Live data from Hacker News

My experience being blocked by Google Safe Browsing (2022)

brennan.io

41–50 of 66 posts

Re: My experience being blocked by Google Safe Browsing (2022)

#41
post #37

> Then, I registered my domain on the “Google Search Console” product (which I’ve already used for other domains). What if one doesn't want to forfeit their personal info to Google and sign / agree to to their policies and TOS?

This is a very fair question - it's worth noting that appealing Google's decision to include you on the GSB list can be done without a Google account.

The other stuff the author does with Google Search Console isn't necessary to get delisted.

Re: My experience being blocked by Google Safe Browsing (2022)

#42
My website also ended up in Safe Browsing list for some reason, and instead of registering on Google, I started to make an example of it to my friends to disable that Safe Browsing feature in their browser. It lasted for a week, perhaps, before it disappeared from the list. I didn't change anything during that time.

Re: My experience being blocked by Google Safe Browsing (2022)

#43
post #19
post #5

I feel the "i want my friends and family to be safe" is similar to the "but think of the kids!" excuse. Maybe its some kind of a Stockholm Syndrome variant of people using Chrome, but its definitely not healthy. I don't actually believe that it has blocked that many people from being phished, and I doubt that all the entries on that list are malicious. It seems like a system that was designed by someone to simply get…

I often click links on phishing mails I get just for fun, and more often than not they result in webpages being blocked by Chrome. Anecdotal, but there you go.

You shouldn't, the links usually have unique data embedded and it will confirm your email as a valid target for future attacks. You are basically adding a "real mailbox with an active, gullible user" tag to your email in the spammers list.

Re: My experience being blocked by Google Safe Browsing (2022)

#45
post #2

Yikes, giving Google the power to block any website to the majority of humankind may not be the best idea.

Let's be real here: Google doesn't need a "safe browsing" list to control website access.

The vast majority of people, when they want to visit a website, go to Google, type in the name of the website, hit search, then click the top result.

Address bar? WTF is an address? WTF is a bar?

When the vast majority of people access websites through google.com, Google already decides where the people go.

Let's also not forget tech enthusiasts and professionals all advise using 8.8.8.8. Guess what: Google literally owns your DNS requests.

Re: My experience being blocked by Google Safe Browsing (2022)

#46

I have never seen a 'wrong' case of safebrowsing warning... Always after sufficient investigation I find that the server has been broken into and there are some malicious PHP files sitting in some directory named '.system' or something similar. Either that or the site allows user uploads and some user has uploaded some malicious JavaScript crypto miner or something. On a mastodon server, it is hard to check all the c…

Everyone just assumes, incorrectly, that their systems are clean and secure. It didn't seem to even occur to OP to seriously investigate his site for "malware or social engineering attacks".

Re: My experience being blocked by Google Safe Browsing (2022)

#47

I have never seen a 'wrong' case of safebrowsing warning... Always after sufficient investigation I find that the server has been broken into and there are some malicious PHP files sitting in some directory named '.system' or something similar. Either that or the site allows user uploads and some user has uploaded some malicious JavaScript crypto miner or something. On a mastodon server, it is hard to check all the c…

Everyone just assumes, incorrectly, that their systems are clean and secure. It didn't seem to even occur to OP to seriously investigate his site for "malware or social engineering attacks".

On this topic: I've encountered multiple small business websites that have a spam JavaScript redirect that on a referral from google.com -- if you go directly to the website (as the business owner or the GoogleBot might), everything is fine, if you click out from Google you get served either a small page with nothing both the JavaScript redirect, or the page with the JavaScript redirect prepended.

Some variants of this use cookies to only serve the redirect on the first click from Google, so if you're like "weird" and try again, everything looks fine the second time.

You can see the problem if you curl such a URL with Google as the referrer.

Re: My experience being blocked by Google Safe Browsing (2022)

#48
post #39

On mobile (Android) it's different. You cannot continue past the warning in Firefox Daylight (or Chrome, of course). about:config is also walled off in every mobile Firefox build except Nightly - and even then, the "safe browsing" keys toggle back every time the app restarts. Android WebView listens to the safe browsing list too, so you can have native apps open up with blood-red warning screens which is very uncomfo…

It really pisses me off that even Firefox on desktop tries to scare you away from about:config with a lie, claiming that using it will void your warranty. Meanwhile the license under which Firefox is provided says "Covered Software is provided under this License on an "as is" basis, without warranty of any kind"

Firefox has no warranty to void. The warning message they make you view the first time you try to use about:config is simply lying to you. You might say "Oh well it's a well intentioned lie", but it's still a lie and there is no reason for this lie to even exist. The warning could be worded without this lie. It could simply say "You might break stuff if you continue" and that would be true enough and still scare off people who don't know what they're doing. So why the hell are they lying?

Re: My experience being blocked by Google Safe Browsing (2022)

#49
post #2

Yikes, giving Google the power to block any website to the majority of humankind may not be the best idea.

I agree, but also what's the alternative. A complete free-for-all doesn't work because malicious actors be malicious and a majority of users aren't competent to protect themselves against such threats. So we need something, if not google, then it would be something else. We can't trust private corporations because of potential for conflicts of interests (between users and profit motives) and we don't seem to want to…

> A complete free-for-all doesn't work because malicious actors be malicious and a majority of users aren't competent to protect themselves against such threats.

It does work. You claim it doesn't because you think the resultant state of affairs is intolerable, but to subsequently claim it "doesn't work" because you don't like the outcome is simply wrong. You might as well claim that allowing people to buy pointy kitchen knives "doesn't work" because sometimes people stab each other and you think murders are simply intolerable. But the reality is that allowing people to have pointy knives even though some people get hurt does work, even though it doesn't produce an outcome the hypothetical you are happy with.

The problem with "think of the children" style arguments is they are always unbounded, and there is always something more controlling than what we're doing presently that could obstensibly make children even safer. Why not have browsers ship a whitelist of trusted websites, and forbid all others? That would be even safer, and if you oppose this then you're not thinking of the children. In fact I find the present state of affairs with bad websites being blacklisted simply intolerable, new malicious websites are permitted by default and that just doesn't work!

Re: My experience being blocked by Google Safe Browsing (2022)

#50

I have never seen a 'wrong' case of safebrowsing warning... Always after sufficient investigation I find that the server has been broken into and there are some malicious PHP files sitting in some directory named '.system' or something similar. Either that or the site allows user uploads and some user has uploaded some malicious JavaScript crypto miner or something. On a mastodon server, it is hard to check all the c…

Everyone just assumes, incorrectly, that their systems are clean and secure. It didn't seem to even occur to OP to seriously investigate his site for "malware or social engineering attacks".

In either case, a clear citation of the alleged "phishing" content would help to avoid ambiguity.

>Maybe I would feel better if there had been more transparency in the process. I was left to guess what Google thought was deceptive about my site.

Post reply on HN