Live data from Hacker News

My experience being blocked by Google Safe Browsing (2022)

brennan.io

51–60 of 66 posts

Re: My experience being blocked by Google Safe Browsing (2022)

#51

Earlier quoted context omitted.

Everyone just assumes, incorrectly, that their systems are clean and secure. It didn't seem to even occur to OP to seriously investigate his site for "malware or social engineering attacks".

In either case, a clear citation of the alleged "phishing" content would help to avoid ambiguity. >Maybe I would feel better if there had been more transparency in the process. I was left to guess what Google thought was deceptive about my site.

If we let Google design our criminal justice system, the accused would never be informed of what crime they broke because that would "help criminals get away with it"

Re: My experience being blocked by Google Safe Browsing (2022)

#52
post #45
post #2

Yikes, giving Google the power to block any website to the majority of humankind may not be the best idea.

Let's be real here: Google doesn't need a "safe browsing" list to control website access. The vast majority of people, when they want to visit a website, go to Google, type in the name of the website, hit search, then click the top result. Address bar? WTF is an address? WTF is a bar? When the vast majority of people access websites through google.com, Google already decides where the people go. Let's also not forget…

there's an enormous difference between people not being able to find a site they don't know about and breaking bookmarks and existing links

yes, it's true that google has a lot of power

Re: My experience being blocked by Google Safe Browsing (2022)

#53

Earlier quoted context omitted.

I agree, but also what's the alternative. A complete free-for-all doesn't work because malicious actors be malicious and a majority of users aren't competent to protect themselves against such threats. So we need something, if not google, then it would be something else. We can't trust private corporations because of potential for conflicts of interests (between users and profit motives) and we don't seem to want to…

> A complete free-for-all doesn't work because malicious actors be malicious and a majority of users aren't competent to protect themselves against such threats. It does work. You claim it doesn't because you think the resultant state of affairs is intolerable, but to subsequently claim it "doesn't work" because you don't like the outcome is simply wrong. You might as well claim that allowing people to buy pointy kit…

Well of course when I said "it doesn't work" I meant that I found the outcome intolerable. That outcome being a majority of users being vulnerable to malicious attacks with a whole host of real world bad consequences for them.

I think that regular people having unrestricted access to enriched plutonium also to have intolerable outcomes. Even if some people would be able to handle the substance safely (both to themselves and others), the ones that don't or can't will cause intolerable outcomes. And yes, this is a 'think of the children' style argument. I don't want the children (or adults) to get radiation sickness. My hot take here is that it would be bad.

Re: My experience being blocked by Google Safe Browsing (2022)

#54
post #39

On mobile (Android) it's different. You cannot continue past the warning in Firefox Daylight (or Chrome, of course). about:config is also walled off in every mobile Firefox build except Nightly - and even then, the "safe browsing" keys toggle back every time the app restarts. Android WebView listens to the safe browsing list too, so you can have native apps open up with blood-red warning screens which is very uncomfo…

It really pisses me off that even Firefox on desktop tries to scare you away from about:config with a lie, claiming that using it will void your warranty. Meanwhile the license under which Firefox is provided says "Covered Software is provided under this License on an "as is" basis, without warranty of any kind" Firefox has no warranty to void . The warning message they make you view the first time you try to use abo…

Does it though? Mine says "Changing advanced configuration preferences can impact Firefox performance or security."

Here is a screenshot: https://i.imgur.com/RYPhiSe.png

This is Firefox 111.0.1 on Kubuntu.

Re: My experience being blocked by Google Safe Browsing (2022)

#55
post #11

Earlier quoted context omitted.

Mastodon, perhaps unwisely, replicates all media it encounters.

Again, it's eight users, one of which has full control over the database plus an approximate timestamp when something went wrong. Super easy to check every outbound click, every post published, every post received... Everything.

I run a single user instance, and I definitely can't review every post received?

Re: My experience being blocked by Google Safe Browsing (2022)

#56
post #38
post #5

I feel the "i want my friends and family to be safe" is similar to the "but think of the kids!" excuse. Maybe its some kind of a Stockholm Syndrome variant of people using Chrome, but its definitely not healthy. I don't actually believe that it has blocked that many people from being phished, and I doubt that all the entries on that list are malicious. It seems like a system that was designed by someone to simply get…

> I don't actually believe that it has blocked that many people from being phished The data says the opposite, the safe browsing list is very effective* which is why many other browsers and systems use the same list to block malicious pages. Google publishes data about the frequency of warnings displayed too: https://transparencyreport.google.com/safe-browsing/overview * Of course it could be better.

Very effective at... what? I mean, they seem to not be able to tell the difference between a legit mastodon instance and a phishing site, so why would they suddenly be able to tell if it effectively blocked a site that was actually malicious?

Yes, blocking sites on a blocklist works very well. Whether those sites are legit or not doesnt matter at that point, to them, as they assume they all are malicious.

Do you see what I mean?

Re: My experience being blocked by Google Safe Browsing (2022)

#57
post #5

I feel the "i want my friends and family to be safe" is similar to the "but think of the kids!" excuse. Maybe its some kind of a Stockholm Syndrome variant of people using Chrome, but its definitely not healthy. I don't actually believe that it has blocked that many people from being phished, and I doubt that all the entries on that list are malicious. It seems like a system that was designed by someone to simply get…

The strange thing about SSL is that it is meant for strangers. If a group knows each other a self signed certificate can be safer because the group controls the certificate. I always assumed the push for SSL everywhere was to institutionalize man in the middle attacks.

Re: My experience being blocked by Google Safe Browsing (2022)

#58

Earlier quoted context omitted.

In either case, a clear citation of the alleged "phishing" content would help to avoid ambiguity. >Maybe I would feel better if there had been more transparency in the process. I was left to guess what Google thought was deceptive about my site.

If we let Google design our criminal justice system, the accused would never be informed of what crime they broke because that would "help criminals get away with it"

See also: "secret evidence"

https://law.hofstra.edu/pdf/academics/journals/lawreview/lrv...

Re: My experience being blocked by Google Safe Browsing (2022)

#59
post #5

I feel the "i want my friends and family to be safe" is similar to the "but think of the kids!" excuse. Maybe its some kind of a Stockholm Syndrome variant of people using Chrome, but its definitely not healthy. I don't actually believe that it has blocked that many people from being phished, and I doubt that all the entries on that list are malicious. It seems like a system that was designed by someone to simply get…

The strange thing about SSL is that it is meant for strangers. If a group knows each other a self signed certificate can be safer because the group controls the certificate. I always assumed the push for SSL everywhere was to institutionalize man in the middle attacks.

GPG is so criticised because of the web of trust concept.

Re: My experience being blocked by Google Safe Browsing (2022)

#60
post #39

On mobile (Android) it's different. You cannot continue past the warning in Firefox Daylight (or Chrome, of course). about:config is also walled off in every mobile Firefox build except Nightly - and even then, the "safe browsing" keys toggle back every time the app restarts. Android WebView listens to the safe browsing list too, so you can have native apps open up with blood-red warning screens which is very uncomfo…

It really pisses me off that even Firefox on desktop tries to scare you away from about:config with a lie, claiming that using it will void your warranty. Meanwhile the license under which Firefox is provided says "Covered Software is provided under this License on an "as is" basis, without warranty of any kind" Firefox has no warranty to void . The warning message they make you view the first time you try to use abo…

I think it was meant as a joke.
Post reply on HN