Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

391–400 of 558 posts

Re: Google Safe Browsing can kill a startup

#391
post #299
post #244

Earlier quoted context omitted.

Have you considered requesting that your domain be added to the public suffix list? https://publicsuffix.org/ If subdomains of your domain should be treated as independent sites, the public suffix list is (sadly) how you communicate that to browsers. (Disclosure: I work for Google, speaking only for myself)

Fascinating. I had never heard of this, and cloudfront.net is in there, which might provide a clue as to why Google only blacklisted our subdomain and not the whole thing (imagine that!). Is there any downside to being on this list?

> Is there any downside to being on this list?

If example.com were on list then a cookie set on a.example.com couldn't be read on b.example.com. In this case that would probably be a good thing, since the subdomains represent independent sites, but if a site were erroneously added that could be a problem (mail.yahoo.com and groups.yahoo.com should share login cookies, for example).

The list was originally created to handle cookies, but more recently it's been used for other notions of "site", like cache sharding.

Re: Google Safe Browsing can kill a startup

#392
post #247

Earlier quoted context omitted.

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

> Google's desire for scale, scale, scale, meant that interactions must be handled through The Algorithms That's fine when you're a plucky growth startup. Less fine when you run half the internet. If Google doesn't want to admit it's a mature business and pivot into margin-eating, but risk-reducing support staffing, then okay: break it back up into enough startup-sized chunks that the response failure of one isn't an…

> That's fine when you're a plucky growth startup. Less fine when you run half the internet.

It's never fine.

The abdication of responsibility and, more importantly, liability to algorithms is everything that's wrong with the internet and the economy. The reason these tech conglomerates are able to get so big when companies before them couldn't is because it's impossible to scale the way they have without employing thousands of humans to do the jobs that are being poorly done by their algorithms. Nothing they're doing is really a new idea, they just cut costs and made the business more profitable. The promise is that the algorithms/AI can do just as good of a job as humans but that was always a lie and, by the time everyone caught on, they were "too big to fail".

Re: Google Safe Browsing can kill a startup

#393
post #338
post #244

Earlier quoted context omitted.

Have you considered requesting that your domain be added to the public suffix list? https://publicsuffix.org/ If subdomains of your domain should be treated as independent sites, the public suffix list is (sadly) how you communicate that to browsers. (Disclosure: I work for Google, speaking only for myself)

> the public suffix list is (sadly) how you communicate that to browsers Sadly, indeed. Had they never heard of DNS?

How would you propose handling this with DNS? Here are some things it covers:

* a.example.com and b.example.com are the same site

* a.co.uk and b.co.uk are not the same site

* a.cloudfront.net and b.cloudfront.net are not the same site

* a.higashikawa.hokkaido.jp and b.higashikawa.hokkaido.jp are not the same site

* a.example.higashikawa.hokkaido.jp and b.example.higashikawa.hokkaido.jp are the same site

There is a proposal to do something similar using response headers and .well-known urls: https://github.com/privacycg/first-party-sets

Re: Google Safe Browsing can kill a startup

#394

Earlier quoted context omitted.

Jon Williams, circa 1987, wrote a story of a far-flung humanity's future in "Dinosaurs," in which humans had been engineered into a variety of specialized forms to better serve humanity. After nine million years of tweaking, most of them are not too bright but they are perfect at what they do. Ambassador Drill is trying to prevent a newly discovered species, the Shar, from treading on the toes of humanity, because if…

Sounds like a non-aligned AI.

It essentially is a non-aligned AI. AIs don't need to be implemented in silico. Bureaucracy is by itself a computing medium too.

Re: Google Safe Browsing can kill a startup

#395
post #352

Earlier quoted context omitted.

Here-here! I really wish there was more human involvement in a lot of these seemingly arbitrary AI-taken actions. Everything from app review to websites and more. This heavy reliance on automated systems has led us down this road. Shoot, keep it, just give us the option to guarantee human review - with of course transparency. We don't need anymore "some human looked at this and agreed, the decisions is final, goodbye…

It's interesting how closely the unfolding of this awful scenario has followed an entirely predictable path based on the shifting incentives: now hundreds of thousands of businesses face the same massive hazard of blocklisted without adequate human review, and with mediocre options to respond to it if it occurs. Without a shift in incentives, its unlikely the outlook will improve. Unless the organisations affected (a…

> this awful scenario has followed an entirely predictable path

The interesting things about predictable paths is that at the start there are a LOT of them, then over time there becomes just one of them. I don't see that this path was any more predictable at the start than any other.

Re: Google Safe Browsing can kill a startup

#396

Earlier quoted context omitted.

There's a very obvious reason not to do that: if you apparently maliciously cry wolf a few times, people won't trust your cries any more, and, for example, other browsers might choose to stop using the Google Safe Browsing list.

No, I don't think that's how it would play out. 1. Google bans parler.com on Jan. 8th by adding it as an "unsafe URL" to their blacklist. 2. Mozilla issues statement: "While we don't believe it was prudent to use the Safe Browsing blacklist for this purpose, given recent events, we will not be unblocking parler.com, and do not currently deem it necessary to maintain a separate safe browsing list." 3. Something simila…

The problem is, if a mainstream browser goes against the flow, it becomes "The Nazi Browser." Its market share was already less than Chrome's, and now it's getting all these new users who are outcasts.

This whole problem only started because browsers stopped being neutral to the content and basically adopted the harmful "if you're not with us, you're against us" stance that seems to be propagating through everything these days. None of the "smaller" browsers (and I mean smaller than Firefox - the Dillos, Netsurfs, and Lynxes) do anything like this.

Re: Google Safe Browsing can kill a startup

#397
I learned the hard way that other companies than Google also contribute to the blacklist. A site I was working on got falsely flagged by netcraft.com (which they admitted after I spent a week explaining it to them). They do some kind of active AI cyber defence bollocks and have netflix as a customer. Their Automated Idiot classified our login page as trying to phish netflix.

The fun part of this is that I could have prevented this if I had seen the warning email that Google sent me, but since Gmail classified it as an email phishing attempt, I never saw it (straight to spam folder). How ironic.

Consequences:

- Our website was blocked in all major browsers, not just chrome

- AWS, who also look at the blacklist and were contacted by netcraft automatically, threatened to delete our account. I had to convince both parties that we did nothing wrong

- One week offline

Re: Google Safe Browsing can kill a startup

#399

Earlier quoted context omitted.

Sounds like a non-aligned AI.

It essentially is a non-aligned AI. AIs don't need to be implemented in silico . Bureaucracy is by itself a computing medium too.

That makes me wonder if someone has ever written a scientific paper proving that the bureaucratic processes in place at their company are Turing Complete. You can imagine some sort of Rule 110 cellular automaton being implemented in TPS reports.

Re: Google Safe Browsing can kill a startup

#400

Earlier quoted context omitted.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

This. Why is there an implicit agreement that okay Google is the gatekeeper. It shouldn't be. The internet did not appoint Google as the gatekeeper.

>The internet did not appoint Google as the gatekeeper.

Uh, it kind of did, when internet-savvy early adopters (and developers) convinced all their friends, then family, then acquaintances, to switch to Chrome a decade ago.

I know there's probably a very large number of FOSS-only types on this site who would disagree with that assessment, and claim that they've always been in the Firefox camp, but the sheer market share of chrome clearly shows that they are the minority.

Everyone switched to chrome because they were tired of IE having too much power and not conforming to standards. Nowadays web devs often build chrome-first, using chromium-only features, and the shoe has almost migrated to the other foot.

Post reply on HN