Live data from Hacker News

Thanks HN: Lessons learned after Google nearly killed my site

uploader.win

11–20 of 296 posts

Re: Thanks HN: Lessons learned after Google nearly killed my site

#11
post #5

To be quite honest, this seems like a case of Libel and possibly Tortious Interference on behalf of Google/Alphabet. Especially if you can show damages/customers cancelling service, I think this would be a hill to die on. Google et al have too much power, even over people and orgs that aren't even customers. Its high time we reign their powers in, find them strongly culpable for what they do (and what they change and…

I think it's fairly easy to acknowledge the the following are all true:

1. The poster was hosting malicious content from their domain (user uploaded no doubt, but still on the domain they control).

2. On one hand, it is desirable that people who are not malicious be given enough information as fast as possible to rectify their sites.

3. On the other hand, this same sort of information can make it easier for malicious users to evade detection.

That is, it seems to me like there is an inherent tension between #2 and #3 that make a simple solution difficult.

Seems to me that:

1. As the poster discovered, user content should always be hosted on a separate domain. Google should recommend this as a standard good practice.

2. Perhaps I'm missing something, but when Google blocks an entire domain, I don't see the harm in telling the site owner which subdomain is causing the flag, which could let good users identify the problem faster.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#12
post #5

To be quite honest, this seems like a case of Libel and possibly Tortious Interference on behalf of Google/Alphabet. Especially if you can show damages/customers cancelling service, I think this would be a hill to die on. Google et al have too much power, even over people and orgs that aren't even customers. Its high time we reign their powers in, find them strongly culpable for what they do (and what they change and…

I think it's fairly easy to acknowledge the the following are all true: 1. The poster was hosting malicious content from their domain (user uploaded no doubt, but still on the domain they control). 2. On one hand, it is desirable that people who are not malicious be given enough information as fast as possible to rectify their sites. 3. On the other hand, this same sort of information can make it easier for malicious…

If you're hosting lots of malware on different subdomains, there is harm in Google telling you which ones it detected. You could use that information to keep hosting the undetected malware, perhaps out of laziness.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#13

Quick notes: Site owner has not confirmed they screened all uploaded content for malware - this is a major issue these days and google and others will flag you if you host viruses and pump out malware. And no - you cannot sue google to force them to allow users to be infected. It’s not clear that all customer content is hosted on a separate domain, and each customer on a separate sub domain . Your reputation will be…

Something tells me that Google doesn't ban G Drive, Dropbox or MS's what ever it is named when those host malware. I rather not have only the giants host user generated content ...

Re: Thanks HN: Lessons learned after Google nearly killed my site

#14
The issue with this black lists is that all the antiviruses/security tools will immediately put you on their list but it can take days or weeks to have them remove you and you can still get some customer that uses some weird security program that he still gets the issue. One of the anti-viruses company has a form to submit a dispute but their form was broken for weeks.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#15

Quick notes: Site owner has not confirmed they screened all uploaded content for malware - this is a major issue these days and google and others will flag you if you host viruses and pump out malware. And no - you cannot sue google to force them to allow users to be infected. It’s not clear that all customer content is hosted on a separate domain, and each customer on a separate sub domain . Your reputation will be…

Is not about the viruses, a pdf that looks like phishing can be reported and you get your website blocked. If anyone knows of a way to scan pdfs please let me know(I think it would involve finding the links in the pdf, try to follow them and detect if are phishing but maybe the link is fine at the pdf upload time and it changes after)

Re: Thanks HN: Lessons learned after Google nearly killed my site

#16

Quick notes: Site owner has not confirmed they screened all uploaded content for malware - this is a major issue these days and google and others will flag you if you host viruses and pump out malware. And no - you cannot sue google to force them to allow users to be infected. It’s not clear that all customer content is hosted on a separate domain, and each customer on a separate sub domain . Your reputation will be…

Something tells me that Google doesn't ban G Drive, Dropbox or MS's what ever it is named when those host malware. I rather not have only the giants host user generated content ...

Google does the silly separate domain dance GP recommended. I couldn't figure out what is it for, until I read this advice in the previous discussion.

Disclaimer: I'm a Google SRE. But never supported anything reachable from the outside.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#17
post #8

From the article: > So after a lot of brainstorming and ideas from HNers I finally figured out the culprit(s). > We have a live demo on our home where people can upload a test file. [...] > We also give all users a 20MB test storage. [...] > I believe that somebody signed up for our service (it’s free to sign up) and then uploaded a malicious file on our test storage and abused this feature. If that is correct, Googl…

Why? Should GDrive be banned if a single user uploads a malicious file and links to it from a Gdoc?

Re: Thanks HN: Lessons learned after Google nearly killed my site

#18
They can remove your YouTube account, app, entire Google account or even your website at any time and you can only make guesses why did that happen, because they always make the rules really vague and it's never clear what is or is not allowed. And even when they do admit the mistake and get you back up, they still won't explain anything and nothing is ever fixed. Thank you Google, very cool.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#20
> But there are plenty of Google engineers and good helpful people on Hacker news.

> (from a screenshot) I work at Google [...] so I escalated your issue [...]

> I believe the HN thread getting on the homepage tremendously helped me and somebody from Google saw it and expedited the review after all

So, once more an issue with FAANG could only be fixed because somebody knew somebody else and went out of his way to get this to the right eyes.

This could easily have gone another way and OP would have received no help whatsoever and would have waited for days or weeks to get this issue cleared and lost his business.

Maybe it's only me but I find it unbearable that you'll usually not be able to reach any real person at all for issues like these and it's pure luck what happens to you.

Post reply on HN