Live data from Hacker News

Remove any Site From Google (even if you don't control it)

jamesbreckenridge.co.uk

21–30 of 102 posts

Re: Remove any Site From Google (even if you don't control it)

#21

Earlier quoted context omitted.

I know, I am an engineer and I obviously let bugs pass too. But this is a little too obvious to me, to check if the user is allowed to remove this url. Maybe I am neurotic? :)

I can see having this pass by a reviewer or two. They look and see all of this: - There are permission checks - The user has to be logged in to GWT - The user has to have access to this page - The user has to be the owner of the siteUrl After all those permission checks, it might appear that everything was covered. It's just one little omission, verifying that the urlt parameter corresponds to a page within the siteU…

eh? I don't see that as one little omission. It's kind of straightforward that you would need to be the owner of the actual URL to be deleted, so checking the siteUrl is not sufficient. I can understand if they only intended to allow relative paths from the siteUrl, and if there was some kind of bug in special characters or parameter parsing. But no, this is as bad as that bug in Citibank's site where you could just change the account number in the address bar [1]. Color me disillusioned with Google's security practices.

[1] http://consumerist.com/2011/06/how-hackers-stole-200000-citi...

Re: Remove any Site From Google (even if you don't control it)

#22
post #14

Earlier quoted context omitted.

most bugs are obvious after someone has pointed them out to you.

I think the point is that it's a basic dev and QA fail not to check for this, especially with people of the caliber that Google is supposed to recruit.

Process always falls down at some point, it's why we have bugs in the first place. The point of view that "obvious bugs should never happen" is pretty obviously broken, you just try to make them as rare as humanly possible. Besides, simple looking things from the outside can be maddeningly complex from the inside - for all we know this could be related to an obscure bug in their test framework marking it as passed when it isn't.

Most of the time when people say "what a stupid mistake" they mean "that's a mistake I haven't made yet"

Re: Remove any Site From Google (even if you don't control it)

#23

Earlier quoted context omitted.

I know, I am an engineer and I obviously let bugs pass too. But this is a little too obvious to me, to check if the user is allowed to remove this url. Maybe I am neurotic? :)

I can see having this pass by a reviewer or two. They look and see all of this: - There are permission checks - The user has to be logged in to GWT - The user has to have access to this page - The user has to be the owner of the siteUrl After all those permission checks, it might appear that everything was covered. It's just one little omission, verifying that the urlt parameter corresponds to a page within the siteU…

This is a pretty amateurish mistake, actually, and I'm shocked that it was in production at Google. Proper authorization checks are web programming 101.

Re: Remove any Site From Google (even if you don't control it)

#24
This bug could have been exploited for millions of dollars. Imagine giving a mafia boss control over the heartbeat of every rival. One blackhat SEO could have dominated any number of lucrative keywords.

If this bug has existed for a long time it's quite possible some guy is sailing around on a yacht that this bug paid for.

It's such a blindingly obvious bug that I really do wonder whether this might have been a backdoor/inside job by an employee. Google should very closely inspect the code change history.

Hopefully they also maintain a history of all page removal requests to see who might have been exploiting this.

Re: Remove any Site From Google (even if you don't control it)

#26
post #24

This bug could have been exploited for millions of dollars. Imagine giving a mafia boss control over the heartbeat of every rival. One blackhat SEO could have dominated any number of lucrative keywords. If this bug has existed for a long time it's quite possible some guy is sailing around on a yacht that this bug paid for. It's such a blindingly obvious bug that I really do wonder whether this might have been a backd…

It's not a back door, it's an abuse of an existing approach.

Google could weight the process in one of two ways:

    1. in favour of the complaint-maker.
    2. in favour of the website-owner.
If they favour the complainant, then website deletion is presumed to go ahead. If the webmaster, then it is presumed to be held up.

Google chose a compromise: the complaint is acted on, after a delay. The webmaster gets notified through webmaster tools; after some period of time the removal goes ahead.

If Google flip the compromise around, they will make it nigh impossible to remove any websites from the index.

Re: Remove any Site From Google (even if you don't control it)

#27

Earlier quoted context omitted.

I can see having this pass by a reviewer or two. They look and see all of this: - There are permission checks - The user has to be logged in to GWT - The user has to have access to this page - The user has to be the owner of the siteUrl After all those permission checks, it might appear that everything was covered. It's just one little omission, verifying that the urlt parameter corresponds to a page within the siteU…

This is a pretty amateurish mistake, actually, and I'm shocked that it was in production at Google. Proper authorization checks are web programming 101.

If you make a checklist of security practices the QA testers should look for, they'd see and check off "proper authorization checks", as they were done on other fields of the same page. If you can't imagine a professional making this mistake, your mental image of an engineer is not realistic. Humans are not that perfect, and this mistake does not make everyone that reviewed this code an amateur.

Re: Remove any Site From Google (even if you don't control it)

#28
post #9

I don't know how is possible that a so obvious bug passed their quality department, and I wonder if someone didnt discovered it before and was doing this to take out competitors indexes..

Bugs happen. Even big ones like this. Any engineer worth his money knows that no amount of Q&A will discover 100% of the bugs. But, as Joel Spolsky said somewhere, bugs are just bugs, you fix them and then they're fixed.

Quoting Spolky regarding bugs and bug fixes? He has a horse in the game, I wouldn't quote him for anything bug-related.

Regarding bugs: a fast thinker always thinks about the consequences of checking in any code. Checking in code, not to mention releasing it, changes the word (in a very minor way but it still does). Not exploring the possible consequences and the alternative options is just negligence and/or lack of experience. You don't have to be a perfectionist to see this, you just have to be fast: finding a wise, balanced solution quickly every time you change the world.

Re: Remove any Site From Google (even if you don't control it)

#29
post #24

This bug could have been exploited for millions of dollars. Imagine giving a mafia boss control over the heartbeat of every rival. One blackhat SEO could have dominated any number of lucrative keywords. If this bug has existed for a long time it's quite possible some guy is sailing around on a yacht that this bug paid for. It's such a blindingly obvious bug that I really do wonder whether this might have been a backd…

welcometo: http://www.fullmalls.com The website wholesale for many kinds of fashion shoes, like the

nike,jordan,prada,, also including the jeans,shirts,bags,hat and

the decorations. All the products are free shipping, and the the

price is competitive, and also can accept the paypal payment.,after

the payment, can ship within short time. free shippingcompetitive priceany size availableaccept the paypal ===== http://www.fullmalls.com =====

jordan shoes $32nike shox $32Christan Audigier bikini $23 Ed Hardy Bikini $23Smful short_t-shirt_woman $15ed hardy

short_tank_woman $16Sandal $32christian loubo utin $80 Sunglass $15 COACH_Necklace $27handbag $33AF tank woman $17puma slipper woman $30

===== http://www.fullmalls.com =====

===== http://www.fullmalls.com =====

===== http://www.fullmalls.com =====

===== http://www.fullmalls.com =====

===== http://www.fullmalls.com =====

Re: Remove any Site From Google (even if you don't control it)

#30
post #24

This bug could have been exploited for millions of dollars. Imagine giving a mafia boss control over the heartbeat of every rival. One blackhat SEO could have dominated any number of lucrative keywords. If this bug has existed for a long time it's quite possible some guy is sailing around on a yacht that this bug paid for. It's such a blindingly obvious bug that I really do wonder whether this might have been a backd…

It's not a back door, it's an abuse of an existing approach. Google could weight the process in one of two ways: 1. in favour of the complaint-maker. 2. in favour of the website-owner. If they favour the complainant, then website deletion is presumed to go ahead. If the webmaster, then it is presumed to be held up. Google chose a compromise: the complaint is acted on, after a delay. The webmaster gets notified throug…

I think you're misunderstanding the article. Google webmaster tools allows the website owner to request links to their own sites be removed. The poster has discovered that this form can be used to request any url be removed, and Google will think it's being submitted by the owner of that URL.

This has nothing to do with users complaining about a URL.

Post reply on HN