Live data from Hacker News

Remove any Site From Google (even if you don't control it)

jamesbreckenridge.co.uk

41–50 of 102 posts

Re: Remove any Site From Google (even if you don't control it)

#41

I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)

http://goo.gl/vulnz

Re: Remove any Site From Google (even if you don't control it)

#42
Somewhat related: I wish GWT had a "pattern" removal.

With one of my sites, by the time I noticed that certain pages were missing the "noindex" tag Google happily indexed over 4000 pages. Considering the rate Google is crawling those pages it may take years to be removed from the index. Obviously, submitting each link one by one is rather tedious.

Hopefully the author is going to release that extension after Google fixes this bug. I may actually bother clicking 4K times just to see that site "fixed"...

Re: Remove any Site From Google (even if you don't control it)

#43
post #34
post #24

This bug could have been exploited for millions of dollars. Imagine giving a mafia boss control over the heartbeat of every rival. One blackhat SEO could have dominated any number of lucrative keywords. If this bug has existed for a long time it's quite possible some guy is sailing around on a yacht that this bug paid for. It's such a blindingly obvious bug that I really do wonder whether this might have been a backd…

> This bug could have been exploited for millions of dollars. Quite possibly exploited for non-savvy website owners. Savvy owners would be checking their ranking regularly and noticing it disappear one day. Anyone who ranks highly for lucrative keywords and does not check their ranking is asking to lose it, whether ethically or otherwise. So I don't think it would have been exploited for the millions you think, but p…

> Anyone who ranks highly for lucrative keywords and does not check their ranking is asking to lose it, whether ethically or otherwise.

Your ranking is not your responsibility as a webmaster. It's Google's responsibility to its users to rank good answers highly.

Re: Remove any Site From Google (even if you don't control it)

#44

I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)

It's obnoxious how hard it is to report bugs to Google. And posting in their forum is a joke anyway. Google's new two-factor authentication? Really neat right? Yeah, well, it's buggy and there is no way to report bugs for it. I posted in the forum and was received by crickets. I don't mind it most of the time, but when I have a real issue or something that is obviously broken and unnoticed, it sure is frustrating. ed…

My favorite has always been the google apps problems that tell you to contact support to get a resolution but you can only contact support if you are a paying customer.

support is not google's strong suit.

Re: Remove any Site From Google (even if you don't control it)

#45
post #36

Earlier quoted context omitted.

The article delivers. Why is this linkbait?

[deleted]

He included screenshots and a description. Neither are impossible to fake, but either it's a genuine mistake (in which case I would imagine someone would have pointed it out) or he's faking it.

You seem to be accusing him of faking, without any evidence or even a motive.

Edit: also http://www.jamesbreckenridge.co.uk/what-i-learned-today.html

Re: Remove any Site From Google (even if you don't control it)

#46

Earlier quoted context omitted.

What's a great trick for SEO is this sensationalist linkbait article.

The article delivers. Why is this linkbait?

How does the article deliver? I don't see, in the comments on his blog or here, any evidence that this has been independently reproduced. He's got a description, and some "screenshots" and, oh, Google seems to already have fixed it. How... convenient?

I'm not saying it's fake, but I don't see any reason to believe it. Am I missing something?

Re: Remove any Site From Google (even if you don't control it)

#47

Earlier quoted context omitted.

If you make a checklist of security practices the QA testers should look for, they'd see and check off "proper authorization checks", as they were done on other fields of the same page. If you can't imagine a professional making this mistake, your mental image of an engineer is not realistic. Humans are not that perfect, and this mistake does not make everyone that reviewed this code an amateur.

Well, people are down voting me, but everyone ripped the developers of Diaspora apart for basically the same exact flaw in an early alpha release of their system. The Google fanboyism seems to be running strong here.

Those flaws were all over their entire codebase in very basic parts of the site's functionality. They had literally zero authorization checks.

Re: Remove any Site From Google (even if you don't control it)

#49

I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)

I'm not sure how he was unable to find their security@google.com email address. Searches like "Google security" and "Google report vulnerability" have http://www.google.com/about/corporate/company/security.html (which has a prominent section on reporting security issues) as their first result.

Because now you know the email is spelled "security@google.com", it would be easy to come up with search query that returns that email address after the fact. If you going by the instinct, search for "google bug report", ...I'm on page 20 and still couldn't find that email. (Personalize search turned off.)

Re: Remove any Site From Google (even if you don't control it)

#50
post #45
post #36

Earlier quoted context omitted.

[deleted]

He included screenshots and a description. Neither are impossible to fake, but either it's a genuine mistake (in which case I would imagine someone would have pointed it out) or he's faking it. You seem to be accusing him of faking, without any evidence or even a motive. Edit: also http://www.jamesbreckenridge.co.uk/what-i-learned-today.html

Was it the "I'm not saying it's fake" part that made it seem to you that I seem to be accusing him of faking?

My point is that the evidence is wholly insufficient. It was the first post on a new blog (i.e. no reputation), no way to reproduce the reported issue, no reports of it having been reproduced by anyone else, no acknowledgment from Google (ok, maybe it's a little early for that), etc. I mean, from a journalistic, much less scientific, standpoint, it's pretty poor.

How can I provide evidence of a negative? Would you please provide evidence disproving my assertion that flying saucers visited my house last night? And motive? Wasn't that covered earlier by the word "linkbait"?

Maybe my calibration is way off today, but I'm surprised by the level of credulity I've been seeing. My original post (which I deleted and then reposted, sorry about that) got downvoted to subzero with no explanation. I agree with other posters that bugs happen, but I would have thought that such a major claim against a generally competent player like Google would require at least one independent verification.

I'll be curious to see if Google mentions this. Otherwise, we'll really never know. Well, you may, but I guess I'm a little more skeptical.

Post reply on HN