Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

231–240 of 558 posts

Re: Google Safe Browsing can kill a startup

#231
post #49

Can anyone "in the know" objectively comment if Google Safe Browsing (GSB) has had a net positive result or outcome for the Internet, at large? Has GSB helped users, more than it has hurt them? The anti-Google rhetoric [on HN] is becoming more tiresome as of late. Personally, I welcome the notifications in my browsers that a domain is unsafe. I can't possibly be the only one.

What about false positives? From the fine article: one Google system was detecting emails coming from another Google system as phishing. This is ridiculous.

It's needed to make sure you can not claim bias. For example Google blocking competitors, or unfavourable information.

Re: Google Safe Browsing can kill a startup

#232

Our company [0] was also hit by this too. We receive email for our customers and a portion of that is spam (given the nature of email). Google decided out of the blue to mark our attachment S3 bucket as dangerous, because of one malicious file. What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome.…

> What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)?

Sounds rather too resource-intensive? I've just tried with current Chrome on Windows and a 32MB zip on my personal domain, Wireshark says the file has not been sent anywhere.

Re: Google Safe Browsing can kill a startup

#233

A bit of deception on how their site ended up on the block list. They strangely block out a part of their response, but we can see "was cleared", which sounds a lot like "the malware some nefarious agent put on my site was removed". How sites end up on the block list- -they host malware, either intentionally or because they were hacked. -they host a phishing site, either intentionally or because they were hacked. Pro…

Author here. I blocked the message in the screenshot because I narrated the first incident, but took screenshots during the second one, so the redacted part was referencing the first one in which, as described, our domain was cleared without actually doing anything.

Protecting end users from nothing at all (like I said, there is no offending URL) is not more important than making sure Google doesn't literally gatekeep the entire Internet, IMO.

Re: Google Safe Browsing can kill a startup

#234

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Google Safe Search is only half the story. Another huge problem is Google's opaque and rash decisions about what sites throw up warnings in Chrome.

I once created a location-based file-transfer service called quack.space [0] very similar to Snapdrop, except several years before they existed. Unfortunately the idiot algorithms at Chrome blocked it, throwing up a big message that the site might contain malware. That was the end of it.

I had several thousand users at one point, thought that one day I might be able to monetize it with e.g. location based ads or some other such, but Google wiped that out in a heartbeat with a goddamn Chrome update.

People worry about AI getting smart enough to take over humans. I worry about the opposite. AI is too stupid today and is being put in charge of things that humans should be in charge of.

[0] https://www.producthunt.com/posts/quack-space

[1] https://snapdrop.net/

Re: Google Safe Browsing can kill a startup

#235
post #188

Earlier quoted context omitted.

As of today there are no legal protection framework for digital services. Banking is heavily regulated , you are protected by hundreds if not thousands of laws. For digital services ? Twitter and Google can legitimately suspend ALL your accounts because you liked a Trump video on YouTube or Tweeted something « Hateful » to Biden. You can try to go court. You will loose 100% of the time. They are private businesses op…

In this case they do not provide a service to the OP. There is no agreement between OP and Google. This is happening on browsers of their customers. And I'm quite sure that if Google hits a company that competes with Google services there must be a law that they will be breaking. There was a big case in Poland where Google blocked a SaaS web shop provider using the same exact mechanism [0]. Polish courts decided that…

Aside from abusive dominent position there is no law they would break.

When you download and use chrome you ACCEPT the Terms and Conditions of Google.

There is no law that prevents a web browser from blocking access to a website or modifying the page . If the TOS stipulate « pages may differ from the original or be subject to third party software » , they are in within their rights and the customer accepted it when he started using the product.

Don’t get me wrong. I’m on OP sides and everything , but we have let big tech become too big by giving us free stuff for decades.

Now they they decide what’s good for us or not with side effects that often damage small business.

But I insist that in 99% , they operate within the law.

Re: Google Safe Browsing can kill a startup

#236
post #187

It's a relatively long article - but it does not answer one simple question, which is quite important when discussing this: were there any malicious files hosted on that semi-random Cloudfront URL ? I realise that Google did not provide help identifying it - but that does not mean one should simply recomission the server under a new domain and continue as if nothing has happened! From TFA: > We quickly realized an Am…

I am just guessing here, but in case the author had their service compromised, maybe he can't disclose the information. Feels like they know what they are doing, and at least to me, reading between the lines, it looks like they fixed their problem and they advice people to fix it too:

> If your site has actually been hacked, fix the issue (i.e. delete offending content or hacked pages) and then request a security review.

Re: Google Safe Browsing can kill a startup

#237
post #228

Earlier quoted context omitted.

> I keep reading this on the internet as if it’s some sort of truism I don’t believe this statement was initially intended to be axiomatic, rather, to serve as a reminder that the injury one is currently suffering is perhaps more likely than not, the result of human frailty.

I'm not sure it's even attributable to stupidity (necessarily) as attributable to automation or, more long-windedly, attributable to the fact that automation at scale will sometimes scale in wacky ways and said scale also makes it nearly impossible--or at least unprofitable--to insert meaningful human intervention into the loop. Not Google, but a few months back I suddenly couldn't post on Twitter. Why? Who knows. I…

>said scale also makes it nearly impossible--or at least unprofitable--to insert meaningful human intervention into the loop.

Retail and hotels and restaurants can insert meaningful human intervention with less than 5% profit margins, but a company with consistent $400k+ profit per employee per quarter can not?

https://csimarket.com/stocks/singleEfficiencyeit.php?code=GO...

This is what I'm talking about in my original comment about the malice and stupidity aphorism.

Someone or some team of people is making the conscious decision that the extra profit from not having human intervention is worth more than avoiding the harm caused to innocent parties.

This is not a retail establishment barely surviving due to intense competition that may have false positives every now and then because it's not feasible to catch 100% of the errors.

This is an organization that has consistently shown they value higher profits due to higher efficiencies from automation more than giving up even an ounce of that to prevent destroying some people's livelihoods. And they're not going to state that on their "About Us" page on their website. But we can reasonably deduce it from their consistent actions over 10+ years.

Re: Google Safe Browsing can kill a startup

#238

Earlier quoted context omitted.

I was thinking about this this week in the context of online shopping with in store delivery. My wife recently waited nearly half an hour for a “drive up” delivery where she had to check in with an app. Apparently the message didn’t make it to the store, and when she called half way into her wait she wasn’t greeted with consolation, but derision for not understanding the failure points in this workflow. It seems that…

Very poignant observation. I have run into this as well in situations in meat-space everywhere from the DMV queue to grocery pickup. Empathy and understanding for fellow humans is at an all time low, no doubt exacerbated by technologies dehumanizing us into data points and JSON objects in a queue waiting for the algorithm to service. As wonderful as tech has made our lives, it is not fully in the category of "better"…

One of the things I hate the most is people I'm transacting with telling me something has to be done in a certain way because that's how "their system" works.

A recent example, I forgot to pay my phone bill on time and network access got turned off. I came to pay it on Friday, and they tell me the notice will appear in their systems only on Monday and then it takes 2 days for the system to automatically reactivate my access. No, they can't make a simple phone call to someone in the company, yes I will be charged full monthly price for the next month even though I didn't have access for a few days, nothing we can do - ciao

Post reply on HN