https://www.apple.com/legal/privacy/data/en/safari/
https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
Microsoft seems to do its own thing for Edge, though.
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-...
131–140 of 183 posts
https://www.apple.com/legal/privacy/data/en/safari/
https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...
Microsoft seems to do its own thing for Edge, though.
https://learn.microsoft.com/en-us/deployedge/microsoft-edge-...
Earlier quoted context omitted.
How does flagging a domain that was actively hosting phishing sites demonstrate that Google has too much power? They do, but this is a terrible example, undermining any point you are trying to make.
The thing about Google is that they regularly get this stuff wrong, and there is no recourse when they do. I think most people working in tech know the extent to which Google can screw over a business when they make a mistake, but the gravity of the situation becomes much clearer when it actually happens to you. This time it's a phishing website, but what if the same happens five years down the line because of an unf…
Putting user content on another domain and adding that domain to the public suffix list is good advice. So good, in fact, that it should have been known to an infrastructure provider in the first place. There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance.
This is of course true! It just takes an incident like this to get ones head out of ones ass and actually do it. :)
Github discovered the same thing a long long time ago which is why you now have the github.io domain.
> In order to limit the impact of similar issues in the future, all sites on statichost.eu are now created with a statichost.page domain instead. This read like a dark twist in a horror novel - the .page tld is controlled by Google! https://get.page/
So… you were hosting user generated content on the same TLD as your website, without using the PSL, and you blamed G when things went south? By putting UGC on the same TLD you also put your own security at risk, so they basically did you a favor…
Many commenters are implying that there is a security issue here, and that I'm putting everyone in danger. That is quite frankly a pretty absurd claim to just casually make. I'm of course very curious to hear more details on what the security risk here actually would be? Do you think I'm reading/writing sensitive data to/from subdomain-wide cookies? Also, yes, the PSL is a great tool to mitigate (in practice eliminat…
Earlier quoted context omitted.
I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this case what actually happened is because of me not putting enough effort into fending off bad guys. The new separate domain is pending inclusion in the PSL, yes. Edit: the "effort" I'm talking about above refers to more real time moderation of c…
"Google does good thing, therefore Google has too much power over the internet" is not a convincing point to make. This safety feature saves a nontrivial number of people from life-changing mistakes. Yes we publishers have to take extra care. Hard to see a negative here.
> To be fair, many or even most sites on the Google Safe Browsing blacklist are probably unworthy. But I’m pretty sure this was not the first false positive. The bigger issue is that the internet needs governance . And, in the absence of regulation, someone has stepped in and done it in a way that the author didn't like. Perhaps we could start by requiring that Google provide ways to contact a living, breathing human…
why do you assume that the living, breathing human hired by theGoogs will be competent at handling all of the crazy that will be flung at them by the living, breathing human on the other end of the line. One single person cannot handle that. Naturally, you need a team of living, breathing humans. You might even have them in triage level groups like level 1 support, level 2 support and so on where each level is a more…
Google services simply behaved the way I would expect them to here. Who knows... they may even have saved some users from coming to harm.
Earlier quoted context omitted.
I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this case what actually happened is because of me not putting enough effort into fending off bad guys. The new separate domain is pending inclusion in the PSL, yes. Edit: the "effort" I'm talking about above refers to more real time moderation of c…
> My point is primarily that Google has too much power over the internet. That is probably true, but in this case I think most people would think that they used that power for good. It was inconvenient for you and the legitimate parts of what was hosted on your domain, but it was blocking genuinely phishing content that was also hosted on your domain.