Live data from Hacker News

Thanks HN: Lessons learned after Google nearly killed my site

uploader.win

191–200 of 296 posts

Re: Thanks HN: Lessons learned after Google nearly killed my site

#191

>Now we run automated tests to monitor server uptime and check server for problems every 30 seconds. Unfortunately automated test scripts were happily getting HTTP/200 replies while people using the Chrome browser were being told this is a scam business trying to steal their bank account information. I was surprised this wasn't part of the lessons learned. But it seems the monitoring basically failed but that wasn't…

When talking about checks on the order of twice a minute, curl is probably the right approach. You can/should still do a full check, but that can be done at a lower frequency.

Not sure why you're getting downvoted, personally I agree.

For example:

- a frequent/simple check dealing directly (on the internal network) with the webserver ("does it work well yes/no, what's the raw response time, etc..."). Here is where I would definitely use "curl".

- another less frequent test involving as well the DNS and the external network.

- another end-to-end test (e.g. once every 10 minutes?) involving as well one or more real browsers (this would test as well for example revoked SSL certs).

=> all these infos/metrics should be quite helpful to identify problems, or at least to shrink the potential area that is causing it.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#192
post #91

Earlier quoted context omitted.

The site is https://nextails.com/ I just ran ads with headlines like Nextjs + TailwindCSS Landing Pages Apparently somehow I ran afoul of their Circumventing Systems policy. I don't know how this qualifies and when I appealed they came back saying the same thing.

FYI you’re also blocked by some lists on NextDNS, consequently I couldn’t view your site. I bet that’s a consequence of the google issue, best of luck solving this.

Oh no! But how would they know? Now I'm worried some malware is running on my site or something...

Re: Thanks HN: Lessons learned after Google nearly killed my site

#194
post #18

They can remove your YouTube account, app, entire Google account or even your website at any time and you can only make guesses why did that happen, because they always make the rules really vague and it's never clear what is or is not allowed. And even when they do admit the mistake and get you back up, they still won't explain anything and nothing is ever fixed. Thank you Google, very cool.

One one hand I understand that any site can be hacked anytime and that that can have huge repercussions, therefore I'm happy if Google reacts quickly when it detects something like that (if I were the owner of such a site I would be even thankful to Google to limit the damage).

One the other hand it seems, based on this and many other posts, that there isn't much communication from Google to its "clients" to 1) explain what's wrong and 2) quickly/directly ask for a reevaluation (e.g. after the problem has been fixed, to question the validity of the problem, etc)?

I understand that there might be bad actors around doing everything on purpose on their website/app and that therefore #1 (basically telling the bad people why they got detected) would be a bit of a gray zone, but at least #2 should be a no-brainer (e.g. in the case of the previous ".ass"-files-case anybody in any support desk could have immediately whitelisted that "problem")?

Re: Thanks HN: Lessons learned after Google nearly killed my site

#195

Earlier quoted context omitted.

Or... it’s not Google’s job to police all sites of malware?

Whose should it be? Why would they be better than Google?

It would be individual users job to police what sites they go to. It would be hosting providers jobs to police the content of their hosters. The person who makes the search engine, and the browser, and the black list should not be one in the same.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#196
post #190

Earlier quoted context omitted.

Whose should it be? Why would they be better than Google?

The job of the police

Police take reports from victims then what? How do police protect you from a site hosted outside their jurisdiction?

I think tech companies deciding what people can access is the most likely endgame no matter what. People will demand protection. Whether it's a great firewall, a whitelist-only internet, ...or just automated filtering like this, which may be the most liberal option we can realistically expect.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#197
post #18

They can remove your YouTube account, app, entire Google account or even your website at any time and you can only make guesses why did that happen, because they always make the rules really vague and it's never clear what is or is not allowed. And even when they do admit the mistake and get you back up, they still won't explain anything and nothing is ever fixed. Thank you Google, very cool.

The reason it is made vague is because there are people who will set their site up so it technically passes the rules but it certainly does not pass the spirit of what was trying to be done by the rules. By making it opaque they do get to cast a wider net and keep those a$$hats from harming others but they certainly catch other fish with that net.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#198
post #183

Earlier quoted context omitted.

People want three things: 1. publishers want to be able to put content on the Web without undergoing background checks 2. everyone wants to be able to discover content with as little friction as possible 3. consumers don’t want to drown in unwanted crap The incomprehensible Algorithm is the result of trying to square that circle. Give up any of those requirements, and the arms race would end: Give up #1, and it’ll be…

> In order to sue them, you need to come up with something that they should’ve done but didn’t. How so? If you sue for damages, you only have to prove you were harmed by Google's actions, no? And actively misrepresenting your website as dangerous and deceptive to your customers is sort of libelous and clearly damaging.

Google has no obligation to list you on their search results or allow access to your site through their browser.

> ctively misrepresenting your website as dangerous and deceptive to your customers is sort of libelous and clearly damaging.

Except the OP even said someone uploaded a malicious file that was put in a place publicly accessible. Google was not being libelous. There was a malicious file.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#199
post #71

Ironically I had the opposite issue a couple of weeks ago: I've found a phishing website (for Facebook) that was hosted on a Google server and was actively used. I sent an email to Google's abuse email address - got an automated reply back saying basically "use this other form instead". Did that, never got a reply back. I have reported the website to their SecureSearch (or whatever the name is) product, entered the U…

Let's do an experiment, please post the URL here and see if someone at google takes notice :)

Well, enjoy: https://nbbdfxhqcc[ remove me ]fll.agilecrm.com/landing/6754083888234496#0.593636668875394

You are warned: the above link is a phishing website that when used will spam you whole Facebook friends with the same link via message. Google Chrome, still today, shows it as a normal website: https://imgur.com/a/1bsFutr

Re: Thanks HN: Lessons learned after Google nearly killed my site

#200

Earlier quoted context omitted.

For me that actually ended up the only way to gain access back to an old account of mine. Luckily I was able to cooperate with the new owner of the number, and he was helpful enough to give me the code that was sent, otherwise I'd have lost a Google account with several hundred euros of purchases on it, despite having the password, control of the backup email, knowing all security questions, and knowing the exact dat…

The obvious issue with this is that the new owner of the number doesn't actually know if it's the owner of the old account trying to sign into it - it could be anyone trying to take over an account whos owner forgot to change the number for. And how do they know you're not trying to sign into their account? The text messages don't specify which account is being attempted or anything.

That's actually the big issue — but if you can meet with the person, and do the whole process IRL, it's much less risky.
Post reply on HN