26 ms·
Google Safe Browsing can kill a startup
- Triv888 6y agoMost of Google's "safety" features are somewhat evil in some way. I don't want any of them, but some of them can't be disabled (like the one that can lock you out of your account even if you have the correct password).
- 1vuio0pswjnm7 6y agoWhich one is that.
- Triv888 6y agoSometime Google doesn't recognize your device and then your password is not enough... even if you have second-factor authentication disabled. So if you don't have a second form of contact like another phone number or another email for recovery, then you are fucked. Sometime they even ask you for a previous password for recovery, so if you use a password manager that doesn't keep history, you might also be fucked.
- 1vuio0pswjnm7 6y agoIs this only when using MFA. Sometimes, without MFA enabled, if you just change the user-agent header they send an email that they have detected a "new device". What if you just exported all mail each day, maybe this could be automated, then in the event of a lockout at least you have all of the stored mail.
- Triv888 6y agoI don't use MFA. Also, I have my emails backed up, but that doesn't help for authentication/recovery with other services/external accounts that were created using that Gmail account... Maybe I need to host my own but that comes with a plethora of other problems.
- cadence- 6y agoI can confirm everything that was said in that article. I run a free dynamic dns service (freemyip.com) and every time someone creates a subdomain that later hosts some questionable material, Google will immediately block my whole domain. Their response time for clearing these up varies from a few hours to two weeks. It feels completely random. I once had a malicious subdomain that I removed within two hours, yet the ban on Google lasted for more than two weeks. Now, this is a free service so bans like these don’t really matter that much to me, but if it was a business, I would have most likely gone bankrupt already. I noticed that recently, they are only sending me the warning, but don’t block me right away. Perhaps after a few years of these situations I advanced to a more “trusted” level at Google where they give me some time to react before they pull the plug on my domain. I don’t know. But I would be truly petrified of Google if this was my real business.
- gomox 6y agoAuthor here. This is fascinating because I figured Google would definitely not ban cloudfront.net entirely and that's why they blacklisted the subdomain, but had this been hosted on our actual company domain, would we have been spared?
- jefftk 6y agoHave you considered requesting that your domain be added to the public suffix list? https://publicsuffix.org/ https://publicsuffix.org/ If subdomains of your domain should be treated as independent sites, the public suffix list is (sadly) how you communicate that to browsers. (Disclosure: I work for Google, speaking only for myself)
- specialist 6y ago1- Ban self dealing. Even the appearance of a conflict of interest should be treated as an actual conflict of interest. Among all the other countermeasures being considering, breaking apart these monopoly's end-to-end integrations should be top priority. For comparison: I'm a huge Apple fan boy. I'm in a happy monogamist relationship with Apple (h/t NYU Prof Scott Galloway). There's no question their awesome products are largely due to their keiretsu, monopsony, and other anti-competitive practices. So despite my own joy, I also support breaking up Apple, for the greater good. The same applies to Google's offerings. Google Chrome cannot be allowed to operate without oversight. Once a product or service becomes an important pillar in a market, it must be held accountable. 2- Fair and impartial courts. Governments make markets. Google (et al) act as sovereign governments running their private markets. This is unacceptable. We all must have the right to negotiate contracts, appeal decisions, and other misc tort. To be adjudicated in an open, fair, impartial courts overseen by professional and accountable judges. In other words, I demand the rule of law. Again using Apple as my example. As a customer, I benefit hugely from Apple's App Store, where they vet and curate entries. This is awesome. But Apple must be held accountable for all of their decisions. All participants must have the right to sue for damages. In a fair and impartial court system, independent of Apple's total control over the market. Similarly, however Google is administrating the Safe Browsing infrastructure, it must be transparent, accountable, auditable. -- I'm still working on this messaging, phrasing. Criticisms, editing, word smithing much appreciated.
- hedora 6y agoMust be held accountable -> must be operated autonomously from the rest of the business
- specialist 6y agoYes. I'd like this better explained. Those "Chinese firewalls" meant to keep biz units apart always seem to be completely fictional. Ditto "self policing".
- kubanczyk 6y ago> Criticisms, editing, word smithing much appreciated. My loose thoughts, feel free to use. (Reordered 2 before 1.) 2. In any bigg-ish privately regulated market, the membership needs to be based on public, objective rules and under a real jurisdiction. If you paid and obeyed the regulations and have been banned/mistreated, you can sue. 1. For any market, if a company (Google or other) has a clear majority of it, they have additional responsibilities. "Customer is free to go away to our competitors" does not tell a full story (illustrated by OP). The cost to switch is the real deal here.
- chiefalchemist 6y agoAdd to the list of preventative measures: - Establish a Twitter account for anything dev ops related. Don't assume you'll have the ability to communicate via your internal infrastructure. It also helps customers to know there is a 3rd party medium for staying informed and getting in touch. Knowing that such things exist, while minor, is good marketing fodder as well. It walks the comms are important talk.
- joseph_grobbles 6y agoA bit of deception on how their site ended up on the block list. They strangely block out a part of their response, but we can see "was cleared", which sounds a lot like "the malware some nefarious agent put on my site was removed". How sites end up on the block list- -they host malware, either intentionally or because they were hacked. -they host a phishing site, either intentionally or because they were hacked. Protecting users is a monumentally more critical task than your concerns. And this system is incredibly valuable. When I get a text to a phishing site, I immediately report it to the safe browsing list. I also notify the nameserver, the hosting agent, and if applicable the SSL cert provider. Bit.ly if in the chain, though they never do anything [fun fact, even -- phishers and malware authors love putting bit.ly in the chain because they're paying subscribers, and as domains are taken down they can just change the destination. Bit.ly exists on the backs of scumbags, and itself should be on the safe browsing exclusion list] Usually the safe browsing list addition happens within an hour, saving many people from being exploited. The nameserver and host -- DAYS. Namecheap takes an eternity to do anything, even for outrageously blatant phishing sites. GoDaddy - an eternity. SSL providers seem to act quickly, but propagation delays makes that negligible. EDIT: 11 days ago I reported the scn- prefixed netflix.com to all of the above. This is a blatant phishing site, and was mass texted to Canadians. It was blacklisted by safe browsing within an hour, likely saving a lot of people grief. Namecheap, who I informed by their email and by their garbage ticket system, still host the nameserver and physical hosting for this site. 11 days later. Grossly negligent behavior, and there needs to be some window of responsiveness because these players are just grotesque at this point.
- gomox 6y agoAuthor here. I blocked the message in the screenshot because I narrated the first incident, but took screenshots during the second one, so the redacted part was referencing the first one in which, as described, our domain was cleared without actually doing anything. Protecting end users from nothing at all (like I said, there is no offending URL) is not more important than making sure Google doesn't literally gatekeep the entire Internet, IMO.
- joseph_grobbles 6y ago
- tomaszs 6y agoIt is quite good Google cares about users. But it does not care about website owners. There is one and only reason. For Google WWW is a competition for Google Play marketplace. Literally open internet is a competition for Google. That is why the company has no problem to issue domain wide ban, without informing website owner, without any explanation and with showing a scary message to website users to make them go away. Author of the blog post seems to believe it is an AI action. But what I can see his company was hit with some serious damage due to a company that, I assume, has some competing apps on its Google Play platform. I can believe AI can be the cause, but it should be a court to decide if there is no collusion and who should pay for the damage.
- vaduz 6y agoIt's a relatively long article - but it does not answer one simple question, which is quite important when discussing this: were there any malicious files hosted on that semi-random Cloudfront URL? I realise that Google did not provide help identifying it - but that does not mean one should simply recomission the server under a new domain and continue as if nothing has happened! From TFA: > We quickly realized an Amazon Cloudfront CDN URL that we used to serve static assets (CSS, Javascript and other media) had been flagged and this was causing our entire application to fail for the customer instances that were using that particular CDN > Around an hour later, and before we had finished moving customers out of that CDN, our site was cleared from the GSB database. I received an automated email confirming that the review had been successful around 2 hours after that fact. No clarification was given about what caused the problem in the first place. Yes, yes, Google Safe Browsing can use its power to wipe you off the internet, and when it encounters a positive hit (false or true!) it does so quite broadly, but that is also exactly what is expected for a solution like that to work - and it will do it again if the same files are hosted under a new URL as soon as detects the problem again.
- deleted 6y ago[deleted]
- irae 6y agoI am just guessing here, but in case the author had their service compromised, maybe he can't disclose the information. Feels like they know what they are doing, and at least to me, reading between the lines, it looks like they fixed their problem and they advice people to fix it too: > If your site has actually been hacked, fix the issue (i.e. delete offending content or hacked pages) and then request a security review.
- gomox 6y agoAuthor here. We didn't do anything other than request the flag to be reviewed. The recommended steps for dealing with the issue listed in the article were not what we used, just a suggested process that I came up with when putting the article together. Clearly, if the report you receive from Google Search Console is correct and actually contains malware URLs, the correct way to deal with the situation is to fix the issue before submitting it for review.
- ballenf 6y agoIt seems like the FTC should be running this for US based customers and browsers should default to a local resource and/or let users override the default source of truth.
- sdenton4 6y agoCool, then we can complain about false positives at the FTC instead of at Google! IMHO, it doesn't really matter who runs it, so long as they're not actively working in bad faith. False positives are a fact of life, garaunteed so long as we have an adversarial malware ecosystem. (For example, the fixes for bad decisions are pretty much indistinguishable from bad actors evading correct decisions.) The other side of the coin is a web that looks like my missed calls list - everything is assumed to be spam and malware infested until proven otherwise. No one will use your startup anyway, because any given site is probably terrible. The whitelist becomes a thing that people maintain in their heads, and, again, you get a massive incumbent advantage. The right balance is somewhere in-between, and involves fine tuning the false positive rate. The false positives are always going to be unhappy, and hard to tell apart from true positives trying to keep their scam going.
- dharmab 6y agoIts not just startups. I work at a major company and we’ve had internal domains flagged in the past due to internal security testing. We resolved it by making some calls to people at Google because the Safe Browsing dashboard is so slow to fix things. This is especially troublesome if you allow customers to upload code to run on your systems (e.g. Javascript for webpages or interactive data analytics) You have to isolate every customer on separate domains.
- yuriko_boyko 6y agoBut you can smother the damage; startups can't.
- scott00 6y agoDo you need a real domain for each customer or is a subdomain sufficient isolation?
- mr_toad 6y ago> You have to isolate every customer on separate domains. Allowing unvetted JavaScript to be served from your main domain is something of a security risk anyway.
- phreack 6y agoThere's an effective monopoly on web browsing, and then any private decision here becomes de facto censorship. How can this be constitutional, ants need to rise and get some rulings down on this topic, the web needs to be brought back to how it was.
- cozzyd 6y agoroot.cern was affected by this in the fall, apparently due to a false positive in the windows installer. It was resolved relatively quickly (a day or so?) but hugely inconvenient for e.g. documentation, and of course the particle physics community has connections. root.cern.ch worked but the internal links were all over the place.
- BlueTemplar 6y agoBTW, did using another giant's (Amazon) services (like Cloudflare) made the problem better or worse?
- lrem 6y agoIsn't this way to get hurt by a Google's bot a brand new discovery as of 2008 or so? And the bottom line of "letting users upload things is dangerous" is no newer?
- deleted 6y ago[deleted]
- justaguy88 6y agoThis is really terrible, I sure hope the EU causes a stink about this
- yuriko_boyko 6y agoGoogle:Don't be evil. Yes, don't be evil but opaque and inconsiderate. It's amazing how a company as profitable as Google has such a horrible customer service.
- alacombe 6y ago"Don't be evil" - It's been forgotten about a long time ago. https://en.wikipedia.org/wiki/Don%27t_be_evil https://en.wikipedia.org/wiki/Don%27t_be_evil
- nautilus12 6y agoWhy can't companies like google just have a warning and review period before taking actions like this?
- gomox 6y agoThey don't even validate that blacklist entries actually contain an offending URL in the report. That's how much they care.
- _Microft 6y agoReviews would have to be done by humans and humans doing things themselves is bad for the bottom line.
- kayodelycaon 6y agoGoogle doesn’t need to do it, so they won’t spend the effort to do it.
- acheron 6y ago“We don’t care, we don’t have to.”
- xenocratus 6y agoI have no extra knowledge on the subject, but if the flagged website was indeed serving malicious content, the brakes would have to come down pretty hard. If you have a review period you can end up serving malware to hundreds/thousands of people. Don't know how often this happens, though, and what the false positive rate is, it'd be interesting to see.
- spaetzleesser 6y agoThat would probably cut a lot into their profits. Automating these tasks even if some people get cancelled wrongly is way cheaper than hiring people for reviews. Hey are so big that losing a few customers doesn’t mean much to them. I am waiting for the day when this happens to a large company. My company has more and more stuff on AWS. If Amazon cuts us off by accident the damage will quickly go into the billions.
- 6y ago
- CPLX 6y agoMaybe there should be a law that any business that has over ten billion dollars in annual revenues has to answer the phone when you call them and have a reasonable resolution process for complaints. If that ruins your business model, cool. Just spin off parts of the business until each one is back under ten billion in revenue and do whatever you want.
- spaetzleesser 6y agoThat’s not a bad idea. In general I am believing more and more that businesses that exceed a certain size are harmful for the overall economy. They may be more efficient and generate lower customer prices but they also harm innovation and prevent smaller companies from succeeding.
- cyral 6y agoIdeally, we would be able to choose the best company, such as the one that does answer their phones. In this case we can't, which is the real problem.
- sircastor 6y agoI’ve being increasingly wary of Google’s offerings altogether. Their ban hammer seems to be driven by Mr Magoo, who looks at everything and sees threats, and makes judgements.
- p2t2p 6y agoEventually, Google will get to the point when regulators will come to gut it and the crowd will be cheering
- amelius 6y agoBut, left with fewer resources, Google's security might become like the security of smaller companies, and the crowd will be crying.
- hirundo 6y agoIs there any reason that Google couldn't, or wouldn't, repurpose Google Safe Browsing to blacklist sites that are "unsafe" due to under- or poorly moderated content? E.g. doing this to Parler after they find hosting again? I can't think of a reliable one.
- TazeTSchnitzel 6y agoThere's a very obvious reason not to do that: if you apparently maliciously cry wolf a few times, people won't trust your cries any more, and, for example, other browsers might choose to stop using the Google Safe Browsing list.
- heipei 6y agoSo what would they use instead? It's not like there are any other free, real-time and mostly accurate malicious-URL databases around for people to plug into their browsers and products.
- TazeTSchnitzel 6y agoPerhaps “comes the hour, comes the man” would apply? It's a difficult problem, but if there was an urgent need for a solution, I'm sure one could be found.
- the8472 6y agoNothing at all. Many people survive exposure to the internet without being protected by corporate firewalls, think-of-the-children filters and antivirus. Or do we expect UK citizens to curl up in fetal position and start screaming as soon as they leave their country because they're no longer protected by their ISP filters?
- heipei 6y agoAs someone who tracks phishing pages I would disagree. The amount of really high-quality fast flux phishing put out every day on completely legitimate-looking domains is astonishing. I know plenty of people who would immediately fall for it, and I wouldn't blame them one bit.
- sethherr 6y agoI think another take away from this article is “don’t allow users to upload malicious files that you then host from your domain” This seems easier to do than jumping domains.
- gomox 6y agoAuthor here. That is definitely a good idea, and I recommend it. But that should not be the main takeaway. In our particular case, that was not found to be the problem (we think it was some sort of false positive), and there are valid reasons for users to do that anyway (upload a phishing email attachment onto an IT support ticket, for example).
- marricks 6y agoPretty sure the main point was a private company can effectively delist you from the internet without any rhyme or reason. Most of us have heard Google horror stories when you use their products the fact you can be free of them and have any new customers bounce from your sight in terror is uh, terrifying. I would like to emphasize of course they have good stated reasons for warning users before accessing websites. The issue is that they are a private company whose behavior affects all major browsers and (for kicks) they have an extremely opaque review process. If you ran a "divest from Big Tech" website which started gaining steam they could delist like this and the only real force stopping them is public backlash. If you think you can effectively sue Google to stop them I have a bridge to sell you.
- jdsalaro 6y ago> I think another take away from this article is “don’t allow users to upload malicious files to your domain” I disagree, at which point did we all accept Google's role as defacto regulator and arbiter of the Internet? Why should we tacitly accept the constraints they deem as appropriate and modify the way we build the web? In other words, those are our domains, our apps, our systems and we'll do as we please; that includes worrying about content moderation, or not. When and why did we accept google as the Internet's babysitter? Apologies if this sounds aggressive, but your takeaway reflects an appalling and quite fatalistic mindset; one which I sadly believe is increasingly common: big corporations knows best, big corporations say and we do, big corporations lead the way. On the other hand, probably I'm just biased and tired considering how tiresome it's been to explain to my friends and family why Signal is the better alternative after the WhatsApp/Facebook fiasco. /EndRant
- possiblelion 6y agoThe section about ants and Google shifting on its planetary chair is perhaps the best part of this article. A sobering way to look at it.
- bikamonki 6y agoAre there any no win, no fee law firms that specialize in these cases? What if for every hour offline, your SAAS loses X money? For this particular case, what if due to the service disruption, some customers decide to move their business elsewhere? Enforce an SLA?
- gomox 6y agoAuthor here. That was exactly our situation with the impacted systems. We got lucky with the fast "review" and it happened late enough in the day that only PST customers were impacted meaningully. But still, quite frightening, hence the post. It's not a failure mode we had in mind when we established the SLAs.
- exabrial 6y agoWe seriously need to break up Google. This is a chokepoint for innovation, should not be controlled by one company, and has serious downstream consequences on economic growth as a nation.
- xwdv 6y agoImagine a future where multiple big tech companies share “blacklists” of individuals and applications that should be banned across their networks. Your entire business and digital life could be snuffed out in an instant. Already seen it happen, now it just has to scale.
- freedomben 6y agoAfter years of seeing developments like this, getting worse and worse, it fills me with rage to think about how clearly nobody in power at Google cares. I naively used to think, "they probably don't realize what's happening and will fix it." I always try to give benefit of the doubt, especially having been on the other side so many times and seeing how 9 times out of 10 it's not malice, just incompetence, apathy, or hard priority choices based on economic constraints (the latter not likely a problem Google has though). At this point however, I still don't think it's outright malice, but the doubling down on these horrific practices (algorithmically and opaquely destroying people) is so egregious that it doesn't really matter. As far as I'm concerned, Google is to be considered a hostile actor. It's not possible to do business on the internet in any way without running into them, so "de-Googling" isn't an option. Instead, I am going to personally (and advise my clients as well) to: Consider Google as a malicious actor/threat in the InfoSec threat modeling that you do. Actively have a mitigation strategy in place to minimize damage to your company should you become the target of their attack. As with most security planning/analyzing/mitigation, you have to balance the concerns of the CIA Triad. You can't just refuse Google altogether these days, but do NOT treat them as a friend or ally of your business, because they are most assuredly NOT. I'm also considering AWS and Digital Ocean more in the same vein, although that's off topic on this thread. (I use Linode now as their support is great and they don't just drop ban hammers and leave you scrambling to figure out what happened). Edit: Just to clarify (based on confusion in comments below), I am not saying Google is acting with malice (I don't believe they are personally). I am just suggesting you treat it as such for purposes of threat modeling your business/application.
- rossjudson 6y agoFollowing "Consider Google as a malicious actor/threat" with "I am not saying Google is acting with malice" is probably a strong indicator that you should have thought it through before posting it.
- gilrain 6y ago"Consider as" does not mean "is". Your lack of reading comprehension is not the fault of the poster.
- ptero 6y agoThis is not new; such things happened many times in the past (25 years ago Microsoft was the behemoth trampling small companies) and will happen again. I do not think Google is doing it consciously -- this is probably just collateral damage from some bot or rule. The way to handle it is to reduce dependencies on the cloud. This does not mean cutting cloud services altogether, but once the company is big enough (and the author talks about 1000s SMEs and millions of users), plan for graceful degradation with a fallback to a different provider and another fallback to owned servers. This takes work and reduces capability during the crunch, but it is often a lot easier and cheaper than people think if planned properly and not in a shotgun style of crisis engineering. My 2c.
- gomox 6y agoAuthor here. The scary bit is that the blacklist is enforced client side in Chrome and other programs. Our servers and systems were running just fine when this happened, but if Google Chrome refuses to open your website, you're still down. The closest parallel I can think of are expired SSL certificates, but the level of transparency and decentralization of that system vs. this opaque blacklist is not really on the same league.
- imhoguy 6y agoSome derisking solution may be wrapping your web app as native client. E.g. Electron app is Chrome technically but you get more control over its settings. I know Microsoft (SmartScreen) and Apple may block apps for many reasons too but at least you get more baskets for your eggs.
- anovikov 6y agoYeah i read stories that Yahoo in 1990s called itself a media company and it's product managers "producers" out of fear that once you call yourself a software company - Microsoft will crush you... As for using clouds - there is absolutely no point in the world to use them for anything above staging level, or very very low level launches. People should switch away from cloud as soon as they see even tentative signs of a product-market fit.
- mikesabbagh 6y agoBeing completely blacklisted is very bad, but u know at least that something needs fixing. Imagine if google partially punishes u and downrank you in the search for no reason. This is harder to figure out. It took us several months to discover such a problem until finally we registered to google websmaster tool.
- markyc 6y agowhat was the problem?
- skeletal88 6y agoWhat are you talking about? The article said that they didn't change anything, because they found nothing wrong with the site. The ban from google was totally random without any explanation. And it went away without any changes or explanations about what was wrong.
- heybrendan 6y agoCan anyone "in the know" objectively comment if Google Safe Browsing (GSB) has had a net positive result or outcome for the Internet, at large? Has GSB helped users, more than it has hurt them? The anti-Google rhetoric [on HN] is becoming more tiresome as of late. Personally, I welcome the notifications in my browsers that a domain is unsafe. I can't possibly be the only one.
- z3t4 6y agoIt's hard to argue against "safe". If they would name it "filtered browsing" it might be something arguable, but "safe browsing" who wouldn't want that?
- heipei 6y agoI think GSB is great because there is no other product like it, it is very fast to respond to most threats and it can be used for free. The only thing about it that's not great is, in typical fashion, the lack of transparency about some of the processes. Not about how phishing verdicts are created, this should remain a closely guarded secret, but about what actually happens when you send a report or send a review request.
- gomox 6y agoAuthor here. It's not really rhetoric, I wrote the post because it's downright scary that your business of over 10 years can vanish in a puff of smoke because Google didn't bother to require an offending URL field in an internet-wide blacklist. At the level they operate, there needs to be a semblance of due process.
- heybrendan 6y agoUpdated my post to make it more clear I was referring to HN and not your post specifically.
- lrossi 6y agoWhat about false positives? From the fine article: one Google system was detecting emails coming from another Google system as phishing. This is ridiculous.
- fortran77 6y agoThe story he links to, about the "Online Slang Dictionary" being removed from google search because the founder of Urban Dictionary was friends with googlers (true) and (allegedly) used his influence is fascinating: http://onlineslangdictionary.com/pages/google-panda-penalty/ http://onlineslangdictionary.com/pages/google-panda-penalty/
- DanBC 6y agoYou may want to read these posts: https://news.ycombinator.com/item?id=9977372 https://news.ycombinator.com/item?id=9977372 https://news.ycombinator.com/item?id=5419890 https://news.ycombinator.com/item?id=5419890 And this too: https://news.ycombinator.com/item?id=24109168 https://news.ycombinator.com/item?id=24109168
- WalterGR 6y agoMy plans to trickle out details of my conversation with the Google employee were put on hold due to a massive change in my life responsibilities due to the novel coronavirus, but it’s my intention to resume soon. As I say on the website, this will culminate in my releasing the MBOX formatted file of the conversation, with full headers.
- heipei 6y agoYes, the power of something like Google Safe Browsing is scary, especially if you consider the many many downstream consumers who might have an even worse update / response time. Responsiveness by Google is not great, as expected, we recently contacted Google to get access to the paid WebRisk API and haven't heard anything in a few months... However, phishing detection and blocking is not a fun game to be in. You can't work with warning periods or anything like that, phishing websites are stood up and immediately active, so you have to act within minutes to block them for your users. Legitimate websites are often compromised to serve phishing / malicious content in subdirectories, including very high-level domains like governments. Reliable phishing detection is hard, automatically detecting when something has been cleaned up is even harder. Having said all that, a company like Google with all of its user telemetry should have a better chance at semi-automatically preventing high-profile false positives by creating an internal review feed of things that were recently blocked but warrant a second look (like in this case). It should be possible while still allowing the automated blocking verdicts to be propagated immediately. Google Safe Browsing is an opaque product / team, and its importance to Google was perhaps represented by the fact that Safe Browsing was inactive on Android for more than a year and nobody at Google noticed: https://www.zdnet.com/article/mobile-chrome-safari-and-firefox-failed-to-show-phishing-warnings-for-more-than-a-year/ https://www.zdnet.com/article/mobile-chrome-safari-and-firef... Lastly, as a business owner, it comes down to this: Always have a plan B and C. Register as many domains of your brandname as you can (for web, email, whatever other purpose), split things up to limit blast radius (e.g. employee emails not on your corporate domain maybe, API on subdomain, user-generated content on a completely separate domain) and don't use external services (CDN) so you can stay in control.
- deleted 6y ago[deleted]
- lrossi 6y ago> I received an automated email confirming that the review had been successful around 2 hours after that fact. No clarification was given about what caused the problem in the first place. ... We never properly established the cause of the issue, but we chalked it up to some AI tripping on acid at Google's HQ. I expect more of this Kafkaesque experience to come in the future. This is no longer a technical problem, but a social one. It can only be solved through legislation.
- gomox 6y agoAuthor here. The second time around, the review confirmation email took around 12 hours to get to us.
- lrossi 6y agoThank you for posting all the info here. And I’m glad that you managed to fix the problem. I think it must have caused you a lot of stress.
- gomox 6y agoYes, this was a massive headache and we got very lucky with the timing of the incident and the blast radius of the system in question. I can't really say the issue is fixed so much as it is mitigated, hence the writeup to gain some awareness. Some of the other comments have valuable anecdotes too.
- hoppla 6y agoGreat, so legitimate businesses need to implement tactics commonly used by c2c and malware to operate successfully
- gremlinsinc 6y agoI wonder if a blockchain/bittorrent decentralized option could exist to replace google. most people don't have billions lying around to compete, but you could reward people who rented out space for the indexing data, and have advertisements baked in that could maybe still use some retargeting but without tracking any personally identifiable data about a person. Nodes could double as ai/cpu processing for algorithms related to search and storage. Computation and storage amounts could have their own payout per action, or per time on storage. Most people have their computers on all the time anyways, so if they're working in the background for them to earn some side income, while helping create a better internet. Would need some centralization I'd imagine though, I think the problem with de-centralization is the goal is ALL or nothing. Like one or two big servers that maybe tie everything to the rest, and push 'updates' on algorithms, contracts,etc... to end users. Maybe a segregation index, knowing all airplane related searches are indexed on cluster c which has nodes 1-8, so you know where to go to get the info being searched. I'm a mainly full-stack but 'dumb' developer, not an algorithms wiz, mostly focused on crud apps. But this would be fun to build.
- ed25519FUUU 6y agoWait until this is also applied to a list of domains from the SPLC and other groups to further censor “hate speech” on the internet.
- Pulcinella 6y agoI wonder if it would be faster to deal with this through legal. I’m not a lawyer, but I wonder if you could send a C&D to Google legal or something because this seems like an actual case of slander and reputation damage.
- dharmab 6y agoIf you are a big enough company your lawyers could have a stern but relatively friendly chat with Google’s lawyers. I can neither confirm or deny this myself...
- Pulcinella 6y agoYeah my thought behind this was you are a large enough or wealthy enough company that you can afford lawyers. If you are an individual or mom and pop business whose blog or small e-commerce shop are blocked then you are probably SOL.
- gomox 6y agoIf your systems have any number of nines in their SLA, drafting a letter to Google's legal department is not a viable strategy.
- freedomben 6y agoTo any lawyers or even well-read armchair legal analysts, could this be a case of libel?
- laurent92 6y agoOnce you enter litigation with Google, good luck accessing your Android. You may believe this is extreme, but many people have had their Gmail account suspended without known reason. So if they also have a reason...
- xg15 6y agoSo de-google first, then sue. Otherwise you might as well give up and conclude that google not just controls the internet but is also above the law.
- veesahni 6y agoOur company [0] was also hit by this too. We receive email for our customers and a portion of that is spam (given the nature of email). Google decided out of the blue to mark our attachment S3 bucket as dangerous, because of one malicious file. What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. To mitigate, we now operate a number of proxies in front of the bucket, so we can quickly replace any that get marked as dangerous. We also now programmatically monitor presence of our domains in Google's "dangerous site" database (they have APIs for this). 0: https://www.enchant.com https://www.enchant.com - software for better customer service
- gomox 6y agoAuthor here. I'm not sure exactly how they actually decide to flag. Alternatively, Amazon might somehow be reporting files in S3 onto the Google blacklist. It would seem surprising, but it's the other possibility.
- judge2020 6y ago> What's most interesting is that the bucket is private, so the only way they could identify that there is something malicious at a URL is if someone downloads it using Chrome. I'm assuming they make this decision based on some database of checksums. Doesn't Chrome upload everything downloaded to VirusTotal (a Google product)?
- deleted 6y ago[deleted]
- londons_explore 6y agoThe hashes of all things that match a "probably evil" bloom filter, yes. Hosting a virus on a domain and then downloading it a few times with different chrome installations sounds like a good way to get the whole domain blacklisted...
- 6y ago
- dgudkov 6y agoOne corporation must not have so much power over billions of citizens of many countries. A power like that must only come from a transparent non-profit organization with a publicly elected management board. We will get to that point sooner or later. But the road there will be long and painful.
- KronisLV 6y ago> We will get to that point sooner or later. Is there anything in particular that makes you believe that it'll eventually happen? Because personally my outlook on things is a bit more pessimistic - oftentimes the main concerns of individuals and organizations alike are financially-oriented and few share the enthusiasm for transparency and openness like Richard Stallman does. The trend of SaaSS ( https://www.gnu.org/philosophy/who-does-that-server-really-serve.html https://www.gnu.org/philosophy/who-does-that-server-really-s... ) because of companies not wanting to invest time in engineering their own solutions or even using FOSS, alongside with how many of them are handling GDPR and even cookie compliance, with the use of UX "dark paths" (e.g. it being easier to accept advertising cookies rather than deny them) doesn't let me keep a positive outlook on things. It feels like we'll all be reliant on the "tech giants" for a variety of things for the decades to come, even "de-Googling" oneself not always being feasible.
- dgudkov 6y ago>Is there anything in particular that makes you believe that it'll eventually happen? Humans have demonstrated the ability to eventually improve social systems to make them account for the needs and demands of the majority of stakeholders. In the offline world it has evolved into what is known as democracy. It started several centuries ago and eventually evolved into modern governments as we know it - publicly elected management boards. Recently, there was an excellent article [1] on HN. It rightfully compared the current state of internet to the feudal times and warlords common in the offline world many centuries ago. From that point through a long and painful process we've come to elected governments as the most sustainable form of governing a large number of humans. All other forms of government turned out to be unsustainable (no matter how attractive they were to certain individuals or organizations) and inevitably led to all kinds of social catastrophes. I believe, the same will eventually happen to the internet, our new brave world we used to love, but now seem to become increasingly disenchanted with. [1] https://locusmag.com/2021/01/cory-doctorow-neofeudalism-and-the-digital-manor/ https://locusmag.com/2021/01/cory-doctorow-neofeudalism-and-...
- sfg 6y agoIf their claim is false, then is it, in any jurisdiction, libelous? Maybe, legislation to bring consequences for false claims will help ensure algorithms, and the support teams that monitor them, do a better job. In an internet focused world, especially one with lock downs, wiping sites off of the internet with false claims is a heinously bad act.
- asien 6y agoAs of today there are no legal protection framework for digital services. Banking is heavily regulated , you are protected by hundreds if not thousands of laws. For digital services ? Twitter and Google can legitimately suspend ALL your accounts because you liked a Trump video on YouTube or Tweeted something « Hateful » to Biden. You can try to go court. You will loose 100% of the time. They are private businesses operating within their own terms, there is not « false » flag or wrong « ban » They’re private businesses offering a free service, they can cease to offer that at any moment that they want.
- Isinlor 6y agoIn this case they do not provide a service to the OP. There is no agreement between OP and Google. This is happening on browsers of their customers. And I'm quite sure that if Google hits a company that competes with Google services there must be a law that they will be breaking. There was a big case in Poland where Google blocked a SaaS web shop provider using the same exact mechanism [0]. Polish courts decided that Google claims displayed on block page were untrue. Unfortunately, the suing company did not receive compensation, because Google Poland does not operate Chrome browser. The court indicated that the right party to sue is Google incorporated in USA... [0] https://www.silesiasem.pl/iai-przegralo-proces-sadowy-z-google-poland https://www.silesiasem.pl/iai-przegralo-proces-sadowy-z-goog...
- asien 6y agoAside from abusive dominent position there is no law they would break. When you download and use chrome you ACCEPT the Terms and Conditions of Google. There is no law that prevents a web browser from blocking access to a website or modifying the page . If the TOS stipulate « pages may differ from the original or be subject to third party software » , they are in within their rights and the customer accepted it when he started using the product. Don’t get me wrong. I’m on OP sides and everything , but we have let big tech become too big by giving us free stuff for decades. Now they they decide what’s good for us or not with side effects that often damage small business. But I insist that in 99% , they operate within the law.
- mcguire 6y agoOf particular note: "Don't host any customer generated data in your main domains. A lot of the cases of blacklisting that I found while researching this issue were caused by SaaS customers unknowingly uploading malicious files onto servers. Those files are harmless to the systems themselves, but their very existence can cause the whole domain to be blacklisted. Anything that your users upload onto your apps should be hosted outside your main domains. For example: use companyusercontent.com to store files uploaded by customers."
- psyc 6y agoPardon my ignorance as I have few years of web dev experience. What exactly does it mean to store data on a domain? Does he mean serve data via a domain URL? And if so, how does Google have discovery of that data?
- mirthflat83 6y agoHow would you even “store” data on a domain?
- dharmab 6y agoLook up how DoH and ECH store public keys in the DNS system :) Not what the author intended but DNS as a Database is a thing.
- mirthflat83 6y agoAh yes, customer generated data sounds just like public keys
- dharmab 6y agoWe’re pretty sure they get reports from Chrome. A security researcher at my workplace was running an exploit against a dev instance as part of their secops role and got the domain flagged, despite the site being an isolated and firewalled instance not accessible to the internet.
- baxtr 6y ago> Proactively claim ownership of all your production domains in Google Search Console. That's one of the first things you should do, when registering a domain and setting up a website. It takes about 2 minutes. So I wonder a bit why a business of this size would learn doing this through such a crisis.
- gomox 6y agoAuthor here. The impacted domain was a Cloudfront CDN subdomain with random characters in it, not company.com (thankfully!). I doubt anyone signs up for Search Console on that type of domain that they don't even really own.
- lmarcos 6y agoThis is sad. When you open a business in the real world, sure you have to tell the authorities about it (because it's the law!). When you open a digital business, you have to tell Google (via Google Search Console) about it... But Google is not the law, not even an authority; it just happens that Google owns google.com and Chrome and that makes Google the de facto Godfather of the internet: if you don't comply, your business is practically dead. Again, sad.
- stingraycharles 6y ago“Don't host any customer generated data in your main domains. ” This is extremely important for multiple reasons. One reason is the blacklisting as mentioned in the article, the other reason is security: browser typically implement security policies around domains as well, such as cookie scoping and whatnot. Putting all user generated content under a completely separate domain avoids a whole category of potential issues.
- jefftk 6y agoFor example, if someone manages to upload HTML and trick your system into serving it with a content type that browsers will interpret as HTML, then they can modify or exfiltrate your user's cookies. This could allow impersonation attacks, XSS, etc. (Disclosure: I work for Google, speaking only for myself)
- CodeWriter23 6y agoAvoids the issue until your ugcweb.com is blacklisted and users who uploaded clean ugc are blocked from the portal.
- Marazan 6y agoYou upload action is hosted on a different domain from the domain that serves the content.
- londons_explore 6y agoYes, but when Google blocks either domain, your webapp will still be broken...
- mattmanser 6y agoAnd in 10 minutes you grab a new domain and it's back up. You change the config setting in your app to use the new domain and, boom, done. That's the point, it's a sacrificial domain. If you lose it you don't care, it's not your brand.
- woeirua 6y agoThis is an area where regulatory action should be taken against Google. Google needs to implement a process with manual review in a reasonable timeframe, or they should be broken up for having monopolistic power over which sites are on the internet.
- erwinh 6y agoposted on medium which decided to paywall after years of being publicly available.
- gomox 6y agoAuthor here - I haven't signed up for Medium's "pay the author" thing, which I think should make my content free to read and paywall free, is that not the case for you?
- knowhy 6y agoCan Google be held legally accountable for this behavior? Seems like they are hurting businesses by spreading false information. With their market power there need to be some incentive for them to react quicker and with human oversight.
- judge2020 6y agoIf the business wants to argue that, they can sue Google for defamation/libel.
- EVa5I7bHFq9mnYK 6y agoDoesn't Safe Browsing require every URL you visit to be sent to G$$gle first? I know Chrome users "have nothing to hide", but this looks like complete surrender.
- judge2020 6y agoChrome automatically reports URLs and some page content to Google if "Help improve security on the web for everyone" is enabled. This is not enabled by default, even if 'help make Chrome better' is checked before install. https://i.judge.sh/discrete/Rumble/WindowsSandboxClient_w4Ta4Dz4kv.png https://i.judge.sh/discrete/Rumble/WindowsSandboxClient_w4Ta...
- gomox 6y agoThere is the expected privacy-surrendering API in which you send all your URLs to Google, and a more defensible one in which you download some sort of database to then query locally: https://developers.google.com/safe-browsing/v4 https://developers.google.com/safe-browsing/v4
- remus 6y agoI don't know what the implementation actually looks like in chrome, but it could work on a blacklist that's stored locally and updated on a regular basis.
- adamkf 6y agoNo, it does local checks first, then only checks the full URL if there's a high probability of a match: https://www.chromium.org/developers/design-documents/safebrowsing https://www.chromium.org/developers/design-documents/safebro...
- tester756 6y agowhy would it? chrome can just load $black_list from time to time and just perform local check
- nathias 6y agoThis happens when the ticket for braking anti-monopoly laws is magnitudes cheaper than the profit you rake in breaking it.
- badwolf 6y agoone of my apps my company makes is a chat app, when someone clicks a link in chat, we bounce them to a URL redirect page ("Warning, you're leaving $app, don't enter your account password/information phishing warning" type page) with a button "Continue to $url" - We also have a domain blocklist to block known phishing sites for our app. Because of this, Google blocked our entire domain due to malicious urls (the "This link was blocked" page) It took us weeks to get it unblocked. Just an utter pain in the butt. We're an established business, but having our entire website blocked by Chrome for weeks nearly killed the entire app.
- loopdoend 6y agoYep this happened to me too and I came to exactly the same conclusions. We have a list of completely separate “API domains” that our scripts talk to and which also host the cloudfront CDN. We also cohort our customers by Sift score and keep trusted enterprise customers away from endpoints given to new signups. This way if someone new does something sketchy to get you flagged it won’t affect your core paying customers.
- kyledrake 6y agoI run https://neocities.org https://neocities.org, and safe browsing has been my nightmare overlord for a long time. No way to manage reports via an API, no way to contact support. I haven't even been able to find a suggestions box, even that would be an upgrade here. Digging to find "the wizard" gets you into some official google "community support" forum where you learn the forum is actually run by a non-employee lawful neutral that was brainwashed somehow into doing free work for one of the wealthiest companies in the world. A lot of the reports are false and I have no idea how they are added (this would be an excellent way to attack a web site btw). Google will sometimes randomly decide that every link to our over 350,000 neocities sites is "malicious" and tell every gmail user in a pop-up that it is dangerous to go to a neocities site. Users are partitioned to a subdomain but occasionally google will put the warning on the entire domain. It's not clear if it's even the same thing as safe browsing or something completely different, and this one doesn't have a "console" at all so I have no idea how to even begin to deal with it. When users complain, I tell them I can't do anything and to "contact google", which I'm sure just leads them to the same community support volunteer. We actively run anti spam and phishing mechanisms, have a cleaner track record on this than google themselves with their (pretty neglected) site hosting, and because we block uploads of executable files, it is literally impossible for users to host malware on our servers. It is also impossible to POST form data on our servers because it's just static html. None of that matters. Occasionally we also just get randomly, completely soft-blacklisted by safe browsing for no reason (they call this a "manual action", there's never any useful information provided, I have no idea what they imply and I live in fear of them). If things ever got extremely horrible, I used to have a friend that worked at google but she no longer works there (I hated using her for this). The other person I knew that works at google stopped responding to my tinder messages, so I'm pretty much doomed the next time they do something ultra crazy and I need emergency support. It's extremely frustrating and I'm hoping for the day when something gets better here, or they at least provide some way to actually communicate with them on improving things. In the meanwhile, if anyone happens upon the wizard at a ski resort or something, please have them contact me, I have a lot of improvement ideas. edit: Just to add here from a conversation I had a year ago (https://news.ycombinator.com/item?id=21907911 https://news.ycombinator.com/item?id=21907911), Google still hasn't figured out that the web is their content providers and they need to support them, and treating their producers with contempt and neglect is a glorious example of how shortsighted the entire company is right now about their long term strategy (how many ads will you sell when the web is a mobile Facebook app?). They should as soon as possible, as a bare minimum, start providing representatives and support for the content providers that make people actually use the web and help them to be successful, similar to how Twitch has a partnership program.
- Nacdor 6y agoCould this be the basis for a class action lawsuit?
- tingletech 6y agoisn't the problem here keeping the cloudfront hostname, vs. setting up a CNAME from your own domain to point at the distribution?
- gomox 6y agoNot really, we own the entire Cloudfront subdomain, and Google is wise enough to not ban cloudfront.net entirely (now that would be an interesting day on the internet!). Having a CNAME in front wouldn't have made any difference.
- wazoox 6y ago"...And that's reason number 3955430, ladies and gentlemen, why monopolies are bad and MUST be dismantled."
- throwawayttgg5 6y agoWow. I wonder how lng it will be before the Big Tech oligarchy will start blocking websites for “misinformation”. Insane world we’re heading towards.
- waheoo 6y agoJust sue them for damages. It's libel.
- tpurves 6y agoWell, as long as you are spending 6 or 7 figures a year on advertising with Google, you'll have a account rep at Google that you can always reach out to. Your ad spending level works as Google's filter for which websites on the internet that they actually give any care about not killing.
- gomox 6y agoWe spend a nice buck on Google Ads but the impact of getting your SLA-sensitive SaaS app blocked from the Internet is not compatible with reaching out to "someone who might know someone" at a 100K employee company.
- scarface74 6y agoAm I missing something? Is there ever a reason to expose a CloudFront url to the end user instead of using a custom domain?
- gomox 6y agoIs there a problem with doing it? I don't see how that would have helped in this case (if anything, it might have made things worse if Google decided to ban the 1st level domain, which they certainly won't do for Cloudfront.net).
- scarface74 6y agoIt just seems less professional. It’s much like having a .blogger.com or .substack domain. We have been trained for decades not to trust random domains. To the uninitiated, a CloudFront domain is random. I know I’m taken a little aback anytime I go to Amazon’s credit card site - https://amazon.syf.com/login/ https://amazon.syf.com/login/ it looks like a phishing site.
- gomox 6y agoThis Cloudfront URL is not a customer visible URL, it's just referenced for some static assets (images/JS/CSS). The warning is shown instead of the actual SaaS app that is hosted on a "proper" domain, effectively taking the whole thing down.
- hedora 6y agoSue them for libel.
- genericacct 6y agoI have to add that firefox seems to be using the same logic/data for their safe browsing featureand will happily flag sites as malicious with no human oversight.
- bitL 6y agoI wouldn't be surprised if this was done just in order to associate somebody with something interesting Google sees on the Internet and has no ownership information about so "that they know". Benefit of the doubt is already gone.
- ilaksh 6y agoMy idea, which will be ignored as usual, is that the problem is the monopoly. The reason we have a monopoly is because the web browser is now a full operating system that is so complicated that no group can replicate it. Start over with a new protocol. Make it content-centric, i.e. distributed protocols with no central servers. Support download-limited lightweight markdown sites for information sharing. Then for applications and interactive content, add a canvas-light graphics system to web assembly. Again, I suggest limiting download size to keep things snappy. And make sure not to load any applications automatically or put them in the same process as the markdown browser. If you do it right, you will have a common protocol that is straightforward enough that there can actually be several implementations. And it won't be controlled by one company.
- ThePhysicist 6y agoSo, essentially they let someone host malicious content on their CDN, which led to Google blocking it. I don't see the scandal here. Also, it seems Google fixed the issue within 2 hours, which is quite good TBH. There are many open-source & commercial IOC lists in distribution from vendors like Crowdstrike, Team CYMRU etc., a lot of them are being fed into SIEM systems, firewalls and proxies at companies. If you happen to end up on one of these lists it can take months or years to clear your reputation.
- kevingadd 6y agoIf you're going to comment that they did something wrong, you should consider reading the article and notice that the safe browsing flag didn't mention a URL and the block was removed without any follow-up once they requested the removal.
- howmayiannoyyou 6y agoEasily solved using the anti-trust act. Time to break up Google and perhaps a few others.
- smitop 6y agoSome web hosts use Safe Browsing to automatically perm-ban any sites on the list. I've been banned from Heroku for a couple years at this point because one of my sites got added to Safe Browsing as malware and Heroku's systems just automatically perm-banned me (and to make things worse, in the ban email they tell you to send ban appeals to just bounces).
- anticristi 6y agoThis reminds me of email blacklisting. When I was "young" I operated an email server for 6000 users. Keeping that server and our domain away from blacklisting was a full-time job. It wasn't enough to secure your server: Any spam or virus coming from the internal network through that email server could potentially blacklist us. Basically, you had to treat your users as untrusted, and run anti-spam and anti-virus filtering that was as good as whatever the rest of the Internet was running. IIRC, although blacklisting was done by non-profits, it was still rather opaque: Blacklisting should be traumatizing, so that you (and your higher ups) are forced to do a proper risk assessment and actually implement it. It was also opaque to make it harder for the bad guys to move quickly. I hate the increasing influence that big tech has on small tech. But keeping web and email safe and clean is a cat-and-mouse game, which, unfortunately, also adds burden to the good folks.
- slim 6y agotoday Microsoft is the worse. It blacklists your ip from unsuspecting customers using outlook, live.com, etc.. and there is no way to recover from it without becoming yourself a customer. it's vicious because the users of their products are mostly businesses and they are acting as a gateway for doing business with them.
- anticristi 6y agoDefinitely annoying. But how much is this anti-competitive business practices, and how much is this "raising the bar for the bad folks". Unfortunately, the latter inevitably adds burden to good folks too.
- thayne 6y agoThe mitigations suggested are easier said than done. In particular, domains can't share cookies which means switching domains likely means logging out any users that are logged, and losing any local settings. Likewise splitting your site between different domains makes it much more difficult to share state (such as whether you are logged in) between the sites.
- malthejorgensen 6y agoWe got hit by this as well. Very similar story to this and others shared in this thread: Use an S3 bucket for user uploads - and Google then marks the bucket as unsafe. In our case a user had clicked “Save link as...” on a Google Drive file. This saves an HTML file with the Google login page in some cases (since downloading the file requires you to be logged in). The user then proceeded to upload that HTML file. Then it was automatically marked since it looked like we were phishing the Google login page. It should be noted that Firefox uses the Google banlist as well so switching browsers does not work!
- overflyer 6y agoWe all let it come to this. We are all lazy as f and only care about convenience and short term benefit. That is why we have the big 5 now that basically are too powerful now to turn away from.
- jedberg 6y agoThis is actually funny, because I was involved with the creation of this list, way back in 2004. The whole thing started as a way to stop phishing. I was working at eBay/PayPal at the time, and we were finding a bunch of new phishing sites every day. We would keep a list and try to track down the owners of the (almost always hacked) sites and ask them to take it down. But sometimes it would take weeks or months for the site to get removed, so we looked for a better solution. We got together with the other big companies that were being phished (mostly banks) and formed a working group. One of the things we did was approach the browser vendors and ask them if we could provide them a blacklist of phishing sites, which we already had, would they block those sites at the browser level. For years, they said no, because they were worried about the liability of accidentally blocking something that wasn't a phishing site. So we all agreed to promise that no site would ever be put on the list without human verification and the lawyers did some lawyer magic to shift liability to the company that put a site on the list. And thus, the built in blacklist was born. And it worked well for a while. We would find a site, put it on the list, and then all the browsers would block it. But since then it seems that they have forgotten their fear of liability, as well as their promise that all sites on the list will be reviewed by a human. Now that the feature exists, they have found other uses for it. And that is your slippery slope lesson for today! :)
- yuvalr1 6y agoThis is an amazing story. It really demonstrates the way we pave our road to hell with good intentions... We should really do something about this issue, where so few companies (arguably, a single one) hold so much power over the most fundamental technology of the era.
- ocdtrekkie 6y agoThe solution is simple: Liability. As soon as it becomes legally infeasible to let algorithms block people, it will stop happening. Make it easy and affordable to submit legal complaints for tech misbehavior and make the penalties hurt.
- 6y ago
- michaelmrose 6y agoIf customers using google incurs a tax upon business regardless of whether the business does business voluntarily with google why not work on changing that. Start with a snazzy our service works better in firefox. Eventually offer trivial new features in firefox but not chrome terminating with a small discount for using firefox. Over time small price increases can render the discounted price the same as the current price and effectively you are charging your users for using a vendor which costs you to do business with. Google views chrome as a moat around their business keeping other vendors from cutting them off from the revenue stream that powers their entire business. Attack the moat and you might see movement to make your life easier.
- bencollier49 6y agoIs this not libelous? If the site is neither deceptive nor malware-hosting, and Google are telling people that it is?
- patja 6y agoSeems like a good case for a strict content security policies and self hosting static assets.
- simonw 6y agoMcAfee SiteAdvisor recently started flagging the website for my open source project https://datasette.io/ https://datasette.io/ "slightly risky" due to being a "Technical/Business Forums" and a PUP - "Potentially Unwanted Programs I submitted a review a few weeks ago and I just checked and it's green now, which is a big relief. https://www.siteadvisor.com/sitereport.html?url=datasette.io https://www.siteadvisor.com/sitereport.html?url=datasette.io
- f-word 6y agoIf algorithms they own are operating on a list they maintain and they are making you lose profit, exactly why can you not sue them for that lost profis? What's the legal theory here? A product they own and is entirely disconnected from you is banning you. This is not and should not be OK, nor should you be required to do any special dances and magic gestures to try and mitigate the problem.
- rubyist5eva 6y agoHow long until antivirus and safe browsing start marking websites that are "hate sites" as harmful and start, essentially, censoring the internet?
- makecheck 6y agoBefore even imagining all the ways to start regulating a tech company, I think we desperately need a few basic regulations like: - For every major service offered, company must provide 3 ways to contact live support, two of which must be immediate, e.g. chat, phone, E-mail. [As opposed to today’s “standard” of having none of these!] - Every action that can be taken automatically by an AI must be possible for support staff to immediately reverse.
- soheil 6y agoCan we have an ant army already!
- godmode2019 6y agoCool thread I have archived this on my tidbits feed.
- WalterBright 6y ago> losing access to their GMail accounts and their entire digital life. This is why my email address is @ a domain that I own. Thus, if my hoster goes ventral fin up, I find another hoster. I might lose some time, but I won't lose everything permanently. My mail reader (Thunderbird) is also configured to always download all new email and delete it from the server. Hence I have backups going back 25 years, which has turned out to be valuable many times. One case was when I was reconstructing the timeline for "History of the D Programming Language" I had a solid resource rather than my barnacle-encrusted memory. https://dl.acm.org/doi/abs/10.1145/3386323 https://dl.acm.org/doi/abs/10.1145/3386323
- rlt 6y agoSoon enough this will be used to block other kinds of "unsafe" sites containing dangerous things like "hate speech".
- CountVonGuetzli 6y agoI learned the hard way that other companies than Google also contribute to the blacklist. A site I was working on got falsely flagged by netcraft.com (which they admitted after I spent a week explaining it to them). They do some kind of active AI cyber defence bollocks and have netflix as a customer. Their Automated Idiot classified our login page as trying to phish netflix. The fun part of this is that I could have prevented this if I had seen the warning email that Google sent me, but since Gmail classified it as an email phishing attempt, I never saw it (straight to spam folder). How ironic. Consequences: - Our website was blocked in all major browsers, not just chrome - AWS, who also look at the blacklist and were contacted by netcraft automatically, threatened to delete our account. I had to convince both parties that we did nothing wrong - One week offline
- megous 6y agoAnyone knows what happens if you include resource from a banned domain? Is the resource blocked, or will the user get red screen too?
- djrogers 6y ago> A lot of the cases of blacklisting that I found while researching this issue were caused by SaaS customers unknowingly uploading malicious files onto servers. This is terrifying - what business is it of Google’s what party A uploads to MY servers? And how are they getting that information without dramatically violating the privacy of their users?
- kccqzy 6y agoIf party A uploads something to your servers and the stuff isn't publicly accessible, Google doesn't do anything about it. But if that content is accessible by the public, Google feels a need to protect the public.
- ivanhoe 6y agoCould the re-use of IP addresses be the problem here?
- userbinator 6y agoTeach people how to get past the scary warning one way or another, and spread that knowledge far and wide. With enough false positives their blacklist will be diluted to the point of uselessness and hopefully people will also become better educated in the process. Google will of course do everything in their power to stop that from happening, but every little bit of opposition helps --- from recommending others to not install censorware browsers, to showing them articles like this --- because this is a fight for the freedom for the Internet. As big as Google is, the Internet is far bigger.
- lufeng 6y agoA new method of DDos: send the domain to GSB blacklist!
- saladgnu054 6y agoI'm always surprised by the gall of Google and other companies that decide for others if websites are suspicious. I'm always sure to disable all those garbage warnings, together with email spam "features".
- arriu 6y agoThank you for sharing this. I wonder if having a ton of subdomains might also flag Google to blacklist the parent domain...
- alisausa 6y agoTop burny busty chicks only on this site! Follow the link, and you won’t be sorry! - https://adultlove.life https://adultlove.life
- AviationAtom 6y agoHe talks about Google welding too much power with this. Another example is how their spam filtering can pretty prevent a business from being able to relay emails to any of their customers with a Gmail address. This has led to many people just outsourcing their mail relaying to companies like SendGrid, to lessen the chance of having their emails blocked by Google.
- leowoo91 6y agoI'll tell you a mini story about a coffee shop I visited few days ago. That place was hidden in yelp search when I looked for 'coffee & tea' in my area (their yelp page existed). While I don't know the actual reason why this happened, I immediately discovered that coffee shop using google (as a double check). It gave me a charm because it reminded me a fact that if you have the 'right service', people will find out. Given this flow, I started to believe gatekeepers might begin losing their odds.
- jiggawatts 6y agoStupid question: Isn't this clear-cut grounds for a defamation lawsuit? Also, is it possible to have a class-action defamation lawsuit? The fundamental issue that the author gomox is not stating clearly in his article is that there are no consequences to Google for their actions. None. Literally zero. I don't think the best plan is to wait and hope for a government to step in and take action. Hope is not a strategy. Complaining on public forums has similarly done nothing to curb Google's careless wielding of the ban-hammer. So sue them. Cost them money. Punish them in a material way that they can't ignore. I can't imagine anything else working...
- acvny 6y agoI say it's time we get rid of these monopolies?
- gu5 6y agoThis reminds me of ugliest.app - there was a hn post on it a while ago. And then suprise, suprise, someone made a "paypal" login page which was hosted on the main domain. It was put on the blacklist, not sure if it still is.
- _Gyan_ 6y agoI provide Windows builds of ffmpeg, linked via http://ffmpeg.org/download.html http://ffmpeg.org/download.html. The site is entirely static, no user data is collected or stored. Starting in late October, lasting for around a month, users would get the dreaded red page upon visiting the site at https://www.gyan.dev/ffmpeg/builds/ https://www.gyan.dev/ffmpeg/builds/ Search Console would show a couple of files as 'install malicious or unwanted software'. Never mind that all files are plain archives (7z,ZIP) with no installers or even self-extraction, containing CLI apps. These file URLs when scanned via Virustotal (Google-owned) would be flagged by Google Safe-browsing and no other engine. Weird thing is, the same files mirrored at Github would be detected as clean. A review request at SC would get rid of the warning temporarily only to return after a day or two. I found no support email so I opened a thread at Google Webmaster community (now called Search Central community). But there was no help and none of the regulars seem to be Google employees. Finally, I found an email through Mozilla's page on their use of Google's Safe Browsing blacklists at https://support.mozilla.org/en-US/kb/how-does-phishing-and-malware-protection-work https://support.mozilla.org/en-US/kb/how-does-phishing-and-m... which leads to https://safebrowsing.google.com/safebrowsing/report_error/?tpl=mozilla&hl=en https://safebrowsing.google.com/safebrowsing/report_error/?t.... This page's title is 'Report Incorrect Forgery Alert' which would indicate a different purpose but I managed to get hold of human attention. After 10 days or so, the warnings disappeared. Till date, I don't know what triggered the warnings in the first place, and so how to prevent a recurrence.
- mdekkers 6y agoAs much as I like to give Google a hard time, this isn' really Google's fault. Always use your own URL's for everything. Also, why would you allow customers to upload files and then make them available? Unless you are dropbox or similar, that's bad configuration. This really sounds like "We made some configuration mistakes and now blame Google"
- LockAndLol 6y agoWill anybody here stop using safe browsing though? Or Google products for that matter?
- alisaus1 6y agoTop burny busty chicks only on this site! Follow the link, and you won’t be sorry! - https://adultlove.life https://adultlove.life
- alisaus2 6y agoTop burny busty chicks only on this site! Follow the link, and you won’t be sorry! - https://adultlove.life https://adultlove.life
- Const-me 6y agoFor desktop software, antivirus "industry" can be almost equally destructive. For instance, Avast breaks installers of software made with a specific installation framework: https://github.com/wixtoolset/issues/issues/5593 https://github.com/wixtoolset/issues/issues/5593 The problem lasts for years. At one point I've tried to contact them, but people from Avast were either unable or unwilling to fix their software.
- jgalt212 6y agoFor a SaaS, CDN's are of limited utility as you have many returning visitors who have cached these assets already. Of course, YMMV, but for us, it was easier to host almost all static assets locally.