16 ms·
Thanks HN: Lessons learned after Google nearly killed my site
- dang 6y agoThe previous thread: Help HN: Google just blocked my site as deceptive site - https://news.ycombinator.com/item?id=26326528 https://news.ycombinator.com/item?id=26326528 - March 2021 (20 comments)
- hertzrat 6y agoI made a Wordpress site last year to start blogging that had this happen. The only reason I found out in this case was from visiting it in edge, which showed a warning pop up, so maybe it was a Microsoft flag instead of google in this case. I never figured out the cause or a way to remedy it and just took the site offline because it was invisible to all search engines. Pretty disappointing
- mscarborough 6y agoYour cert is triggering SSL_ERROR_BAD_CERT_DOMAIN.
- jacoblambda 6y agoCurious, I'm not seeing it on my end (just another person accessing the site). Which domain is it upset about for you?
- duckfang 6y agoTo be quite honest, this seems like a case of Libel and possibly Tortious Interference on behalf of Google/Alphabet. Especially if you can show damages/customers cancelling service, I think this would be a hill to die on. Google et al have too much power, even over people and orgs that aren't even customers. Its high time we reign their powers in, find them strongly culpable for what they do (and what they change and then refuse to do), and consider breaking up these monster companies up when they show they are against the public interest. Were you, uploaderwin, given a notice prior (say to abuse@uploader.win , admin@uploader.win or other appropriate mails) to being effectively banned WRT google? I'd go on a limb and say you didnt. No, you have to be aware of the right page at Google, register you as an admin to the site, and hope they share what they consider abuse. And frankly, you were lucky you got the social media escalation. You should have never had this happen... But here we are.
- kemayo 6y agoBased on what the article says, it sounds like the Google auto-blocking was correct. The website owner's theory is that someone used their demo to upload a genuinely malicious file, and presumably then shared it to others. Adding the site to their blocklist immediately is a reasonable action taken in defense of Google's users. It's certainly not libel for them to truthfully say the website is hosting malicious content. Well, not in the US; other jurisdictions don't necessarily have truth as a defense. (Tortious interference is complicated, but typically requires that the person interfering knows about the business relationship they're obstructing, and is taking the action for the purpose of obstructing it. It seems like a stretch here.) As always with Google, the real issue here is their awful communication and slow responses to people who can't find a way to go outside the normal channels. EDIT: and the article has some useful suggestions for practices to follow if you need to let people upload files as a demo. I hadn't really considered the purpose of a separate domain for such things from this angle before.
- croh 6y ago> Based on what the article says, it sounds like the Google auto-blocking was correct. Even it is correct, we can't assume it will be always correct. > As always with Google, the real issue here is their awful communication and slow responses to people who can't find a way to go outside the normal channels. Real problem is their slow repsponse can kill business (or may be people). If they are yielding this much power, there must be atleast some paid support service. I guess, it is time, all govs should look into this and regulate FAANG.
- thomas 6y agoAnd now the side it actually dead? Anyone find a cached version? Had something similar almost happen and was curious to read!
- codesternews 6y agowhats your revenue? just curious. Plans are good. Thanks
- vntok 6y agoFrom the article: > So after a lot of brainstorming and ideas from HNers I finally figured out the culprit(s). > We have a live demo on our home where people can upload a test file. [...] > We also give all users a 20MB test storage. [...] > I believe that somebody signed up for our service (it’s free to sign up) and then uploaded a malicious file on our test storage and abused this feature. If that is correct, Google was completely in the right to flag the domain as malicious and warn visitors.
- matsemann 6y agoWhy? Should GDrive be banned if a single user uploads a malicious file and links to it from a Gdoc?
- vntok 6y agoIf you create a folder in GDrive, share it with "anyone with a link" and then publish that link on Twitter, you will instantly collect porn, piracy & generally malicious files from all over the world. And your account will promptly get blocked, as it should.
- ttt0 6y agoLike they were in the right in removing decades of comp.lang.c archives, because it contained some spam? edit: just noticed, their comp.lang.c archives are back up now
- random5634 6y agoQuick notes: Site owner has not confirmed they screened all uploaded content for malware - this is a major issue these days and google and others will flag you if you host viruses and pump out malware. And no - you cannot sue google to force them to allow users to be infected. It’s not clear that all customer content is hosted on a separate domain, and each customer on a separate sub domain . Your reputation will be trashed pretty quickly if you host content on main domain blindly. It’s not clear that all uploaded content is protected from being linked too or downloaded. Google admins and other virus vendors can setup screens on downloads. Anyways - see plenty of shady / scam and incompetent website owners hosting malware - not much sympathy in most cases.
- rightbyte 6y agoSomething tells me that Google doesn't ban G Drive, Dropbox or MS's what ever it is named when those host malware. I rather not have only the giants host user generated content ...
- lrem 6y agoGoogle does the silly separate domain dance GP recommended. I couldn't figure out what is it for, until I read this advice in the previous discussion. Disclaimer: I'm a Google SRE. But never supported anything reachable from the outside.
- alisonkisk 6y agoGoogle doesn't have a separate domain for Drive files, for example, nor do they have separate per-user domains under googleusercontent.com for photos etc
- lrem 6y agoAccording to my Firefox, the JPEG file I just tried came from googleusercontent. But you're right, it's not per-user.
- 6y ago
- simion314 6y agoThe issue with this black lists is that all the antiviruses/security tools will immediately put you on their list but it can take days or weeks to have them remove you and you can still get some customer that uses some weird security program that he still gets the issue. One of the anti-viruses company has a form to submit a dispute but their form was broken for weeks.
- nikita2206 6y agoSounds quite familiar. Similar thing happens in judicial system, at least in my country but from what I observe - in most.
- ttt0 6y agoThey can remove your YouTube account, app, entire Google account or even your website at any time and you can only make guesses why did that happen, because they always make the rules really vague and it's never clear what is or is not allowed. And even when they do admit the mistake and get you back up, they still won't explain anything and nothing is ever fixed. Thank you Google, very cool.
- superzamp 6y agoAt this point they, and other giants, successfully demonstrated that they cannot regulate themselves over these random terminations and that the public needs to step in.
- whatshisface 6y agoRather than further secure their market positions by forcing them to treat their customers well, why not replace the entire company by competition from less insane providers?
- gambiting 6y agoNo. Absolutely hard disagree. To give you an example of this working well: In some countries(UK) regulators recognized that you cannot operate in the society without a bank account. So a rule was made that a bank cannot close down your bank account without a court order. They can block your access to nearly all other services, block all of your cards, but at the end of the day, you cannot lose access to your basic bank account and money in that account unless a judge says otherwise. The solution to the problem of "every citizen needs a bank account to function" wasn't "let the free market sort it out". It was to force banks to maintain access to a basic checking account no matter what until a court order is given. In my opinion, Google should be forced to do exactly the same - no matter what, you should never lose access to your google account without a court order. It might be placed under severe restrictions(no new uploads, restriction to storage etc) pending review, but until a lawful court agrees that you broke the rules somehow and google is free to kill your account? They should be forced by law to keep providing their service.
- deleted 6y ago[deleted]
- martin_a 6y ago> But there are plenty of Google engineers and good helpful people on Hacker news. > (from a screenshot) I work at Google [...] so I escalated your issue [...] > I believe the HN thread getting on the homepage tremendously helped me and somebody from Google saw it and expedited the review after all So, once more an issue with FAANG could only be fixed because somebody knew somebody else and went out of his way to get this to the right eyes. This could easily have gone another way and OP would have received no help whatsoever and would have waited for days or weeks to get this issue cleared and lost his business. Maybe it's only me but I find it unbearable that you'll usually not be able to reach any real person at all for issues like these and it's pure luck what happens to you.
- inglor_cz 6y agoThis is really feudalism replayed. If you know important people at the emperor's court, you have a chance to get yor problem solved.
- alisonkisk 6y agoIt's not "feudalism", it's human social relations and power dynamics.
- inglor_cz 6y agoDemocratic societies try to limit this problem by establishing some semireliable channels to remedy injustice, though.
- x86_64Ubuntu 6y agoI don't think anyone considers this to be in the realm of injustice.
- inglor_cz 6y agoAnyone? That is a strong word. At least I would consider losing an important asset based on a whim of an algorithm without a possibility of appeal to humans quite a gross injustice, though within the limits of the law as it stands today.
- julianlam 6y agoThank you for the write up, I really appreciate how there were actionable suggestions within. NodeBB does host a demo instance to allow people to kick the tires. I don't believe we allow people to upload images, but it is worth double checking just in case.
- fefe23 6y agoCan someone explain to my why Google isn't being drowned in a torrent of lawsuits? We are getting stories like this on a weekly basis now. Google is clearly causing measurable harm to your company and you. And apparently to thousands before you. Considering how much money patent trolls manage to extract from Big Tech with considerably weaker cases, how is it that everybody is treating Google like a fragile grandmother with dementia, going out of their way not to hold them responsible in court? This is not a rhetorical question. I really don't get it. America is the land of getting millions in settlement when McDonald's gives you coffee that is hotter than you anticipated. How the hell is Google getting away with their behavior?
- pja 6y agoBecause Google has set things be up so that they have no legal responsibility & even if they do it's an enormous legal mountain to climb to a) prove it and b) get any kind of reasonable recompense out of them. Currently they have all the benefits of their monopoly with none of the responsibility which is exactly the way they like it.
- jokethrowaway 6y agoGo figure why nobody keeps them accountable. They have enough money to influence the USA government if anything changing the situation were to be introduced.
- 6y ago
- dna_polymerase 6y agoAs an aside, Google themselves use base64 images quite heavily. They are the kings of inlining.
- aboringusername 6y agoAnyone who thinks this is the functioning of a "normal" internet is mistaken. This is a symptom of a decades-in-the-making problem. It strongly appears those in charge of legislation are not technically minded and have no idea "how" the internet works. Or they do and they have data-sharing agreements with all the 'big tech' software and are okay to "appear" to legislate but cannot actually change anything substantial in fear of retaliation (losing access to all that juicy data they collect). Imagine the power Google wields in this scenario, to me they are more scary than any drug cartel boss. I genuinely can't see how this isn't akin to a Coup d'état of the internet as a means of transmitting information. We cannot shut down these tentacles because of how deeply ingrained they are (remember when FB's SDK was having issues? Hundreds of third parties apps just broke). Google should have been regulated years ago, instead, they have been allowed to snap up every smaller company to solidify their position in the market and ensure they and only they are allowed positions of power, control and authority. If Google dislikes you (or their baseless algorithms that are detached from reality) then you are toast. How long before Google's algorithm results in an actual human death? Doesn't seem totally far fetched and entirely plausible. Yet, you let this happen, or rather, it seems this isn't concerning enough for it to warrant a massive protest, after all, Big Tech controls protest online and can just shut it down. Amazon seems to have been mightily effective at stopping any "union" movement, so we know the censor machines are fine tuned and ready to fire at any moment. We need to be talking about this daily, in needs to be front and center for weeks and weeks, and we need to demand accountability. We are ruled and governed not by elected officials but by faceless, nameless and non-human machines. They do not Think. They do not Talk. They do not care. Yet this thread will disappear in a few short hours, and this will be just another episode of the weekly "Google's systems are out of control and one developer got caught out, too bad I hope they are okay". This is happening to thousands of others undoubtedly that do not make hackernews or have the resources/energy to fix it. We should demand better.
- dehrmann 6y ago> How long before Google's algorithm results in an actual human death? Doesn't seem totally far fetched and entirely plausible. https://en.wikipedia.org/wiki/YouTube_headquarters_shooting https://en.wikipedia.org/wiki/YouTube_headquarters_shooting
- denysvitali 6y agoIronically I had the opposite issue a couple of weeks ago: I've found a phishing website (for Facebook) that was hosted on a Google server and was actively used. I sent an email to Google's abuse email address - got an automated reply back saying basically "use this other form instead". Did that, never got a reply back. I have reported the website to their SecureSearch (or whatever the name is) product, entered the URL and all the related infos: nada. The site is still up and running, phishing users, and no alerts are triggered for Chrome users... Sad, really sad.
- guerby 6y agoLet's do an experiment, please post the URL here and see if someone at google takes notice :)
- denysvitali 6y agoWell, enjoy: https://nbbdfxhqcc https://nbbdfxhqcc[ remove me ]fll.agilecrm.com/landing/6754083888234496#0.593636668875394 You are warned: the above link is a phishing website that when used will spam you whole Facebook friends with the same link via message. Google Chrome, still today, shows it as a normal website: https://imgur.com/a/1bsFutr https://imgur.com/a/1bsFutr
- denysvitali 6y agoWell, the HN effect solved it. The page isn't available anymore...
- dgellow 6y agoFrom what I see Google should now be considered an active threat. You have to design your system knowing they will eventually act against you, either your domains or your accounts. And your chances to get it fixed are slim, unless you’re able to get some public outrage. Really a disgusting company.
- marshmallow_12 6y ago>Really a disgusting company that's quite a strong word. For the average Joe, google has immesurably improved their internet experience. The vast majority of people are perfectly happy with google and love it for gmail, youtube etc. Just because they are good at destroying some peoples lives, most users don't really care at all. You might find it hard to recruit supporters just because google are horrible sometimes.
- dgellow 6y agoOther people may have a different opinion. I personally find the company disgusting. A horrible company can bring value to a lot of people. I would still find the company horrible.
- marshmallow_12 6y agoyou are not going to persuade anyone by broadcasting your personal findings.
- dgellow 6y agoI’m not trying to persuade.
- marshmallow_12 6y agothen your comment helps nobody which is against the guidelines.
- HDMI_Cable 6y agoThis is another argument on why we shouldn’t be using Google Safe Browsing. It’s frankly unacceptable that for every 5 (or less!) bad sites it blocks, we get something like this.
- asddubs 6y agoso what was the contents of the actual malicious file that was uploaded?
- yccs27 6y agoIt was likely already deleted, since they only kept files for 24h.
- david422 6y agoThanks for the writeup - I've learned some things. I have a site that allows user image uploads as well. I take each "image" and resize and compress it. If it's not an image after that, it get's rejected. Hopefully this is rejecting any malware. I have gotten warnings from google multiple times about hosting NSFW images (that is not the purpose of the site) that have ads on the page. This isn't google disliking NSFW content - it's google not liking NSFW content and ads together. Due to multiple warnings, and worried about bans, I now actually manually review each image. This is actually easier than it sounds. I wrote myself a batch script and review in chunks before I allow google to view any images.
- lanevorockz 6y agoGoogle is a monopoly and they destroy the lives of anyone that even dares to challenge them or their owners. It's time to break this big tech monopolies. Obviously, through make something better ... This is more of an inevitability than a question.
- bilater 6y agoGlad you got a resolution. Google recently banned my ad account for running ads to my landing page templates and I still don't know what was wrong with that. They just gave me a bs corporate answer and that was it.
- stonecraftwolf 6y agoI’m so sorry this happened to you. Can you show us the site?
- bilater 6y agoThe site is https://nextails.com/ https://nextails.com/ I just ran ads with headlines like Nextjs + TailwindCSS Landing Pages Apparently somehow I ran afoul of their Circumventing Systems policy. I don't know how this qualifies and when I appealed they came back saying the same thing.
- stonecraftwolf 6y agoI hope this attracts attention from someone who knows more than I do, but I can’t see anything wrong with that. The arbitrary and immense power FAANG wields is fucking terrifying.
- deleted 6y ago[deleted]
- bilater 6y agoI hope so - thank you for the support! :)
- mguerville 6y agoFYI you’re also blocked by some lists on NextDNS, consequently I couldn’t view your site. I bet that’s a consequence of the google issue, best of luck solving this.
- kjrose 6y agoEveryone in this thread is clearly stating how this is not a properly functioning system and there is story after story of the kafkaesque disasters to which Google is not responsible at all. The question I have is what can anyone do to really change things? If we all agree this is a major issue why can't we find a reasonable solution to it.
- rgj 6y agoLet’s not forget that the site probably was actually hosting malicious content. The problem is not Google blocking the site, that was the right decision. The problem is that Google is hard to reach in cases like this.
- jhugo 6y agoI believe it’s deliberate. A human-staffed support desk will be vulnerable to social engineering by fraudsters looking to get their site reactivated. A public list of very specific policies and disclosure of which one was violated will be vulnerable to engineering too, by making sites that are fraudulent/deceptive/harmful yet somehow fall between those specific policies.
- that_guy_iain 6y ago>Now we run automated tests to monitor server uptime and check server for problems every 30 seconds. Unfortunately automated test scripts were happily getting HTTP/200 replies while people using the Chrome browser were being told this is a scam business trying to steal their bank account information. I was surprised this wasn't part of the lessons learned. But it seems the monitoring basically failed but that wasn't a lesson. I feel like majority of uptime monitors are falling for this same trap. One of the reasons why for my monitoring service I choose to do full page load monitoring via Chrome instead of just a http request via Curl or whatever. Main reason, people care if the webpage loads or not. People care how long it takes for their webpage to load. Having a website respond in 200ms is great but if it takes 8000ms for all the JS to load and process your website is still slow. I get why sites are just doing curl requests because it's way cheaper but really you're monitoring one part of the stack while really caring about all of it. If your website starts producing javascript errors you want to know, etc. [1] https://www.ootliers.com https://www.ootliers.com (The landing page and everything are terrible and I'm working on improving that)
- nchelluri 6y agoIt's funny you read it that way, you may understand it correctly but I came away with a different interpretation, that they allow-listed the developer's IP and returned good non-phishing-warning responses to the monitoring check, but not to end-users.
- that_guy_iain 6y agoThey said their test scripts worked but people using Chrome got an error. So I take that as in their scripts weren't using Chrome at all. To be fair, I've not had this happen yet so I am going to try and find a site that chrome won't let me visit and see what happens when I visit it programmatically.
- imwillofficial 6y agoWhen that warning page is thrown, is a 200 returned? It could “load” ok, but be blocked by a flag for chrome that isn’t http flag. Total guess. Anyone have any insight on that page showing up?
- ufmace 6y agoI'm wondering if this could actually be spun into being a good thing. I just looked over the site a little more. The business idea seems to be to have a widget to add to your site that can be used to upload arbitrary files to it. The real advantage looks to be that they have a bunch of integrations set up with Facebook, GDrive, Dropbox, Instagram, etc so that all just works without you having to set up and manage developer accounts with 10 different services. Plus built-in image resizing and such things that all just works. Pretty cool, and I might use it if I built a site that needed to do that. One way you can frame the point of this business is that they worry about the details of integrating with these other services so that you don't have to. As they found out, hosting external content is inherently dangerous, and it pays to have someone responsible for that who knows the risks and has experience in mitigating them. If a site owner wasn't using this service, they would have to take that responsibility on for themselves and re-learn these same lessons. So that's just another advantage of using this service - "we have experience in mitigating the risk of hostile users abusing upload services to serve malware, so you don't have to worry about it".
- weef 6y agoClicking the OP link I get a warning page from my ESET AV: "Potential phishing attempt. This web page tries to trick visitors to submit sensitive personal information such as login data or credit card numbers." Is this somehow related to the Google situation?
- mleonhard 6y agoWebsite blacklists exist because of malware and phishing. Malware exists because our browsers and OS's are insecure. Phishing exists because our auth systems are insecure. Solving software security and auth will have wide positive effects on society.
- Kiro 6y ago> But there are plenty of Google engineers and good helpful people on Hacker news. Way less nowadays due to all the employee shaming.
- thinkloop 6y agoSomeone uploaded a "virus" to OP's domain and Google crawler found it and blocked said domain? Is that the mechanics?
- deleted 6y ago[deleted]
- r1ch 6y agoI wonder if the use of a .win domain had any influence. I've seen nothing but spam and malware / phishing from these $2 TLDs. https://symantec-enterprise-blogs.security.com/blogs/feature-stories/top-20-shady-top-level-domains https://symantec-enterprise-blogs.security.com/blogs/feature...
- gortok 6y agoI tried to send the blog post link to another person on Twitter and got a notice that the tweet couldn’t be sent because the site was potentially harmful: https://twitter.com/gortok/status/1368309384619626506?s=21 https://twitter.com/gortok/status/1368309384619626506?s=21
- imwillofficial 6y agoSo this sucks for the developer, but I have another story to share. I was trying to buy a school bus to make a schoolie out of, the Craigslist add directed me to a seemingly innocuous eBay motors link that looks pretty close to the real thing. I was busy and clicked, totally intending to drop $5k. I got distracted and had to come back to it later, when I did, credit card in hand, the page showed the red screen with a huge warning. A closer look revealed the bad url. Saved by google? Oh god, I think I need a shower now.
- sneak 6y agoThe fact that they are sometimes useful does not negate the fact that they have too much power to censor the web.
- colinmhayes 6y agoIt kind of does though? Either people get scammed by broken URLs or google sometimes bans innocent sites. I would expect most chrome users prefer innocent sites occasionally banned.
- trinovantes 6y agoHow do cdn providers (Cloudflare, Cloudfront etc.) avoid the subdomain blacklisting problem? Do they just have some agreement with browser vendors to whitelist their all of their subdomains because they're big enough?
- mhio 6y agoMozilla maintains a public suffix list - https://publicsuffix.org/ https://publicsuffix.org/ https://github.com/publicsuffix/list/blob/master/public_suffix_list.dat https://github.com/publicsuffix/list/blob/master/public_suff...
- julienreszka 6y agoVery scary
- rossdavidh 6y agoSo, clearly Google has too much power over the internet, it's arbitrary and opaque, etc. I agree. However, I think it is worth pointing out that: 1) malware is often very aggressive and fast-spreading, and once it's on a user's computer it's hard to get off, therefore... 2) the system to detect it and stop access to the site has to be automated, not a human-in-the-loop system that might take hours or days to shut off access to a site which is infecting many users per minute, and... 3) the more clarity there is on how exactly that automated system works, the more certain we can be that malware will be able to evade it; it's much like how spam detection or search page rankings are opaque, because the incentives to game the system are very great I'm not saying Google's system is perfect, but I am saying it's a very hard problem to solve in a way that doesn't give us an even worse time stopping malware spread than we already have. So while it is hard to feel sorry for a company as wealthy and powerful as Google, I think the issue is not as clear-cut as some comments on this thread seem to suggest.
- kortilla 6y agoOr... it’s not Google’s job to police all sites of malware?
- jeffgreco 6y agoWhose should it be? Why would they be better than Google?
- rvnx 6y agoThe job of the police
- unishark 6y agoPolice take reports from victims then what? How do police protect you from a site hosted outside their jurisdiction? I think tech companies deciding what people can access is the most likely endgame no matter what. People will demand protection. Whether it's a great firewall, a whitelist-only internet, ...or just automated filtering like this, which may be the most liberal option we can realistically expect.
- chx 6y agoIf you want to avoid this issue with a Drupal site, the file_public_base_url settings is helpful and you might -- or might not, given the latest comment there -- need the patch from this issue: https://www.drupal.org/node/2754273 https://www.drupal.org/node/2754273
- bawana 6y agoSeems like another failure of machine learning at scale.
- person_of_color 6y agoThe comment from the Google engineer who helped the OP is not there. https://news.ycombinator.com/threads?id=daave https://news.ycombinator.com/threads?id=daave What the?
- thayne 6y agoSo... The proposed mitigation is to use multiple top-level domains. At the same time, third party cookies probably won't be around much longer and already don't work for some browsers, so if you want to share state between pages, you need them to be on the same domain (but can be subdomains). There is no winning scenario here.
- gridder 6y agoThis 100%
- pier25 6y ago> Don’t use base-64 images (or inline images) For SVG just paste the markup on your HTML. Browser support is excellent and it will weight less than using a base64 encoded string. You will be able to style it using CSS as if it was regular HTML, use JS, etc.
- noisy_boy 6y agoAnother idea could be to maybe have a separate dedicated companion domain (not a sub-domain) for communication which can be mentioned in the main domain. Atleast if the main domain is affected, you can still have a working channel that is a single place of truth for updates/communications.
- whiner 6y ago> We have a live demo on our home where people can upload a test file. The demo is a way for users to actually see how the uploader will look in their own apps. It's a way for users to test drive the site without actually signing up. > .... > I believe that somebody signed up for our service (it’s free to sign up) and then uploaded a malicious file on our test storage and abused this feature. Step 1 - Allow random users to dump random files onto your website. Step 2 - Random users dump random files on your website. Step 3 - Create an outrage, OMG, OMG!!! Google killed my site!!! Step 4 - Post on HN, generate more outrage and sympathy Step 5 - When the real thing comes to light, oh yeah, I did allow random users to upload random files to my website. Let me write a blog and tell what lessons I learned and still claim "How Google killed my site". Step 6 - Kachinnng, look at all the attention and internet points me and my website earned!!! We had a similar episode where this guy https://news.ycombinator.com/user?id=dcurtis https://news.ycombinator.com/user?id=dcurtis created an uproar and outrage about Apple only to be proven[1] that he was the one at fault and not Apple. Now that the reality came to light, he's no where to be seen, not even an apology. We'll see him back during his next episode of outrage and attention seeking. [1] https://9to5mac.com/2021/03/03/apple-card-apple-id-unrelated/ https://9to5mac.com/2021/03/03/apple-card-apple-id-unrelated...
- matsemann 6y agoWhat an uncharitable and strawman-y way of summarizing the events.. The fact that you felt the need to make a new account for posting this should've been a sign that the way you phrase it is uncool. The discussion about what power Google, Apple etc wields are still worth having.
- 8note 6y agoKeeping user content on a separate domain is something I'll Reber out of this. Suddenly it makes sense why social media sites have so many different domain names
- stevenalowe 6y agoSounds to me like Google protected the Internet from your site after you got hacked, which alerted you to a severe security hole in your system, so what are you complaining about?
- egorfine 6y agoSlightly offtopic: both "Drag and drop" and "Embed on page" examples at https://www.uploader.win/docs/ https://www.uploader.win/docs/ do not work.