Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

461–470 of 558 posts

Re: Google Safe Browsing can kill a startup

#461
post #263

Earlier quoted context omitted.

Fair enough. Scale does make things harder but my $FINANCIAL_INSTITUTION has a lot of scale too and, if I have an issue with my account, I'll have someone on the phone sooner rather than later.

You're saying that as if it contradicts (“but”) what lotsofpulp said, but that was exactly their point: If your bank can do it, then so could Google. That they choose not to is a conscious choice, and not a beneficious one. Conrad's corollary to Hanlon's razor: Said razor having been over-spread and under-understood on the Internet for a long while now, it's time to stop routinely attributing lots of things only to s…

Meta: I’ve vouched for this comment. You have been shadowbanned.

Re: Google Safe Browsing can kill a startup

#462
post #437
post #327

Earlier quoted context omitted.

> I for one never appointed them the guardian of the walled internet. On the other hand, lots of chrome users most likely do trust google to protect them from phishing sites. For those ~3 billion users a false positive on some SaaS they've never heard of is a small price to pay. It's a tricky moral question as to what level of harm to businesses is an acceptable trade off for the security of those users.

I actually don't think this is that hard to fix though. I'm a fan of google doing their best to protect people from scammers. The real issue here is no way to submit an escalated help request when they accidentally mess up. eg they could build a service where -- and I doubt scammers would play -- $100 (or even $1k) would escalate a help request with a 15 minute SLA. I run a business; we would have no problem paying a…

This was the old Microsoft support model: opening a case cost $99(IIRC), but if the case was actually a MS bug/issue they’d waive the fee.

Re: Google Safe Browsing can kill a startup

#463
This reminds me of ugliest.app - there was a hn post on it a while ago. And then suprise, suprise, someone made a "paypal" login page which was hosted on the main domain. It was put on the blacklist, not sure if it still is.

Re: Google Safe Browsing can kill a startup

#464
post #437

Earlier quoted context omitted.

I actually don't think this is that hard to fix though. I'm a fan of google doing their best to protect people from scammers. The real issue here is no way to submit an escalated help request when they accidentally mess up. eg they could build a service where -- and I doubt scammers would play -- $100 (or even $1k) would escalate a help request with a 15 minute SLA. I run a business; we would have no problem paying a…

I can already see the headlines on HN: "How Google Runs a Pay-to-Play Protection Racket"

I mean, that's their whole business anyway, so...

Format your site to suit google, or they don't index it.

Add headers to your emails or google reduces deliverability.

Pay for clicks on your own company's name or google sells ads against the name of your company! They monetize navigation queries.

Run your site through amp and let google steal your traffic or google pushes your search rank down the page.

Let google steal answers to questions contained on your site and display them as answers w/o sending people to your site, or they deindex you (see tons of examples, but also genius).

Let google steal your carefully curated and expensive photographs for google shopping and use them for the item from other vendors or you can't list items in google shopping.

etc etc etc... it's nothing new. So we may as well encourage them to do a more helpful job of what they were going to do anyway.

Re: Google Safe Browsing can kill a startup

#465
post #23

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.

Have you considered not using a 3rd party for hosting your JavaScript? There is always going to be some risk if the code isn’t under your control.

Re: Google Safe Browsing can kill a startup

#466
post #263

Earlier quoted context omitted.

Fair enough. Scale does make things harder but my $FINANCIAL_INSTITUTION has a lot of scale too and, if I have an issue with my account, I'll have someone on the phone sooner rather than later.

You're saying that as if it contradicts (“but”) what lotsofpulp said, but that was exactly their point: If your bank can do it, then so could Google. That they choose not to is a conscious choice, and not a beneficious one. Conrad's corollary to Hanlon's razor: Said razor having been over-spread and under-understood on the Internet for a long while now, it's time to stop routinely attributing lots of things only to s…

I thought I was agreeing. "Fair enough."

Re: Google Safe Browsing can kill a startup

#467

Earlier quoted context omitted.

What happens if it is a hit against the bloom filter / checksum? Would it transmit the URL so that it can be blocklisted?

https://developers.google.com/safe-browsing/v4/update-api#ch... TL;DR is you download a chunk of SHA-256 hashes and check if the hash for your URL is there. There is of course the chance of collision but that is minuscule.

Oh I know that's how that works, I meant, does Google transmit back the URLs once it does get a hit, to protect others from downloading that file?

Re: Google Safe Browsing can kill a startup

#468

> A lot of the cases of blacklisting that I found while researching this issue were caused by SaaS customers unknowingly uploading malicious files onto servers. This is terrifying - what business is it of Google’s what party A uploads to MY servers? And how are they getting that information without dramatically violating the privacy of their users?

If party A uploads something to your servers and the stuff isn't publicly accessible, Google doesn't do anything about it. But if that content is accessible by the public, Google feels a need to protect the public.

Re: Google Safe Browsing can kill a startup

#469

Can anyone "in the know" objectively comment if Google Safe Browsing (GSB) has had a net positive result or outcome for the Internet, at large? Has GSB helped users, more than it has hurt them? The anti-Google rhetoric [on HN] is becoming more tiresome as of late. Personally, I welcome the notifications in my browsers that a domain is unsafe. I can't possibly be the only one.

I'd guess a large net positive among the general population but maybe neutral for the tech literate like HN readers. Most tech-literate people are careful enough to recognize tactics used by phishing sites and won't click on phishing links, or would click and immediately figure out it's phishing. That cannot be said for the general population.

Re: Google Safe Browsing can kill a startup

#470
post #447

Earlier quoted context omitted.

The solution is simple: Liability. As soon as it becomes legally infeasible to let algorithms block people, it will stop happening. Make it easy and affordable to submit legal complaints for tech misbehavior and make the penalties hurt.

Ah, so you suggest liability for the vendors of the software blocking websites, with, in practice [1], no liability for the operators of a compromised website, if it is phishing/malware? This is a great approach, if your goal is to optimize for increasing the amount of dangerous crap on the web. But, eh, that's surely worth it, because the profitability of startups is more important then little things like the securi…

Since phishing is not going to go anywhere with or without blacklists - for obvious reasons, e.g. lists can't cover everything, and you can't add sites to the list instantly - I am willing to tolerate a slight increase in fishing which is going to exist anyway in exchange for not having Google (or any other megacorp, or any other organization for that matter) as a gatekeeper of everybody's access to the internet. The potential for abuse of such power is much greater and much more dangerous than the danger from tiny increase of phishing.
Post reply on HN