Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

351–360 of 558 posts

Re: Google Safe Browsing can kill a startup

#351

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Here-here! I really wish there was more human involvement in a lot of these seemingly arbitrary AI-taken actions. Everything from app review to websites and more. This heavy reliance on automated systems has led us down this road. Shoot, keep it, just give us the option to guarantee human review - with of course transparency. We don't need anymore "some human looked at this and agreed, the decisions is final, goodbye…

> I really wish there was more human involvement in a lot of these seemingly arbitrary AI-taken actions.

Narrator: but it was only ever to get worse

Re: Google Safe Browsing can kill a startup

#352

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Here-here! I really wish there was more human involvement in a lot of these seemingly arbitrary AI-taken actions. Everything from app review to websites and more. This heavy reliance on automated systems has led us down this road. Shoot, keep it, just give us the option to guarantee human review - with of course transparency. We don't need anymore "some human looked at this and agreed, the decisions is final, goodbye…

It's interesting how closely the unfolding of this awful scenario has followed an entirely predictable path based on the shifting incentives: now hundreds of thousands of businesses face the same massive hazard of blocklisted without adequate human review, and with mediocre options to respond to it if it occurs.

Without a shift in incentives, its unlikely the outlook will improve. Unless the organisations affected (and those vulnerable) can organise and exert enough pressure for google to notice and adjust course, we're probably going to be stuck like this -or worse- for a long time.

Re: Google Safe Browsing can kill a startup

#353
post #247

Earlier quoted context omitted.

> Google's desire for scale, scale, scale, meant that interactions must be handled through The Algorithms That's fine when you're a plucky growth startup. Less fine when you run half the internet. If Google doesn't want to admit it's a mature business and pivot into margin-eating, but risk-reducing support staffing, then okay: break it back up into enough startup-sized chunks that the response failure of one isn't an…

This is probably a big part of why Google is invested in (limited) AI, because a good enough "artificial support person" means having their cake and eating it too.

The issue with (limited) AI is that it's seductive. It allows executives to avoid spending actual money on problems, while chalking failures up to technical issues.

The responsible thing would be to (1) staff up a support org to ensure reasonable SLAs & (2) cut that support org when (and if) AI has proven itself capable of the task.

Re: Google Safe Browsing can kill a startup

#354
post #348
post #161

Earlier quoted context omitted.

It's only more secure from Google's blacklist hammer. No significant security is introduced by splitting our company's properties into a myriad of separate domains. This type of incident can be a deadly blow to a B2B SaaS company since you are essentially taking out an uptime sensitive service that a lot of times has downtime penalties written down in a contract. Whether this is downtime will depend on how exactly th…

If you split up your user uploaded material into per client subdomains you will know which one is uploading the malicious files. And your clients can block other subdomains limiting their exposure as well. Is it a huge improvement? No, but at least it's something

It's not clear from other commenters that had similar issues that GSB would not outright ban the entire domain instead of specific subdomains.

In this case, the subdomain they banned was xxx.cloudfront.net, and we know they would not block that whole domain.

We might consider that approach in the future, but I foresee complications in the setup.

Re: Google Safe Browsing can kill a startup

#355

This is actually funny, because I was involved with the creation of this list, way back in 2004. The whole thing started as a way to stop phishing. I was working at eBay/PayPal at the time, and we were finding a bunch of new phishing sites every day. We would keep a list and try to track down the owners of the (almost always hacked) sites and ask them to take it down. But sometimes it would take weeks or months for t…

2 millions phishing sites and counting... with 40000 websites added each week.

https://transparencyreport.google.com/safe-browsing/overview...

I guess the automation started in 2007 or so.

Re: Google Safe Browsing can kill a startup

#356

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Here-here! I really wish there was more human involvement in a lot of these seemingly arbitrary AI-taken actions. Everything from app review to websites and more. This heavy reliance on automated systems has led us down this road. Shoot, keep it, just give us the option to guarantee human review - with of course transparency. We don't need anymore "some human looked at this and agreed, the decisions is final, goodbye…

:s/Here-here/Hear hear/

Re: Google Safe Browsing can kill a startup

#357
post #296
post #292

Earlier quoted context omitted.

unique TLD? that should be very costly? or does GSB not ban the entire TLD when a subdomain has malicious content? Would be great if our overlords at least publish the overzealous rules we need to abide by.

Dropbox DL and Preview urls take a form of https://uc[26 character hex string].dl.dropboxusercontent.com/... and https://uc[26 character hex string].preview.dropboxusercontent.com/... - it does not have to be a separate TLD to avoid being blocked, but it has to be differentiated. This is the same reason why the block of the TFA company did not cause an outage of everyone using CloudFront - GSB does not block full TLD…

Author here. It's really not clear what criteria GSB uses to decide at which level the ban should apply.

Re: Google Safe Browsing can kill a startup

#359
post #23

Earlier quoted context omitted.

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

So browsers should just let users go to obvious phishing sites?

It's easy to take this position when you're very tech savvy. Imagine how many billions of less tech savvy people these kinds of blocklists are protecting.

It's very easy to imagine a different kind of article being written: "How Google and Mozilla let their users get scammed".

Re: Google Safe Browsing can kill a startup

#360
Before even imagining all the ways to start regulating a tech company, I think we desperately need a few basic regulations like:

- For every major service offered, company must provide 3 ways to contact live support, two of which must be immediate, e.g. chat, phone, E-mail. [As opposed to today’s “standard” of having none of these!]

- Every action that can be taken automatically by an AI must be possible for support staff to immediately reverse.

Post reply on HN