Live data from Hacker News

Google Safe Browsing incident

statichost.eu

131–140 of 183 posts

Re: Google Safe Browsing incident

#131
I was curious how other browsers handle this. Apparently Safari and Firefox delegate to Google.

https://www.apple.com/legal/privacy/data/en/safari/

https://support.mozilla.org/en-US/kb/how-does-phishing-and-m...

Microsoft seems to do its own thing for Edge, though.

https://learn.microsoft.com/en-us/deployedge/microsoft-edge-...

Re: Google Safe Browsing incident

#132

Earlier quoted context omitted.

How does flagging a domain that was actively hosting phishing sites demonstrate that Google has too much power? They do, but this is a terrible example, undermining any point you are trying to make.

The thing about Google is that they regularly get this stuff wrong, and there is no recourse when they do. I think most people working in tech know the extent to which Google can screw over a business when they make a mistake, but the gravity of the situation becomes much clearer when it actually happens to you. This time it's a phishing website, but what if the same happens five years down the line because of an unf…

Then that would be an example of a system having failed and one that needs to change. Instead, this is an example of a hosting company complaining about the consequences of skipping some of the basic, well-documented safety and security practices that help to isolate domains for all sorts of reasons, from reputation to little things like user cookies.

Re: Google Safe Browsing incident

#133
post #11

Putting user content on another domain and adding that domain to the public suffix list is good advice. So good, in fact, that it should have been known to an infrastructure provider in the first place. There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance.

This is of course true! It just takes an incident like this to get ones head out of ones ass and actually do it. :)

This is the kind of thing that customers rely on you to do _before_ it causes an incident.

Re: Google Safe Browsing incident

#134

Github discovered the same thing a long long time ago which is why you now have the github.io domain.

Don't forget the `githubusercontent.com` domain, which is specifically used to host risky, user-generated content, and fully documented in https://docs.github.com/en/authentication/keeping-your-accou... (using an open source component that other companies could also use, if they were interested in similar levels of security)

Re: Google Safe Browsing incident

#135

> In order to limit the impact of similar issues in the future, all sites on statichost.eu are now created with a statichost.page domain instead. This read like a dark twist in a horror novel - the .page tld is controlled by Google! https://get.page/

Thank you for this hacker-minded and sharp comment! And for what it's worth, it feels great to actually pay for something Google provides!

Re: Google Safe Browsing incident

#136
post #129

So… you were hosting user generated content on the same TLD as your website, without using the PSL, and you blamed G when things went south? By putting UGC on the same TLD you also put your own security at risk, so they basically did you a favor…

Many commenters are implying that there is a security issue here, and that I'm putting everyone in danger. That is quite frankly a pretty absurd claim to just casually make. I'm of course very curious to hear more details on what the security risk here actually would be? Do you think I'm reading/writing sensitive data to/from subdomain-wide cookies? Also, yes, the PSL is a great tool to mitigate (in practice eliminat…

I am not implying you’re putting “everyone” in danger. I’m merely implying that you’re putting your own service in danger by allowing clients to act like a trusted subdomain like controlpanel.statichost.eu, .secure, or Unicode similarities of www.

Re: Google Safe Browsing incident

#137

Earlier quoted context omitted.

I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this case what actually happened is because of me not putting enough effort into fending off bad guys. The new separate domain is pending inclusion in the PSL, yes. Edit: the "effort" I'm talking about above refers to more real time moderation of c…

"Google does good thing, therefore Google has too much power over the internet" is not a convincing point to make. This safety feature saves a nontrivial number of people from life-changing mistakes. Yes we publishers have to take extra care. Hard to see a negative here.

Is it? Companies like Google coddle users instead of teaching them how to browse smarter and detect phishing for themselves. Google wants people to stay ignorant so they can squeeze them for money instead of phishers.

Re: Google Safe Browsing incident

#138
post #56

> To be fair, many or even most sites on the Google Safe Browsing blacklist are probably unworthy. But I’m pretty sure this was not the first false positive. The bigger issue is that the internet needs governance . And, in the absence of regulation, someone has stepped in and done it in a way that the author didn't like. Perhaps we could start by requiring that Google provide ways to contact a living, breathing human…

why do you assume that the living, breathing human hired by theGoogs will be competent at handling all of the crazy that will be flung at them by the living, breathing human on the other end of the line. One single person cannot handle that. Naturally, you need a team of living, breathing humans. You might even have them in triage level groups like level 1 support, level 2 support and so on where each level is a more…

You really think talking to a human and a bot is the same?

Re: Google Safe Browsing incident

#139

Google services simply behaved the way I would expect them to here. Who knows... they may even have saved some users from coming to harm.

Many phishing attacks originate from Google's owns domains. Gmail users phishing others, scammy youtube videos, scammy comments with links to scams, scammy ads to fake banking pages, etc, etc. But Google would never be hypocritical, never!!

Re: Google Safe Browsing incident

#140

Earlier quoted context omitted.

I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this case what actually happened is because of me not putting enough effort into fending off bad guys. The new separate domain is pending inclusion in the PSL, yes. Edit: the "effort" I'm talking about above refers to more real time moderation of c…

> My point is primarily that Google has too much power over the internet. That is probably true, but in this case I think most people would think that they used that power for good. It was inconvenient for you and the legitimate parts of what was hosted on your domain, but it was blocking genuinely phishing content that was also hosted on your domain.

Every website operator employee worth their salary in this area would have told the site's operator this beforehand, and could have avoided this incident. Hell, even ChatGPT could tell you that by now. The word that comes to mind is incompetence on someone's part, but I don't know of the details on particularly who was the incompetent one in this situation. Thankfully, they've learned a lesson about the situation and ideally won't make the same mistake again going forwards.
Post reply on HN