Earlier quoted context omitted.
Please host the HTML source of a page that throws a warning somewhere. And mention the version of Chrome that gave the warning ( chrome://chrome/ ). Also can you post the thread on the Google forums with a proper bug report? I can't find it.
Try http://dev1.codelathe.com Shows up now with Chrome v27.0.1453.116
Ask HN: Google Chrome heuristic warnings pose threat to our business
71–80 of 85 posts
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#72Earlier quoted context omitted.
Thanks for the really useful tip to look into Chrome's debug log. First of all we see that this so called phishing detection filter's code is found at http://src.chromium.org/svn/trunk/src/chrome/renderer/safe_b... Second, this code and the logic it employs is really bull . The world wide web is not a kiddie playground especially for a browser, and especially for a plugin whose's job is to detect phishing. The way Ch…
As much as I can understand you being upset that Chrome shows a warning for your site, I don't think that the approach they are using is unreasonable. I'd take bets that those criteria show a correlation to phishy sites. Especially if you combine those metrics together. Is it perfect? No. Does it produce false positives? Yes. Is it beneficial on average? I think so. PS: Since you have found the relevant file in the o…
Browser is the window through people sees the world. That’s the reality we live in. In our target market, Google chrome holds 40% market share. Because of its stupid categorization, in one stroke Google harmed our reputation and the reputation of companies we serve. It is not a simple browser compatibility issue. Google chrome is telling the world our software is phishing software while we are not. What is the recourse here?
We don’t care what Chrome’s algorithms are. But the results are not factual and it harms our business. "One cannot escape saying hey that is our algorithm. We don’t do evil…" Remember.
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#73I work at Google but not on this product.. so I escalated your issue to the team that works on the anti-phishing classifier. They're looking into it now, and put you on a temporary whitelist in the mean time (should take effect within 30 mins).
Just one more thing. Since our product is self-hosted by our customers under their own domain, white listing just our development domain is unlikely to help our cause.
I'm sure they will contact you via regular customer support channels (ie. not HN) if they need any more info to debug the problem.
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#74Earlier quoted context omitted.
Please host the HTML source of a page that throws a warning somewhere. And mention the version of Chrome that gave the warning ( chrome://chrome/ ). Also can you post the thread on the Google forums with a proper bug report? I can't find it.
Try http://dev1.codelathe.com Shows up now with Chrome v27.0.1453.116
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#75Earlier quoted context omitted.
Thanks for the really useful tip to look into Chrome's debug log. First of all we see that this so called phishing detection filter's code is found at http://src.chromium.org/svn/trunk/src/chrome/renderer/safe_b... Second, this code and the logic it employs is really bull . The world wide web is not a kiddie playground especially for a browser, and especially for a plugin whose's job is to detect phishing. The way Ch…
@hiddenfeatures Yes. Lets apply this everywhere. Lets electrocute folks based on "heuristics" because there are no other way to find out "bad guys". It is nice to act as an arbiter and spout philosophy isn't it? If you really do think that there is no other better way then I guess there is no more point arguing about this.
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#76Earlier quoted context omitted.
As much as I can understand you being upset that Chrome shows a warning for your site, I don't think that the approach they are using is unreasonable. I'd take bets that those criteria show a correlation to phishy sites. Especially if you combine those metrics together. Is it perfect? No. Does it produce false positives? Yes. Is it beneficial on average? I think so. PS: Since you have found the relevant file in the o…
You are trivializing the underlying issue here. If the same thing happened in a physical world it will be a high profile public defamation case. Browser is the window through people sees the world. That’s the reality we live in. In our target market, Google chrome holds 40% market share. Because of its stupid categorization, in one stroke Google harmed our reputation and the reputation of companies we serve. It is no…
But I don't think that I am trivializing things. The fact is, that phishing sites are causing a real pain (as in millions of dollars lost by the victims, hundreds of thousands of computers becoming zombies, etc). All major browsers are trying to mitigate these risks by implementing phishing & malware filters. None of these implementations are perfect (you probably know a bit or two about bugs in software development).
But on average these filters have a positive ROI - especially for the target market (which is Joe WebUser and sadly NOT your company - or mine for that matter). The costs of a false positive ("I'll go & find that information on another site") far outweigh the costs of a false negative ("I put my login+password into this legitimate looking website and now I can no longer access PayPal").
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#77Earlier quoted context omitted.
@hiddenfeatures Yes. Lets apply this everywhere. Lets electrocute folks based on "heuristics" because there are no other way to find out "bad guys". It is nice to act as an arbiter and spout philosophy isn't it? If you really do think that there is no other better way then I guess there is no more point arguing about this.
Or let everything go through until and unless we are 100% certain that it shouldn't. Like, if someone is pointing a gun at you, do not duck because there is a chance he/she will miss. Because you know, exaggeration is truly a great tactic to convince other stakeholders.
The problem is 1. No clarity on what constitutes a problem. 2. No way to officially contact to clear up a problem
resulting in possible irreparable loss of business.
So, if you insist on interesting and orthogonal "analogies".. please carry on.
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#78Earlier quoted context omitted.
That failing, get money for them blocking a competitor. before downvoting, take the time to explain how this would be different from old good Google suing Microsoft just for not making their product use Google easier than it already allowed.
this is HN, you can't get downvoted:)
and i'm getting downvoted alright, and without any attempt at fulling my request, no less
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#79Earlier quoted context omitted.
Please host the HTML source of a page that throws a warning somewhere. And mention the version of Chrome that gave the warning ( chrome://chrome/ ). Also can you post the thread on the Google forums with a proper bug report? I can't find it.
Try http://dev1.codelathe.com Shows up now with Chrome v27.0.1453.116
No issues.
Re: Ask HN: Google Chrome heuristic warnings pose threat to our business
#80Earlier quoted context omitted.
Or let everything go through until and unless we are 100% certain that it shouldn't. Like, if someone is pointing a gun at you, do not duck because there is a chance he/she will miss. Because you know, exaggeration is truly a great tactic to convince other stakeholders.
Even though this looks like a troll attempt, lets try this. The problem is 1. No clarity on what constitutes a problem. 2. No way to officially contact to clear up a problem resulting in possible irreparable loss of business. So, if you insist on interesting and orthogonal "analogies".. please carry on.
> So, if you insist on interesting and orthogonal "analogies".. please carry on. If it was not clear, I was trying to describe a possible issue with you "lets apply this everywhere" argument.
The two arguments you just put forward, are nowhere close to what you said in the comment I replied to. Yes, there are issues with the current implementation of it, which is very similar to how spam detection/prevention systems work at the moment. Yes, there can be improvements to it. There can be improvements to everything. Yes there is high chance of false negatives in the current system, but this is a problem where false positives can be just as disastrous. If we cannot agree with that, then do not think it is worth continuing this discussion.
Now if you check the top comment on the thread, I believe the communication channels have already been set. They did not work for you as promptly as you would want them to, that's a different issue. But there definitely exists an official contact to clear up the problem - your colleague seems to be aware of it. The lack of clarity of the reasons has been marked as intentional and has been discussed elsewhere on the thread.
It was poor of me to use snark instead of clearly stating my stance, but the stupidity of analogy that you are blaming me for, is not much different from what I was trying to mock.