Live data from Hacker News

Google Safe Browsing incident

statichost.eu

181–183 of 183 posts

Re: Google Safe Browsing incident

#181

Earlier quoted context omitted.

Yes, its generally good advice to keep user content on a separate domain. That said, there are a number of IT professionals that aren't aware of the PSL as these are largely initiatives that didn't exist prior to 2023 and don't get a lot of advertisement, or even a requirement. They largely just started being used silently by big players which itself presents issues. There are hundreds if not thousands of whitepapers…

I'm not sure what to tell you. I'm a professional with nearly two decades of experience in this industry, and I don't read any white papers. I read web publications like Smashing Magazine or CSS Tricks, and more specifically authors like Paul Irish, Jake Archibald, Josh Comeau, and Roman Komarov. Developers who talk about the latest features and standards, and best practices to adopt. The view that professionals in t…

You seem to have not understood what I said conflating academia with whitepapers and then construct the rest on an improper foundation from there.

Whitepapers aren't the sole domain of academia. What we are talking about aren't hosted on Arxiv. We are talking about industry working groups.

The M3AAWG working group, and browser/CA forum publish RFCs and Whitepapers that professionals in this area do read regularly.

There's been insufficient/no professional outreach about PSL. You can't just do things at large players without disclosure for interop, because you harm others by doing so neglecting the imposing fallout from lack of disclosure on everyone else that's impacted within your sphere of influence which as a company running the second most popular browser is global.

When you do so without first doing certain reasonable and expected things (of any professional organization), you are being grossly negligent. This is sufficient to prove general intent for malice in many cases, a reasonable person in such circumstances should have known better.

This paves the way for proving tortuous or vexatious interference of a contract which is a tort and punishable by law when brought against the entity.

> The PSL is surely an imperfect solution but its solving the problem for the moment.

It is not, because the disclosure hasn't happened properly for interop, and in such circumstances it predictably creates a mountain of problems without visibility; a timebomb/poison pill where crisis arises from the brittle structure later following shock doctrine utilizing the snowball effect (a common tactic of the corrupt and deceiver alike).

Your entire line of reasoning which you constructed is critically flawed. You presume trust is important to this, and that such systems require trust, but trust doesn't have anything to do with the reputational metrics which the systems we are talking about are using to impose cost. Apples to Oranges.

You can't enumerate badness. Lots of professionals know this. Historic reputational blacklists also punish those that are innocent after-the-fact when not properly disclosed, or engineered for due process. A permanent record deprives anyone from using a blacklisted entry after it changes hands from the criminal to some unsuspecting person.

Your reasoning specifically frames a false dichotomy about security. This follows almost identically the same reasoning the Nazi's used (ref at the bottom).

No one is arguing that Safe Browsing and other mechanisms are useful as mitigation, but they are temporary solutions that must be disclosed to a detailed level that allows interoperability to become possible.

If you only tell your friends, and impose those draconian costs on everyone else, you are abusing your privileged position of trust for personal gain (a form of corruption), and causing harm on others even if you can't see it.

Chrome does not have an opt-out. You have to re-compile the browser from scratch to turn those subsystems off. Same with Firefox. That is not allowing you to disable that feature since users aren't reasonably expected to be able to recompile their software to change a setting.

There is no idealism/pacifism here. I'm strictly being pragmatic.

You neglect the harm you don't directly see, in the costs imposed on business. Second, Third, and n-order effects must be considered but have not been (this must necessarily grow in consideration based on the scope/scale of impact).

There are a few areas where doing such blind things may directly threaten existential matters (i.e. food production where failure of logistics lead to shortages, which whipsaw into chaos). It won't happen immediately, and we live in a growingly brittle but still somewhat resilient society, but it will happen eventually if such harm is adopted and allowed as standard practice; though the method is indirect the scope starts off large.

If you only look through a lens at a small part of the cycle of the dynamics that favors your argument which you set in motion, ignoring everything else; that is called cherry-picking or also commonly known as the fallacy of isolation.

Practically speaking, that line of reasoning is without foundational support and unsound. Its important to properly discern and reason about things as they actually exist in reality.

Competent professionalism is not an idealistic perspective. The harm naturally comes when one doesn't meet well established professional requirements. When the rule of law fails to hold destructive people to account for their actions; that's a three-alarm fire as a warning sign of impending societal collapse. The harms of which are incalculable.

Ref: "Of course the people don't want war. But after all, it's the leaders of the country who determine the policy, and it's always a simple matter to drag the people along whether it's a democracy, a fascist dictatorship, or a parliament, or a communist dictatorship. Voice or no voice, the people can always be brought to the bidding of the leaders.

(Your implications follow this part closely): That is easy. All you have to do is tell them they are being attacked, and denounce the pacifists for lack of patriotism, and exposing the country to greater danger."

    -- Herman Goering at the Nuremberg trials

Re: Google Safe Browsing incident

#182

Earlier quoted context omitted.

It's fine if you personally didn't know that. But if I'm paying for a service, I expect the provider to understand basic security best practices that have been industry standard for 20+ years. And if they don't, they should be hiring people who do. XKCD 1053 is not a valid excuse for what amounts to negligence in a production service.

Author here. What kind of security negligence are you referring to? What would be a specific attack vector that I left open? Regarding the PSL - and I can't believe I'm writing this again: you cannot get on there before your service is big enough and "the request authentically merits such widespread inclusion"[1]. So it's kind of a chicken and egg situation. Regarding the best practice of hosting user content on a se…

> What kind of security negligence are you referring to?

I am not talking about "security negligence". I am talking about "negligence". The negligence was to not follow standard best practices known for over 20 years which led to disruption in your services.

Re: Google Safe Browsing incident

#183

Earlier quoted context omitted.

I mean, it's a very big field, and it's easy enough for me to armchair quarterback and call it a skill issue without being vulnerable and putting my own credentials into question. There's a whole big world of things to know about making and running websites, and I'll readily admit I don't know everything. I don't do a lot of CSS or website SEO or run ad campaigns, so someone experienced there will run circles around…

I agree this isn't knowledge that takes a lot. The problem is these companies don't explain why they do what they do, in fact a lot of security stuff along these lines in the past has been tight-lipped secrecy bound stuff. You can wonder, but the answer isn't out there unless you know an insider willing to break a broadly worded NDA (not gonna happen, and some are quite broad). The idea to segment certain types of tr…

Thank you for your well thought out reply. At the end of the day, what I was getting at is that there's a reason why people in our industry get paid what they do, especially when you could hire a random nobody who's new to the game who doesn't know what they're doing for way cheaper. You're right in pointing out that there's anti-competitive consolidation going on and that's not great.
Post reply on HN