Live data from Hacker News

Google Safe Browsing can kill a startup

gomox.medium.com

541–550 of 558 posts

Re: Google Safe Browsing can kill a startup

#541
post #390

Earlier quoted context omitted.

The solution is for the legitimate sites that are driven out of business by Google AI to sue Google for tortuous interference and libel.

This helps one group and hurts another. If Google is liable for blocking potential malware and phishing pages, they'll either stop blocking it, or adjust their algorithm to strongly err on the side of allowing phishing sites. Businesses become safer, but more regular people will get phished.

The problem isn't the company that blocked it. The problem is the company that reported that there was a problem when there wasn't. In this case it sounds like Google is both companies.

Re: Google Safe Browsing can kill a startup

#542

Earlier quoted context omitted.

The internet was a much kinder trusting place back then. We assumed when the browser makers agreed to not use it for bad things, we believed them.

I think as always great ideas do not account for human nature...

> there is no chance in hell that the government will try to break them up.

Government is not the only option. Railroads were fixed by Congress. If you want to fix or split Google, writing your representative about your concerns might help.

Re: Google Safe Browsing can kill a startup

#543
post #519

Earlier quoted context omitted.

Well enough that it will still be a blocker.

Well, that goes without saying. If you want a blocker, you want a blocker. So all the nigerian princes and the like should still be blocked. You just don't want to give control over the blocking blacklist/whitelist to a single entity, even less so to a huge powerful one, possibly in a country other than your own (which e.g. forces their foreign policy dictums to your blacklist), and even less so the one that already…

I don't think this solves the problem from the article, since small businesses will still have to deal with getting mistakenly blocked by whatever the popular blockers are. With 40,000 new phishing sites per week, it's not an easy task. If the blockers are free (I imagine they'd have to be to get widespread adoption), who's going to review the false positives? Volunteers?

But also, it would leave the people most vulnerable to phishing unprotected, namely those not tech-savvy enough to install a phishing protection service. Most internet users don't even have ad-blockers.

Re: Google Safe Browsing can kill a startup

#544
post #502

Earlier quoted context omitted.

And then they will choose the same block list and sites will have the same problem.

All? I doubt it. Not to mention they could offer control to override whatever you like.

> they could offer control to override

Chrome lets you override and proceed to the site. The problem for the small business is that a large fraction of their customers see the scary red warning page.

Re: Google Safe Browsing can kill a startup

#545

After years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or…

> I use Linode now as their support is great and they don't just drop ban hammers and leave you scrambling to figure out what happened.

Linode once gave me 48 hours to respond (with threats to take down the site) because a URL was falsely flagged by netcraft based on what looked like an automated security scan of software I was hosting. Granted, they did not take any action and dropped the report once I pointed out that it was bullshit, but I do not consider this great service. If there is no real evidence of wrongdoing I should not be receiving ultimatums.

Re: Google Safe Browsing can kill a startup

#546
post #75

Of particular note: " Don't host any customer generated data in your main domains. A lot of the cases of blacklisting that I found while researching this issue were caused by SaaS customers unknowingly uploading malicious files onto servers. Those files are harmless to the systems themselves, but their very existence can cause the whole domain to be blacklisted. Anything that your users upload onto your apps should b…

I imagine your service still won't have a great time when Google blacklists companyusercontent.com

A proper mitigation would be to serve user data from one domain per user, no?

Re: Google Safe Browsing can kill a startup

#547
post #187

It's a relatively long article - but it does not answer one simple question, which is quite important when discussing this: were there any malicious files hosted on that semi-random Cloudfront URL ? I realise that Google did not provide help identifying it - but that does not mean one should simply recomission the server under a new domain and continue as if nothing has happened! From TFA: > We quickly realized an Am…

Yes, I guess if you're allowing users to upload arbitrary files that may contain viruses or malware, and you're not scanning the files, that makes you a potential malware host. That's how Google may see it. They're trying to protect their users, and you've created a vector for infection.

Too bad they don't ban googleusercontent.com.

Re: Google Safe Browsing can kill a startup

#548
post #342

Earlier quoted context omitted.

Systems (normally) model organizational processes, so companies with garbage processes usually have garbage systems in place too. This highly specific case reeks of fraud, and you should be able to report them to some kind of ombudsman so you could get your couple days' worth of fees back.

Yes, the terms probably were written when it took two days for a check to clear. No, the ombudsman probably can’t get legal to update the T&Cs

Contracts by definition cannot bind people into illegal conditions, and there's degrees of neglect that can be considered illegal. The entire point of an ombudsman is to keep actors within "this is not illegal" lines; I'm guessing you could do this on small claims court too, but with the plague and everything it can take a lot longer

Re: Google Safe Browsing can kill a startup

#549
post #479
post #470

Earlier quoted context omitted.

Since phishing is not going to go anywhere with or without blacklists - for obvious reasons, e.g. lists can't cover everything, and you can't add sites to the list instantly - I am willing to tolerate a slight increase in fishing which is going to exist anyway in exchange for not having Google (or any other megacorp, or any other organization for that matter) as a gatekeeper of everybody's access to the internet. The…

> I am willing to tolerate a slight increase in fishing According to Google's most recent transparency report[1], as of December 20th of last year they were blocking around 27,000 malware distribution sites and a little over 2,000,000 phishing sites. In your view, would turning off those blacklists and allowing those >2,000,000 sites to become functional again count as a "slight" increase? (edit: That's a real questi…

You can also be certain that these numbers include all the false-positives. One of the Open Source pages I maintain got blocked as well, because too many AV reported one library package as malware.

There's no "report as false-positive" button at Google, so these reports likely have a lot of false positives in them...

Re: Google Safe Browsing can kill a startup

#550
post #536

Earlier quoted context omitted.

(Googler) You are only focusing on the negatives while completely ignoring the positives here. Here are a few questions to consider that may give you better perspective: 1) Do you know the magnitude of financial and psychological damage caused by malware, phishing, etc on the web? 2) Do you believe that it is possible to have a human review every piece of automation generated malware on the internet? 3) Do you believ…

Author here - I don't underestimate the complexity of the task that Google Safe Browsing tries to accomplish. But: Do you believe there is no room for improvement in an automated, opaque system with clear evidence of malfunction, that quite succinctly decides if hundreds of people go unemployed when their company tanks for nothing other than an incorrectly set threshold on some algorithm? That is the real question to…

I do agree that there's room for improvement. There's always room for improvement, but there are also limits to the transparency one should provide for an anti-abuse system. It's difficult for anybody except for an expert in this area to say what would be a safe and satisfactory way to expose appeal and remediation for false positives. In the example from the story it looks like the turn around time was just an hour for your case, which seems rather good. The fact that not all consumers of this data were as responsive looks out of Google's control, and should be taken up with those companies.

I don't agree with the premise of your last question. It's not Google's responsibility to protect the internet and provide a free anti-abuse database for other browser vendors, and yet Google does do this at significant cost. The fact that they don't do it perfectly is not a rationale for killing it or providing it with infinite resources.

Post reply on HN