40 ms·
Ask HN: Microsoft SmartScreen is destroying our business
About a month ago, Microsoft SmartScreen suddenly started flagging the login page of our SaaS dashboard as 'unsafe', scaring away our customers.
We understand false flags can happen. So we took to the official SmartScreen feedback site to report the false flag (as the website owner). Received an email that stated it would take up to 24hrs to analyse: 'If the status of your site has not changed after 24 hours, please contact us with a reply to this message'.
Sep 8 - first ticket sent.
Sep 9 (24h later) - nothing. So we replied to the message as instructed.
Sep 12 - still nothing. One more reply sent. Asked some of our customers to report our site as safe.
Sep 15 - crickets. Tried calling phone support, impossible to get through; they just hang up on us. Reached out to MS support on Twitter, said they would look into the case.
Sep 22 - no changes - MS twitter support has been unable to find the correct person internally. We replied to the SmartScreen ticket once more. Opened two new tickets. Asked more customers to report the site as safe.
Sep 30 (Today) - now the warning has started to spread from our login page to our entire dashboard. Still no word from Microsoft.
We are totally baffed that MS allows a false flag to stay up this long, totally ignoring us for almost a full month, meanwhile destroying a business that did nothing wrong...
We suspect one of our competitors is responsible for falsely reported us. Is 'weaponized SmartScreen' a thing?
Does anyone have a similar experience? Any advince on resolving this matter is greatly appreciated!
- missedthecue 4y agoWhen this happened to my software product I fixed it by purchasing a Comodo EV code signing certificate. It cost me $502, it was FedExed to me in a USB, and I signed my program. Tens of thousands of installs later, I have never had an issue with smart screen. Note that there are two types of code signing certs, you want the EV Code Signing Certificate. It will instantly give your program reputation that ends the smartscreen filter issue. Is it a corrupt system? Pay to play? Sure. But this is a guaranteed way to solve the problem. And way cheaper and 1000x faster and less of a headache than contacting an attorney (which a surprising number of people here are recommending!)
- WesolyKubeczek 4y agoLooks like protection racket.
- Eleison23 4y agoWell, when you're driving and you get pulled over, you show your driver's license to the police and they don't arrest you for driving without a license. It seems like asking to run code on other people's machines is a privilege, too. Unfortunately the World Wide Web has trained consumers to grant that privilege willy-nilly to every web page they visit. I am thankful that code signing and validation is ending the party in that way.
- Sodman 4y agoSure, but "Pay $502 for the privilege of running code on other people's machines" doesn't seem like a big improvement? At least to get a driver's license you need to pass a driving test, and return periodically to update the photo and pass an eye exam.
- WesolyKubeczek 4y agoYes, but quis custodiet ipsos custodes? With the driver's license, the police officer can usually easily see if you've been behaving like someone who found their license in a packet of chips or not. Does the certificate issuer perform any kind of due diligence to determine if the certificate should be given to this program? Racket protection's determining characteristic is that the outfit can't care less what you do as long as you pay your dues and don't cross them. And if you don't, it doesn't matter how upright a citizen you are or how paranoid about safety you are, your shop will burn.
- Eleison23 4y agoThe code-signing certificate says nothing about whether the program is worthy. The code-signing certificate authenticates the publisher. That's how it's supposed to be used. The due diligence for code security is up to the publisher, because they're staking their reputation by certifying it. The certificate authorities are separately run, by the way. I don't know how you could say Microsoft has a protection racket when they accept certificates from disparate authorities. Code-signing certificates enable users to discern reputation. A certificate confers a reputation and not holding a certificate means an unknown reputation. If I drive a car without a license, I can probably drive that car for years as long as I'm obeying laws and not causing trouble. A police officer who pulls me over may perhaps not ask for a license after all, but he doesn't know my reputation of obeying traffic laws; he's got to check my privilege. A driver's license in my jurisdiction carries reputation beyond just the driving privilege: infractions will rack up points.
- lixtra 4y ago> It cost me $502, it was FedExed to me in a USB, and I signed my program. I’m surprised that it apparently had to be delivered physically. Did Comodo generate the private key for you?
- chabad360 4y agoIIRC you are able to get the cert signed to an existing HSM USB (depends on the provider tho).
- meltedcapacitor 4y agoThe point is the private key is on the USB gadget and stays there. It's not a dumb USB drive.
- deleted 4y ago[deleted]
- midislack 4y agoAre you in the same competitive space as MS? If so you shouldn’t act surprised.
- jotm 4y agoYou need to buy an EV certificate which is why many Devs complain SmartScreen made Windows Pay2Win. But you can pay for it by implementing malware in your newly whitelisted app :D
- gw99 4y agoI had problems with Windows Defender finding a false positive in the output of a product I was working on. This was an EV code signed MSI package with signed exe. This eventually inflamed SmartScreen and despite getting the thing sorted as a false positive by the AV guys it took 3 months for it to stop being flagged. After working on Microsoft dev for ~20 years, 2019 was the last thing I touched. I handed everything else over and moved on. I will NEVER deal with that company again. Nothing but fucking shit for that entire time. The grass /is/ greener on the other side.
- yashg 4y agoOh yes! I have a desktop software and MS defender sometimes flags it as unsafe. Mostly happens after I release a new version. It scares away new users, even existing users get spooked. Have to file a report and have to send customers scan report from other scanners and convince them it's a false flag. Feel really hopeless in such a situation.
- crumpled 4y agoI'm having the same issue, but it's Xfinity blocking my site from their business customers. The official contact form seems to be a sinkhole. It's beyond frustrating. I feel maligned and defamed.
- mkl95 4y agoThe answer is in your logs. If there are no logs, Microsoft know your site better than you do.
- rsync 4y agoWhere can I go to test what "smartscreen" thinks of a particular URL ? I am neither a "smartscreen" nor even a Microsoft customer - is it possible for me to see what they think of a particular domain/adress/URL ?
- FateOfNations 4y agoGo to the website in Microsoft Edge and see what happens. If there's a SmartScreen issue, you will be given a warning message.
- TheLoafOfBread 4y agoI sorted this out by buying a certificate and digitally signing the binaries. You can get it from GoDaddy, Sectigo, etc.
- timnetworks 4y agoMicrosoft SmartScreen is a broken product staffed by presumably broken people. [edit] buy a cert like the smart people are saying
- simooooo 4y agoThis happened to me too because a subdomain was the same as a popular product brand name. This was kicked off by chrome/google, then feed through to smart screen. Which took a few days to sort out. Had to claim the domain on google search tools and find the reason
- bombcar 4y agoDo you have a link to the domain? Perhaps it can be determined why it is triggering.
- phrz 4y agoHave you considered that your service, unbeknownst to you, may have been compromised at some point in time, and the source of some phishing page or other malicious material? Besides that possibility, if your business is truly being "destroyed," have you contemplated retaining counsel to escalate things with Microsoft?
- marcosdumay 4y agoDoes it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? And yes, that is a major defamation campaign led by Microsoft against the OP. And since MS even refuses to clarify their claim about the OP's wrongdoing, I imagine he would have an easy time in a court.
- Quarrelsome 4y ago> Does it hurt Microsoft in any way to answer those tickets with "no, your site is participating in a phishing campaign"? And maybe tell the OP how, so that he can clean the malicious material? Ye, it tells bad actors how the detection system works.
- biorach 4y agoNo it doesn't. It simply tells that the detection system _has_ worked.
- ohbtvz 4y agoImagine that MS replies "we detected malware spreading from your site" without any other details. What is OP supposed to do then? Won't they be just as frustrated, if not more, than before?
- yamtaddle 4y agoThere is a 0% chance that a site could be spreading malware and there's not a single thing MS could point to to help out the owners find it that wouldn't leak Super Secret Advanced Mega-Genius Malware Detection Methods. They just don't want to because that costs more money than being a huge piece of shit does.
- gypon 4y agoWhat if it's a true flag? Your website might be compromised and serving malware. What sort of business is it? If it's something particularly scammy, it might be being screened for that reason.
- wahnfrieden 4y agoGood luck getting them to care
- dboreham 4y agoI've noticed that the people running automated flagging systems seem to become inordinately smug to the point that they believe their false positive result over all forms of external evidence. So to them you are a criminal and that's that.
- floren 4y agoSee: spam blacklists
- dboreham 4y agoMy own experience was with Wells Fargo, where I conduct quite a bit of business, but they still treated me like a criminal because their dumb AI thought that "I don't often initiate wire transfers online" and "my voice didn't sound like my age".
- raverbashing 4y ago> "my voice didn't sound like my age". Which actually should be a desirable characteristic as it is an unique identifier, but it kinda makes sense with so many 'lulzhackers' out there (not that I think this is the reason - I do attribute these issues mostly to incompetence)
- deleted 4y ago[deleted]
- myself248 4y ago> "my voice didn't sound like my age" Wow, hello marginalization! I wonder where their training data set came from.
- SpaceManNabs 4y agoI hate being demanded to set up voice verification. Even more annoying when the representative suggests that you active your voice despite you saying no. Voice verification is such a weak security system.
- 4y ago
- shishy 4y agoDo you have any scripts loading that might be malicious / triggering a flag? What's the website?
- jcrawfordor 4y agoVery important that you develop complete confidence that there isn't anything wrong with your product. It's not uncommon, in fact it's very common, for compromise kits for websites to take measures to avoid detection. A common one is only serving the malicious content when a specific referrer is present (I've seen this be Yahoo Search in the case of compromised Drupal installations multiple times, not really sure why). It might be wise to engage a security firm to conduct an investigation if you don't have in-house expertise in this area. You should definitely review logs carefully for any unusual inbound traffic. Sometimes looking up your own domain on services like virustotal can reveal the problem, as it might turn up samples of malware retrieved from your website. I say this because I have been involved in this exact situation multiple times: website flagged by some or other security service, website operator has no idea why and insists it is fine, website turns out to be serving the landing page of a major pharma scam campaign unnoticed by the website operator due to anti-detection measures.
- golemiprague 4y ago
- celestialcheese 4y agoHijacking for tangentially related question: > It might be wise to engage a security firm to conduct an investigation if you don't have in-house expertise in this area. Any good security firms you recommend for a small to midsize website?
- m3047 4y agoDo you practice know your customer (are you required to)? Is this shared hosting? Who runs the site? Who is responsible for security? What are your assets? Any other way(s) for them to be compromised? Where are your backups; did someone get ahold of those? What about all of the garbage that people pull in from the webs (and into their customer's browsers)? Do you know why fonts.google.com is controversial? Is some ad network participating in a watering hole attack? Got a chatbot on your payment page? Once you have a handle on that, you can start looking for answers. If that's too much to ask, then the time to start paring down your attack surface is before there are questions. Use hosting that provides such guarantees. Use an MxP. Don't keep customer information you don't need. What you quote is facile.
- Guid_NewGuid 4y agoSame thing happened to us, after a week or so we just had to change subdomain of our login site. No answer was ever forthcoming on the previous domain and the new one remains unflagged months later.
- vfclists 4y ago
- d35007 4y ago> Too many Microsoft shills here. Can you quote one of the shills? I see people saying that OP should verify that it's a false flag. Are those the shills to whom you're referring?
- Dylan16807 4y agoGiven the second sentence of 'Microsoft should be able to state exactly what is wrong.', then they probably mean these: https://news.ycombinator.com/item?id=33037323 https://news.ycombinator.com/item?id=33037323 https://news.ycombinator.com/item?id=33037211 https://news.ycombinator.com/item?id=33037211 And these ones showed up right after they posted: https://news.ycombinator.com/item?id=33037364 https://news.ycombinator.com/item?id=33037364 https://news.ycombinator.com/item?id=33037349 https://news.ycombinator.com/item?id=33037349 Edit: actually that first one was after they posted too? So their comment may not have been accurate the second they made it, but three comments defending microsoft's secrecy showed up in the next five minutes.
- d35007 4y agoAll of those comments seem pretty reasonable to me. Does that make me a shill too?
- _8j50 4y agoDo you allow user generated content at all that is internet accessible? Have you looked up your domain and IPS in virustotal and other similar services? Can users host any type of file that can be accessed without authentication? Yes/no/yes to the above questions means that is where you should look.
- captain_dfx 4y agoWe’re a web analytics product. We don’t show any user generated content. All pages (except login/signup/etc..) are behind an authwall.
- _8j50 4y agoI recommend two things as a minimum then: 1) Check your DNS registrar and make sure there are no new subdomains. dnsdumpster can also help a bit. 2) Check for any new files in the directory tree of public facing sites. If you're sure all is good you just have to keep escalating with microsoft and creating new requests to remove your domain multiple times a day from different IPs and emails so you can land in the right queue eventually. Squeaky wheel and all (don't forget social media noise).
- swayvil 4y agoLook at most of the replies here. "Nuh uh, it's you. You have failed to check the obvious..." It inspires paranoia I tell you.
- codegeek 4y agoThis happens to some of our customers (they have custom domains on our SAAS). It is beyond ridiculous.
- lixtra 4y agoGet a lawyer. Ask for an injunction by a court. Make smartscreen liable for the damage they do to you.
- progre 4y agoYou sound like a lawyer.
- neilv 4y agoYes, poster needs to talk with a lawyer. Ideally, a company would do this on Day One of the situation. And keep all the data you can (from Web, marketing, ads, etc.), to try to figure out and show how much this is costing you. "And here's where the hockey stick snapped in half."
- Animats 4y agoOf course. As an outside party, you're not bound by Microsoft's EULA. You can go after them for defamation, tortuous interference with contract, etc. You're in a much better legal position than a customer. This is when you have a lawyer send a letter. That's cheap. That gets your lawyer talking to Microsoft's lawyers. Most commercial disputes are, in practice, resolved that way.
- ROTMetro 4y agoWould it be possible to hire a lawyer to send them a letter notifying them you intend to sue for defamation of character?
- twistslider 4y agoI've seen someone with a similar experience to you (and also a SaaS) a few days ago: https://twitter.com/xhfloz/status/1574404009288425472 https://twitter.com/xhfloz/status/1574404009288425472 Not sure if they solved it, but might be helpful asking them.
- captain_dfx 4y agoThanks, I'll contact them!
- t0bia_s 4y agoSimilar thing happen to me. My OneDrive links that I share with clients end in their email spam folder. It took mi few weeks before I realized that few clients was still waiting for my work, because they did not have it in inbox. I know that it is problem of email providers, but still I would like to leave OneDrive, but I cannot find alternative that is in similar price range as OneDrive (about 2 USD/month for 1TB).
- Benanov 4y agoIs your login page vulnerable to an Open Redirect? Run your page against OWASP top 10. You might find something
- nickhalfasleep 4y agoI encountered this, I had a cloud service that I had spun up services on with some DNS records pointing to, and then abandoned. The IP address was then used by malware, but because my DNS pointed to it, my whole domain got blacklisted.
- genewitch 4y agohow exactly does this work? I had to request that one of my server's IP address reverse mapped to the domain name. In that circumstance i could see "abandoning" that ip, and maybe it gets reused by someone i can't send a nasty letter to, but other than that, how would some subdomain on my domain pointing to an AWS IP i haven't used in a decade remotely trace back to me or my domain? Maybe i am too tired and am missing some feature in whois or something.
- djbusby 4y agoThis is a good point, to properly "offline" your old hostnames and IPs. I've seen many of these cases where stale DNS started pointing to $BAD_THING
- jefftk 4y agoThis is risky for things other than malware blacklisting. For example, the attacker can get a certificate for your domain, and then they can access any HTTPONLY and/or SECURE cookies set at the registrable domain level and impersonate your users just by getting someone to visit their page.
- rjc 4y agoI'm so sick and tired of businesses abusing my trust and/or not publishing their security breaches that I'm using plus ('+') email addresses everywhere, i.e.: my_account+site_address@example.org for regular interactions, or: my_account+site_address-current_date@example.org for one-off interactions. Won't help with historical abuses/data breaches but it'll certainly be invaluable in the future.
- aetherspawn 4y agoI started doing the same years ago and nothing came out of it. Most spam I got subscribed to, seemed to get my details some other way (or sanitised my email).
- cdaringe 4y agoSame. I still do, but 90% of the spam that actually lands is due to a biz I legitimately gave info to illegitimately sharing it with others
- ok123456 4y agoAbout 10% of sites don't allow you to use a plus sign in your email address.
- freedomben 4y agoAs has already been said, there's a chance that you are compromised and don't know. Obviously keep trying to contact MS, but in the mean time I'd make as much sure as you can that they don't have a legitimate beef. If you're willing to share more details about your site such as your tech stack, we can probably give you more specific advice beyond "check your logs for weirdness and hire a consultancy firm that deals with breach detection," though that is good advice. For what it's worth I went through something similar to this not too long ago, so I know how maddening it is. My client never found any breach (though I did find some PHP library CVE's that could have conceivably been chained together to wreak some havoc), but I ended up rebuilding their prod environment clean and the flag went away on it's own after a couple days, probably because whatever malware was in there had disappeared.
- NohatCoder 4y agoIf MS have found a compromise they should share it. Making the allegation but not disclosing any reason is just slander.
- jefftk 4y agoThat's not actually slander/libel. Truth is an absolute defence, and that does not require you to disclose details up front. You'd only need to demonstrate truth to defend yourself if sued. In this case I also expect it's all very carefully worded ("Be careful! This site might be trying to harm your computer") to be legal even in cases when they accidentally (and inevitably) miscategorize a site.
- fxtentacle 4y agoWeaponized flagging is totally a thing on Amazon, so I wouldn't be surprised if with SmartScreen, too.
- gkoberger 4y agoI know you probably don't want to dox yourself, but this post has a good amount of traction. It wouldn't hurt to include either contact information or the site in question, just in case someone who can do something sees this!
- jbk 4y agoAnd yet, when we submit crapware clones of VLC repackaged, while giving extensive details about the spyware, adware and services installed, MS refuses to block them… I love Smartscreen…
- nvr219 4y agoPeople talking about is it a false flag, real flag... Post your SaaS URL and you'll get a free security assessment from a dozen hners.
- freedomben 4y agoThat's undoubtedly true, but you'll also get a lot of assholes and script kiddies hoping to pwn your site for lulz, and they often don't care who gets hurt along the way. By posting you've just given them an easy legal defense. If it were me, I wouldn't do it. Not worth the risk. I would however, probably be willing to DM people individually after doing a small amount of due diligence on their comment history. I guess it depends on sensitivity of the site and how desperate they are.
- MrStonedOne 4y ago
- nvr219 4y ago> you'll also get a lot of assholes and script kiddies hoping to pwn your site for lulz, and they often don't care who gets hurt along the way. Yes... "Free security assessment" was a euphemism I'm afraid.
- stickfigure 4y agoThat is such a weird take. You get assholes and script kiddies the moment your IP interface starts accepting packets. If you don't advertise to people who can help you (be it customers or potential advocates/partners) then what on earth are you doing? I put my company's website in my HN profile. Go ahead, make my day. (I'm not the OP and as far as I know don't have any security issues)