Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

331–340 of 558 posts

Re: Google Safe Browsing can kill a startup

#331

Google:Don't be evil. Yes, don't be evil but opaque and inconsiderate. It's amazing how a company as profitable as Google has such a horrible customer service.

"Don't be evil" - It's been forgotten about a long time ago.

https://en.wikipedia.org/wiki/Don%27t_be_evil

Re: Google Safe Browsing can kill a startup

#332
post #247

Earlier quoted context omitted.

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

> Google's desire for scale, scale, scale, meant that interactions must be handled through The Algorithms That's fine when you're a plucky growth startup. Less fine when you run half the internet. If Google doesn't want to admit it's a mature business and pivot into margin-eating, but risk-reducing support staffing, then okay: break it back up into enough startup-sized chunks that the response failure of one isn't an…

This lack of staffing is something that really annoys me. It's all over the big tech companies, and is often cited as the reason why (for example) YouTube, Twitter, Facebook, etc cannot possibly proactively police (before publishing) all their user content due to the huge volume.

Of course they can; Google and the rest earn enough to throw people at the problems they cause/enable. If they can't, then they should stop. If you cannot scale responsibly, then you should not scale at all as your business has simply externalised your costs onto everyone else you impact.

Re: Google Safe Browsing can kill a startup

#333
post #301

Earlier quoted context omitted.

That's why user uploads are worth some thought and consideration. File uploads normally gets treated as a nuisance by developers because it can become kind of fiddly even when it works and you are getting file upload bugs from support. It normally isn't that much of a challenge to mitigate the issues, but other things get priorities. Companies end up leaving pivots to XSS attacks and similar bugs too.

Google has a great service for this called Checksum. You upload a file checksum and it validates it against the database of all known bad checksums that might flag your website as unsafe. The pricing is pretty reasonable too and you can proxy file uploads through their service directly. I'm actually not telling the truth but at what point did you realize that? And what would be the implications if Google actually did…

Ha! You got me. I was like, wow, that sounds really useful. I'd love to sign up for that, and built my app to use it, if that were the case.

But then, I realized: 1). I'd be integrating further into Google because of a problem they created (racketeering), and 2). They seem to really dislike having paying customers (even if they made it, they'd kill it before long).

Re: Google Safe Browsing can kill a startup

#334

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

"never attribute to malice that which is adequately explained by stupidity" and all that, but after the events and the almost perfectly orchestrated behavior we've seen in the past and last couple of weeks it's becoming increasingly difficult, at least to me, to not attribute this to malice. Probably deliberate negligence is a better term. They know their systems can make mistakes, of course they do, and yet they bui…

Employees and managers at Google get promoted by launching features and products. They're constitutionally incapable of fixing problems caused by over-active features for the same reason they've launched seven different chat apps.

Re: Google Safe Browsing can kill a startup

#335
post #83

> Proactively claim ownership of all your production domains in Google Search Console. That's one of the first things you should do, when registering a domain and setting up a website. It takes about 2 minutes. So I wonder a bit why a business of this size would learn doing this through such a crisis.

This is sad. When you open a business in the real world, sure you have to tell the authorities about it (because it's the law!). When you open a digital business, you have to tell Google (via Google Search Console) about it... But Google is not the law, not even an authority; it just happens that Google owns google.com and Chrome and that makes Google the de facto Godfather of the internet: if you don't comply, your business is practically dead. Again, sad.

Re: Google Safe Browsing can kill a startup

#336

Its not just startups. I work at a major company and we’ve had internal domains flagged in the past due to internal security testing. We resolved it by making some calls to people at Google because the Safe Browsing dashboard is so slow to fix things. This is especially troublesome if you allow customers to upload code to run on your systems (e.g. Javascript for webpages or interactive data analytics) You have to iso…

Do you need a real domain for each customer or is a subdomain sufficient isolation?

Re: Google Safe Browsing can kill a startup

#337
post #282

Earlier quoted context omitted.

"the fact that Google's own legitimate emails are flagged as phishing by their own filters is pretty telling about the reliability of the whole thing" It detects blacklisted URLs in emails and sends warnings, retroactively given that sites are caught some indeterminate time after they might have been communicated (flagging if you have interacted with the email and thus might have been compromised). It seems like it w…

If Google flagging its own e-mails is your idea of a perfectly reliable phishing detection system, I don't think we are going to find much common ground. For what it's worth, it's all true :) Good luck to you.

Sure it is. Keep on harping about a warning system working perfectly (because, again, you clearly fail to understand it)...it makes a really good case for your screed.

Re: Google Safe Browsing can kill a startup

#338
post #244

I can confirm everything that was said in that article. I run a free dynamic dns service (freemyip.com) and every time someone creates a subdomain that later hosts some questionable material, Google will immediately block my whole domain. Their response time for clearing these up varies from a few hours to two weeks. It feels completely random. I once had a malicious subdomain that I removed within two hours, yet the…

Have you considered requesting that your domain be added to the public suffix list? https://publicsuffix.org/ If subdomains of your domain should be treated as independent sites, the public suffix list is (sadly) how you communicate that to browsers. (Disclosure: I work for Google, speaking only for myself)

> the public suffix list is (sadly) how you communicate that to browsers

Sadly, indeed. Had they never heard of DNS?

Re: Google Safe Browsing can kill a startup

#339

Earlier quoted context omitted.

Sometime Google doesn't recognize your device and then your password is not enough... even if you have second-factor authentication disabled. So if you don't have a second form of contact like another phone number or another email for recovery, then you are fucked. Sometime they even ask you for a previous password for recovery, so if you use a password manager that doesn't keep history, you might also be fucked.

Is this only when using MFA. Sometimes, without MFA enabled, if you just change the user-agent header they send an email that they have detected a "new device". What if you just exported all mail each day, maybe this could be automated, then in the event of a lockout at least you have all of the stored mail.

I don't use MFA.

Also, I have my emails backed up, but that doesn't help for authentication/recovery with other services/external accounts that were created using that Gmail account... Maybe I need to host my own but that comes with a plethora of other problems.

Re: Google Safe Browsing can kill a startup

#340
post #26

This is not new; such things happened many times in the past (25 years ago Microsoft was the behemoth trampling small companies) and will happen again. I do not think Google is doing it consciously -- this is probably just collateral damage from some bot or rule. The way to handle it is to reduce dependencies on the cloud. This does not mean cutting cloud services altogether, but once the company is big enough (and t…

> I do not think Google is doing it consciously -- this is probably just collateral damage from some bot or rule.

"Collateral damage" from some bot or rule just means that Google doesn't care enough about the edge cases (which, at Google scale, are particularly harmful): Google consciously decided this when implementing their algorithms.

Post reply on HN