Chrome Flagging Cloud Help Desk as a "Deceptive Site"
Incident Report for Spiceworks
Resolved
This incident has been resolved.
Posted Aug 07, 2020 - 08:53 CDT
Update
We are continuing to monitor for any further issues.
Posted Aug 07, 2020 - 08:53 CDT
Monitoring
Based on investigation into multiple user reports we believe a small subset of Cloud Help Desk ticket attachments/uploads may have been responsible for triggering a sudden broader flagging of many unrelated ticket attachment URLs (when accessing those URLs in Google Chrome). The logic and thresholds used to determine whether a URL will be flagged by Chrome are unclear. Attachment URLs for many, but not all, Cloud Help Desk accounts appear to have been affected. Using all available sampled data from Google, we identified multiple false positives along with a handful of legitimately malicious files in isolated Cloud Help Desk accounts. We have taken steps to clean up known malicious files, and will be making improvements to isolate the behaviors of malicious actors and prevent the ticket attachments feature from being abused in the future. In the meantime, we believe Google Chrome may intermittently and unexpectedly flag your “safe” ticket attachment URLs because ticket attachments for all Cloud Help Desk accounts share a top level domain.
Posted Aug 06, 2020 - 16:18 CDT
Update
Developers continue to look into this issue and are working with Google to sort it out.
Posted Aug 06, 2020 - 15:21 CDT
Investigating
We've received reports from users indicating that the Cloud HD is being flagged by Chrome as a 'deceptive site'. We're investigating the issue and will update this page when more is known. Once the error is clicked through, however, the Help Desk functions normally.
Posted Aug 06, 2020 - 09:58 CDT
This incident affected: Cloud Help Desk.