Live data from Hacker News

Google Safe Browsing incident

statichost.eu

61–70 of 183 posts

Re: Google Safe Browsing incident

#61
post #53
post #49

Earlier quoted context omitted.

One can only imagine the other beginner mistakes made by this operator.

Well, you're responding to him, so questions or suggestions are probably better than speculation. My comment about vitriol was more directed at the HN commenters than Eric himself. Really, I think a discussion about web infrastructure is more interesting than a hatefest on Google. Thankfully, the balance seems to have shifted since I posted my top-level comment.

> Well, you're responding to him, so questions or suggestions are probably better than speculation.

I suspect the author is unaware of their other blindspots. It's not 2001 anymore. Holding yourself out as a hosting provider comes with some baseline expectations.

Re: Google Safe Browsing incident

#62
post #56

> To be fair, many or even most sites on the Google Safe Browsing blacklist are probably unworthy. But I’m pretty sure this was not the first false positive. The bigger issue is that the internet needs governance . And, in the absence of regulation, someone has stepped in and done it in a way that the author didn't like. Perhaps we could start by requiring that Google provide ways to contact a living, breathing human…

why do you assume that the living, breathing human hired by theGoogs will be competent at handling all of the crazy that will be flung at them by the living, breathing human on the other end of the line. One single person cannot handle that. Naturally, you need a team of living, breathing humans. You might even have them in triage level groups like level 1 support, level 2 support and so on where each level is a more trained/experienced living, breathing human. Eventually, you'll have an entire department of people of varying degrees of skill. Oh, wait, I'm sorry, I thought it was the year 2000.

Hopefully, this helps you understand why your living, breathing human is such a farcical idea for theGoogs to consider.

Re: Google Safe Browsing incident

#63

Github discovered the same thing a long long time ago which is why you now have the github.io domain.

In Github's case, I think it was also because a lot of security boundaries were using TLD which led x.github.com potentially grab cookies of y.github.com or worse, github.com itslef

https://news.ycombinator.com/item?id=5500612

Re: Google Safe Browsing incident

#64
post #4

Earlier quoted context omitted.

It always was. You're one upload and a complaint to your ISP/Google/AWS/MS away from having your account terminated.

Any services successfully offloading UGC to other moderated platforms? E.g. developer tools relying on GitHub instead of storing source/assets in the service itself, and Microsoft can take care of most moderation needs. But are there consumer apps that do things like this?

I think imgur and disqus are good examples of that, there are probably quite a few.

Re: Google Safe Browsing incident

#65
I don't like nor trust google, but "Use your own judgement and hard-earned Internet street smarts" doesn't work either, because the median internet user does not have anything resembling internet street smarts.

Re: Google Safe Browsing incident

#66
post #4
post #2

It feels like unless you're one of the big social media companies, accepting user content is slowly becoming a larger and larger risk.

It always was. You're one upload and a complaint to your ISP/Google/AWS/MS away from having your account terminated.

Your equally just one fake report to an automated system away having your account shut down. So, yes, your actions have consequences, but more worrying to me is the ability of someone with a grudge causing consequences for you as well.

Re: Google Safe Browsing incident

#67
post #60

This is a bit of a tangent, the whole concept of "domain reputation" can be infuriating. For example, my blog has been marked as suspicious by spamhaus.org: https://check.spamhaus.org/results?query=dynomight.net As a result, some ISPs apparently block the domain. Why is it listed? I have no idea. There are no ads, there is no user content, and I've never sent any email from the domain. I've tried contacting spamhaus,…

From reading that my guess would be that the IP of your host gotten from your hosting provider had some spammy history before you started hosting your blog on it.

Either that or your DNS provider hosts a lot of spam.

Re: Google Safe Browsing incident

#69
post #7

Hosts phishing sites, gets blocked by anti phishing mechanism. Works as expected from my point of view. Get yourself on public suffix list or get better moderation. But of course just moaning about bad google is easier.

You are right, of course. I'm not sure if those of you who disagree with me think that Safe Browsing did its job (which it did!), that Safe Browsing is a good thing (which it maybe is, but which I slightly disagree with), or that it's ok that Google monitors everything everyone does. The last point is actually the one I'm trying to make.

It's hard to get that point because you're conflating two different stories.

Folks around here are generally uneasy about tracking in general too, but remove big brother monitoring from Safe Browsing and this story could still be the same: whole domain blacklisted by Google, only due to manual reporting instead.

"Oh, but a human reviewer would've known `*.statichost.eu` isn't managed by us"—not in a lot of cases, not really.

Re: Google Safe Browsing incident

#70
post #60

This is a bit of a tangent, the whole concept of "domain reputation" can be infuriating. For example, my blog has been marked as suspicious by spamhaus.org: https://check.spamhaus.org/results?query=dynomight.net As a result, some ISPs apparently block the domain. Why is it listed? I have no idea. There are no ads, there is no user content, and I've never sent any email from the domain. I've tried contacting spamhaus,…

From reading that my guess would be that the IP of your host gotten from your hosting provider had some spammy history before you started hosting your blog on it. Either that or your DNS provider hosts a lot of spam.

Hmmm, I use https://njal.la/ for DNS. Could spamhaus really just auto-mark every njalla user as suspicious?
Post reply on HN