Live data from Hacker News

Thanks HN: Lessons learned after Google nearly killed my site

uploader.win

271–280 of 296 posts

Re: Thanks HN: Lessons learned after Google nearly killed my site

#271

Earlier quoted context omitted.

What's up with the loaded rhetoric? You can still do most things without card access: - keep standing orders flowing; - transfer your money out through the mobile app or website; - withdraw money from an ATM using an authenticator (nation-wide example in Poland: https://www.blik.com/); - if push comes to shove, go to a branch and withdraw your money in person.

> What's up with the loaded rhetoric? How is that rhetoric loaded? What rhetoric? > if push comes to shove, go to a branch and withdraw your money in person. When I was starting out in my IT career, the nearest branch of my credit union was more than an hour away by car, and for much of that time I didn't even have a car. If my credit union had restricted my account to "thou must visiteth a branch and speaketh with a…

>>When I was starting out in my IT career, the nearest branch of my credit union was more than an hour away by car

But then.....why did you open an account with a bank without a branch nearby? Not being funny, but that's your own failing, not of the bank.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#272
post #8

From the article: > So after a lot of brainstorming and ideas from HNers I finally figured out the culprit(s). > We have a live demo on our home where people can upload a test file. [...] > We also give all users a 20MB test storage. [...] > I believe that somebody signed up for our service (it’s free to sign up) and then uploaded a malicious file on our test storage and abused this feature. If that is correct, Googl…

Why? Should GDrive be banned if a single user uploads a malicious file and links to it from a Gdoc?

If you create a folder in GDrive, share it with "anyone with a link" and then publish that link on Twitter, you will instantly collect porn, piracy & generally malicious files from all over the world. And your account will promptly get blocked, as it should.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#273
post #32

Can someone explain to my why Google isn't being drowned in a torrent of lawsuits? We are getting stories like this on a weekly basis now. Google is clearly causing measurable harm to your company and you. And apparently to thousands before you. Considering how much money patent trolls manage to extract from Big Tech with considerably weaker cases, how is it that everybody is treating Google like a fragile grandmothe…

how are they not "being downed in a torrent of lawsuits?" because nearly all would-be litigants believe they can't persevere against google's depth of resources. so they don't try.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#274

Earlier quoted context omitted.

Check the webmaster tools on Google, Bing, and any other relevant search engine. If they've detected malware on your site, the webmaster tooling will highlight it. Virustotal.com also supports URL scanning, of you're concerned about a specific payload.

Thanks - at least the online tools like Virustotal don't show anything.

You're ublocked now. Just checked

Re: Thanks HN: Lessons learned after Google nearly killed my site

#275
post #257

Earlier quoted context omitted.

> So you need a google quality malware detection filter to allow user content upload on your site? That's a pretty big barrier to entry. No, but IF you allow people to anonymously upload malware to your site, Google-quality malware detection filters will absolutely do what they were designed to do and detect the malware on your site. I just don't understand the people insisting on arguing that somehow this was a fals…

my problem isn't that it flagged some user-uploaded malware, my problem is that the entire site is blocked without warning. I am genuinely curious how you would prevent your site from being blocked like this? Sure in this case it was a demo, but what if it was an actual image hosting service that required login? What's to stop a bad actor from creating an account and uploading malicious content. Maybe you even have s…

Strictly that's not correct. The whole experience here was a "warning", though it was given to users of the site and not the owners directly. Chrome will allow access through that warning page via an override, and of course they have the option of using other browsers.

But even interpreting you narrowly: How much warning do you think Google should be expected to give before flagging sites with known malicious content? Would you apply that same logic to the sites you visit as a user?

I just don't see how the principle you want is going to work in concert with a world with rampant malware. Most of us very much want the trigger happy filers, because it keeps the problem manageable at the cost of some inconvenience and increased vigilance on the part of the content providers, which is IMHO exactly where it should be.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#276
post #136

> But there are plenty of Google engineers and good helpful people on Hacker news. > (from a screenshot) I work at Google [...] so I escalated your issue [...] > I believe the HN thread getting on the homepage tremendously helped me and somebody from Google saw it and expedited the review after all So, once more an issue with FAANG could only be fixed because somebody knew somebody else and went out of his way to get…

That quote is from an 8-year-old comment: https://news.ycombinator.com/item?id=5972927 .

You're right, didn't look closely enough to see the timestamp. Saw it in the screenshot in the post and thought it was a recent comment.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#277

Earlier quoted context omitted.

Why not run a fully functional monitoring job i.e. upload file with a monitoring account and check the results to validate that it is working end to end. Doing this even once a minute shouldn't put any load and is a much more reliable test.

It would have needed to be done through Chromium in non-headless (likely full Xvfb) mode, with step screenshots, and screenshot comparison (always flaky!), for the Safe Browsing interstitial to have generated an alert.

How about headless mode with validating response by parsing expected output? I don't have a lot of experience so not sure if what I'm saying is feasible.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#278
post #183

Earlier quoted context omitted.

> In order to sue them, you need to come up with something that they should’ve done but didn’t. How so? If you sue for damages, you only have to prove you were harmed by Google's actions, no? And actively misrepresenting your website as dangerous and deceptive to your customers is sort of libelous and clearly damaging.

Google has no obligation to list you on their search results or allow access to your site through their browser. > ctively misrepresenting your website as dangerous and deceptive to your customers is sort of libelous and clearly damaging. Except the OP even said someone uploaded a malicious file that was put in a place publicly accessible. Google was not being libelous. There was a malicious file.

> allow access to your site through their browser.

So what? Google has no right to tell falsehoods about your website as a whole to your customers, though.

I'm pretty sure google will not blacklist github.com if one malicious file is hosted on there, either.

None of the links provided by Google in their console were said to be malicious, either. So what then?

Re: Thanks HN: Lessons learned after Google nearly killed my site

#279
post #261

Earlier quoted context omitted.

> you cannot lose access to your basic bank account and money in that account unless a judge says otherwise. "Losing access to the money in that account" is blatantly stealing from you. It's should be obvious that no company should be able to do this under any circumstances, but that is a separate issue from the question of adequate competition. You still need competition because a monopoly can find an unlimited numb…

> Which allows banks to remain an uncompetitive How exactly is a bank uncompetitive with this regulation?

It isn't this regulation that makes the bank uncompetitive, it's all the other regulations that make banks uncompetitive, i.e. hard to switch between and have high barriers to entry. Without that, this regulation would be unnecessary because you would find a dozen other banks willing to take your business and switching to them would be no more than a minor inconvenience.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#280
post #240

Earlier quoted context omitted.

I think if Google is going to decide to police the web like this, they need to alert people more proactively. The first the OP should have heard of this was Google emailing them through uploader.win's Contact Us email address. It's easy and obvious to find on the site; seems like that should be part of the automated process.

Locating contact info for websites is not something that can be automated. Some sites provide an email address, some a form, some point people at twitter or facebook and some don't provide any contact information at all. None of this is arranged in any sort of standard way. Contact info may be under a link marked "contact" or "about" or "bio" or appear at the bottom of every page.

of course it can. there have always been well known contact addresses: hostmaster, postmaster, webmaster, security, abuse, etc. addition now there is the .well-known URL which has an RFC.
Post reply on HN