I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)
I'm not sure how he was unable to find their security@google.com email address. Searches like "Google security" and "Google report vulnerability" have http://www.google.com/about/corporate/company/security.html (which has a prominent section on reporting security issues) as their first result.
Remove any Site From Google (even if you don't control it)
91–100 of 102 posts
Re: Remove any Site From Google (even if you don't control it)
#92Earlier quoted context omitted.
I am a google apps paying customer and it took them 4 weeks to get my domain issue corrected ! In that time i wasnt able to get mail so i had to change my mail to use godaddy until they got back to me. When they finally did they said it was because my dns records were pointing to godaddy ! After 1 week of not getting mails i would say an alternative is required. I actually had a feeling that this would happen :) I re…
Setting up your DNS is not really something Google should do for you. You should have had an IT pro who's done this sort of transition before, manage the move. You could have had this resolved in hours not weeks. I agree though Google support sucks, the key is to not depend on it.
Re: Remove any Site From Google (even if you don't control it)
#93Earlier quoted context omitted.
Personally, I would be more concerned if someone with malicious intent and the ability to keep silent about what they have done had found & exploited this. [0] Advertise: remove your competitor from Google's search results for a day! If I didn't think it was illegal, I'd probably pay for that, were I in such a situation. [0] If, of course, it even existed in the first place. It seems plausible enough to me, even if I…
Eh, ok it would be more concerning . But Lulzsec would have made quite a spectacle out of it.
Re: Remove any Site From Google (even if you don't control it)
#94I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)
Sending an email to security@google.com will result in a quick response. As part of their bug bounty program Google would have paid $1,000 for this bug if not more.
Re: Remove any Site From Google (even if you don't control it)
#95Earlier quoted context omitted.
Bugs happen. Even big ones like this. Any engineer worth his money knows that no amount of Q&A will discover 100% of the bugs. But, as Joel Spolsky said somewhere, bugs are just bugs, you fix them and then they're fixed.
I know, I am an engineer and I obviously let bugs pass too. But this is a little too obvious to me, to check if the user is allowed to remove this url. Maybe I am neurotic? :)
Sometimes testers use the shotgun approach, and things get missed. It can help to write exhaustive tests (you have a computer, right?) and try everything. But the problem space has to be orderly, orthogonal, something that can be spanned. This bug is in a pretty small problem space - an API with many dimensions (arguments), external dependencies. I'm not at all surprised something got thru.
Re: Remove any Site From Google (even if you don't control it)
#96I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)
It's obnoxious how hard it is to report bugs to Google. And posting in their forum is a joke anyway. Google's new two-factor authentication? Really neat right? Yeah, well, it's buggy and there is no way to report bugs for it. I posted in the forum and was received by crickets. I don't mind it most of the time, but when I have a real issue or something that is obviously broken and unnoticed, it sure is frustrating. ed…
Re: Remove any Site From Google (even if you don't control it)
#97Re: Remove any Site From Google (even if you don't control it)
#98Earlier quoted context omitted.
> This bug could have been exploited for millions of dollars. Quite possibly exploited for non-savvy website owners. Savvy owners would be checking their ranking regularly and noticing it disappear one day. Anyone who ranks highly for lucrative keywords and does not check their ranking is asking to lose it, whether ethically or otherwise. So I don't think it would have been exploited for the millions you think, but p…
> Anyone who ranks highly for lucrative keywords and does not check their ranking is asking to lose it, whether ethically or otherwise. Your ranking is not your responsibility as a webmaster. It's Google's responsibility to its users to rank good answers highly.
Re: Remove any Site From Google (even if you don't control it)
#99Earlier quoted context omitted.
Sending an email to security@google.com will result in a quick response. As part of their bug bounty program Google would have paid $1,000 for this bug if not more.
That was my immediate thought when I read the article. "Wow, this guy just chucked away hundreds of dollars". Always check for a bounty program before you go and release information like this.
Re: Remove any Site From Google (even if you don't control it)
#100Earlier quoted context omitted.
That was my immediate thought when I read the article. "Wow, this guy just chucked away hundreds of dollars". Always check for a bounty program before you go and release information like this.
Google should probably still give this guy the bounty