Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

251–260 of 558 posts

Re: Google Safe Browsing can kill a startup

#251

I run https://neocities.org , and safe browsing has been my nightmare overlord for a long time. No way to manage reports via an API, no way to contact support. I haven't even been able to find a suggestions box, even that would be an upgrade here. Digging to find "the wizard" gets you into some official google "community support" forum where you learn the forum is actually run by a non-employee lawful neutral that wa…

Since you are putting different users on different subdomains, have you considered asking to have neocities.org added to the public suffix list? See my response to the person who runs freemyip.com and has the same problem: https://news.ycombinator.com/item?id=25804371

Re: Google Safe Browsing can kill a startup

#252

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

> It simply lumbers forward, doing its thing. It is to be modeled as a threat not because it is malign, but because it doesn't notice you exist as it takes another step forward.

This is a concept that I think deserves more popular currency. Every so often, you step on a snail. People actually hate doing this, because it's gross, and they will actively seek to avoid it. But that doesn't always work, and the fact that the human (1) would have preferred not to step on it; and (2) could, hypothetically, easily have avoided doing so, doesn't make things any better for the snail.

This is also what bothers me about people who swim with whales. Whales are very big. They are so big that just being near them can easily kill you, even though the whales generally harbor no ill intent.

Re: Google Safe Browsing can kill a startup

#253
post #23

Earlier quoted context omitted.

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

This. Why is there an implicit agreement that okay Google is the gatekeeper. It shouldn't be. The internet did not appoint Google as the gatekeeper.

Re: Google Safe Browsing can kill a startup

#254
post #80
post #46

Earlier quoted context omitted.

Great article. It’s not malice, it’s indifference. Googles execs and veeps don’t care about small businesses, because most are career ladder climbers who went straight from elite colleges to big companies. Conformists who won’t ever know what it’s like to be a startup. As a group, empathy isn’t a thing for them.

Don't a lot of startup founders go to elite colleges and come from big companies?

The funded ones with the 2 year timelines generally are. But most startups are more bootstrap/angel investor with a bright owner who has a fatal flaw.

Re: Google Safe Browsing can kill a startup

#255

Its not just startups. I work at a major company and we’ve had internal domains flagged in the past due to internal security testing. We resolved it by making some calls to people at Google because the Safe Browsing dashboard is so slow to fix things. This is especially troublesome if you allow customers to upload code to run on your systems (e.g. Javascript for webpages or interactive data analytics) You have to iso…

But you can smother the damage; startups can't.

Re: Google Safe Browsing can kill a startup

#256
post #187

It's a relatively long article - but it does not answer one simple question, which is quite important when discussing this: were there any malicious files hosted on that semi-random Cloudfront URL ? I realise that Google did not provide help identifying it - but that does not mean one should simply recomission the server under a new domain and continue as if nothing has happened! From TFA: > We quickly realized an Am…

They seem to be unable to answer this question since Google provided no URL. Without knowing what is considered malicious, how could they check if there was anything? What if it is a false positive?

Re: Google Safe Browsing can kill a startup

#257

Earlier quoted context omitted.

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

> It simply lumbers forward, doing its thing. It is to be modeled as a threat not because it is malign, but because it doesn't notice you exist as it takes another step forward. This is a concept that I think deserves more popular currency. Every so often, you step on a snail. People actually hate doing this, because it's gross, and they will actively seek to avoid it. But that doesn't always work, and the fact that…

I'm curious if whales more dangerous on an hour-by-hour basis than driving?

That's generally my rubric for whether a safety concern is possibly worth avoiding an activity over.

Re: Google Safe Browsing can kill a startup

#258
post #105

Earlier quoted context omitted.

Author here. Yes, "serve" is the correct interpretation. It is not clear how Google gets ahold of offending URLs within blacklisted domains (like the article says, there were no offending URLs provided to us). Theories: * Obtained from users of Google Chrome that load specific URLs in their browsers * Obtained from scanning GMail emails that contain links to URLs * Obtained from third parties that report these URLs

The main way is via the Googlebot crawler. They also use user reports from Chrome, and links in "mark phishing" emails from Gmail. Those latter two cases the URL is considered private data, so won't be reported in webmaster tools.

We’ve seen internal firewalled URLs in the webmaster tools, so I’m not sure the private data works as intended.

Re: Google Safe Browsing can kill a startup

#259
post #232

Earlier quoted context omitted.

> What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)?

Sounds rather too resource-intensive? I've just tried with current Chrome on Windows and a 32MB zip on my personal domain, Wireshark says the file has not been sent anywhere.

I believe there are limits on the virus checking size. You can see this when trying to download really large files from Google drive (> 100mb)

Re: Google Safe Browsing can kill a startup

#260
post #187

It's a relatively long article - but it does not answer one simple question, which is quite important when discussing this: were there any malicious files hosted on that semi-random Cloudfront URL ? I realise that Google did not provide help identifying it - but that does not mean one should simply recomission the server under a new domain and continue as if nothing has happened! From TFA: > We quickly realized an Am…

Whether or not this author's site was or was not hosting malicious content is irrelevant to the thrust of the article, which is that due to browser marketshare, Google has a vast censorship capability at the ready that nobody really talks about or thinks about.

Think about the jurisdiction Google is in deciding that they want to force Google to shut down certain websites that correspond to apps that they've already had them and Apple ban from the App Store, for "national security" or whatever.

This is one mechanism for achieving that.

Post reply on HN