Live data from Hacker News

Google Safe Browsing incident

statichost.eu

111–120 of 183 posts

Re: Google Safe Browsing incident

#111

Earlier quoted context omitted.

Your equally just one fake report to an automated system away having your account shut down. So, yes, your actions have consequences, but more worrying to me is the ability of someone with a grudge causing consequences for you as well.

This is a direct consequence of centralization of services. We're doing this to ourselves.

You say "we" like it is the population of internet users. They have no choice in this other than to use whatever sites are available. It is the megaEvilCorps that are doing it to us. They start with a novel idea that is rewarded by lots of users. They then decide to weaponize their site against us to become money printing machines. They then use that money to buy up any competition which artificially limits the end user's choices. WE aren't doing shit to ourselves. Profit seeking megaEvilCorps are doing it to us.

On top of the megaEvilCorps are evilScammyHackers that have made the internet a dangerous place. So entrepreneurial minded folks came up with some cool things to help protect users and site owners from these evilScammyHackers. Problem is, it takes scaled services to do it which again takes money which naturally limits those that are able to provide those services. This is again not we doing anything to ourselves.

If you mean we has a species, then sure, but that's a really stretched definition of we

Re: Google Safe Browsing incident

#112

Earlier quoted context omitted.

Where'd you see/hear that? It hasn't been my experience at least - but maybe I've just been lucky or undercounting the sites. There are required steps to follow but none are "have x users" or "see a lot of spam". It's mostly "follow proper DNS steps and guidelines in the given format" with a little "show you're doing this for the intended reason rather than to circumvent something the PSL is not meant for/for somethi…

https://github.com/publicsuffix/list/wiki/Guidelines#validat... "Projects that are smaller in scale or are temporary or seasonal in nature will likely be declined. Examples of this might be private-use, sandbox, test, lab, beta, or other exploratory nature changes or requests. It should be expected that despite whatever site or service referred a requestor to seek addition of their domain(s) to the list, projects not…

[deleted]

Re: Google Safe Browsing incident

#113
post #94

Earlier quoted context omitted.

why do you assume that the living, breathing human hired by theGoogs will be competent at handling all of the crazy that will be flung at them by the living, breathing human on the other end of the line. One single person cannot handle that. Naturally, you need a team of living, breathing humans. You might even have them in triage level groups like level 1 support, level 2 support and so on where each level is a more…

Well, Google did self-appoint itself the "internet police," and the general job of the police is to deal with screwballs. So you can't take one part of the responsibility and abdicate the other part!

Playing devil's advocate, who else was going to step into that role? Who would have the clout to be trusted? The Googs would want to do something just as a self protecting action that evolved into a self aggrandizing sense of empowerment that they might not be the protector we need but the one we deserved

Re: Google Safe Browsing incident

#114
post #70

Earlier quoted context omitted.

From reading that my guess would be that the IP of your host gotten from your hosting provider had some spammy history before you started hosting your blog on it. Either that or your DNS provider hosts a lot of spam.

Hmmm, I use https://njal.la/ for DNS. Could spamhaus really just auto-mark every njalla user as suspicious?

Yeah, possibly. Privacy related services are often used by spammers.

Re: Google Safe Browsing incident

#115
post #7

Hosts phishing sites, gets blocked by anti phishing mechanism. Works as expected from my point of view. Get yourself on public suffix list or get better moderation. But of course just moaning about bad google is easier.

You are right, but then again, nobody flags facebook because of the scamming taking place in some facebook pages.

Generally because Facebook polices Facebook (imperfectly, but the effort is demonstrated) and the damage radius is limited to Facebook users mostly. As long as the easiest way to avoid damage from the Facebook domain is "Don't use Facebook," the larger Internet doesn't need a mechanism to police it.

If Facebook became a trap that frequently hosted malware to strangers, the rest of the net would begin to interpret it as damage and route around it.

Re: Google Safe Browsing incident

#116

It's generally good advice, but I don't see that Safe Browsing did anything wrong in this case. First, it sounds like they actually were briefly hosting phishing sites: > All sites on statichost.eu get a SITE-NAME.statichost.eu domain, and during the weekend there was an influx of phishing sites. Second, they should be using the public suffix list ( https://publicsuffix.org/ ) to avoid having their entire domain tagg…

Getting on the public suffix list is easier said than done [1]. They can simply say no if they feel like it and are making sure to be able to keep said rights as a "project" vs a "business," [2] which has its pros and cons.

[1] https://github.com/publicsuffix/list/blob/main/public_suffix...

[2] https://groups.google.com/g/publicsuffix-discuss/c/xJZHBlyqq...

Re: Google Safe Browsing incident

#118
I have recently had the pleasure of speaking with Google senior leadership involved in the Safe Browsing product on the topic of getting my SaaS product placed on their, "naughty list." The platform was down for 6 or so hours due to a false positive hit for phishing.

I have read A LOT of blogs/rants/incidents on social media about startups, small businesses, and individuals getting screwed by large companies in similar capacities. I am VERY sympathetic to those cries into the sky, shaking fists at clouds, knowing very well we are all very small and how the large providers seem to not care. With that in mind, I am not blind to the privilege my organization has to rope in Google to discuss root causes for incidents.

I am writing about it here because I believe most people will never be able to pull a key Google stakeholder into a 40 minute video call to deeply discuss the RCAs. The details of the discussion are probably protected by NDA so I'll be speaking in general terms.

Google has a product called Web Risk (https://cloud.google.com/web-risk/docs/overview), I hear it's mostly used by Google Enterprise customers in regulated verticals and some large social media orgs. Web Risk protects the employees of these enterprise organizations by analyzing URLs for indicators of risk, such as phishing, brand impersonation, etc.

My SaaS platform is well established and caters mostly to large enterprise. I provide enterprise customers with optional branded SSO landing pages. Customers can either use sign-in from the branded site (SP-initiated) or redirect from their own internal identity provider to sign-in (IdP-initiated). The SSO site branding is directed by the customer, think along the lines of what Microsoft does for Entra ID branded sign-in pages. Company logo(s), name, visual styling, and other verbiage may be included. The branded/vanity FQDN is (company).productname.mydomain.com.

You may be able to see where I'm headed at this point... Why was my domain blocked? For suspected phishing.

A mutual enterprise customer was subscribed to Google's Web Risk. When their employees navigated to their SSO site, Google scanned it. Numerous heuristics flagged the branded SSO site as phishing and we were blocked by Safe Browsing across all major web browsers (Safari, Chrome, Firefox, Edge, and probably others). Google told us that had our customer put the SSO site on their Web Risk allow-list, we wouldn't have been blocked.

I'm no spring chicken, I cannot rely nor expect a customer to do that, so I pressed for more which led to a lengthy conversation on risk and the seemingly, from my perspective, arbitrary decisions made by a black box without any sort of feedback loop.

I was provided a tiny bit of insight into the heuristic secret sauce, which led to prescribed guidance on what could be done to greatly reduce the risk of getting false positive flag for phishing again. Those specifics I assume I cannot detail here, however the overall gist of it is domain reputation. Google was unable to positively ascertain my domain's reputation.

My recommendation is for those of you out there in the inter-tubes who have experienced false positive Safe Browsing blocks, think about what you can do to increase your domain's public reputation. Also, get a GCP account so if you do get blocked, you can open a ticket from that portal. I was told it would be escalated to the appropriate team and be actioned on within 10-15 minutes.

Re: Google Safe Browsing incident

#119
Another day, another IT company learning the hard way about the public suffix list, or well-known URIs, or some other well-documented-but-niche security technology.

I love that IT is a field where there's no required formal education track and you can succeed with any learning path, but we definitely need some better way to make sure new devs are learning about some of these gotchas.

Re: Google Safe Browsing incident

#120
post #11

Putting user content on another domain and adding that domain to the public suffix list is good advice. So good, in fact, that it should have been known to an infrastructure provider in the first place. There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance.

The PSL is something you find out about after it goes wrong. It's a weird thing, to be honest, a Github repo mentioned nowhere in any standards that browsers use to treat some subdomains differently. Information like this doesn't just manifest itself into your brain once you start hosting stuff, and if I hadn't known about its existence I wouldn't have thought to look for a project like this either. I certainly would…

To be pedantic, the GitHub repo is not the source of truth, this is:

https://publicsuffix.org/list/public_suffix_list.dat

It even says so in the file itself. If Microsoft goes up in flames, they can switch to another repository provider without affecting the SoT.

Post reply on HN