Google Safe Browsing incident
21–30 of 183 posts
Re: Google Safe Browsing incident
#22Anyone who can upload HTML pages to subdomain.domain.com can read and write cookies for *.domain.com, unless you declare yourself a public suffix and enough time has passed for all the major browsers to have updated themselves.
I've seen web hosts in the wild who could have their control panel sessions trivially stolen by any customer site. Reported the problem to two different companies. One responded fairly quickly, but the other one took several years to take any action. They eventually moved customers to a separate domain, so the control panel is now safe. But customers can still execute session fixation attacks against one another.
Re: Google Safe Browsing incident
#23If user1.statichost.page gets blacklisted now will it affect user2.statichost.page as well?
Re: Google Safe Browsing incident
#24Google has some sort of internal flag for determining origin is different on some platforms. We don't get a complete takedown of Neocities every time there's a spam site reported. It is likely that they were not on that list but perhaps have been manually added to whatever that internal list is at this point. The public suffix list ( https://publicsuffix.org/ ) is good and if I were to start from scratch I would do i…
Re: Google Safe Browsing incident
#25Re: Google Safe Browsing incident
#26Earlier quoted context omitted.
It always was. You're one upload and a complaint to your ISP/Google/AWS/MS away from having your account terminated.
But something has definitely changed over the past few years. Back in the days, it felt completely normal for individuals to spin up and run their own forums. Small communities built and maintained by regular people. How many new truly independent, individual-run forums can you name today? Hardly any. Instead we keep hearing about long-time community sites shutting down because individuals can no longer handle the ri…
I have mixed opinions about discord and if I can be honest, I have mixed opinions about forums as well
My opinion is to take things like forums and transfer them over to things like xmpp/(Irc?)/(signal?)/(matrix most prefered)
There are bridges as well for matrix Irc if this is something that interests you, there are bridges for everything but I prefer matrix with cinny and I generally think that due to its decentralized nature, it might be better than centralized forums maybe as well.
Re: Google Safe Browsing incident
#27Re: Google Safe Browsing incident
#28Earlier quoted context omitted.
It always was. You're one upload and a complaint to your ISP/Google/AWS/MS away from having your account terminated.
But something has definitely changed over the past few years. Back in the days, it felt completely normal for individuals to spin up and run their own forums. Small communities built and maintained by regular people. How many new truly independent, individual-run forums can you name today? Hardly any. Instead we keep hearing about long-time community sites shutting down because individuals can no longer handle the ri…
Re: Google Safe Browsing incident
#29Hosts phishing sites, gets blocked by anti phishing mechanism. Works as expected from my point of view. Get yourself on public suffix list or get better moderation. But of course just moaning about bad google is easier.
The last point is actually the one I'm trying to make.
Re: Google Safe Browsing incident
#30Still not sure why it's legal for Google to slander companies like this. They often have no proof or it's a false positive, meanwhile they're screaming about how malicious you are.
Because Google has absolutely nothing to lose and you do, besides that they can outlast anybody except for nation states in court.