Live data from Hacker News

Google Safe Browsing incident

statichost.eu

21–30 of 183 posts

Re: Google Safe Browsing incident

#22
It's also good from a security perspective.

Anyone who can upload HTML pages to subdomain.domain.com can read and write cookies for *.domain.com, unless you declare yourself a public suffix and enough time has passed for all the major browsers to have updated themselves.

I've seen web hosts in the wild who could have their control panel sessions trivially stolen by any customer site. Reported the problem to two different companies. One responded fairly quickly, but the other one took several years to take any action. They eventually moved customers to a separate domain, so the control panel is now safe. But customers can still execute session fixation attacks against one another.

Re: Google Safe Browsing incident

#24

Google has some sort of internal flag for determining origin is different on some platforms. We don't get a complete takedown of Neocities every time there's a spam site reported. It is likely that they were not on that list but perhaps have been manually added to whatever that internal list is at this point. The public suffix list ( https://publicsuffix.org/ ) is good and if I were to start from scratch I would do i…

If you're not using separate domains then I hope you don't have any kind of sensitive information stored in cookies. You can't rely on the path restrictions for cookies because it's easily bypassed.

Re: Google Safe Browsing incident

#25
I don't see how a separate domain would solve the main issue here. If something on that separate domain was flagged, it would still affect all user content on that domain. If your business is about serving such user content, the main service of your business would be down, even though your main domain would still be up.

Re: Google Safe Browsing incident

#26
post #4

Earlier quoted context omitted.

It always was. You're one upload and a complaint to your ISP/Google/AWS/MS away from having your account terminated.

But something has definitely changed over the past few years. Back in the days, it felt completely normal for individuals to spin up and run their own forums. Small communities built and maintained by regular people. How many new truly independent, individual-run forums can you name today? Hardly any. Instead we keep hearing about long-time community sites shutting down because individuals can no longer handle the ri…

I feel like yes forums are being closed because they have migrated to the likes of things like discord

I have mixed opinions about discord and if I can be honest, I have mixed opinions about forums as well

My opinion is to take things like forums and transfer them over to things like xmpp/(Irc?)/(signal?)/(matrix most prefered)

There are bridges as well for matrix Irc if this is something that interests you, there are bridges for everything but I prefer matrix with cinny and I generally think that due to its decentralized nature, it might be better than centralized forums maybe as well.

Re: Google Safe Browsing incident

#28
post #4

Earlier quoted context omitted.

It always was. You're one upload and a complaint to your ISP/Google/AWS/MS away from having your account terminated.

But something has definitely changed over the past few years. Back in the days, it felt completely normal for individuals to spin up and run their own forums. Small communities built and maintained by regular people. How many new truly independent, individual-run forums can you name today? Hardly any. Instead we keep hearing about long-time community sites shutting down because individuals can no longer handle the ri…

Is it consolidation of services? Waaaaay back in the day, imageboards like 4chan were "one complaint away from being shut down" but 24-hours later they'd be up again on another rag-tag hosting provider. Nowadays it's like one complaint to cloudflare or AWS and the site is dead dead.

Re: Google Safe Browsing incident

#29
post #7

Hosts phishing sites, gets blocked by anti phishing mechanism. Works as expected from my point of view. Get yourself on public suffix list or get better moderation. But of course just moaning about bad google is easier.

You are right, of course. I'm not sure if those of you who disagree with me think that Safe Browsing did its job (which it did!), that Safe Browsing is a good thing (which it maybe is, but which I slightly disagree with), or that it's ok that Google monitors everything everyone does.

The last point is actually the one I'm trying to make.

Re: Google Safe Browsing incident

#30
post #5
post #3

Still not sure why it's legal for Google to slander companies like this. They often have no proof or it's a false positive, meanwhile they're screaming about how malicious you are.

Because Google has absolutely nothing to lose and you do, besides that they can outlast anybody except for nation states in court.

How does this answer the question of legality?
Post reply on HN