Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

361–370 of 558 posts

Re: Google Safe Browsing can kill a startup

#361
post #263

Earlier quoted context omitted.

>said scale also makes it nearly impossible--or at least unprofitable--to insert meaningful human intervention into the loop. Retail and hotels and restaurants can insert meaningful human intervention with less than 5% profit margins, but a company with consistent $400k+ profit per employee per quarter can not? https://csimarket.com/stocks/singleEfficiencyeit.php?code=GO... This is what I'm talking about in my origin…

Fair enough. Scale does make things harder but my $FINANCIAL_INSTITUTION has a lot of scale too and, if I have an issue with my account, I'll have someone on the phone sooner rather than later.

You're saying that as if it contradicts (“but”) what lotsofpulp said, but that was exactly their point: If your bank can do it, then so could Google. That they choose not to is a conscious choice, and not a beneficious one.

Conrad's corollary to Hanlon's razor: Said razor having been over-spread and under-understood on the Internet for a long while now, it's time to stop routinely attributing lots of things only to stupidity, when allowing that stupidity to continue unchecked and unabated actually is a form of malice.

(Hm, yeah, might need a bit of polishing, but I hope the gist is clear.)

Re: Google Safe Browsing can kill a startup

#362

Earlier quoted context omitted.

I would agree, but "apparently maliciously" is too subjective. According to US conservatives this is what Twitter, Facebook, Amazon, Google, Apple, Twilio, Snapchat, etc all did to Parler for political reasons. According to US progressives/liberals it was absolutely not malicious, but rather the polar opposite: protecting people. These days there is no common agreement on that stuff, and given the recent events I see…

Sounds like a full inversion of terms "conservative" and "progressive/liberal" has happened?

Indeed, although I suspect it's just because of the politics here. If Parler had been a progressive/liberal haven conservatives would support censoring while progressives would be outraged at the violation of free speech.

The reason I think this is that's what happened with "private companies can do what they want." Giant corporations imposing their values on individuals is not a problem for progressives when it's big tech. Likewise Conservatives don't seem to support private property rights and no regulation anymore.

Re: Google Safe Browsing can kill a startup

#363
post #292
post #276

Earlier quoted context omitted.

Dropbox actually provides an unique domain for each and every user - and separates the UGC from the web front code and Dropbox own assets that way - that's where the files you preview/download are actually coming from. I have no doubt a fair number of those is blacklisted.

unique TLD? that should be very costly? or does GSB not ban the entire TLD when a subdomain has malicious content? Would be great if our overlords at least publish the overzealous rules we need to abide by.

My Google-fu is failing me right now, but there is a list of domains like dropboxusercontent.com that are treated as pseudo second-level domains for purposes like this.

e.g. u1234.dropboxusercontent.com is treated as a unique domain just like u1234-dropboxusercontent.com would be.

Edit: here we go, from another comment - the Public Suffix List: https://publicsuffix.org/

Re: Google Safe Browsing can kill a startup

#364
post #232

Earlier quoted context omitted.

Sounds rather too resource-intensive? I've just tried with current Chrome on Windows and a 32MB zip on my personal domain, Wireshark says the file has not been sent anywhere.

Wouldnt it be more efficient to grab it in parallel to your download?

That only shifts the bandwidth cost between the original server and the user, Google's resources are unaffected. And it's not what GP claimed.

I just checked the nginx access logs - both the 32MB and the 8MB zip files have been accessed only once (both were created only for this experiment).

Re: Google Safe Browsing can kill a startup

#365
post #342

Earlier quoted context omitted.

One of the things I hate the most is people I'm transacting with telling me something has to be done in a certain way because that's how "their system" works. A recent example, I forgot to pay my phone bill on time and network access got turned off. I came to pay it on Friday, and they tell me the notice will appear in their systems only on Monday and then it takes 2 days for the system to automatically reactivate my…

Systems (normally) model organizational processes, so companies with garbage processes usually have garbage systems in place too. This highly specific case reeks of fraud, and you should be able to report them to some kind of ombudsman so you could get your couple days' worth of fees back.

I would bet they have some terms & conditions the person agreed to that leaves them legally SOL.

Re: Google Safe Browsing can kill a startup

#366

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

Modern large corporations are just an more inefficient, less effective paperclip maximizer, with humans gumming up the works.

Google is striving hard to remove the "human" part of the problem.

Re: Google Safe Browsing can kill a startup

#367

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Here-here! I really wish there was more human involvement in a lot of these seemingly arbitrary AI-taken actions. Everything from app review to websites and more. This heavy reliance on automated systems has led us down this road. Shoot, keep it, just give us the option to guarantee human review - with of course transparency. We don't need anymore "some human looked at this and agreed, the decisions is final, goodbye…

Couldn’t agree more, the transparency is key. It enables faith in the system and outcome.

The counter argument to transparency will be that it provides too much information to those who aim to build phishing sites not blocked by the filter.

That said, we’ve experienced systems in which obfuscation wins out over transparency and it would be nice to tackle the challenges of transparency.

Re: Google Safe Browsing can kill a startup

#369
post #357
post #296

Earlier quoted context omitted.

Dropbox DL and Preview urls take a form of https://uc[26 character hex string].dl.dropboxusercontent.com/... and https://uc[26 character hex string].preview.dropboxusercontent.com/... - it does not have to be a separate TLD to avoid being blocked, but it has to be differentiated. This is the same reason why the block of the TFA company did not cause an outage of everyone using CloudFront - GSB does not block full TLD…

Author here. It's really not clear what criteria GSB uses to decide at which level the ban should apply.

Probably when the ratio of bad sites to good sites at a particular subdomain level passes a threshold.

Re: Google Safe Browsing can kill a startup

#370
post #355

This is actually funny, because I was involved with the creation of this list, way back in 2004. The whole thing started as a way to stop phishing. I was working at eBay/PayPal at the time, and we were finding a bunch of new phishing sites every day. We would keep a list and try to track down the owners of the (almost always hacked) sites and ask them to take it down. But sometimes it would take weeks or months for t…

2 millions phishing sites and counting... with 40000 websites added each week. https://transparencyreport.google.com/safe-browsing/overview... I guess the automation started in 2007 or so.

I think you mean 2017? 2007 is when the feature launched.
Post reply on HN