.

> Too many Microsoft shills here. Can you quote one of the shills? I see people saying that OP should verify that it's a false flag. Are those the shills to whom you're referring?

Given the second sentence of 'Microsoft should be able to state exactly what is wrong.', then they probably mean these: https://news.ycombinator.com/item?id=33037323 https://news.ycombinator.com/item?id=33037211 And these ones showed up right after they posted: https://news.ycombinator.com/item?id=33037364 https://news.ycombinator.com/item?id=33037349 Edit: actually that first one was after they posted too? So their…

All of those comments seem pretty reasonable to me. Does that make me a shill too?
Post reply on HN