6 ms·
Any Gmail person can tell me why Gmail is tolerating Gmail phishing emails that use Google's own services (e.g. https://storage.googleapis.com/savelinge/ https:
by dvh 5mo ago
Any Gmail person can tell me why Gmail is tolerating Gmail phishing emails that use Google's own services (e.g. https://storage.googleapis.com/savelinge/ https://storage.googleapis.com/savelinge/... ?
More info here: https://news.ycombinator.com/item?id=46665414 https://news.ycombinator.com/item?id=46665414
- dewey 5mo agoThe same reason spam filtering is hard. It's not possible to catch every misuse of the service without too many false positives.
- dvh 5mo agoThe same 5 urls has been used for 3 months
- dewey 5mo agoThat doesn't really change the fact that it's hard. Do you know how many full movies are on YouTube that infringe on copyright? How many pirated streams are hosted on S3? How many piracy sites are behind Cloudflare. It's just very hard to police at scale and if something is flying below the radar it will be there for a while. They probably spread out their assets over many accounts, or even use misconfigured buckets with write permissions to drop some files in there.
- unholiness 5mo agohttps://xkcd.com/277/ https://xkcd.com/277/
- hydrogen7800 5mo ago"It's so easy when you don't know how". I'm not sure if this phrase is in common use at all, or if I just misheard it once and attributed it to mean that when the details of a problem aren't obvious, its easy to conclude the solution is simple. "Why don't they just do ___?"
- irishcoffee 5mo agoAt the companies I've worked at, I refer to this as the "well, can't you just...?" Yeah, I can "just" after I "just" do A, and B, and C, and D, and E, and F, and G. Drives me batty on top of being insulting. "Surely you realize I thought about that weeks ago, and if it were that simple, we wouldn't be having this conversation." But hey, I get paid every 2 weeks.
- spaqin 5mo agoI kinda lost the plot here - what does piracy have to do with spam and phishing?
- BLKNSLVR 5mo agoGoogle's inability to scale their services should be a regulatory issue. If their platforms (Gmail, YouTube, DoubleClick) are being used to launch scams, they're failing at scale and governments are failing at legislating / regulating. The only way to use Google services somewhat safely is with hefty ad (and the rest) blocking. All this ID and surveillance and privacy invasion and metadata retention and yet all these scams only seen to grow. It never seems to end up protecting anyone deserving of protection. I wonder what it's all been in aid of...
- intended 5mo agoTrust and safety doesn’t have the same maturity as cyber security. Things like trend and signal sharing between tech firms doesn’t exist, except through informal slack channels and WhatsApp groups. The first major safety conferences for trust and safety came together only in 2023.
- csomar 5mo agoThis argument actually doesn’t work in Google/your-point favor since finding pirated content on Google is now practically impossible. The reality is, Google is driven strictly by incentives and there are no consequences for letting spam/scams run wild vs. pirated content which gets automatically removed when a DMCA notice is received.
- JakkTrent 5mo agoThere is 100% pirated content on Youtube - not too much from Hollywood and you won't find anime on it - but if you watch foreign language media, there is very often the Official account and then like 4-5 others just blatantly providing the identical content, which is promoted alongside the legitmate content, so its fairly easy to start watching legit stream and find yourself not watching legitimatly a few episodes later, playlists are huge to prevent that. The problem with this is the piecemeal enforcement all but proves they only care about stuff they get a cut of and that fact became more clear to me recently when I was watching a random drama made in Asia that I wont name due it being one of the best historical and educational shows I've ever watched - but there was a scene (this was made in the 90s btw) that was entirely innocent, not sexualized - it was done humorously, but I'm not a pdf file either so - anyways, there were fully naked children, with absolutely no censorship, on Youtube - 100% long enough to be noticed by their trackers - they obviously just are not reviewing certain content, at all. I don't care about piracy at all - I'd still use Youtube if it was the primary source for pirated content, the idea that there may be some obscure content, that seems totally fine, in a language nobody really uses - except for Epstein types, if ever that was discovered - that Youtube had become a haven for pdf files bc of lax application of standards - I would want Youtube split away from Alphabet and force sold on the cheap to a more responsible owner (like Tiktok minus the responsible owner part) - plus an enormous fine. I didn't believe that such content could exist at all on the platform - until I literally saw with my eyes that it obviously can.
- cyanydeez 5mo agoOk, it's even harder when you do not care because they people are either freeloaders or locked into your solution because it's a customized mess.
- estimator7292 5mo ago[dead]
- benoau 5mo agoIt's probably possible to catch a lot more of them, but why look too hard when you can hide behind section 230 immunity and pocket ginormous profits instead of spending on this lol...
- torben-friis 5mo agoSpam is getting horrible lately. I get all sorts of new techniques including: - using legitimate sites to bypass filters, like sending you a bill through a legitimate bill-creation site - pretending to be a tracking service for something you supposedly ordered, then over the course of days pretending the package got lost on the way and offering a discount code for the 'purchased' amount, expecting you to use it on their phising site. Gmail not only fails at spam classification, they classify these messages as important and nag you with first priority notifications and summaries.
- traviswingo 5mo agoI can’t prove it, but it feels like the world recently decided that spamming/scamming is acceptable, so the number of spammers/scammers has increased dramatically. The number of spam calls, texts, emails, iCloud account unlock requests, etc I’ve received in the last year is insane.
- abirch 5mo agoIt's AI that's doing a lot of it. For a lot of spam, scammers would want to exclude anyone who may not fall for the scam due to the costs associated with dealing with people who won't pay you. Now that AI decreases the need for a human scammer to scam, expect them to start to widen their scam nets.
- BLKNSLVR 5mo agoThe decline had been happening long before AI hit mainstream. It's been a _lot_ of years that I've hesitated to answer calls from unknown numbers.
- afavour 5mo agoYeah this feels like one of those cases where the term "AI" gets broadened out so far it becomes meaningless. This stuff is automated. The ability to automate spam calls (using the same form of APIs developers love, like Twilio) make it absurdly easy for one person to set up a spam machine. No AI required.
- Aboutplants 5mo agoIt follows the same logic as physical junk mail. We accept the fact that we will receive junk mailers in our physical mailbox and just toss them out.
- 000000000001 5mo agoYeah, but junk mail funds the USPS, without it Republicans would've killed the postal service long ago, See the Pension requirement that they pushed in a vain attempt.
- mminer237 5mo agoThere is a big difference between advertising your services and trying to literally steal people's money.
- xp84 5mo agoThis is an underrated distinction. Sadly, the line is so much more blurred now than even when I was a kid in the 90s. There are so many businesses now which exist mainly to cheat you, operating at the very edge of what’s technically legal, and relying on their customers not really understanding the full terms of the deals they’re agreeing to. It’s sickening.
- dotancohen 5mo agoCan you post an example? Thank you.
- redsocksfan45 5mo agoEvery payday loan company, the "we buy houses for cash" companies, rent-to-own companies, title loan companies, the entire buy-now-pay-later ecosystem, the timeshare industry. Seriously dotancohen, get your people under control.
- dotancohen 5mo ago
- tclancy 5mo agoAh! I have no answer for it, but am happy, Virgil-like, to now have a theory why the same stupid, obvious "Costco" spam from an @gmail.com address keeps showing up in my inbox no matter how many I mark as spam.
- deng 5mo agoGoogle is fine with everything if it's their service. I've completely blocked *.bc.googleusercontent.com, because it's basically used as a spam farm for years now, but Google couldn't care less as they apparently can't be bothered to even slightly inconvenience their compute engine users.
- deaton 5mo ago[dead]
- Barbing 5mo agoThey seem unable to prevent phishers from using their acquisition, AppSheet, to send relatively convincing, targeted (to nobodies like me) emails that make it to primary inbox. So, pleas ignored, forward these recruitment scam emails to the legal/fraud/phishing teams of the impersonated brands. For a company without the appearance of caring (in my opinion), perhaps law firm letterhead can encourage necessary prioritization.
- brandonwindson 5mo ago[dead]
- gowld 5mo agoThat page looks phishing-related but doesn't appear to directly serving abusive content? Does that XML get processed by a mailreader? <ListBucketResult xmlns="http://doc.s3.amazonaws.com/2006-03-01 http://doc.s3.amazonaws.com/2006-03-01"> <Name>savelinge</Name> <Prefix/> <Marker/> <IsTruncated>false</IsTruncated> <Contents> <Key>winbridge.html</Key> <Generation>1775478745793193</Generation> <MetaGeneration>2</MetaGeneration> <LastModified>2026-04-06T12:32:25.871Z</LastModified> <ETag>"3616712a8e68db66062a3f514b5fb7c8"</ETag> <Size>626</Size> </Contents> </ListBucketResult>
- dvh 5mo agoI shortened url to remove PII. Full url causes few redirects before landing on scam site.
- zzo38computer 5mo agoI am guessing that service returns the XML file as a directory listing; the file called winbridge.html does exist in that directory (and contains a JavaScript code to redirect to a different URL). (Another comment said they shortened the URL to remove PII (which I am guessing was in the fragment part of the original URL; the JavaScript code makes a new URL from randomly selecting a domain name (even though the list has only one) and appending the fragment part as the path), so I suppose the file name was removed and then this directory listing is the result.)