8 ms·
Remove any Site From Google (even if you don't control it)
- wccrawford 15y agoI think it's sad that he had to resort to publicly releasing this exploit because he couldn't find a way to contact Google about it. In the past, when I've had problems, I couldn't contact them either. They've done a great job at making sure there's no human contacts available. You have to post something in a public forum and hope they'll contact you. (They won't.)
- deleted 15y ago[deleted]
- ssclafani 15y agoSending an email to security@google.com will result in a quick response. As part of their bug bounty program Google would have paid $1,000 for this bug if not more.
- aristus 15y agoThe biggest problem when the 911 (and equivalent emergency services) was getting the word out there that it existed. It required a huge, years-long marketing campaign. Perhaps they should have inhouse ads targeted at keywords like "report vulnerability".
- shadowfox 15y agoI wonder if large companies are willing to advertise to the general public the possibility that they could have vulnerabilities.
- elmomalmo 15y agoHmm, which is more valuable, $1000 or #1 on HN?
- mike-cardwell 15y ago$1000
- TeMPOraL 15y agoSometimes (not necessarily in this case) #1 on HN. Being noticed in the right place at a right time may proove to be much better for one's life than a quick money boost.
- StavrosK 15y agoYou can get both.
- mike-cardwell 15y agoThat was my immediate thought when I read the article. "Wow, this guy just chucked away hundreds of dollars". Always check for a bounty program before you go and release information like this.
- jc123 15y agoGoogle should probably still give this guy the bounty
- mike-cardwell 15y agoOne of the main reasons they have a bounty program is to prevent people releasing information about bugs before they have been fixed. I don't see why they should give him a bounty.
- dave1010uk 15y agoI emailed security@google.com when I found a security issue with Google +1 (http://news.ycombinator.com/item?id=2630355 http://news.ycombinator.com/item?id=2630355) but didn't get any response. I guess it's not really an issue for them.
- silverbax88 15y agoNo, it won't. Trying to contact Google when I was working for a major corporation and TRYING TO GIVE GOOGLE MONEY resulted in the exact same issue as the OP, and this was in 2006, not 2011. The only way to get their attention was create a blog post about how I couldn't contact them.
- michaelfairley 15y agoI'm not sure how he was unable to find their security@google.com email address. Searches like "Google security" and "Google report vulnerability" have http://www.google.com/about/corporate/company/security.html http://www.google.com/about/corporate/company/security.html (which has a prominent section on reporting security issues) as their first result.
- sirn 15y agoBecause now you know the email is spelled "security@google.com", it would be easy to come up with search query that returns that email address after the fact. If you going by the instinct, search for "google bug report", ...I'm on page 20 and still couldn't find that email. (Personalize search turned off.)
- nbpoole 15y agoBecause the security email address is not a place for bug reports: it shouldn't be ranking for that query. If it did, the team would just be swamped with "bug reports" ;) Try searching for "google report security" or "security vulnerability google" and you'll find the right information.
- TeMPOraL 15y agoWhich is sad, because in this case we have a security vulnerability and a bug at the same time, so how one expresses that in a web search depends only on one's current mindframe and set of associations. Eg. when I hear "Google security" I imagine guys with guns, not a place for bug reports.
- michaelfairley 15y agoAny company worth its weight that stands to lose big time from a security vulnerability will have a page with info on how to report it to them, and searching "[company name] security" will usually get you right to it. Disclosure is what you do after you've contacted them and not heard back. http://www.apple.com/support/security/ http://www.apple.com/support/security/ http://www.microsoft.com/security/msrc/report.aspx http://www.microsoft.com/security/msrc/report.aspx https://www.dropbox.com/terms/#security https://www.dropbox.com/terms/#security http://www.amazon.com/gp/help/customer/display.html/ref=hp_left_ac?ie=UTF8&nodeId=551434 http://www.amazon.com/gp/help/customer/display.html/ref=hp_l...
- drivebyacct2 15y agoIt's obnoxious how hard it is to report bugs to Google. And posting in their forum is a joke anyway. Google's new two-factor authentication? Really neat right? Yeah, well, it's buggy and there is no way to report bugs for it. I posted in the forum and was received by crickets. I don't mind it most of the time, but when I have a real issue or something that is obviously broken and unnoticed, it sure is frustrating. edit: There's also no category for "generic login problems" or "Other". So I'm stuck posting it in Gmail.
- spooneybarger 15y agoMy favorite has always been the google apps problems that tell you to contact support to get a resolution but you can only contact support if you are a paying customer. support is not google's strong suit.
- sidman 15y agoI am a google apps paying customer and it took them 4 weeks to get my domain issue corrected ! In that time i wasnt able to get mail so i had to change my mail to use godaddy until they got back to me. When they finally did they said it was because my dns records were pointing to godaddy ! After 1 week of not getting mails i would say an alternative is required. I actually had a feeling that this would happen :) I really love google as a company, their products, api's, their talks and all the events they hold are so great, i have learnt alot, BUT man, when i couldn't access my mail as a paying customer and got the runaround for support for 4 weeks even though they said it was high on the priority list ... GRRR thinking about it just makes me mad. Anyway on a good note, after this issue everything is working fine and i guess aslong as you dont need support then everything is good :)
- gcb 15y agothanks, always avoided paying them because i thought the experience would be like that...
- RexRollman 15y agoSadly, from what I have read over the years, your experience is not a solitary one. I hope Google, at some point, will address their customer service issues.
- andreyf 15y agohttp://goo.gl/vulnz http://goo.gl/vulnz
- latch 15y agoHis first blog post...talk about setting high expectations.
- deleted 15y ago[deleted]
- cooldeal 15y agoThe story goes: The huge printing presses of a major Chicago newspaper began malfunctioning on the Saturday before Christmas, putting all the revenue for advertising that was to appear in the Sunday paper in jeopardy. None of the technicians could track down the problem. Finally, a frantic call was made to the retired printer who had worked with these presses for over 40 years. “We’ll pay anything; just come in and fix them,” he was told. When he arrived, he walked around for a few minutes, surveying the presses; then he approached one of the control panels and opened it. He removed a dime from his pocket, turned a screw 1/4 of a turn, and said, “The presses will now work correctly.” After being profusely thanked, he was told to submit a bill for his work. The bill arrived a few days later, for $10,000.00! Not wanting to pay such a huge amount for so little work, the printer was told to please itemize his charges, with the hope that he would reduce the amount once he had to identify his services. The revised bill arrived: $1.00 for turning the screw; $9,999.00 for knowing which screw to turn.
- zach 15y agoMore versions of the story and many others: http://www.snopes.com/business/genius/where.asp http://www.snopes.com/business/genius/where.asp
- GFischer 15y agoI like that story, but I also usually think of some extra lessons (for the printing-press owners): - Operations-critical knowledge should be documented - mitigate the "bus factor" (http://www.ask.com/wiki/Bus_factor http://www.ask.com/wiki/Bus_factor) - There are often-neglected big support advantages of buying from large suppliers with good support. (ok, big corporations do take that into account, but for small startups, making sure that the buyer feels at ease not having such a case blow up in their faces is important, and same for buying mission-critical software, though having a disruptive/competitive-advantage generating app might be worth the risk)
- suking 15y agoI suspect some googlers are going to have a long night :-).
- brownie 15y agoDespite it being "fixed" not long after the blog post went live, I wonder how long/how many people knew about this bug. Seems like it would be a great trick for SEO (build page to certain PR/remove opponents ranking above you)
- _gingerhendrix 15y agoWhat's a great trick for SEO is this sensationalist linkbait article.
- ashconnor 15y agoThe article delivers. Why is this linkbait?
- deleted 15y ago[deleted]
- nl 15y agoHe included screenshots and a description. Neither are impossible to fake, but either it's a genuine mistake (in which case I would imagine someone would have pointed it out) or he's faking it. You seem to be accusing him of faking, without any evidence or even a motive. Edit: also http://www.jamesbreckenridge.co.uk/what-i-learned-today.html http://www.jamesbreckenridge.co.uk/what-i-learned-today.html
- pmadden 15y agoWas it the "I'm not saying it's fake" part that made it seem to you that I seem to be accusing him of faking? My point is that the evidence is wholly insufficient. It was the first post on a new blog (i.e. no reputation), no way to reproduce the reported issue, no reports of it having been reproduced by anyone else, no acknowledgment from Google (ok, maybe it's a little early for that), etc. I mean, from a journalistic, much less scientific, standpoint, it's pretty poor. How can I provide evidence of a negative? Would you please provide evidence disproving my assertion that flying saucers visited my house last night? And motive? Wasn't that covered earlier by the word "linkbait"? Maybe my calibration is way off today, but I'm surprised by the level of credulity I've been seeing. My original post (which I deleted and then reposted, sorry about that) got downvoted to subzero with no explanation. I agree with other posters that bugs happen, but I would have thought that such a major claim against a generally competent player like Google would require at least one independent verification. I'll be curious to see if Google mentions this. Otherwise, we'll really never know. Well, you may, but I guess I'm a little more skeptical.
- juliano_q 15y agoI don't know how is possible that a so obvious bug passed their quality department, and I wonder if someone didnt discovered it before and was doing this to take out competitors indexes..
- DrJokepu 15y agoBugs happen. Even big ones like this. Any engineer worth his money knows that no amount of Q&A will discover 100% of the bugs. But, as Joel Spolsky said somewhere, bugs are just bugs, you fix them and then they're fixed.
- juliano_q 15y agoI know, I am an engineer and I obviously let bugs pass too. But this is a little too obvious to me, to check if the user is allowed to remove this url. Maybe I am neurotic? :)
- trotsky 15y agomost bugs are obvious after someone has pointed them out to you.
- cooldeal 15y agoI think the point is that it's a basic dev and QA fail not to check for this, especially with people of the caliber that Google is supposed to recruit.
- trotsky 15y agoProcess always falls down at some point, it's why we have bugs in the first place. The point of view that "obvious bugs should never happen" is pretty obviously broken, you just try to make them as rare as humanly possible. Besides, simple looking things from the outside can be maddeningly complex from the inside - for all we know this could be related to an obscure bug in their test framework marking it as passed when it isn't. Most of the time when people say "what a stupid mistake" they mean "that's a mistake I haven't made yet"
- staunch 15y agoThis bug could have been exploited for millions of dollars. Imagine giving a mafia boss control over the heartbeat of every rival. One blackhat SEO could have dominated any number of lucrative keywords. If this bug has existed for a long time it's quite possible some guy is sailing around on a yacht that this bug paid for. It's such a blindingly obvious bug that I really do wonder whether this might have been a backdoor/inside job by an employee. Google should very closely inspect the code change history. Hopefully they also maintain a history of all page removal requests to see who might have been exploiting this.
- jacques_chester 15y agoIt's not a back door, it's an abuse of an existing approach. Google could weight the process in one of two ways: 1. in favour of the complaint-maker. 2. in favour of the website-owner. If they favour the complainant, then website deletion is presumed to go ahead. If the webmaster, then it is presumed to be held up. Google chose a compromise: the complaint is acted on, after a delay. The webmaster gets notified through webmaster tools; after some period of time the removal goes ahead. If Google flip the compromise around, they will make it nigh impossible to remove any websites from the index.
- jmillikin 15y agoI think you're misunderstanding the article. Google webmaster tools allows the website owner to request links to their own sites be removed. The poster has discovered that this form can be used to request any url be removed, and Google will think it's being submitted by the owner of that URL. This has nothing to do with users complaining about a URL.
- jacques_chester 15y agoIn which case, I think I have too.
- xiaoqmashh 15y agowelcometo: http://www.fullmalls.com http://www.fullmalls.com The website wholesale for many kinds of fashion shoes, like the nike,jordan,prada,, also including the jeans,shirts,bags,hat and the decorations. All the products are free shipping, and the the price is competitive, and also can accept the paypal payment.,after the payment, can ship within short time. free shippingcompetitive priceany size availableaccept the paypal ===== http://www.fullmalls.com http://www.fullmalls.com ===== jordan shoes $32nike shox $32Christan Audigier bikini $23 Ed Hardy Bikini $23Smful short_t-shirt_woman $15ed hardy short_tank_woman $16Sandal $32christian loubo utin $80 Sunglass $15 COACH_Necklace $27handbag $33AF tank woman $17puma slipper woman $30 ===== http://www.fullmalls.com http://www.fullmalls.com ===== ===== http://www.fullmalls.com http://www.fullmalls.com ===== ===== http://www.fullmalls.com http://www.fullmalls.com ===== ===== http://www.fullmalls.com http://www.fullmalls.com ===== ===== http://www.fullmalls.com http://www.fullmalls.com =====
- orblivion 15y agoImagine if LulzSec found this first
- ethereal 15y agoPersonally, I would be more concerned if someone with malicious intent and the ability to keep silent about what they have done had found & exploited this. [0] Advertise: remove your competitor from Google's search results for a day! If I didn't think it was illegal, I'd probably pay for that, were I in such a situation. [0] If, of course, it even existed in the first place. It seems plausible enough to me, even if I think it unlikely.
- xtal 15y agoHow do you know they haven't?
- pbz 15y agoSomewhat related: I wish GWT had a "pattern" removal. With one of my sites, by the time I noticed that certain pages were missing the "noindex" tag Google happily indexed over 4000 pages. Considering the rate Google is crawling those pages it may take years to be removed from the index. Obviously, submitting each link one by one is rather tedious. Hopefully the author is going to release that extension after Google fixes this bug. I may actually bother clicking 4K times just to see that site "fixed"...
- bostonvaulter2 15y agoGrrr, google and it's acronym's, I thought GWT stood for Google Web Toolkit and I was really confused for a second. Instead this GWT stands for Google Webmaster Tools...
- deleted 15y ago[deleted]
- deleted 15y ago[deleted]
- amritayannayak 15y agoThe link is broken. I'm not able to load the page.
- ImperatorLunae 15y ago<i>otherwise although it is a loophole I am pretty sure it is illegal.</i> It would <i>seem</i> that this is illegal, but I've never heard of a law protecting one's right to be listed in a search engine. Perhaps, if this process requires you to be the owner, it qualifies as fraud?
- dwwoelfel 15y agoIf you want italics, use asterisks instead of <i></i>'s. For example, *italic* produces italic. http://news.ycombinator.com/formatdoc http://news.ycombinator.com/formatdoc
- ImperatorLunae 15y agothanks!
- praptak 15y ago"but I've never heard of a law protecting one's right to be listed in a search engine." I believe that in most countries where computer crime law exists, removing or modifying data that is not yours(1) is covered by the law. (1) What's "yours" and what's not is of course a very tricky question when it comes to immaterial things. Whether a listing for your webpage generated by a third party is yours, I wouldn't bet (on either side.)
- tetha 15y agoIn germany, you might have a stab at sueing for lost income, for example if you are a shop with a large number coming from google search, or if you get large amounts of ad revenue from visitors from google.
- retube 15y agoDoes this _actually_ work though? You get the message "URL pending for removal" but does that mean it's really going to be removed? Perhaps this is just a default response. Were any non-owned sites/urls actually removed?
- yaix 15y agoI am always amazed how experienced programmers can make such obvious errors when processing user input. Why would I ask for a URL of the WMT account in the query string? I just hope that there is no "for the lulz" guy running a batch script to see how many million URLs he'll be able to remove before this gets fixed.
- MNUO 15y agothat's really funny but very serious
- Hisoka 15y ago4 months ago one of my sites totally disappeared from Google. I wonder if this is because of this??? It's not a shady site, and there's no reason Google would remove ALL the pages.. if anything they'd penalize it.