5 ms·
Thanks so much for sharing thoughts. In our case all our start pages are delivered via cloudflare's web workers so we are safe from dangling DNS records being p
by nstart 3y ago
Thanks so much for sharing thoughts. In our case all our start pages are delivered via cloudflare's web workers so we are safe from dangling DNS records being poisoned in that way.
In our case, Google's search console shows clearly what subdomain was guilty of the issue and that subdomain has been cleared now. Just really want to expedite the review process since Google's safe browsing has decided to block the entire domain instead of the offending subdomain :-/
I've submitted a review but they do say that reviews related to malware take a few days to process. This is a little hard to be honest given that it's not even our site that is hosting the malware. It was a page linking to google drive which is where the malware actually is hosted.
Hoping we get a response soon. Appreciate the supportive chime in.
- danpalmer 3y ago> since Google's safe browsing has decided to block the entire domain instead of the offending subdomain This does, unfortunately, seem to be the right call. There's no way to differentiate between the subdomain user being malicious, the domain owner being malicious, or the domain owner getting hacked. The only granularity of data available is that something under the start.page domain was distributing malware, so it makes sense to quarantine the whole domain. I hope this gets resolved quickly! I think the response is likely the correct one though.
- nstart 3y agoThis does make for a really tricky future though tbh. It’s trivial for folks to password protect a zip file containing malware and for it to be uploaded to google drive or Dropbox and then be linked to from a start page. If there’s a risk that each time that happens the entire domain could be blocked, that’s a lot of risk to try and mitigate. Especially seeing that many of the bigger providers also struggle to mitigate this kind of content despite having technical teams that are larger by an order of magnitude (or more).
- deleted 3y ago[deleted]
- Brian_K_White 3y agoBut why isn't google.com blocked? I see no reason to accept any rationales that don't apply to themselves.
- FFP999 3y agoWhy _would_ they block themselves? How would that be to their advantage?
- Brian_K_White 3y agoIrrelevant. Google does something and gives a rationale for it. If that rationale were valid, it would apply to everyone, including google. If the rationale does not apply to google, then it does not apply to anyone else. Please gooogle (if they let you) the concept "double standard".
- FFP999 3y agoMy point is not whether the rationale is valid or invalid: the point is, they're not going to do it. Is that wrong, in the ethical sense? Quite possibly. Do they care? No. Try googling the "Golden Rule" and you'll find a version that says "they who have the gold make the rules".
- Brian_K_White 3y agoYou had no point. Obviously the reason anyone applies a double standard is to advantage themselves. Congratulations on that insight. Can you next explain why anyone would steal?
- FFP999 3y agoOh, sorry, I thought you wanted to have a discussion, I wasn't clear on the fact that you just want to be a condescending dick. Have a nice life.
- lolinder 3y ago
- codetrotter 3y ago> There's no way to differentiate between the subdomain user being malicious, the domain owner being malicious, or the domain owner getting hacked. The only granularity of data available is that something under the start.page domain was distributing malware, so it makes sense to quarantine the whole domain. Or, you know, take into account the number of subdomains serving malware relative to the total number of subdomain. 1 out of 1000’s seems unfair reason. If it was 10’s or 100’s of subdomains out of 1000, then it makes more sense to punish the whole domain. But when it’s just a few, blocking the individual subdomains would be the better way.
- danpalmer 3y agoI empathise with the viewpoint, but I don't think you're thinking like a hacker about this. If safe browsing only blocked the subdomain when you have a certain threshold of "safe" subdomains, then attackers would just have a sufficient number of "safe" subdomains. Also how do you set the threshold? It's dependent on the market that the subdomain hosting provider targets, it's dependent on how good their moderation is, it's dependent on how quickly they get indexed, all sorts. Any solution needs to work for the case of malicious users, and needs to work at a scale of billions of pages, i.e. you can't use any human review or non-machine-identifiable information.
- codetrotter 3y ago> If safe browsing only blocked the subdomain when you have a certain threshold of "safe" subdomains, then attackers would just have a sufficient number of "safe" subdomains. If a website has a.example.com, b.example.com, foo.example.com, baz.example.com and they serve malware on baz, I’m saying put that subdomain on the bad list. If they serve malware from many subdomains, block the whole domain. The issue is that Google blocked a whole domain for just one bad subdomain. That seems too strict, and is very sad for all of the users of that domain.
- danpalmer 3y agoSo to distribute malware, I can buy a domain, set up a thousand subdomains, but only put malware on one of them. Then when that gets found I can move the malware to another, and so on, always being able to trivially work around blocking? At least when done at the domain level there's a cost involved for getting a new domain, which disincentivises the creation of many malware hosting domains.