Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

311–320 of 558 posts

Re: Google Safe Browsing can kill a startup

#311
post #277

Earlier quoted context omitted.

They care, but the dominant policy in Google's calculus about what features should be released is "Don't let the exceptional case drown the average case." A legitimate SaaS providing business to customers might get caught by this. But the average case is it's catching intentional bad actors (or even unintentional bad actors that could harm the Chrome user), and Google isn't going to refrain from releasing the entire…

Nah-- I think you've got it all wrong. The problem isn't the false positive/false negative ratio chosen. The problem is that there's false positives with substantial harm caused to others and with little path left open to them by Google to fix them / add exceptions-- in the name of minimizing overhead. Google gets all of the benefit of the feature in their product, and the cost of the negatives is an externality born…

One solution, perhaps, could be to have some kind of turnaround requirement---a "habeas corpus" for customer service.

By itself, it won't solve the problem... The immediate reaction could be to address the requirement by resolving issues rapidly to "issue closed: no change." But it could be a piece of a bigger solution.

Re: Google Safe Browsing can kill a startup

#312

This reminds me of email blacklisting. When I was "young" I operated an email server for 6000 users. Keeping that server and our domain away from blacklisting was a full-time job. It wasn't enough to secure your server: Any spam or virus coming from the internal network through that email server could potentially blacklist us. Basically, you had to treat your users as untrusted, and run anti-spam and anti-virus filte…

today Microsoft is the worse. It blacklists your ip from unsuspecting customers using outlook, live.com, etc.. and there is no way to recover from it without becoming yourself a customer. it's vicious because the users of their products are mostly businesses and they are acting as a gateway for doing business with them.

Re: Google Safe Browsing can kill a startup

#313

Earlier quoted context omitted.

"never attribute to malice that which is adequately explained by stupidity" and all that, but after the events and the almost perfectly orchestrated behavior we've seen in the past and last couple of weeks it's becoming increasingly difficult, at least to me, to not attribute this to malice. Probably deliberate negligence is a better term. They know their systems can make mistakes, of course they do, and yet they bui…

>”never attribute to malice that which is adequately explained by stupidity" I keep reading this on the internet as if it’s some sort of truism, but every situation in life is not a court where a prosecutor is trying to prove intent. There is insufficient time and resources to evaluate each and every circumstance to determine each and every causative factor, so we have to use heuristics to get by and make the best gu…

The saying is for your own sanity. If you go around assuming every mistake is malicious, it’s going to fuck up your interactions with the world.

Everyone I know who approaches the world with a me vs. them mentality appears to be constantly fraught with the latest pile of actors “trying to fuck them”.

It’s an angry, depressing life when you think that the teller at the grocery store is literally trying to steal from you when they accidentally double scan something.

Re: Google Safe Browsing can kill a startup

#314

So, essentially they let someone host malicious content on their CDN, which led to Google blocking it. I don't see the scandal here. Also, it seems Google fixed the issue within 2 hours, which is quite good TBH. There are many open-source & commercial IOC lists in distribution from vendors like Crowdstrike, Team CYMRU etc., a lot of them are being fed into SIEM systems, firewalls and proxies at companies. If you happ…

If you're going to comment that they did something wrong, you should consider reading the article and notice that the safe browsing flag didn't mention a URL and the block was removed without any follow-up once they requested the removal.

Re: Google Safe Browsing can kill a startup

#316
This is actually funny, because I was involved with the creation of this list, way back in 2004. The whole thing started as a way to stop phishing.

I was working at eBay/PayPal at the time, and we were finding a bunch of new phishing sites every day. We would keep a list and try to track down the owners of the (almost always hacked) sites and ask them to take it down. But sometimes it would take weeks or months for the site to get removed, so we looked for a better solution. We got together with the other big companies that were being phished (mostly banks) and formed a working group.

One of the things we did was approach the browser vendors and ask them if we could provide them a blacklist of phishing sites, which we already had, would they block those sites at the browser level.

For years, they said no, because they were worried about the liability of accidentally blocking something that wasn't a phishing site. So we all agreed to promise that no site would ever be put on the list without human verification and the lawyers did some lawyer magic to shift liability to the company that put a site on the list.

And thus, the built in blacklist was born. And it worked well for a while. We would find a site, put it on the list, and then all the browsers would block it.

But since then it seems that they have forgotten their fear of liability, as well as their promise that all sites on the list will be reviewed by a human. Now that the feature exists, they have found other uses for it.

And that is your slippery slope lesson for today! :)

Re: Google Safe Browsing can kill a startup

#317
post #259
post #232

Earlier quoted context omitted.

Sounds rather too resource-intensive? I've just tried with current Chrome on Windows and a 32MB zip on my personal domain, Wireshark says the file has not been sent anywhere.

I believe there are limits on the virus checking size. You can see this when trying to download really large files from Google drive (> 100mb)

https://developers.virustotal.com/v3.0/reference#files-scan

Seems I might have just hit the limit? ... Nope, 8.1MB zip file also wasn't sent anywhere.

Re: Google Safe Browsing can kill a startup

#318

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

It's probably "scale thinking" that makes google seem like they don't care: Everything is huge when you're "at scale"; the impact of a small blunder can take down companies or black out nation states. It's part of the game of being "at scale". They probably believe that it's untenable to build the necessary infrastructure to where everything (website, startup, person, etc.) matters. This will sound crass, but it remi…

Your comment reminds me of the first 30 seconds of this scene from The Third Man https://youtu.be/vSc-91F5Wiw

Re: Google Safe Browsing can kill a startup

#319

Earlier quoted context omitted.

No, I don't think that's how it would play out. 1. Google bans parler.com on Jan. 8th by adding it as an "unsafe URL" to their blacklist. 2. Mozilla issues statement: "While we don't believe it was prudent to use the Safe Browsing blacklist for this purpose, given recent events, we will not be unblocking parler.com, and do not currently deem it necessary to maintain a separate safe browsing list." 3. Something simila…

I guess just entirely inventing the slope and start points as well as a predicted trajectory is a new achievement in "slippery slope" arguments. Congratulations. More seriously, maybe invent imaginary third parties rather than arbitrarily assigning your imagined bad motives and awful consequences to real people who did none of what you've suggested? Google could, if they wanted, just add a new category to Safe Browsi…

How is talking about mechanisms for taking parler.com offline "entirely inventing the slope"? It was taken offline by its cloud provider and its apps were removed. Google was even involved in the takedown. Nothing outlandish is being discussed here.

As for "bad motives and awful consequences", what are you talking about? Is wanting to take parler.com offline an objectively "bad motive"? Is succeeding in that endeavor an "awful consequence"? This is the heart of the problem: Weighing consequences is hard when faced with real threats. So when the two consequences are "parler.com becomes inaccessible" and "the integrity of the Google Safe Browsing URL list is slightly compromised", I think it's at least possible that executives would decide to compromise the list.

Re: Google Safe Browsing can kill a startup

#320
If customers using google incurs a tax upon business regardless of whether the business does business voluntarily with google why not work on changing that.

Start with a snazzy our service works better in firefox. Eventually offer trivial new features in firefox but not chrome terminating with a small discount for using firefox. Over time small price increases can render the discounted price the same as the current price and effectively you are charging your users for using a vendor which costs you to do business with.

Google views chrome as a moat around their business keeping other vendors from cutting them off from the revenue stream that powers their entire business. Attack the moat and you might see movement to make your life easier.

Post reply on HN