I do not know how to contact the proper person, but I have extreme experience with Trend Micro and their URL blocking system.
They throw false positives like a programmers first day on the job throws errors.
For no reason other than some app or JavaScript that even remotely looks like something that a
Phishing site uses they will block it and possibly your domain.
When this happens you get blocked by Microsoft, Google, Yahoo, IE 7 Phishing filter and all Trend Micro
software and at the server level by URL BLs. In other words GOOD BYE site.
Before any developers start adding this to clients sites Facebook had better get with Trend Micro and
get their app secure and whitelisted.
We all could get sued for billions if Trend Micro blocked sites with Connect on them because Phishers
are using Facebook looking forms to get FB logins.
This is very serious. My five year old domain was blocked for a false positive in August.
November 1st I went flat broke without a sale in 7 weeks. Had to start over from scratch doing
consulting again.
This is not an attempt to get any consulting work, I am full up right now.
This is an attempt to help you all avoid my mistakes and Facebook, CALL TREND MICRO NOW!
If someone at Facebook would like to contact me I will be glad to bring you up to speed.
NO ONE else please do not ask me to help you on this, Facebook needs to solve this and let us know
it is taken care of. I am a nice guy but have 0 time right now.
Get this hashed out before everyone loses what I did because Trend Micro is a loose cannon.
Google it, it is there, but I can't help you right now.
Get this hashed out before everyone loses what I did because Trend Micro is a loose cannon.
Chris Lang
Email Delivery Jedi
Offline
I just talked to my Trend Micro contact and he said although they do the best to connect with big sites, BUT it is up to the site to make sure that the app does not get misidentified.
That is not the issue. The issue is that phishing sites will target the app and make it look like a Facebook Connect widget. Then when you try to log in they will grab the username and login and send a bunch of spam on Facebook. As soon as that happens Trend Micro will disable the app or block sites.
Don't think so? They blocked AdSense when phishing sites spoofed AdSense panels. ADSENSE, you know, by Google? True Trend Micro is closely aligned with Microsoft. But if they are willing to block Google's best source of income do you really think Facebook Connect could not suffer the same fate?
What I am concerned about is clients suing me! I could care less about Facebook. I want to make sure my clients don't get blocked. If Trend Micro blocks a site, it disappears from cyberspace. No email is delivered with the domain in it, TM blocks all web requests and IE 7 disables the site.
I have a top level connection in Trend Micro and I can get my clients sites whitelisted. However if it was not for this I would not touch this thing. I hope someone kicks this upstairs to Facebook and they get with TM and save us, them and our clients the loss of their business.
This is not something to shrug off and say "Microsoft will take care of it." My five year old domain got blocked due to a false positive. I lost $30K before I got to the bottom of it. Now tell me some little blog cannot suffer the same fate because some Phisher bastard spamed all of Facebook and got the app blacklisted because it is unsecured.
Then the guy goes broke and sues me and then I go broke. Now my kids don't eat. Not something I am willing to leave up Microshaft.
BTW Microsoft has a go with it now fix it later rep. Bought any of their products lately? Ever notice Microsoft is not real popular with the hacker crowd? The pro Google hate anything Microsoft does crowd? They would pull this just to screw MS.
Chris Lang
emaildeliveryjedi.com
Offline
This is some pretty tinfoil hat sounding stuff. Do you even have any credible sources about TrendMicro blocking adsense? All I see is a few forum posts.
At any event, what kind of scenarios are you envisioning? The way I see it there are two possible tragedies:
1) Your site uses FB Connect in some unorthodox way that resembles phishers. This could certainly be a problem for you, but that would be something for you to be proactive about on your end.
2) TrendMicro accidentally blocks anything using Facebook Connect. That's a lot of collateral damage, and Facebook would be on it pretty quick after the fact. They'd get it worked out a lot faster than you did when it was just your blog under the gun, so I doubt you'd lose $30k.
Anyhow, if Facebook ever makes good on their promise to only show login dialogs in popup windows (I still see them in lightboxes every now and then), there won't be any problem with them and phishers. As for spamming, I'm sure FB gets enough of that anyhow and would be pretty quick to deal with them (thus not arousing TM's suspicions). I know I haven't had a problem with spam on Faceobok (aside from people sending me invitations to crappy applications like that Vampire crap, but I don't suppose that technically counts as spam)
Offline
@vt_mruhlin
I know about Trend Micro because they blocked my site, destroyed my business and cost me over $30,000 in income.
I was making $5K a week, then nothing. WENT BROKE and LOST EVERYTHING!
http://emaildeliveryjedi.com/email-blog … m-filters/
My contact is the lead developer at Trend Micro for anti phishing.
BTW fbcdn.net the site Facebook uses to run scripts just got listed in Firefox and Chrome as a phishing site just now and you can't even browse to the site.
Not listed in Trend Micro, just checked. TIN FOIL stuff? Try feeding your kids when Trend Micro blocks your domain with URL RBLs. Then tell my concerns are TIN FOIL STUFF!!!!!!!!!!!!!!
Better yet install an unsecured Facebook app on a client's site and when they get blocked and you get sued by your client and can't feed your kids let me tell you it's TIN FOIL STUFF! Please do not insult me like that again.
Thanks for your sympathy to another human beings plight...
Offline
TechCrunch just picked up my blog post and is saying Facebook is not usable in Firefox, Chrome AND now Firefox. Guess my concerns are just tin foil stuff not too, HUH? I even tried to head this off by posting here, since Facebook does not return emails, well you can't say I did not try to help.
http://www.techcrunch.com/2008/12/03/go … hing-site/
But my concerns are only of the tin foil type, so I guess I am just a jackass, or someone is...
Offline
fbcdn.net was listed as a phishing site, but it has now been resolved. Thanks for the heads-up Chris.
@vt_mruhlin: there is an outstanding bug where the login dialog gets shown in a lightbox. it happens if you go to a site while you are logged into Facebook, so the login_status call fetches your logged-in credentials. You then log out of Facebook in a separate tab, go back to the site, and it will show you the lightbox version. it's on the bug list and we plan to fix it. aside from that edge case, all logins are done through browser popups now.
Offline
Glad I could be of any help. I do have the ear of the Trend Micro lead developer. If you would like me to have him contact someone at Facebook to work together on them whitelisting Facebook Connect I can pass a number along or email. Just shoot me something off forum.
Glad for once my conspiracy theories (all kidding aside) helped someone out besides making me sound like a nutt.
Offline
Ha, it is kind of ironic that they got blocked right after you rambled about it. You didn't do something sneaky, did you? ![]()
Seriously though, I'm not surprised that a site called "How to Avoid Spam Filters" got flagged as spam. Removing the big popup asking people to give you their email addresses might also help you look more legit.
Offline