Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

221–230 of 558 posts

Re: Google Safe Browsing can kill a startup

#221
post #188
post #71

If their claim is false, then is it, in any jurisdiction, libelous? Maybe, legislation to bring consequences for false claims will help ensure algorithms, and the support teams that monitor them, do a better job. In an internet focused world, especially one with lock downs, wiping sites off of the internet with false claims is a heinously bad act.

As of today there are no legal protection framework for digital services. Banking is heavily regulated , you are protected by hundreds if not thousands of laws. For digital services ? Twitter and Google can legitimately suspend ALL your accounts because you liked a Trump video on YouTube or Tweeted something « Hateful » to Biden. You can try to go court. You will loose 100% of the time. They are private businesses op…

In this case they do not provide a service to the OP. There is no agreement between OP and Google.

This is happening on browsers of their customers. And I'm quite sure that if Google hits a company that competes with Google services there must be a law that they will be breaking.

There was a big case in Poland where Google blocked a SaaS web shop provider using the same exact mechanism [0]. Polish courts decided that Google claims displayed on block page were untrue. Unfortunately, the suing company did not receive compensation, because Google Poland does not operate Chrome browser. The court indicated that the right party to sue is Google incorporated in USA...

[0] https://www.silesiasem.pl/iai-przegralo-proces-sadowy-z-goog...

Re: Google Safe Browsing can kill a startup

#222
post #105
post #100

Earlier quoted context omitted.

Pardon my ignorance as I have few years of web dev experience. What exactly does it mean to store data on a domain? Does he mean serve data via a domain URL? And if so, how does Google have discovery of that data?

Author here. Yes, "serve" is the correct interpretation. It is not clear how Google gets ahold of offending URLs within blacklisted domains (like the article says, there were no offending URLs provided to us). Theories: * Obtained from users of Google Chrome that load specific URLs in their browsers * Obtained from scanning GMail emails that contain links to URLs * Obtained from third parties that report these URLs

The main way is via the Googlebot crawler.

They also use user reports from Chrome, and links in "mark phishing" emails from Gmail. Those latter two cases the URL is considered private data, so won't be reported in webmaster tools.

Re: Google Safe Browsing can kill a startup

#223

Can anyone "in the know" objectively comment if Google Safe Browsing (GSB) has had a net positive result or outcome for the Internet, at large? Has GSB helped users, more than it has hurt them? The anti-Google rhetoric [on HN] is becoming more tiresome as of late. Personally, I welcome the notifications in my browsers that a domain is unsafe. I can't possibly be the only one.

It's hard to argue against "safe". If they would name it "filtered browsing" it might be something arguable, but "safe browsing" who wouldn't want that?

Re: Google Safe Browsing can kill a startup

#224

Earlier quoted context omitted.

Avoids the issue until your ugcweb.com is blacklisted and users who uploaded clean ugc are blocked from the portal.

You upload action is hosted on a different domain from the domain that serves the content.

Yes, but when Google blocks either domain, your webapp will still be broken...

Re: Google Safe Browsing can kill a startup

#225
post #168

Earlier quoted context omitted.

Your users did decide to use it, though - and this particular feature is one of the reasons why that particular browser if popular. It was one of the major differentiators of the "better" browsers in the sad old IE days. For all you "use Firefox [etc], don't use Chrome" pundits: it also uses Google Safe Browsing [0], and for that matter so does Safari, which may compound it by using Tencent version instead if you hap…

This is a weak take. Are we saying that any feature built into a web browser is desirable by virtue of the products popularity? 99% of chrome users use it because they recognize the interface from school laptops. Do you really want to live in this world where massive corporations can put whatever they want in their products and the justification is “yeah well people still downloaded it?”

No, we are saying that a site owner should not get to choose which features of the browser the users decide to use. It's the same reason why HN is dogpiling on any site that announces "Only works in Google Chrome", "Best viewed in Safari" or, for older users, "Designed for IE".

One of the reasons why users decided to jump ship to browsers implemneting more advanced security features (which invariably including some sort of malware/phishing actors filter) was the realisation that even a site that has been safe to visit before may serve you malicious content. PHP.net, for instance, was compromised in a way that is eerily similar to what the author here describes - JS files were variably serving malware depending on certain conditions [0], and the first warning anyone got was GSB blocking it. You can read and compare the outrage that 'it can't be true' that particular blocking has caused at your own convenience [1].

Whilst you can convince the users to jump ship to some fringe browser that does not use the technology (and I do invite you to try to find one which does not use either Google, Microsoft or Tencent filters and has at least 0.1% of global usage!), it is a losing proposition from the start. The take is: the vast majority of users is actually comfortable and happy to get this message, as long as they can trust that it is warranted.

Should filters be hosted and adjusted by a major technology company like Google? Probably not, and some indepdendent non-profit hosting them (for the sake of the argument, even StopBadware that kick-started the whole mess [2]) would be welcome to try to take that responsibility. But the filters are here to stay until we come up with something better as a solution.

[0] https://news.ycombinator.com/item?id=6604251 [1] https://support.google.com/webmasters/forum/AAAA2Jdx3sUpuLmv... [2] https://www.stopbadware.org/

Re: Google Safe Browsing can kill a startup

#226

Earlier quoted context omitted.

There's a very obvious reason not to do that: if you apparently maliciously cry wolf a few times, people won't trust your cries any more, and, for example, other browsers might choose to stop using the Google Safe Browsing list.

I would agree, but "apparently maliciously" is too subjective. According to US conservatives this is what Twitter, Facebook, Amazon, Google, Apple, Twilio, Snapchat, etc all did to Parler for political reasons. According to US progressives/liberals it was absolutely not malicious, but rather the polar opposite: protecting people. These days there is no common agreement on that stuff, and given the recent events I see…

Sounds like a full inversion of terms "conservative" and "progressive/liberal" has happened?

Re: Google Safe Browsing can kill a startup

#227

I can confirm everything that was said in that article. I run a free dynamic dns service (freemyip.com) and every time someone creates a subdomain that later hosts some questionable material, Google will immediately block my whole domain. Their response time for clearing these up varies from a few hours to two weeks. It feels completely random. I once had a malicious subdomain that I removed within two hours, yet the…

Author here. This is fascinating because I figured Google would definitely not ban cloudfront.net entirely and that's why they blacklisted the subdomain, but had this been hosted on our actual company domain, would we have been spared?

Re: Google Safe Browsing can kill a startup

#228

Earlier quoted context omitted.

>”never attribute to malice that which is adequately explained by stupidity" I keep reading this on the internet as if it’s some sort of truism, but every situation in life is not a court where a prosecutor is trying to prove intent. There is insufficient time and resources to evaluate each and every circumstance to determine each and every causative factor, so we have to use heuristics to get by and make the best gu…

> I keep reading this on the internet as if it’s some sort of truism I don’t believe this statement was initially intended to be axiomatic, rather, to serve as a reminder that the injury one is currently suffering is perhaps more likely than not, the result of human frailty.

I'm not sure it's even attributable to stupidity (necessarily) as attributable to automation or, more long-windedly, attributable to the fact that automation at scale will sometimes scale in wacky ways and said scale also makes it nearly impossible--or at least unprofitable--to insert meaningful human intervention into the loop.

Not Google, but a few months back I suddenly couldn't post on Twitter. Why? Who knows. I don't really do politics on Twitter and certainly don't post borderline content in general. I opened a support ticket and a follow-up one and it got cleared about a week later. Never found out a reason. I could probably have pulled strings if I had to but fortunately didn't need to. But, yeah, you can just randomly lose access to things because some algorithm woke up on the wrong side of the bed.

Re: Google Safe Browsing can kill a startup

#229

I wonder if it would be faster to deal with this through legal. I’m not a lawyer, but I wonder if you could send a C&D to Google legal or something because this seems like an actual case of slander and reputation damage.

If you are a big enough company your lawyers could have a stern but relatively friendly chat with Google’s lawyers. I can neither confirm or deny this myself...

Yeah my thought behind this was you are a large enough or wealthy enough company that you can afford lawyers. If you are an individual or mom and pop business whose blog or small e-commerce shop are blocked then you are probably SOL.

Re: Google Safe Browsing can kill a startup

#230

Earlier quoted context omitted.

> What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)?

The hashes of all things that match a "probably evil" bloom filter, yes. Hosting a virus on a domain and then downloading it a few times with different chrome installations sounds like a good way to get the whole domain blacklisted...

That's why user uploads are worth some thought and consideration. File uploads normally gets treated as a nuisance by developers because it can become kind of fiddly even when it works and you are getting file upload bugs from support.

It normally isn't that much of a challenge to mitigate the issues, but other things get priorities. Companies end up leaving pivots to XSS attacks and similar bugs too.

Post reply on HN