Hacker News new | ask | show | jobs
by burnished 1401 days ago
Just a guess, but I think they don't want to serve as an oracle for the people whose malware they are trying to block.

Not saying that isn't shit or frustrating.

2 comments

> don't want to serve as an oracle for the people whose malware they are trying to block

Those people don't have a registered business; The people contacting Microsoft do.

There are probably a bunch of excuses we can come up with that would make sense... but I think most people know the real reason, it's the same as with Google and Apple... they don't do customer support, and they don't take responsibility for any negative effects their services might have on others, at least not until someone big enough makes a fuss or lawyers get involved.

> Those people don't have a registered business; The people contacting Microsoft do.

I don't think you understand how sophisticated malware distribution can be.

There's absolutely nothing stopping a "legitimate business" from distributing malware.

He's not saying there is. He's saying that it's pretty unlikely that the malware authors are going to phone Microsoft and ask why their site is flagged, so putting in some reasonable road blocks that a legitimate business would definitely jump over (e.g. talking to real people) would be plenty to remove the oracle issue.
They don't? How do you know? Having one seems like it would be a real benefit.
Saying they detected malware already does that.

Being slightly more specific shouldn't be a problem.

Sure, maybe not display it in the publicly visible warnings, but if the admins of a domain email you from the same domain as the flagged site, then maybe providing more detail at that point is an acceptable method of fixing the issue.

Saying "we know you are compromised and know exactly where, but we're not going to tell" is very childish. Now, if they said for a nomial fee, we'd be happy to share the results of our work, would be another thing totally.

"we know you are compromised and know exactly where, but we're not going to tell"

The sad think is they didn't even tell that, they gave the admins no ways to be able to differentiate between:

- we don't care if we destroy your company with a false positive and

- we are sure we are right, if you didn't do it intentionally you are probably compromised

TXT DNS records are used by Google, Microsoft and LE exactly for this purpose.
Not sure what you are saying here. I've only ever used TXT DNS records by copying&pasting whatever the original certbot told me to do or when setting up custom domain with 3rd party email. I have no idea what they do, who can read them, when, where, why, etc.

Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance? What does law enforcement do with this info?

> but if the admins of a domain email you from the same domain as the flagged site

Email domains aren't always match with domains running the web-site (don't forget only ten years ago www. was still expected and people redirected you there from non-www. name).

But having access to DNS zone you can prove 'ownership' (at least technical) of the domain (even if it doesn't have the associated MX records for e-mail), precisely why LE is doing it.

> by copying&pasting whatever the original certbot

> I have no idea what they do, who can read them, when, where, why, etc

Oh my...

> Are you saying that if you have this info correctly set up, these companies can verify your email domain is the same to provide assistance?

More like "to prove you are the one responsible for tailspintoys.com - create a TXT record under that domain with 'dylan604 is admin here'".

> I have no idea what they do

TXT records are just plain text strings (in ASCII), nothing more, nothing less.

> who can read them, when, where, why

Everyone, anytime, anywhere, because it is you who placed it there in a system of Public DNS servers

Except that it could help attackers beefen up their tools. A certain amount of obscurity is good to keep the attackers from having too much information.

I've been in the situation where a company kinda 'ghosts' me before. And found out I was indeed the bad player (unintentionally, of course).