Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

441–450 of 558 posts

Re: Google Safe Browsing can kill a startup

#441

Earlier quoted context omitted.

We’re pretty sure they get reports from Chrome. A security researcher at my workplace was running an exploit against a dev instance as part of their secops role and got the domain flagged, despite the site being an isolated and firewalled instance not accessible to the internet.

Yes, I have noticed that creating a brand new dev domain with crawler blocking norobots file, it is not found on any search on Google, until I open the dev url in Chrome, then bam! watch as their crawler starts trying to search through the site just from opening the url in Chrome . This is why I never use Chrome. They scrape the Google Safe Browsing sent from chrome browsers and just do not care about privacy.

You realize that robots.txt is an "on your honor" system and that any one can write a script that doesn't look at robots.txt and post anything they find to the internet and that therefore other sites could find your site via 3rd party data.

Chrome does not do what you claim it does

Re: Google Safe Browsing can kill a startup

#442
post #393
post #338

Earlier quoted context omitted.

> the public suffix list is (sadly) how you communicate that to browsers Sadly, indeed. Had they never heard of DNS?

How would you propose handling this with DNS? Here are some things it covers: * a.example.com and b.example.com are the same site * a.co.uk and b.co.uk are not the same site * a.cloudfront.net and b.cloudfront.net are not the same site * a.higashikawa.hokkaido.jp and b.higashikawa.hokkaido.jp are not the same site * a.example.higashikawa.hokkaido.jp and b.example.higashikawa.hokkaido.jp are the same site There is a p…

[deleted]

Re: Google Safe Browsing can kill a startup

#443
post #184

Earlier quoted context omitted.

"Consciously malicious" is not a good rule of thumb standard to measure threats to yourself or your business; it only accounts for a tiny bit of all possible threats. GP isn't claiming that Google is consciously malicious, they are claiming that you should prepare as if they were. These are not the same thing. A lion may not be malicious when it's hunting you, it's just hungry; look out for it anyway. A drunk driver…

"The decisions are arbitrary, impossible to appeal, and may ruin you." This is a monopoly.

Google may be a monopoly, but this quote has nothing to do with monopoly status. It has to do with power.

As a local businessman I can ruin someone’s life by applying the right legal pressure. Likewise, if one of my customers is reliant on my product to run their own business, and I drop them suddenly (akin to what google sometimes does), that could ruin them. But it’s not because I’m a monopoly, only because people rely on me. Monopoly implies there’s no choice, and while that IS true with google and search. It is not implied by “arbitrary, impossible to appeal, and may ruin you”. The two are distinct (though often related) problems that are both exemplified in Google.

Re: Google Safe Browsing can kill a startup

#444
post #433
post #421

Earlier quoted context omitted.

_i_am_tld.cloudfront.net IN TXT "yes" _i_am_tld.higashikawa.hokkaido.jp IN TXT "yes"

This requires sites to opt in before it works, right? I think this would have been hard to introduce, because it requires so much coordination.

Isn't opting in how almost everything got on the list?

Re: Google Safe Browsing can kill a startup

#445
post #433

Earlier quoted context omitted.

This requires sites to opt in before it works, right? I think this would have been hard to introduce, because it requires so much coordination.

Isn't opting in how almost everything got on the list?

No: Mozilla wrote the initial list based on their understanding of TLDs, and they maintain it based on a combination of opt-in and people noticing that domains should be on the list.

Have a look: https://publicsuffix.org/list/public_suffix_list.dat

Re: Google Safe Browsing can kill a startup

#446
post #434

Earlier quoted context omitted.

Are you implying that the list no longer has a good intention? I wouldn't be surprised if there are multiple orders of magnitude more phishing and hacked websites in 2021 than there was in 2004. Even with human checking, I doubt you'll even have 0% failure rate. Is the solution to just give up on blocking phishing sites?

>Is the solution to just give up on blocking phishing sites? IMHO yes. It's too much power for one company to wield. And especially a company with such questionable morals as Google. This cure is worse than the disease.

I thought you said, the curse is worse than the disease... which also would've made sense.

Re: Google Safe Browsing can kill a startup

#447

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

The solution is simple: Liability. As soon as it becomes legally infeasible to let algorithms block people, it will stop happening. Make it easy and affordable to submit legal complaints for tech misbehavior and make the penalties hurt.

Ah, so you suggest liability for the vendors of the software blocking websites, with, in practice [1], no liability for the operators of a compromised website, if it is phishing/malware?

This is a great approach, if your goal is to optimize for increasing the amount of dangerous crap on the web. But, eh, that's surely worth it, because the profitability of startups is more important then little things like the security of the average netizen...

[1] Even if you make the operators liable [2], in practice, you'll never be able to collect from most of them. Whereas the blacklist curators are a singular, convenient target...

[2] If you can demonstrate how the operators of compromised websites can be held liable for all the harm they cause, I will happily agree that we should do away with blacklists. Unfortunately, the technical and legislative solutions for this are much worse than the disease you are trying to treat.

Re: Google Safe Browsing can kill a startup

#448

Earlier quoted context omitted.

It essentially is a non-aligned AI. AIs don't need to be implemented in silico . Bureaucracy is by itself a computing medium too.

That makes me wonder if someone has ever written a scientific paper proving that the bureaucratic processes in place at their company are Turing Complete. You can imagine some sort of Rule 110 cellular automaton being implemented in TPS reports.

> proving that the bureaucratic processes... are Turing Complete

It's called COBOL

Re: Google Safe Browsing can kill a startup

#449
post #23

Earlier quoted context omitted.

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

Is this list only maintained by Google? Do Firefox and Bing use the same list, is their process better/different? Is there any sharing happening?

SmartScreen is a different list. (And has a "This website isn't malicious!" button.)

Re: Google Safe Browsing can kill a startup

#450
post #247

Earlier quoted context omitted.

> Google's desire for scale, scale, scale, meant that interactions must be handled through The Algorithms That's fine when you're a plucky growth startup. Less fine when you run half the internet. If Google doesn't want to admit it's a mature business and pivot into margin-eating, but risk-reducing support staffing, then okay: break it back up into enough startup-sized chunks that the response failure of one isn't an…

This lack of staffing is something that really annoys me. It's all over the big tech companies, and is often cited as the reason why (for example) YouTube, Twitter, Facebook, etc cannot possibly proactively police (before publishing) all their user content due to the huge volume. Of course they can; Google and the rest earn enough to throw people at the problems they cause/enable. If they can't, then they should stop…

There is a limit to which problems you can throw people at, though. Facebook’s and Youtube’s human moderators suffer from the trauma of watching millions of awful videos every day. Policing provocative posts that are dogwhistling while still allowing satire and legitimate free expression is incredibly challenging and requires lots of context in very different fields. It’s not as simple as setting up a side office in the Philippines and hiring a thousand locals for moderation.
Post reply on HN