Dropbox flagged as unsafe by IE
forums.dropbox.com
forums.dropbox.com
EDIT: It looks like it's gotten some attention from MS at some point as it seems to have cleared up now.
The more cynical side of me would say that MS got a chuckle out of this. After all, Dropbox is a competitor to SkyDrive.
Only in rare cases will the company in question sheepishly admit they fucked up. Most of the time the site remains tight lipped, or blames $browservendor and maintains their innocence.
As far as malware goes, vendors should exclude domains which are basically user-administrated file lockers. Someone uploading a file which may or may not be sketchy should never be cause for blocking of the entire freaking subdomain!
And who's responsible for building that list? Does the vendor have to add things manually? Is there a submission process? How do you stop genuine malware sites from hosting multiple copies on subdomains and claiming innocence?
What about where you don't use subdomains, but a url structure like example.com/user/file/?
Making exceptions always sounds like the easy option, until you have to try doing it, and running it at any scale.
Separate subdomains, having a human spend 30 seconds clicking around and deciding "Oh, this is a file locker. Obviously not a malware host or infected site. Whitelisted".
>And who's responsible for building that list? Does the vendor have to add things manually? Is there a submission process?
The vendor. Which is how its done already. So yes and depends.
>How do you stop genuine malware sites from hosting multiple copies on subdomains and claiming innocence?
This is Dropbox, not TotallyLegitFiles302.ru
I see what you're getting at, but something this high visiblity (and obviousness to pretty much everyone) points to something rotten in their process somewhere.
Furthermore, it's more effective and efficent to just register a new domain than to haggle (in broken english, another red flag) with the platform owner.
The real issue isn't what we don't allow/block, but what we do allow/let pass.
There's no way to disable this checking globally aside from using a command line flag. If you hit the link for more information, you are taken to this page (https://support.google.com/chrome/bin/answer.py?hl=en&an...), which states:
> Some plug-ins, such as Flash, are used by many websites on the Internet. Other plug-ins are only used by a small number of sites. Since plug-ins can occasionally be a security risk, Google Chrome now blocks plug-ins that are not widely used.
Which runs counter to the conventional wisdom that a larger installed base means a larger attack target and seems a bit anti-competitive especially since Google is trying to push WebM over the Apple-backed H.264 and the deal Google made with Adobe to bundle Flash.
Google Chrome still includes H.264 support. They said they were going to remove it a year ago, but never did. There's no need to install plugins to play H.264 video with Chrome.
PS. Pushing a royality-free standard over a heavily patented one is anti-competitive?
When Chrome does lose H.264 support, I'll be using the QuickTime plugin even more to play H.264 videos. Then, the only way for me to watch H.264 in Chrome is by a plugin that is purposefully given an inferior user experience for a BS reason. If security were the real reason, the Flash plugin should also get the same treatment as QuickTime given its history of security flaws and crappy performance (at least on OS X).
Nevertheless, the handling of QuickTime stinks. They should check the version number and only disable if it is out of date. Their current approach is just inviting complaints.
Our settings are managed by policy, though, so I can't say what security features are on/off. I've seen the Safe Browsing stuff before, though.
of course this makes an assumption about why IE flagged Dropbox.
www.google.com/search?&tbm=isch&q=google+chrome+malware+page
I already pointed out months ago that this was mostly an illusion due to their greater amount of false positives: http://www.morbo.org/2011/08/note-on-malware-detection-perfo...
Instead of throwing up more dialog boxes or making them look prettier or more noticeable or just different they actually need to address the security of their products. It seems like they're just being stubborn and instead of rewriting what needs rewriting they wrap every security hole with new, ever more annoying dialog boxes with every major release.
I agree that it is annoying, but I'm very interested to hear what they should be addressing here.
I kept thinking, "Will this ever get resolved?"