Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

161–170 of 558 posts

Re: Google Safe Browsing can kill a startup

#161
post #145
post #23

Earlier quoted context omitted.

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

IMHO, it sounds like it worked. The things you changed sound like it's made your site more secure. In the future, Googles hammer can be a bit more precise since you've segregated data. And you don't know what triggered it. It's possible that one of your clients was compromised or one of their customers was trying to use the system to distribute malware.

It's only more secure from Google's blacklist hammer.

No significant security is introduced by splitting our company's properties into a myriad of separate domains.

This type of incident can be a deadly blow to a B2B SaaS company since you are essentially taking out an uptime sensitive service that a lot of times has downtime penalties written down in a contract. Whether this is downtime will depend on how exactly the availability definition is written.

Re: Google Safe Browsing can kill a startup

#162
post #154

Am I missing something? Is there ever a reason to expose a CloudFront url to the end user instead of using a custom domain?

Is there a problem with doing it? I don't see how that would have helped in this case (if anything, it might have made things worse if Google decided to ban the 1st level domain, which they certainly won't do for Cloudfront.net).

It just seems less professional. It’s much like having a .blogger.com or .substack domain.

We have been trained for decades not to trust random domains. To the uninitiated, a CloudFront domain is random.

I know I’m taken a little aback anytime I go to Amazon’s credit card site - https://amazon.syf.com/login/ it looks like a phishing site.

Re: Google Safe Browsing can kill a startup

#163

Can anyone "in the know" objectively comment if Google Safe Browsing (GSB) has had a net positive result or outcome for the Internet, at large? Has GSB helped users, more than it has hurt them? The anti-Google rhetoric [on HN] is becoming more tiresome as of late. Personally, I welcome the notifications in my browsers that a domain is unsafe. I can't possibly be the only one.

The problem, from HN's perspective, is that false positives on GSB hurt businesses a lot more than they hurt users or the internet at large. If I'm a random person browsing the internet at large, and a website I try to visit gets flagged as "possibly malicious", well, I probably didn't need the information or services on that particular website that badly anyway. I can find another website that offers the same inform…

> an internet business, on the other hand, would prefer a false negative to a true positive, let alone a false positive.

[Emphasis mine]

This is crucial and it's why the sub-threads imagining suing Google aren't going anywhere. Google will very easily convince a judge that what they're doing is beneficial to the general public, because it is, even though some HN contributors hate it because they'd prefer to meet a much lower standard.

What I'm seeing a lot of in this thread is people saying OK, maybe a burger we sold did have rat droppings in it, but I feel like our kitchen ought to be allowed to stay open unless they buy at least a few hundred burgers and find rat droppings in a statistically significant sample and even then shouldn't I get a few weeks to hire an exterminator? Isn't that fairer to me?

Re: Google Safe Browsing can kill a startup

#164

Being completely blacklisted is very bad, but u know at least that something needs fixing. Imagine if google partially punishes u and downrank you in the search for no reason. This is harder to figure out. It took us several months to discover such a problem until finally we registered to google websmaster tool.

what was the problem?

Re: Google Safe Browsing can kill a startup

#165
post #68
post #55

Earlier quoted context omitted.

So what would they use instead? It's not like there are any other free, real-time and mostly accurate malicious-URL databases around for people to plug into their browsers and products.

Nothing at all. Many people survive exposure to the internet without being protected by corporate firewalls, think-of-the-children filters and antivirus. Or do we expect UK citizens to curl up in fetal position and start screaming as soon as they leave their country because they're no longer protected by their ISP filters?

As someone who tracks phishing pages I would disagree. The amount of really high-quality fast flux phishing put out every day on completely legitimate-looking domains is astonishing. I know plenty of people who would immediately fall for it, and I wouldn't blame them one bit.

Re: Google Safe Browsing can kill a startup

#166

I run https://neocities.org , and safe browsing has been my nightmare overlord for a long time. No way to manage reports via an API, no way to contact support. I haven't even been able to find a suggestions box, even that would be an upgrade here. Digging to find "the wizard" gets you into some official google "community support" forum where you learn the forum is actually run by a non-employee lawful neutral that wa…

If Google is falsely claiming your malicious and its harming your business it seems like a pretty clear case of slander/tortuous interference.

Re: Google Safe Browsing can kill a startup

#168
post #140

Earlier quoted context omitted.

When you installed their browser.

I didn’t install their browser.

Your users did decide to use it, though - and this particular feature is one of the reasons why that particular browser if popular. It was one of the major differentiators of the "better" browsers in the sad old IE days.

For all you "use Firefox [etc], don't use Chrome" pundits: it also uses Google Safe Browsing [0], and for that matter so does Safari, which may compound it by using Tencent version instead if you happen to be in China [1]

[0] https://wiki.mozilla.org/Security/Safe_Browsing [1] https://support.apple.com/en-us/HT210675

Re: Google Safe Browsing can kill a startup

#169
I can confirm everything that was said in that article. I run a free dynamic dns service (freemyip.com) and every time someone creates a subdomain that later hosts some questionable material, Google will immediately block my whole domain. Their response time for clearing these up varies from a few hours to two weeks. It feels completely random. I once had a malicious subdomain that I removed within two hours, yet the ban on Google lasted for more than two weeks. Now, this is a free service so bans like these don’t really matter that much to me, but if it was a business, I would have most likely gone bankrupt already.

I noticed that recently, they are only sending me the warning, but don’t block me right away. Perhaps after a few years of these situations I advanced to a more “trusted” level at Google where they give me some time to react before they pull the plug on my domain. I don’t know. But I would be truly petrified of Google if this was my real business.

Re: Google Safe Browsing can kill a startup

#170

Our company [0] was also hit by this too. We receive email for our customers and a portion of that is spam (given the nature of email). Google decided out of the blue to mark our attachment S3 bucket as dangerous, because of one malicious file. What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome.…

Or you could screen your attachments for malware?

We do, but it's not good enough for Google.
Post reply on HN