Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

431–440 of 558 posts

Re: Google Safe Browsing can kill a startup

#431

A bit of deception on how their site ended up on the block list. They strangely block out a part of their response, but we can see "was cleared", which sounds a lot like "the malware some nefarious agent put on my site was removed". How sites end up on the block list- -they host malware, either intentionally or because they were hacked. -they host a phishing site, either intentionally or because they were hacked. Pro…

> When I get a text to a phishing site, I immediately report it to the safe browsing list. Please, don't do that. You're just giving more power to a private company (Google). It's so deceiving, I know: reporting/blocking malware sites is a good thing, but doing so via Google diminishes the returns so greatly that it's no longer worth it.

As opposed to what alternative? Google's safe browsing list is used by everyone, and is currently the gold standard. There exists no alternative. NextDNS uses it. Safari uses it. Firefox uses it.

Yeah, I'm not feeling guilty about this, and I'll do it every time.

Note that the list isn't like a spam list or something where bad actors can just flag something and get them blacklisted. When you report to the safe browsing list it is actually verified, and when it's a fake bank/netflix/Amazon/etc login, it's pretty easy for them.

Re: Google Safe Browsing can kill a startup

#432
Stupid question: Isn't this clear-cut grounds for a defamation lawsuit?

Also, is it possible to have a class-action defamation lawsuit?

The fundamental issue that the author gomox is not stating clearly in his article is that there are no consequences to Google for their actions. None. Literally zero.

I don't think the best plan is to wait and hope for a government to step in and take action. Hope is not a strategy.

Complaining on public forums has similarly done nothing to curb Google's careless wielding of the ban-hammer.

So sue them. Cost them money. Punish them in a material way that they can't ignore.

I can't imagine anything else working...

Re: Google Safe Browsing can kill a startup

#433
post #421
post #393

Earlier quoted context omitted.

How would you propose handling this with DNS? Here are some things it covers: * a.example.com and b.example.com are the same site * a.co.uk and b.co.uk are not the same site * a.cloudfront.net and b.cloudfront.net are not the same site * a.higashikawa.hokkaido.jp and b.higashikawa.hokkaido.jp are not the same site * a.example.higashikawa.hokkaido.jp and b.example.higashikawa.hokkaido.jp are the same site There is a p…

_i_am_tld.cloudfront.net IN TXT "yes" _i_am_tld.higashikawa.hokkaido.jp IN TXT "yes"

This requires sites to opt in before it works, right? I think this would have been hard to introduce, because it requires so much coordination.

Re: Google Safe Browsing can kill a startup

#434

Earlier quoted context omitted.

This is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.

Are you implying that the list no longer has a good intention? I wouldn't be surprised if there are multiple orders of magnitude more phishing and hacked websites in 2021 than there was in 2004. Even with human checking, I doubt you'll even have 0% failure rate. Is the solution to just give up on blocking phishing sites?

>Is the solution to just give up on blocking phishing sites?

IMHO yes. It's too much power for one company to wield. And especially a company with such questionable morals as Google. This cure is worse than the disease.

Re: Google Safe Browsing can kill a startup

#435

Earlier quoted context omitted.

Assuming that this site "serving malware" isn't doing it purposely. What if someone made a site that inspected malware and went in depth on how it worked and allowed you to download the malware to inspect yourself so you desire. Google would flag this site as bad and blacklist it, but in reality it's a research site.

There are standardized ways to share malware downloads. Google likely respects them.

What is that standardized way?

Encrypted zip files with the password listed on the website is the easiest one that comes to mind. I wonder if googlebot will some day decrypt those files because a lot of pirated software is distributed in encrypted zip files. Scanning those files for viruses would be pretty useful for the average user.

I guess captchas are the only bulletproof solution

Re: Google Safe Browsing can kill a startup

#436
post #235

Earlier quoted context omitted.

In this case they do not provide a service to the OP. There is no agreement between OP and Google. This is happening on browsers of their customers. And I'm quite sure that if Google hits a company that competes with Google services there must be a law that they will be breaking. There was a big case in Poland where Google blocked a SaaS web shop provider using the same exact mechanism [0]. Polish courts decided that…

Aside from abusive dominent position there is no law they would break. When you download and use chrome you ACCEPT the Terms and Conditions of Google. There is no law that prevents a web browser from blocking access to a website or modifying the page . If the TOS stipulate « pages may differ from the original or be subject to third party software » , they are in within their rights and the customer accepted it when h…

You ignored the issue of libel, though. Do you have a reason it's not?

Re: Google Safe Browsing can kill a startup

#437
post #327

Earlier quoted context omitted.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

> I for one never appointed them the guardian of the walled internet. On the other hand, lots of chrome users most likely do trust google to protect them from phishing sites. For those ~3 billion users a false positive on some SaaS they've never heard of is a small price to pay. It's a tricky moral question as to what level of harm to businesses is an acceptable trade off for the security of those users.

I actually don't think this is that hard to fix though.

I'm a fan of google doing their best to protect people from scammers. The real issue here is no way to submit an escalated help request when they accidentally mess up. eg they could build a service where -- and I doubt scammers would play -- $100 (or even $1k) would escalate a help request with a 15 minute SLA. I run a business; we would have no problem paying an escalation fee.

Re: Google Safe Browsing can kill a startup

#438

Earlier quoted context omitted.

They have the option of not wielding the hammer. I for one never appointed them the guardian of the walled internet.

This. Why is there an implicit agreement that okay Google is the gatekeeper. It shouldn't be. The internet did not appoint Google as the gatekeeper.

> Why is there an implicit agreement that okay Google is the gatekeeper.

Because they run a popular browser and don't want their users getting scammed?

For each tech savvy person mad about this, there's 10 non-tech-savvy people completely oblivious that could get scammed by phishing sites we'd consider obvious.

Sure, they should do a better job, but that blacklist is probably millions of websites big at this point. It's the kind of thing where a perfect job is essentially impossible, and the scale means that even doing a decent job is going to be extremely difficult.

Re: Google Safe Browsing can kill a startup

#439
post #437
post #327

Earlier quoted context omitted.

> I for one never appointed them the guardian of the walled internet. On the other hand, lots of chrome users most likely do trust google to protect them from phishing sites. For those ~3 billion users a false positive on some SaaS they've never heard of is a small price to pay. It's a tricky moral question as to what level of harm to businesses is an acceptable trade off for the security of those users.

I actually don't think this is that hard to fix though. I'm a fan of google doing their best to protect people from scammers. The real issue here is no way to submit an escalated help request when they accidentally mess up. eg they could build a service where -- and I doubt scammers would play -- $100 (or even $1k) would escalate a help request with a 15 minute SLA. I run a business; we would have no problem paying a…

I can already see the headlines on HN:

"How Google Runs a Pay-to-Play Protection Racket"

Re: Google Safe Browsing can kill a startup

#440
post #264

Earlier quoted context omitted.

I agree. Google is such a large behemoth who actively tries to avoid customer support if they can. Splitting it to smaller business with a bit of autonomy and not having to rely on ad money fueling everything else means those smaller businesses have to give a shit about customers and compete on even ground. Same applies to Facebook and other tech companies. The root issue is taking huge profits from area of business…

> However anti-trust in US has eroded significantly. Perhaps compared to the 40s-70s, but certainly not compared to the Reagan era. Starting with the Obama administration, there's been a strong rebirth of the anti-trust movement and it's only gaining momentum (see many recent examples of blocked mergers)[1]. [1] https://hbr.org/2017/12/the-rise-fall-and-rebirth-of-the-u-s...

The Obama admin used it only to attack enemies.

Renata Hesse was part of that effort, and has since worked for Google and Amazon, and is now expected to be in charge of anti-trust at Biden's DOJ.

Post reply on HN