Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

381–390 of 558 posts

Re: Google Safe Browsing can kill a startup

#381
post #374

Earlier quoted context omitted.

I think you mean 2017? 2007 is when the feature launched.

january/february 2007 looks like the time the list jumped from a few hundred to tens of thousands of sites.

That was the normal volume of manually identified sites at the time. Before 2007 there weren’t a lot of participants because it was in beta.

Re: Google Safe Browsing can kill a startup

#382

Earlier quoted context omitted.

We’re pretty sure they get reports from Chrome. A security researcher at my workplace was running an exploit against a dev instance as part of their secops role and got the domain flagged, despite the site being an isolated and firewalled instance not accessible to the internet.

Yes, I have noticed that creating a brand new dev domain with crawler blocking norobots file, it is not found on any search on Google, until I open the dev url in Chrome, then bam! watch as their crawler starts trying to search through the site just from opening the url in Chrome . This is why I never use Chrome. They scrape the Google Safe Browsing sent from chrome browsers and just do not care about privacy.

Maybe it's from search suggestion API? Anyway, I turn that off as soon as I create a new browser profile, along with the safe browsing list and automatic search when I type unrecognized URL. When I want to search I use search input of the browser. (ctrl+k) URL bar is for URLs only.

Re: Google Safe Browsing can kill a startup

#383

Earlier quoted context omitted.

How would you even “store” data on a domain?

Look up how DoH and ECH store public keys in the DNS system :) Not what the author intended but DNS as a Database is a thing.

Ah yes, customer generated data sounds just like public keys

Re: Google Safe Browsing can kill a startup

#384

Earlier quoted context omitted.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

So browsers should just let users go to obvious phishing sites? It's easy to take this position when you're very tech savvy. Imagine how many billions of less tech savvy people these kinds of blocklists are protecting. It's very easy to imagine a different kind of article being written: "How Google and Mozilla let their users get scammed".

I mean, it was barely a decade ago when my parents computers regularly got filled with malware and popups and scams. They regularly fell for bullshit online. Maybe they have gotten more savvy, but I feel like this has overall greatly decreased, in a world where there's actually increasingly more bad actors.

Re: Google Safe Browsing can kill a startup

#385
post #23

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

Is this list only maintained by Google? Do Firefox and Bing use the same list, is their process better/different? Is there any sharing happening?

Re: Google Safe Browsing can kill a startup

#386
> losing access to their GMail accounts and their entire digital life.

This is why my email address is @ a domain that I own. Thus, if my hoster goes ventral fin up, I find another hoster. I might lose some time, but I won't lose everything permanently.

My mail reader (Thunderbird) is also configured to always download all new email and delete it from the server. Hence I have backups going back 25 years, which has turned out to be valuable many times. One case was when I was reconstructing the timeline for "History of the D Programming Language" I had a solid resource rather than my barnacle-encrusted memory.

https://dl.acm.org/doi/abs/10.1145/3386323

Re: Google Safe Browsing can kill a startup

#388
post #245

Earlier quoted context omitted.

> What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)?

> Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)? It doesn't, unless you opt for SafeSearch "Enhanced Protection" or enable "Help improve security on the web for everyone" in "Standard Protection". Both are off by default, IIRC. Without it, it periodically downloads what amounts to bloom filter of "potentially unsafe" URLs/domains. On the other hand, GMail and GDrive do run the checks vi…

What happens if it is a hit against the bloom filter / checksum? Would it transmit the URL so that it can be blocklisted?

Re: Google Safe Browsing can kill a startup

#389

1- Ban self dealing. Even the appearance of a conflict of interest should be treated as an actual conflict of interest. Among all the other countermeasures being considering, breaking apart these monopoly's end-to-end integrations should be top priority. For comparison: I'm a huge Apple fan boy. I'm in a happy monogamist relationship with Apple (h/t NYU Prof Scott Galloway). There's no question their awesome products…

> Criticisms, editing, word smithing much appreciated.

My loose thoughts, feel free to use. (Reordered 2 before 1.)

2. In any bigg-ish privately regulated market, the membership needs to be based on public, objective rules and under a real jurisdiction. If you paid and obeyed the regulations and have been banned/mistreated, you can sue.

1. For any market, if a company (Google or other) has a clear majority of it, they have additional responsibilities.

"Customer is free to go away to our competitors" does not tell a full story (illustrated by OP). The cost to switch is the real deal here.

Re: Google Safe Browsing can kill a startup

#390

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Are you implying that the list no longer has a good intention? I wouldn't be surprised if there are multiple orders of magnitude more phishing and hacked websites in 2021 than there was in 2004. Even with human checking, I doubt you'll even have 0% failure rate. Is the solution to just give up on blocking phishing sites?

The solution is for the legitimate sites that are driven out of business by Google AI to sue Google for tortuous interference and libel.
Post reply on HN