14 ms·
Google's Kenyan ripoff?
- badclient 15y agoTo be clear, I wouldn't consider the scraping of their data as a ripoff. Border-line unethical? May be. But far, far from a ripoff. The ripoff can be if google was trying to use their name which would effectively be phishing. I don't see them really pushing hard on that accusation.
- timerickson 15y agoScraping their data is against the TOS you have to agree to before using it. So yes, it is illegal if they're violating the TOS.
- reverend 15y ago"Don't be evil." -Google
- ColinWright 15y agoSee also: http://news.ycombinator.com/item?id=3460033 http://news.ycombinator.com/item?id=3460033
- rmc 15y agoLet's not jump the gun here. Let's keep the pitchforks at bay till we find out what's going on first.
- danmaz74 15y agoAgreed. But Google needs to give a good explanation... at internet speed. And, if this is true and someone at Google is involved, there should be consequences.
- numbsafari 15y agoGoogle needs to give a good explanation, but they should only do so when they have all the facts and a proper handle on the situation. I see this as the exact type of situation that, in the past, Apple has taken its time to respond to. Rather than move in haste and make a misstatement, it's better to gather all the facts and be fully prepared for all of the obvious questions than to have to go back and restate something later on.
- jws 15y agoEspecially given the source. For those unfamiliar, Cory Doctorow is a professional writer of fiction. Like my favorite sci fi authors, he crafts stories about an "imagine if these conditions were true, how would that world work" starting point. His selection in news carries a similar bent, he likes a news story that would be interesting if true. It's generally best to enjoy them as that. Take a moment, imagine a world where Google actually does this, then remember that it is probably fiction and get on with life until you see the story reappear with journalistic research behind it. Edit: I see Mr. Doctorow updated with a note that he contacted google and google is preparing a response. +1 for journalism.
- rmc 15y agoAlthough Cory Doctorow is a professional fiction writer, he is also a journalist and writer. Just because he has written some scifi doesn't imply that he is some sort of pathological liar.
- lclarkmichalek 15y agoDid Mocality contact Google about the issue before going public about it? I can't find any mention of dialog in the CEO's statement.
- swalsh 15y agoI'm eagerly awaiting a response from google on this. Frankly I suspect that these guys are not actually associated with Google. Google isn't the kind of company that would hire an army of employees to manually click through a website to cold call people.
- guard-of-terra 15y agoThey scan books that way too (manually), aren't they?
- asto 15y agoNo. Here's a description of a patent they filed for their book scanning tech. http://www.npr.org/blogs/library/2009/04/the_granting_of_patent_7508978.html?sc=fb&cc=fp http://www.npr.org/blogs/library/2009/04/the_granting_of_pat...
- travem 15y agoActually there is manual labor involved, see http://techcrunch.com/2007/12/06/google-books-adds-hand-scans/ http://techcrunch.com/2007/12/06/google-books-adds-hand-scan... and http://books.google.com/books?id=lAIJAAAAIAAJ&printsec=frontcover#PPP3,M1 http://books.google.com/books?id=lAIJAAAAIAAJ&printsec=f...
- mikecaron 15y agoSo how do you explain the ip addresses?
- quanticle 15y agoGoogle App Engine? Perhaps the scammer is hosting their scraping app. on GAE.
- alexmuller 15y agoHaving just checked, it's not Google App Engine. GAE appends the string "AppEngine-Google; (+http://code.google.com/appengine http://code.google.com/appengine) " to the user agent regardless of what it's set to. But still, I agree there may well be another explanation. http://code.google.com/p/googleappengine/issues/detail?id=342 http://code.google.com/p/googleappengine/issues/detail?id=34...
- danko 15y agoGoogle is precisely the brand that a non-Google third-party would use to launch a scam like this, so I'm going to wait a few hours before getting the flamethrower out. This really doesn't seem like Google's style from a technical quotient, even if you ignore the ethical angle.
- eof 15y agoAccording to the main source (http://blog.mocality.co.ke/2012/01/13/google-what-were-you-thinking/ http://blog.mocality.co.ke/2012/01/13/google-what-were-you-t...), after setting up the sting, there were a bunch of hits straight from google HQ. These new accesses were coming directly from Google’s network. The IP address 74.125.63.33 made 17,645 requests (15,554 to BusinessProfile.aspx). Activity really kicked off on 22 December 2011, with 8 different user agents mostly running Chrome on Linux: The top 3 are : Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7 11249 64.268982 Mozilla/5.0 (Ubuntu; X11; Linux x86_64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1 4247 24.264412 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.2 (KHTML, like Gecko) Ubuntu/10.04 Chromium/15.0.874.106 Chrome/15.0.874.106 Safari/535.2 1000 5.713306 Search for “tag=mo.request 74.125.63.33″ from 20 December 2011 to 9 January 2012. Found 17,049 requests
- DeusExMachina 15y agoI've seen people justify this saying that it might be an app running on Google App Engine. I wonder though if the GAE data center (or part of it) is in Google HQ. Moreover, as someone (EDIT: the article's author) mentioned in the comments of the article When an IP address registered to Google HQ's internal network is fed a unique phone number, and one hour later that phone number rings from someone who claims to represent Google, and repeats fraudulent claims that have been made for months from entities selling a Google product (that has no affiliate program), it is reasonable to infer that this is taking place with Google's cooperation. Which is indeed suspect. EDIT: as this comment below shows, it cannot be GAE: http://news.ycombinator.com/item?id=3460663 http://news.ycombinator.com/item?id=3460663
- 15y ago
- JS_startup 15y agoIf the statement about the Mountain View IP address is true then it's hard to imagine that these were scammers masquerading as Google. My bet? Google's statement will blame some third party contractors or a miscommunication. Massive damage control and fire fighting for the rest of the day.
- Zirro 15y agoExcept for Kenya, I can only see India mentioned in the original article. Am I missing something, or is Boing Boing publishing incorrect information?
- JS_startup 15y agoShortly after, that IP range stopped visiting Mocality's servers, but another range, this one registered to Google's Mountain View headquarters [edit: this address has previously been used to conduct official Google business in India].. The article is implying that the IP range was one that has been officially used by Google for international business in the past, making it the smoking gun in their accusation.
- Zirro 15y agoI see. I'm not sure if that edit was there when I first read the article. Thanks for the clarification, anyway.
- hackNightly 15y agoI have to admit, this is a little strange. I guess my main question is why does a company as large as Google need to solicit money from any business? Let alone Kenyan businesses well outside the scope of it's main customer base?
- guard-of-terra 15y agoA local Google office might do some funny things. Using the autonomy they've got. The program in question is confined to Kenya.
- josefresco 15y agoThe only evidence so far of this program is from Kenya. To state with certainty that it's confined to Kenya at this point would be a stretch.
- josefresco 15y agoBecause Google needs to grow (shareholders and all that), and with a massive and cheap workforce you can actually pull things like this off (keep in mind it's not PHD's that are doing the cold calling).
- mynegation 15y agoMy guess is that these things are done by rogue Google employee or contractor. Hypothetical profit from this kind of behavior is not worth a tiny bit of potential reputation damage.
- josefresco 15y agoThe article, and evidence gathered by the co seems to say otherwise. Rogue contractor maybe (unlikely IMHO), but not employee.
- rmc 15y agoOr just someone pretending to work for Google. Conmen do that sort of thing all the time.
- redwood 15y agoThing is, conmen wouldn't target Kenya (except for Kenyan conmen and I doubt Kenyan conmen would spend money to hire a large team in India...) they'd go for where the bigger money is. Only mega-companies are working hard everywhere, including the developing countries.
- brudgers 15y agoI would tend to agree except that Google strongly promotes cobranding as a partner benefit. http://www.kbo.co.ke/partnerbenefits http://www.kbo.co.ke/partnerbenefits
- losethos 15y agoGod is just. God says... C:\LoseThos\www.losethos.com\text\HUCKFINN.TXT Tom he turned his head a little, and muttered something or other, which showed he warn't in his right mind; then she flung up her hands, and says: "He's alive, thank God! And that's enough!" and she snatched a kiss of him, and flew for the house to get the bed ready, and scattering orders right and left at the niggers and everybody else, as fast as her tongue could go, every jump of the way. I followed the men to see what they was going to do with Jim; and the old doctor and Uncle Silas follo
- nl 15y agoLet's assume it was Google that did this, and let's assume that it was non-authorised behaviour by a branch office. (I hope for their sake this isn't the case, but there is more than enough evidence to make it possible) What should Google do? Obviously they shouldn't dodge the responsibility, but also they should try and repair the damage somehow. What is an appropriate course of action for them? Paying damages? Transferring customers? I can't think of any good options, really.
- Gring 15y agoApologizing, damages, plus laying the internal groundwork that it never happens again.
- josefresco 15y agoYou forgot to mention someone's getting fired or demoted.
- felipe 15y agoBlame a third-party! It wouldn't be the first time they do it: http://tech.slashdot.org/story/07/04/08/1824210/google-faces-plagiarism-questions-over-chinese-software http://tech.slashdot.org/story/07/04/08/1824210/google-faces... http://www.pcworld.com/article/130502/google_admits_using_outside_source_for_chinese_app.html http://www.pcworld.com/article/130502/google_admits_using_ou...
- nl 15y agoThey seem to have fixed that problem in a weekend, or am I missing something? I'm unclear what you are saying - do you expect perfection from Google? I don't - mistakes happen. But I do expect them to fix things when they do something wrong.
- felipe 15y agoWhat I mentioned was not simply a mistake. They fully knew what they were doing (i. e.: plagiarizing an existing solution), and then they "fixed" it only when they actually got caught.
- raphman 15y agoIt seems this Google IP address was associated with a blog spam scanning bot some time ago: http://www.techjournal.info/2009/12/who-is-abuseiampromcorpgooglecom.html http://www.techjournal.info/2009/12/who-is-abuseiampromcorpg...
- joshaidan 15y agoI would be interested in knowing what the browser client was set to in the HTTP GET request. That would be something to grab next time something like this happens.
- waitwhat 15y agoI would be interested in knowing what the browser client was set to You mean the User-Agent? It's referenced all over mocality's blog post http://blog.mocality.co.ke/2012/01/13/google-what-were-you-thinking/ http://blog.mocality.co.ke/2012/01/13/google-what-were-you-t...
- joshaidan 15y agoYeah, User-Agent. I read the boingboing post and not the original Mocality post. Thanks.
- brown9-2 15y agoThere is another possibility here that I haven't seen mentioned yet: Someone fraudulently representing Mocality attempted to start a joint Google-Mocality venture. Google was misled, and no one at Mocality was aware of the fraud, meaning neither party is guilty.
- shimon 15y agoIs it really plausible that Google would agree to a partnership and provide payment to a false Mocality representative without even speaking to the Mocality CEO? We can't rule this out without more knowledge of the case, but it seems very far-fetched.
- brown9-2 15y agoIt's not hard to imagine that someone could fraudulently claim to be Mocality's CEO either. How often do you verify someone's ID in a business meeting?
- notahacker 15y agoThat suggestion reminds me of Ali Dia, the very limited footballer who ended up playing a game in the English Premier League after Southampton signed him on doubtlessly generous wages without bothering to check whether the call from legendary George Weah recommending his "cousin" was genuine, or whether a player called Ali Dia had ever played internationally for Senegal or Liberia. http://en.wikipedia.org/wiki/Ali_Dia http://en.wikipedia.org/wiki/Ali_Dia
- duaneb 15y agoGoogle may have been under the impression that they HAD talked to the CEO.
- napierzaza 15y agoThere are many more blind speculations to make. This is just one of them. Aliens!
- bh42222 15y agoIP addresses are easy to spoof. Did Mocality try to figure out if it was really Google's IPs, or just someone faking them?
- jrockway 15y agoIP addresses are not easy to spoof. Most ISPs do egress filtering, and most TCP stacks use cryptographically-secure sequence number generation. This makes forging HTTP traffic nearly impossible in practice.
- brazzy 15y agoIP addresses are not easy to spoof if you want receive an answer to your packets. In fact, they're pretty much impossible to spoof unless you control a router between the target and the IP address you want to spoof (though that's not really spoofing anymore at that point, more like capturing).
- lukeschlather 15y agoHow hard is it to bribe a sysadmin on the backbone routers in Kenya? Better yet, how hard is it to become a sysadmin on the backbone routers in Kenya? Of course there are a dozen Google services that could let you serve a webpage from some Google IP, so router-level spoofing seems a bit farfetched for this scenario.
- prostoalex 15y ago>> Better yet, how hard is it to become a sysadmin on the backbone routers in Kenya? Pretty damn hard http://jobsearch.monster.com/search/sysadmin-on-the-backbone-routers_5?q=IP-Spoofing&where=kenya http://jobsearch.monster.com/search/sysadmin-on-the-backbone...
- fhars 15y agoIP adresses are only easy to spoof if you do not intend to receive any ACK packages (or any other reply from the target, like web pages with phone numbers on them). For everything else you need the cooperation of a rogue ISP on the shortest path between the target and the legitimate owner of the address block, or a peering with well connected networks that allows you to mess with BGP, which would be hard to hide and probably cost you your peering agreements.
- moshthepitt 15y agoThere's an interesting twist in this tale. Have a look at: http://blog.mocality.co.ke/2012/01/13/google-what-were-you-thinking/#comment-488 http://blog.mocality.co.ke/2012/01/13/google-what-were-you-t... It says: "OMG!!!!! We received a call on the office line (the one listed on Mocality) from India stating that they were offering website services. I think the guy on phone was Deepak or something (it sounded almost like a scam) the guy said he was from Google Kenya blah blah, we refused the offer as we already have a site. Then few days ago I was just searching our page when I stumbled upon our site on .kbo.co.ke site…I mailed them n told them to take it down! aaaaaaaarg!!!!!!" --- This is one of the small businesses contacted by 'Google'. SO it seems that after they got the call, they later saw their business website put up on kbo.co.ke (which is Google owned). Doesn't this sound like further proof that this is Google sanctioned?
- notahacker 15y agoNot really. A small businessman gets cold-called by an SEO/Adwords agency offering to "get you on Google" at a one time special offer. Intrigued, they search Google for their business and find quite a lot of websites referring to their business they didn't know existed before. Connected? Kbo.ke publicly advertises web hosting for free, and by the sounds of it might be automatically populating the listings. So its a reasonable assumption that someone trying to charge Ks 200 per month for their[?] web hosting service might be aware of the potential to exploit Kbo's existence but isn't acting with their blessing...
- uxp 15y agoMy previous small business would receive cold calls from people claiming to be "with Google" or "working with Google" to sell me SEO services weekly. I can see how non-technical business owners who don't understand how "the internets" work could see that as a direct association, and blaming Google themselves when they dont receive what was advertised or if the relationship goes sour. I haven't checked, but it might be beneficial for Google to come out and say that they will never work with businesses directly to increase their online exposure outside of allowing the business to buy ad space through their official self-serve Adwords platform.
- portentint 15y agoSeems a little too clumsy for Google. I WILL say, though, that their PR handling of late makes them more vulnerable to this kind of BS. "Don't be evil" only works if you aren't, well, EVIL.
- yonasb 15y agoLots of possibilities, but if Google isn't behind this then they should have been close enough to the local biz communities to have heard of it and stopped it
- blhack 15y agoCrossposting this from another thread: Oh, malarky. Here. I set up a page at http://lab2.gibsonandlily.com/google.html http://lab2.gibsonandlily.com/google.html Then I ran it through google translation services. Here is the result in apache's log: 74.125.16.18 - - [13/Jan/2012:10:45:37 -0600] "GET /google.html HTTP/1.1" 200 327 "http://translate.google.com/translate_p?hl=en&sl=fr&tl=en&u=http://lab2.gibsonandlily.com/google.html&usg=ALkJrhjD8_-6RDHslD53lf9XsYx2_J1q4A http://translate.google.com/translate_p?hl=en&sl=fr&... "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.75 Safari/535.7,gzip(gfe) Look familiar? This one is tossing up windows NT, which is strange, but it doesn't seem like a stretch that some of the machines at google for stuff like this are running linux. The scam here isn't being done by google, it's just a run-of-the-mill scammer scamming and using google's name. Dearest mocotality. Turning on referals in apache logs and you'll see where on google this is coming from (if you care to). Here is how: in: /etc/apache2/apache2.conf (or whereever your apache configuration sits) change the "Logformat" option to the following: LogFormat "%h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined and then use option: CustomLog /var/log/apache2/access_log combined (or whatever log path you want). edit: to be clear, I'm not saying that they're using google translate, just demonstrating that "It came from a google IP!" reveals approximately nothing. edit2: it was pointed out in another thread that google is probably forwarding my user agent to the site that is being translated. This makes perfect sense (duh!) and closes the loop on the story. The scammers are using linux, which is consistent with both networks that they were seeing in their logs.
- JS_startup 15y agoA European Google VP just confirmed that it was not scammers or someone posing as Google, it was Google employees.
- orijing 15y agoHere's the original post: http://blog.mocality.co.ke/2012/01/13/google-what-were-you-thinking/ http://blog.mocality.co.ke/2012/01/13/google-what-were-you-t...
- deleted 15y ago[deleted]
- Tichy 15y agoI can't help laughing at all the people jumping to conclusions, quoting the "don't be evil" mantra and so on. Why not wait a little bit until the fog clears up? Disappointing that boing boing also coins the phrase "Google's Kenyan ripoff", as if they were already certain of their guilt. Will be interesting to see which news outlets will ride along with it for cheap thrills ("Goolge might be involved in a scam" etc). My guess is: most of them.
- majani 15y agoThe articles on the web are wrongly portraying Mocality as the little startup that could. Truth is, Mocality is a division of a 14 billion dollar media giant called Naspers. Not saying that Google is right or anything, but I think some people are getting fired up because they view this as a David vs. Goliath story, and it really isn't.
- mbaukes 15y agoBad google ....bad google!
- HMS 15y agoReminds me of Infospace back in the 90's. Same goal: dominate directory services. Started by an ex-Microsoftie. He made millions. But later the truth was revealed. His was not an honest business. Prosecutors moved in on it. No more Infospace. And some Wall Street analysts were banned from ever working on Wall Street again. See BusinessInsider. Google is giving away free websites. It's an easy way to get someone's information for their database, for only yhe cost of electricity and bandwidth. But then they will turn around and sell database access or services to others. Google is doing anything and everything to horde public information. That's fine. But then they want to charge others (businesses) for access. Good luck with that.