Live data from Hacker News

Google marked https://old.reddit.com/r/programming/ as unsafe

transparencyreport.google.com

31–40 of 72 posts

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#31

Earlier quoted context omitted.

Yet there are many more users that actually get protected from actual phishing thanks to Safe Browsing. A microscopic false positive rate does not a bad tool make.

yet there are nonetheless many people harmed by the service, an issue unresolved by any amount of unrelated goodness >A [low] false positive rate does not a bad tool make. It does, if your tool fails to address the issue of false positives to the satisfaction of the people you harm with them, and especially if it fails to provide a quick, easy, direct line to humans, to deal with false positives obviously it's not ac…

> obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!”

That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost.

You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist? That means a significantly higher amount of people getting significantly more inconvenienced than some false positives cause.

> if you can't resolve the negative externalities of your service to the satisfaction of the people you're harming with them, don't roll out the service

Case study of letting the perfect become the enemy of the good.

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#33

Earlier quoted context omitted.

yet there are nonetheless many people harmed by the service, an issue unresolved by any amount of unrelated goodness >A [low] false positive rate does not a bad tool make. It does, if your tool fails to address the issue of false positives to the satisfaction of the people you harm with them, and especially if it fails to provide a quick, easy, direct line to humans, to deal with false positives obviously it's not ac…

> obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!” That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost. You do understand that the alternative would be most phishing sites re…

> That's the thing, the benefits immensely outweigh the small negatives

that's the thing: they don't. both co-exist, and you must address the negative externalities individually, vs. saying "well we think we do more good so suck it, too bad" to the people you harm.

> You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist?

the alternative could be a meteor hitting the planet, that doesn't justify your creating new negative externalities and unleashing them on the world with no reasonable recourse for the people you harm

indeed, your stated excuse for wrongdoing is a case study in letting the ends justify the means

you also neglect the many other alternatives, one of which is properly staffing and funding enough humans to deal with the harm you're inflicting on other people, and providing easy access to them from the people you've harmed, and scaling your service up only so long as you can support that proper level of staffing

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#34
post #16

Earlier quoted context omitted.

I'm not saying this is acceptable in any way... But there IS something you can try to get resolved fairly quickly if it ever happens again. Be sure to claim domain ownership in the Google search console. If there is a flag of some sort, it will show up there. And you can address it there. I worked for a financial services company where this happened. The public-facing .com domain was set up first, before I got there.…

This evidently doesn't work for all flags. Your own experience != all other peoples' experience. My domain ownership was already registered even before it was flagged. I _think_ it was the search console I used to request a review of the flag. But it still took that long to resolve. This wasn't an issue of not realising what had happened for 3 days, it was 3 days after letting Google know they'd got it wrong. And spe…

You want the Postmaster Console for delivery and abuse issues, not the Search Console which is probably why you couldn't find anything.

If you've already verified your domains in the search console it is one click to add them. https://postmaster.google.com/

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#35
post #26

Earlier quoted context omitted.

> old.r... isn't a thing. ... yes it is. It's still up and running at the moment.

no, point is, you don't need it. www. works with preference settings, old UI in all its glory.

[flagged]

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#36
post #14

This bot's behaviour made me drop all Google products. A few years ago it marked my company's entire domain as unsafe without any reason. Any human would have been able to tell the flag was incorrect, but "algorithm says no". There is no team in Google to escalate to, no team managing this service, and no way to get an incorrect flag lifted in anything like an acceptable timeframe. In the meantime, Gmail just silentl…

Not a lawyer and not legal advice, but isn't labelling something malware -- that isn't malware -- libel? I'm wondering if you could sue them for defamation.

No. This all got hashed out in the early 2000s when spammers tried to sue organizations that blacklisted them using everything from libel to contract interference.

One of too many to list: https://archive.is/jvJhl

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#37

Earlier quoted context omitted.

yet there are nonetheless many people harmed by the service, an issue unresolved by any amount of unrelated goodness >A [low] false positive rate does not a bad tool make. It does, if your tool fails to address the issue of false positives to the satisfaction of the people you harm with them, and especially if it fails to provide a quick, easy, direct line to humans, to deal with false positives obviously it's not ac…

> obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!” That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost. You do understand that the alternative would be most phishing sites re…

If a weapons manufacturer made a gun that 1 in every billion times shot you in the head instead of your target, we wouldn't say, "well, sometimes accidents happen" and brush it off.

There would be a full investigation as to how and why this happened and someone somewhere would be held accountable.

Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#38
post #34

Earlier quoted context omitted.

This evidently doesn't work for all flags. Your own experience != all other peoples' experience. My domain ownership was already registered even before it was flagged. I _think_ it was the search console I used to request a review of the flag. But it still took that long to resolve. This wasn't an issue of not realising what had happened for 3 days, it was 3 days after letting Google know they'd got it wrong. And spe…

You want the Postmaster Console for delivery and abuse issues, not the Search Console which is probably why you couldn't find anything. If you've already verified your domains in the search console it is one click to add them. https://postmaster.google.com/

I think you misunderstand. I did challenge the flag in the correct place in Google's byzantine UIs. I just don't remember today exactly which UI that was.

The flag was raised against web content on our domain - it claimed our online demo was a phishing site - not on use or content of our email.

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#39

Earlier quoted context omitted.

> obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!” That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost. You do understand that the alternative would be most phishing sites re…

If a weapons manufacturer made a gun that 1 in every billion times shot you in the head instead of your target, we wouldn't say, "well, sometimes accidents happen" and brush it off. There would be a full investigation as to how and why this happened and someone somewhere would be held accountable. Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.

> If a weapons manufacturer made a gun that 1 in every billion times shot you in the head instead of your target, we wouldn't say, "well, sometimes accidents happen" and brush it off.

A more apt comparison would be with seatbelts or airbags.

> Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.

The market forces are sufficient. If the FP rate climbs too high more people will disable the feature, easy.

Re: Google marked https://old.reddit.com/r/programming/ as unsafe

#40

Earlier quoted context omitted.

> obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!” That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost. You do understand that the alternative would be most phishing sites re…

> That's the thing, the benefits immensely outweigh the small negatives that's the thing: they don't. both co-exist, and you must address the negative externalities individually, vs. saying "well we think we do more good so suck it, too bad" to the people you harm. > You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist? the alternat…

> the alternative could be a meteor hitting the planet, that doesn't justify your creating new negative externalities and unleashing them on the world with no reasonable recourse for the people you harm

Either you have no clue how much phish there really is or you know exactly. In both cases it sucks to be you.

> you also neglect the many other alternatives, one of which is properly staffing and funding enough humans to deal with the harm you're inflicting on other people, and providing easy access to them from the people you've harmed, and scaling your service up only so long as you can support that proper level of staffing

Sure, you're free to pay for an antivirus product that does the same and you can contact them.

It's thankfully not up to you to decide if people want to be inconvenienced or protected by what Google offers for free.

Post reply on HN