Live data from Hacker News

Thanks HN: Lessons learned after Google nearly killed my site

uploader.win

51–60 of 296 posts

Re: Thanks HN: Lessons learned after Google nearly killed my site

#51
From what I see Google should now be considered an active threat. You have to design your system knowing they will eventually act against you, either your domains or your accounts. And your chances to get it fixed are slim, unless you’re able to get some public outrage.

Really a disgusting company.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#54
post #12

Earlier quoted context omitted.

I think it's fairly easy to acknowledge the the following are all true: 1. The poster was hosting malicious content from their domain (user uploaded no doubt, but still on the domain they control). 2. On one hand, it is desirable that people who are not malicious be given enough information as fast as possible to rectify their sites. 3. On the other hand, this same sort of information can make it easier for malicious…

If you're hosting lots of malware on different subdomains, there is harm in Google telling you which ones it detected. You could use that information to keep hosting the undetected malware, perhaps out of laziness.

Perhaps just telling the site owner a max of 1 compromised subdomain, e.g. "We detected malware on sub.yourdomain.com" or "We detected malware on sub.yourdomain.com and potentially other subdomains." Seems like that would provide a huge benefit to people trying to be compliant without much benefit to bad guys hosting lots of malware on different subdomains.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#55
post #16

Earlier quoted context omitted.

Something tells me that Google doesn't ban G Drive, Dropbox or MS's what ever it is named when those host malware. I rather not have only the giants host user generated content ...

Google does the silly separate domain dance GP recommended. I couldn't figure out what is it for, until I read this advice in the previous discussion. Disclaimer: I'm a Google SRE. But never supported anything reachable from the outside.

That's not what it's for. It's to prevent user content from being served from the same origin as Google services. If the content were to be served from the same origin, scripts loaded from that origin would be able to access your google cookies and therefore would be able to access your account data.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#56

> But there are plenty of Google engineers and good helpful people on Hacker news. > (from a screenshot) I work at Google [...] so I escalated your issue [...] > I believe the HN thread getting on the homepage tremendously helped me and somebody from Google saw it and expedited the review after all So, once more an issue with FAANG could only be fixed because somebody knew somebody else and went out of his way to get…

This is the norm with FAANG and it really annoys me. How many of these cases never saw the light of day because of that?

Even with HN it's a complete lottery what contents reaches the front page, so getting issues like these resolved is a matter of extreme luck for a common person.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#57

Earlier quoted context omitted.

This is really feudalism replayed. If you know important people at the emperor's court, you have a chance to get yor problem solved.

It's not "feudalism", it's human social relations and power dynamics.

What if his post had not been seen or he didn't know HN. Google etc are the gatekeepers they decides what allowed and what isn't.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#59
post #16

Earlier quoted context omitted.

Google does the silly separate domain dance GP recommended. I couldn't figure out what is it for, until I read this advice in the previous discussion. Disclaimer: I'm a Google SRE. But never supported anything reachable from the outside.

That's not what it's for. It's to prevent user content from being served from the same origin as Google services. If the content were to be served from the same origin, scripts loaded from that origin would be able to access your google cookies and therefore would be able to access your account data.

Oh. I even heard about this mechanism before ;)

Thanks, this makes more sense.

Re: Thanks HN: Lessons learned after Google nearly killed my site

#60

Earlier quoted context omitted.

It's not "feudalism", it's human social relations and power dynamics.

Democratic societies try to limit this problem by establishing some semireliable channels to remedy injustice, though.

I don't think anyone considers this to be in the realm of injustice.
Post reply on HN