Live data from Hacker News

Remove any Site From Google (even if you don't control it)

jamesbreckenridge.co.uk

91–100 of 102 posts

Re: Remove any Site From Google (even if you don't control it)

#91

I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)

I'm not sure how he was unable to find their security@google.com email address. Searches like "Google security" and "Google report vulnerability" have http://www.google.com/about/corporate/company/security.html (which has a prominent section on reporting security issues) as their first result.

I don't think it's reasonable to expect most people not immersed in the proper culture to see this as a "security" issue. They'd agree with "vulnerability" if you suggested it to them, but "bug" is really the first word that comes to mind.

Re: Remove any Site From Google (even if you don't control it)

#92
post #58

Earlier quoted context omitted.

I am a google apps paying customer and it took them 4 weeks to get my domain issue corrected ! In that time i wasnt able to get mail so i had to change my mail to use godaddy until they got back to me. When they finally did they said it was because my dns records were pointing to godaddy ! After 1 week of not getting mails i would say an alternative is required. I actually had a feeling that this would happen :) I re…

Setting up your DNS is not really something Google should do for you. You should have had an IT pro who's done this sort of transition before, manage the move. You could have had this resolved in hours not weeks. I agree though Google support sucks, the key is to not depend on it.

I think you misread what the problem was.

Re: Remove any Site From Google (even if you don't control it)

#93

Earlier quoted context omitted.

Personally, I would be more concerned if someone with malicious intent and the ability to keep silent about what they have done had found & exploited this. [0] Advertise: remove your competitor from Google's search results for a day! If I didn't think it was illegal, I'd probably pay for that, were I in such a situation. [0] If, of course, it even existed in the first place. It seems plausible enough to me, even if I…

Eh, ok it would be more concerning . But Lulzsec would have made quite a spectacle out of it.

Now that, I must agree with.

Re: Remove any Site From Google (even if you don't control it)

#94

I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)

Sending an email to security@google.com will result in a quick response. As part of their bug bounty program Google would have paid $1,000 for this bug if not more.

No, it won't. Trying to contact Google when I was working for a major corporation and TRYING TO GIVE GOOGLE MONEY resulted in the exact same issue as the OP, and this was in 2006, not 2011. The only way to get their attention was create a blog post about how I couldn't contact them.

Re: Remove any Site From Google (even if you don't control it)

#95
post #9

Earlier quoted context omitted.

Bugs happen. Even big ones like this. Any engineer worth his money knows that no amount of Q&A will discover 100% of the bugs. But, as Joel Spolsky said somewhere, bugs are just bugs, you fix them and then they're fixed.

I know, I am an engineer and I obviously let bugs pass too. But this is a little too obvious to me, to check if the user is allowed to remove this url. Maybe I am neurotic? :)

...but Intel released the Pentium and it couldn't divide by 10.

Sometimes testers use the shotgun approach, and things get missed. It can help to write exhaustive tests (you have a computer, right?) and try everything. But the problem space has to be orderly, orthogonal, something that can be spanned. This bug is in a pretty small problem space - an API with many dimensions (arguments), external dependencies. I'm not at all surprised something got thru.

Re: Remove any Site From Google (even if you don't control it)

#96

I think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)

It's obnoxious how hard it is to report bugs to Google. And posting in their forum is a joke anyway. Google's new two-factor authentication? Really neat right? Yeah, well, it's buggy and there is no way to report bugs for it. I posted in the forum and was received by crickets. I don't mind it most of the time, but when I have a real issue or something that is obviously broken and unnoticed, it sure is frustrating. ed…

What problems have you run into? I recently switched over to 2-factor auth and while it's working fabulously I'd be interested to learn about any problems I could run into.

Re: Remove any Site From Google (even if you don't control it)

#98
post #43
post #34

Earlier quoted context omitted.

> This bug could have been exploited for millions of dollars. Quite possibly exploited for non-savvy website owners. Savvy owners would be checking their ranking regularly and noticing it disappear one day. Anyone who ranks highly for lucrative keywords and does not check their ranking is asking to lose it, whether ethically or otherwise. So I don't think it would have been exploited for the millions you think, but p…

> Anyone who ranks highly for lucrative keywords and does not check their ranking is asking to lose it, whether ethically or otherwise. Your ranking is not your responsibility as a webmaster. It's Google's responsibility to its users to rank good answers highly.

By that logic, your comment being understood isn't your responsibility, it's the responsibility of your reader.

Re: Remove any Site From Google (even if you don't control it)

#99

Earlier quoted context omitted.

Sending an email to security@google.com will result in a quick response. As part of their bug bounty program Google would have paid $1,000 for this bug if not more.

That was my immediate thought when I read the article. "Wow, this guy just chucked away hundreds of dollars". Always check for a bounty program before you go and release information like this.

Google should probably still give this guy the bounty

Re: Remove any Site From Google (even if you don't control it)

#100
post #99

Earlier quoted context omitted.

That was my immediate thought when I read the article. "Wow, this guy just chucked away hundreds of dollars". Always check for a bounty program before you go and release information like this.

Google should probably still give this guy the bounty

One of the main reasons they have a bounty program is to prevent people releasing information about bugs before they have been fixed. I don't see why they should give him a bounty.
Post reply on HN