Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

321–330 of 558 posts

Re: Google Safe Browsing can kill a startup

#321
post #71

If their claim is false, then is it, in any jurisdiction, libelous? Maybe, legislation to bring consequences for false claims will help ensure algorithms, and the support teams that monitor them, do a better job. In an internet focused world, especially one with lock downs, wiping sites off of the internet with false claims is a heinously bad act.

I'm unsure whether it would be ruled libel, but I lean towards yes it would. There are two ways of seeing it:

1) It is a false statement by google themselves (so no §230 protection) that caused material damage and is thus libelous 2) It is an opinion protected under free speech, and the free behavior of a private company, and the words like "may have" show it is not a statement of fact, and "deceptive" is just an opinion.

Yet it feels very wrong and definately Google's fault, and Google should be responsible for the damages, morally speaking.

It's more than just a false statement, the pop-up is keeping users from visiting the website. However, Google doesn't intend to harm these companies in order to gain competitive advantage, it just harms them accidently, so the monopoly argument also has problems.

It seems to me that we need a new law, or that current jurisprudence has let this one slip through and perhaps there will (in America) never be a proper crime for this situation due to divergent jurisprudence in this space that left open this gap.

I would like to know whether it has been tested in court, or if anyone is in process of doing so.

Re: Google Safe Browsing can kill a startup

#322
post #296
post #292

Earlier quoted context omitted.

unique TLD? that should be very costly? or does GSB not ban the entire TLD when a subdomain has malicious content? Would be great if our overlords at least publish the overzealous rules we need to abide by.

Dropbox DL and Preview urls take a form of https://uc[26 character hex string].dl.dropboxusercontent.com/... and https://uc[26 character hex string].preview.dropboxusercontent.com/... - it does not have to be a separate TLD to avoid being blocked, but it has to be differentiated. This is the same reason why the block of the TFA company did not cause an outage of everyone using CloudFront - GSB does not block full TLD…

I wonder if there's a threshold here.. When I researched this issue (while we were figuring out how to mitigate it), I did encounter some people who had their entire domains blocked because 1 subdomain had bad content. In fact, this thread itself has mention of that happening to neocities

Re: Google Safe Browsing can kill a startup

#324

Earlier quoted context omitted.

Which one is that.

Sometime Google doesn't recognize your device and then your password is not enough... even if you have second-factor authentication disabled. So if you don't have a second form of contact like another phone number or another email for recovery, then you are fucked. Sometime they even ask you for a previous password for recovery, so if you use a password manager that doesn't keep history, you might also be fucked.

Is this only when using MFA. Sometimes, without MFA enabled, if you just change the user-agent header they send an email that they have detected a "new device". What if you just exported all mail each day, maybe this could be automated, then in the event of a lockout at least you have all of the stored mail.

Re: Google Safe Browsing can kill a startup

#325

This is actually funny, because I was involved with the creation of this list, way back in 2004. The whole thing started as a way to stop phishing. I was working at eBay/PayPal at the time, and we were finding a bunch of new phishing sites every day. We would keep a list and try to track down the owners of the (almost always hacked) sites and ask them to take it down. But sometimes it would take weeks or months for t…

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions...

We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Re: Google Safe Browsing can kill a startup

#326

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Massive bureaucratic nightmares never act with malice, but the people get crushed all the same.

Worms on the sidewalk.

Re: Google Safe Browsing can kill a startup

#327
post #23

Earlier quoted context omitted.

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

> I for one never appointed them the guardian of the walled internet.

On the other hand, lots of chrome users most likely do trust google to protect them from phishing sites. For those ~3 billion users a false positive on some SaaS they've never heard of is a small price to pay.

It's a tricky moral question as to what level of harm to businesses is an acceptable trade off for the security of those users.

Re: Google Safe Browsing can kill a startup

#328
post #30
post #26

This is not new; such things happened many times in the past (25 years ago Microsoft was the behemoth trampling small companies) and will happen again. I do not think Google is doing it consciously -- this is probably just collateral damage from some bot or rule. The way to handle it is to reduce dependencies on the cloud. This does not mean cutting cloud services altogether, but once the company is big enough (and t…

Author here. The scary bit is that the blacklist is enforced client side in Chrome and other programs. Our servers and systems were running just fine when this happened, but if Google Chrome refuses to open your website, you're still down. The closest parallel I can think of are expired SSL certificates, but the level of transparency and decentralization of that system vs. this opaque blacklist is not really on the s…

Some derisking solution may be wrapping your web app as native client. E.g. Electron app is Chrome technically but you get more control over its settings. I know Microsoft (SmartScreen) and Apple may block apps for many reasons too but at least you get more baskets for your eggs.

Re: Google Safe Browsing can kill a startup

#329

Earlier quoted context omitted.

>”never attribute to malice that which is adequately explained by stupidity" I keep reading this on the internet as if it’s some sort of truism, but every situation in life is not a court where a prosecutor is trying to prove intent. There is insufficient time and resources to evaluate each and every circumstance to determine each and every causative factor, so we have to use heuristics to get by and make the best gu…

The saying is for your own sanity. If you go around assuming every mistake is malicious, it’s going to fuck up your interactions with the world. Everyone I know who approaches the world with a me vs. them mentality appears to be constantly fraught with the latest pile of actors “trying to fuck them”. It’s an angry, depressing life when you think that the teller at the grocery store is literally trying to steal from y…

One does not have to choose between assuming everything is malice or everything is stupid. Situations in the real world are more nuanced, and hence the saying is inane.
Post reply on HN