Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

211–220 of 558 posts

Re: Google Safe Browsing can kill a startup

#211

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

> they probably don't realize what's happening and will fix it

“If only the czar knew!”

Re: Google Safe Browsing can kill a startup

#212
post #100

Earlier quoted context omitted.

Pardon my ignorance as I have few years of web dev experience. What exactly does it mean to store data on a domain? Does he mean serve data via a domain URL? And if so, how does Google have discovery of that data?

How would you even “store” data on a domain?

Look up how DoH and ECH store public keys in the DNS system :)

Not what the author intended but DNS as a Database is a thing.

Re: Google Safe Browsing can kill a startup

#213
post #98

Can Google be held legally accountable for this behavior? Seems like they are hurting businesses by spreading false information. With their market power there need to be some incentive for them to react quicker and with human oversight.

If the business wants to argue that, they can sue Google for defamation/libel.

Re: Google Safe Browsing can kill a startup

#214

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

Sounds like a non-aligned AI.

Re: Google Safe Browsing can kill a startup

#215

I wonder if it would be faster to deal with this through legal. I’m not a lawyer, but I wonder if you could send a C&D to Google legal or something because this seems like an actual case of slander and reputation damage.

If you are a big enough company your lawyers could have a stern but relatively friendly chat with Google’s lawyers.

I can neither confirm or deny this myself...

Re: Google Safe Browsing can kill a startup

#216

I run https://neocities.org , and safe browsing has been my nightmare overlord for a long time. No way to manage reports via an API, no way to contact support. I haven't even been able to find a suggestions box, even that would be an upgrade here. Digging to find "the wizard" gets you into some official google "community support" forum where you learn the forum is actually run by a non-employee lawful neutral that wa…

If Google is falsely claiming your malicious and its harming your business it seems like a pretty clear case of slander/tortuous interference.

I honestly wonder if you could take them to small claims court...

Re: Google Safe Browsing can kill a startup

#217

It seems like the FTC should be running this for US based customers and browsers should default to a local resource and/or let users override the default source of truth.

Cool, then we can complain about false positives at the FTC instead of at Google!

IMHO, it doesn't really matter who runs it, so long as they're not actively working in bad faith. False positives are a fact of life, garaunteed so long as we have an adversarial malware ecosystem. (For example, the fixes for bad decisions are pretty much indistinguishable from bad actors evading correct decisions.)

The other side of the coin is a web that looks like my missed calls list - everything is assumed to be spam and malware infested until proven otherwise. No one will use your startup anyway, because any given site is probably terrible. The whitelist becomes a thing that people maintain in their heads, and, again, you get a massive incumbent advantage.

The right balance is somewhere in-between, and involves fine tuning the false positive rate. The false positives are always going to be unhappy, and hard to tell apart from true positives trying to keep their scam going.

Re: Google Safe Browsing can kill a startup

#218

Our company [0] was also hit by this too. We receive email for our customers and a portion of that is spam (given the nature of email). Google decided out of the blue to mark our attachment S3 bucket as dangerous, because of one malicious file. What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome.…

> What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)?

The hashes of all things that match a "probably evil" bloom filter, yes.

Hosting a virus on a domain and then downloading it a few times with different chrome installations sounds like a good way to get the whole domain blacklisted...

Re: Google Safe Browsing can kill a startup

#219
post #32

Yes, the power of something like Google Safe Browsing is scary, especially if you consider the many many downstream consumers who might have an even worse update / response time. Responsiveness by Google is not great, as expected, we recently contacted Google to get access to the paid WebRisk API and haven't heard anything in a few months... However, phishing detection and blocking is not a fun game to be in. You can…

[deleted]
Post reply on HN