3 ms·
If you were hosting phishing sites then I'm glad they did this. You should have better controls.
by robk 6y ago
If you were hosting phishing sites then I'm glad they did this. You should have better controls.
- acituan 6y agoAccording to the postmortem they had removed the site in question a week back. Google was acting on a week old data. Besides, any user-content serving platform will have to deal with malicious users. It is not a perfect process, especially against bot traffic. Shutting down the whole domain was very heavy handed.
- mthoms 6y agoI'll say it was. I can't believe they shut them down for content that had been removed over a week prior. I realize some things take time, but the onus is on them to do a final verification before flipping the switch to shut down an entire business(!) Google is "saving money" on support costs while simultaneously destroying their brand image (at least among the tech crowd). It will be near impossible for them to re-earn that goodwill. It's such ridiculously short sighted thinking. I'm moving off of G-Suite this week. This is the final straw.
- MattGaiser 6y agoThere is spam on Facebook, there is spam on Reddit, there is spam on Twitter, there is spam on Hacker News. Proactive spam control is not a solved problem anywhere. Banning a website over it is absurd.
- ben509 6y agoNuking a domain with no warning for any reason is nuts. They started to shut it down before the email notification. And any time support or PR is droning on about "muh policies" you know there are problems.
- heipei 6y agoAutomatically detecting phishing sites is surprisingly hard to do reliably. The only thing you can really do is rely on flagging and human verification. I've seen domains like google5[.]$tld which contained a fake Google Login form, up for close to an hour with zero detects in VirusTotal and no detection by Google Safe Browsing itself. If Google fails at detecting phishing against their own brand, what chances do smaller shops realistically have? Here's the example I mentioned: https://twitter.com/urlscanio/status/1178043405529763841 https://twitter.com/urlscanio/status/1178043405529763841
- ben509 6y agoIs it even possible? If I'm phishing and I get shut down, I'd just modify my page slightly until it passes the detection. It seems like a problem as hard as detecting spam.