Live data from Hacker News

Google Safe Browsing incident

statichost.eu

91–100 of 183 posts

Re: Google Safe Browsing incident

#91

I’ve got a random subdomain hosting a little internal tool. About twice a year, Google Safe Browsing decides it’s phishing and flags it. Sometimes they flag the whole domain for good measure. Search Console always points to my internal login page, which isn’t public and definitely isn’t phishing. They clear it quickly when I appeal, and since it’s just for me, I’ve mostly stopped worrying about it.

I encountered something similar. I have `*.domain.tld` pointed to an internal IP address, and over the past few years it happened a few times where some subdomain would be flagged as dangerous by Google Safe Browsing.

Re: Google Safe Browsing incident

#92

Earlier quoted context omitted.

I respectfully disagree with your premise. In this specific case, yes, "Google does good thing" in a sense. That is not why I'm saying Google has too much power. "Too much" is relative and whether they do good or bad debatable, of course, but it's hard to argue that they don't have a gigantic influence on the whole internet, no? :) Helping people avoid potentially devastating mistakes is of course a good thing.

What point are you trying to make here? You hosted phishing sites on your primary domain, which was then flagged as unsafe. You chose not to use the tools that would have marked those sites as belonging to individual users, and the system worked as designed.

Please note that this tool (PSL) is not available until you have a significant user base. Which probably means a significant amount of spam as well.

Re: Google Safe Browsing incident

#93
post #71
post #7

Hosts phishing sites, gets blocked by anti phishing mechanism. Works as expected from my point of view. Get yourself on public suffix list or get better moderation. But of course just moaning about bad google is easier.

If youtube.com doesn't end up on the Safe Browsing blacklist because of phishing videos, but your own website can easily end up there, it's a pretty clear case of Google abusing their power.

What is a phishing video?

Re: Google Safe Browsing incident

#94
post #56

> To be fair, many or even most sites on the Google Safe Browsing blacklist are probably unworthy. But I’m pretty sure this was not the first false positive. The bigger issue is that the internet needs governance . And, in the absence of regulation, someone has stepped in and done it in a way that the author didn't like. Perhaps we could start by requiring that Google provide ways to contact a living, breathing human…

why do you assume that the living, breathing human hired by theGoogs will be competent at handling all of the crazy that will be flung at them by the living, breathing human on the other end of the line. One single person cannot handle that. Naturally, you need a team of living, breathing humans. You might even have them in triage level groups like level 1 support, level 2 support and so on where each level is a more…

Well, Google did self-appoint itself the "internet police," and the general job of the police is to deal with screwballs.

So you can't take one part of the responsibility and abdicate the other part!

Re: Google Safe Browsing incident

#95
post #61
post #53

Earlier quoted context omitted.

Well, you're responding to him, so questions or suggestions are probably better than speculation. My comment about vitriol was more directed at the HN commenters than Eric himself. Really, I think a discussion about web infrastructure is more interesting than a hatefest on Google. Thankfully, the balance seems to have shifted since I posted my top-level comment.

> Well, you're responding to him, so questions or suggestions are probably better than speculation. I suspect the author is unaware of their other blindspots. It's not 2001 anymore. Holding yourself out as a hosting provider comes with some baseline expectations.

> baseline expectations

Do you have more details? That sounds interesting.

Re: Google Safe Browsing incident

#96

Earlier quoted context omitted.

What point are you trying to make here? You hosted phishing sites on your primary domain, which was then flagged as unsafe. You chose not to use the tools that would have marked those sites as belonging to individual users, and the system worked as designed.

Please note that this tool (PSL) is not available until you have a significant user base. Which probably means a significant amount of spam as well.

Where'd you see/hear that? It hasn't been my experience at least - but maybe I've just been lucky or undercounting the sites.

There are required steps to follow but none are "have x users" or "see a lot of spam". It's mostly "follow proper DNS steps and guidelines in the given format" with a little "show you're doing this for the intended reason rather than to circumvent something the PSL is not meant for/for something the public can't get to anyways" (e.g. tricking rate limits, internal only or single user personal sites) added on top.

Re: Google Safe Browsing incident

#97
post #11

Putting user content on another domain and adding that domain to the public suffix list is good advice. So good, in fact, that it should have been known to an infrastructure provider in the first place. There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance.

> There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance.

For what it's worth, this makes it sound like you think the vitriol should be aimed at the author's ignorance rather than the circumstances which led to it, presuming you meant the latter.

Re: Google Safe Browsing incident

#98
post #52

Earlier quoted context omitted.

This is of course true! It just takes an incident like this to get ones head out of ones ass and actually do it. :)

The good news is, once known, a lesson like this is hard to forget. The PSL is one of those load-bearing pieces of web infrastructure that is esoteric and thanklessly maintained. Maybe there ought to be a better way, both in the sense of a direct alternative (like DNS), and in the sense of a better security model.

There’s some value in the public suffix list being shared, with mild sanity checking before accepting entries: it maintains a distinction between site (which includes all subdomains) and origin (which doesn’t). Safe Browsing wants to block sites, but if you can designate your domain a public suffix without oversight, you can bypass that so that it will only manage to block your subdomains individually (until they adjust their heuristics to something much more complicated and less reliable than what we have now).

Re: Google Safe Browsing incident

#99
post #11

Putting user content on another domain and adding that domain to the public suffix list is good advice. So good, in fact, that it should have been known to an infrastructure provider in the first place. There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance.

> There's a lot of vitriol here that is ultimately misplaced away from the author's own ignorance. For what it's worth, this makes it sound like you think the vitriol should be aimed at the author's ignorance rather than the circumstances which led to it, presuming you meant the latter.

I do think the author's ignorance was a bigger problem--both in the sense of he should have known better and also in the sense that the PSL needs to be more discoverable--than anything Google('s automated systems) did.

However, I'm now reflecting on what I said as "be careful what you wish for", because the comments on this HN post have done a complete 180 since I wrote it, to the point of turning into a pile-on in the opposite direction.

Re: Google Safe Browsing incident

#100

Earlier quoted context omitted.

I'm not saying that Google or Safe Browsing in particular did anything wrong per se. My point is primarily that Google has too much power over the internet. I know that in this case what actually happened is because of me not putting enough effort into fending off bad guys. The new separate domain is pending inclusion in the PSL, yes. Edit: the "effort" I'm talking about above refers to more real time moderation of c…

How does flagging a domain that was actively hosting phishing sites demonstrate that Google has too much power? They do, but this is a terrible example, undermining any point you are trying to make.

The thing about Google is that they regularly get this stuff wrong, and there is no recourse when they do.

I think most people working in tech know the extent to which Google can screw over a business when they make a mistake, but the gravity of the situation becomes much clearer when it actually happens to you.

This time it's a phishing website, but what if the same happens five years down the line because of an unflattering page about a megalomaniac US politician?

Post reply on HN