4 ms·
Quick notes: Site owner has not confirmed they screened all uploaded content for malware - this is a major issue these days and google and others will flag you
by random5634 6y ago
Quick notes:
Site owner has not confirmed they screened all uploaded content for malware - this is a major issue these days and google and others will flag you if you host viruses and pump out malware.
And no - you cannot sue google to force them to allow users to be infected.
It’s not clear that all customer content is hosted on a separate domain, and each customer on a separate sub domain . Your reputation will be trashed pretty quickly if you host content on main domain blindly.
It’s not clear that all uploaded content is protected from being linked too or downloaded. Google admins and other virus vendors can setup screens on downloads.
Anyways - see plenty of shady / scam and incompetent website owners hosting malware - not much sympathy in most cases.
- rightbyte 6y agoSomething tells me that Google doesn't ban G Drive, Dropbox or MS's what ever it is named when those host malware. I rather not have only the giants host user generated content ...
- lrem 6y agoGoogle does the silly separate domain dance GP recommended. I couldn't figure out what is it for, until I read this advice in the previous discussion. Disclaimer: I'm a Google SRE. But never supported anything reachable from the outside.
- alisonkisk 6y agoGoogle doesn't have a separate domain for Drive files, for example, nor do they have separate per-user domains under googleusercontent.com for photos etc
- lrem 6y agoAccording to my Firefox, the JPEG file I just tried came from googleusercontent. But you're right, it's not per-user.
- asdfasgasdgasdg 6y agoThat's not what it's for. It's to prevent user content from being served from the same origin as Google services. If the content were to be served from the same origin, scripts loaded from that origin would be able to access your google cookies and therefore would be able to access your account data.
- lrem 6y agoOh. I even heard about this mechanism before ;) Thanks, this makes more sense.
- temp667 6y agoFirst - most of these places are running pretty advanced virus / malware scanners. So when you go to download a file from drive etc, a scan is done (at least for files that are not enormous). This is actually a big issue sometimes for folks who use google drive, because malware will infect their files, they will then be synced to google, then blocked from downloading them ever again! That leads to support requests list this: https://support.google.com/a/thread/60528209?hl=en https://support.google.com/a/thread/60528209?hl=en Even if you pay the ransomeware fee, google WILL NOT let you access your own files again. So years worth of files - GONE. They do use different origins for these services. Google DOES actively ban users (everything, youtube, drive and email) from their service even users using google services (vs a third party upload service). Ie, if you are going to run a phishing scam, host the image on this service, not google, or your drive account + a lot of other stuff is at risk. I've even seen google follow links to other accounts your google account is an admin on, so can have business impacts and more. I don't know where the idea comes from that google is very hands off on this stuff, they run a major spam fighting op that blocks lots of even potentially legit email, they do tons of scans through chrome, they do advanced stuff for opt-in domains on their paid platforms (even more intrusive but let's them pick stuff up behind password locked pages etc). This last one can really confuse site owners, when NON PUBLIC content results in site bans.
- simion314 6y agoIs not about the viruses, a pdf that looks like phishing can be reported and you get your website blocked. If anyone knows of a way to scan pdfs please let me know(I think it would involve finding the links in the pdf, try to follow them and detect if are phishing but maybe the link is fine at the pdf upload time and it changes after)
- gpm 6y ago> And no - you cannot sue google to force them to allow users to be infected. Has anyone tried, genuinely curious how this would turn out.
- wnoise 6y ago> We never allow anything other than video and image files either. I would have thought this would be an excellent way to not host malware.
- freeone3000 6y agoNot quite. There have been several flaws in WMF that have caused video and image files to be viral vectors. https://en.m.wikipedia.org/wiki/Windows_Metafile_vulnerability https://en.m.wikipedia.org/wiki/Windows_Metafile_vulnerabili...
- deleted 6y ago[deleted]
- hamburglar 6y agoI haven’t read all comments so I don’t know if anyone made this suggestion already, but for a demo uploader, you could probably just have all the file contents replaced with zeros, or stand-in data of the same content type (eg all videos turn into a video saying thanks for trying it out, padded with zeros to the original upload size)