10 ms·
Ask HN: Google Chrome heuristic warnings pose threat to our business
Many businesses use our Enterprise File Sharing Product called FileCloud (http://www.tonido.com/filecloud). Think of it as a self-hosted alternative to Dropbox. With the latest Chrome update, the browser is showing phishing warning (http://patch.codelathe.com/foruser/phish_1.jpg) with our installations. The warning is not based on the domain and it appears in our different customer installations. It has to be heuristic based because it generates warning even on a debug/local webpage. The chrome browser heuristically decides our login page as a phishing page and gives the wrong warning. We are trying to find if there are any published "guidelines" as to legitimate web pages should NOT be doing to trigger these? Either there should be clear methods to resolve these warnings or Chrome should avoid doing this blanket-so-called-protection racket.
Because of Google’s missteps, our reputation as well as customer reputation got a hit. We have spent countless hours in our resources to see what is going on and all thing points to heuristic decision making by Chrome browser. There is no way to contact Google Chrome team to resolve this issue. We have lost few large deals. Now all our support team is pretty much focused on this issue and fielding queries from our customers.
Since our UI code (Developed in GWT) is common between our Enterprise and Consumer product (Tonido), if we this error start appearing in our consumer version (half a million users) it is an EXISTENTIAL RISK to our company that we have built over 5 years.
We have 2 questions.
1. How to get in touch with Chrome team and solve the issue?
2. Are there any legal avenues or precedence to force Google to take action and claim compensation for lost business?
Please provide us with your suggestions.
P.S: It is happening to our software today. It may happen to your products tomorrow.
- fotcorn 13y agoHave you tried to produce a minimal version of the software to show the problem? If not do it now and post it on the Google Chrome Bug tracker: http://code.google.com/p/chromium/issues/list http://code.google.com/p/chromium/issues/list Other contact forms: Mailing Lists: http://www.chromium.org/developers/discussion-groups http://www.chromium.org/developers/discussion-groups IRC Channel: http://dev.chromium.org/developers/irc http://dev.chromium.org/developers/irc
- gcb0 13y agoThat failing, get money for them blocking a competitor. before downvoting, take the time to explain how this would be different from old good Google suing Microsoft just for not making their product use Google easier than it already allowed.
- jsun 13y agothis is HN, you can't get downvoted:)
- emhart 13y agoI'm assuming some people are downvoting you to help disprove your point, but to be clear, once you've reached a karma threshold you can downvote.
- deleted 13y ago[deleted]
- gcb0 13y agoYOU can't downvote because you don't have enough "karma" and i'm getting downvoted alright, and without any attempt at fulling my request, no less
- retube 13y agoHmm that sucks. All I can suggest is you systematically remove content from the page until the error stops - this way perhaps you can identify the offending content (or combination of content which aggregates to an "offence")
- hitchhiker999 13y agoYou may also be interested in this article: https://medium.com/surveillance-state/32ba2b38c219 https://medium.com/surveillance-state/32ba2b38c219
- Filecloud 13y agoYeap. That summarizes our issue. The next step for us is to hire PR and go public. We are spending 1500$ per month on google adwords now. May be use that money to get some legal help. In a physical world it is a clear public defamation case.
- ccleve 13y agoGet a lawyer. Send a demand letter to Google's corporate counsel that they stop falsely identifying your software as dangerous. Fax, FedEx, and email it. If they don't respond in 24 hours, have your lawyer file an emergency injunction in federal court. Google's failure to respond to issues like this is appalling, and it's probably going to take a lawsuit and public embarrassment to get them to stop being evil.
- toddmorey 13y agoExternal dependencies on that page? Anything being pulled from a domain that might have made the list? It might not be specific to your page, it might be on a JS library you are including.
- Filecloud 13y agoWe checked all that. 3 guys are working full time on this issue. The irony is we use GWT for our UI which is used by many google products. when we search in web the closest issue we found if from a joomla forum: http://forum.joomla.org/viewtopic.php?f=621&t=802284 http://forum.joomla.org/viewtopic.php?f=621&t=802284
- tjohns 13y agoThis was precisely my thought. If it's happening even on a local staging server, it's highly likely that this is being caused by a third-party dependency somewhere in your site. I'd start by looking at any JS libraries you're loading.
- blauwbilgorgel 13y agoReport an incorrect phishing warning at http://www.google.com/safebrowsing/report_error/ http://www.google.com/safebrowsing/report_error/ . If you received a phishing warning but believe that this is actually a legitimate page, please complete the form below to report the error to Google. Information about your report will be maintained in accordance with Google's privacy policy. Try posting a thread on the Google forums and decribe the false positive in neutral terms: http://productforums.google.com/forum/#!forum/chrome http://productforums.google.com/forum/#!forum/chrome Use Google Webmaster Tools for your product site and check for issues: https://www.google.com/webmasters/tools/home?hl=en https://www.google.com/webmasters/tools/home?hl=en Try to come up with a reason why this may not be a false positive. Perhaps you have trademark issues? etc. More info: http://blog.chromium.org/2008/11/understanding-phishing-and-malware.html http://blog.chromium.org/2008/11/understanding-phishing-and-... This includes the URL of the website you are visiting, as well as the URL of any included resources (such as included JavaScript or Adobe Flash movies) https://support.google.com/chrome/answer/99020 https://support.google.com/chrome/answer/99020 https://www.usenix.org/legacy/event/hotbots07/tech/full_papers/provos/provos.pdf https://www.usenix.org/legacy/event/hotbots07/tech/full_pape... [pdf] The Ghost In The Browser. Analysis of Web-based Malware (a paper to make this post interesting to others)
- Filecloud 13y agoUnfortunately we have done all that. It is not a domain issue or safe browsing issue. The best analogy here is let us say lot of customers run a default drupal or joomla site under their domain and Google chrome show these sites as phishing site.
- blauwbilgorgel 13y agoPlease host the HTML source of a page that throws a warning somewhere. And mention the version of Chrome that gave the warning ( chrome://chrome/ ). Also can you post the thread on the Google forums with a proper bug report? I can't find it.
- markshepard 13y ago
- smtddr 13y agoHey there, I actually worked for a "competitor" of yours at one time in my career. We had a very similar problem, turned out that one of our users shared(probably unknowingly) a file containing malware and probably posted it to their twitter or facebook(we had that feature built-in at the time). This URL was caught by a very popular anti-virus company, which posted it on their site. I guess the software phones-home to get all copies out there in sync. So for awhile, anyone with this anti-virus software would get blocked on our site's homepage for malware and/or phishing attempt. My somewhat-educated guess would be that a costumer of yours has hosted something that Google(or whatever Google uses to get its info) considers shady. Our solution was first to contact the company to get delisted, then I think we ended up changing domains for the sharing stuff. Similar to dropbox's dl.dropbox.com for any sharing stuff. Or maybe we did some kind of URL-shortener. But somehow, a change to the URL's domain of anything that hosted user-generated content was the solution to the problem, AFAIK.
- Filecloud 13y agoHi, Our software is little different. It is a self-hosted software. It is hosted by our customers under different domain names in their infrastructure. So it is not the same domain or URL. For Example: Customer 1: fileshare.abcplumbing.com Customer 2: dataanywhere.peterlawfirm.com Thats the real problem here. It affects our customer installations under different domains. To some extent, we are fine if google is blocking one domain because somebody in the domain is sharing malware. The issue here is different.
- smtddr 13y agoAh, we did have a feature sorta-kinda like that too... if you had your own domain you login on our webUI, enter in your own domain and if no other user had it, you'd get it. Then, you add a CNAME record pointing to us and we'd do certain things when we received the request depending on settings the customer provided during the domain-name setup. I think we used the Referrer in the request-headers. So I could point portal.mypersonaldomain.com -> CNAME -> whateverIchoose.yourcompetitor.com and get a custom page, kinda. If we had a customer use a domain that CNAME pointed to us and had a history of questionable content, I wonder if Google would follow the CNAME direct to see where it's going and incorrectly(or correctly?!) decided bad stuff is happening, thus marking the CNAME target as bad. Just my random'ish guess. Hope you find the issue soon.
- alternize 13y agoi'm not seeing the phishing warning when visiting the url from the screenshot using chrome v29.0.1547.0 dev-m. maybe you caught a malware on your computer. did you try from different machines?
- Filecloud 13y agoWe have checked with one of the latest beta builds. In that build it didn't show the warning. It happens with the live chrome version. The issue is much more complex.
- coverband 13y agoOn a Mac with current Chrome (Version 27.0.1453.116) hitting your sample dev URL, I don't get any errors at all...
- tteam 13y agoThis specific instance in the screenshot has been fixed (this is the second time). Basically, in this specific instance if the "Login" button is changed to localize to a specific keyword "Connexion" as part of french translation, it shows up. No other keyword triggers it.. and no way to find out what the heck chrome wants. It is like playing proverbial whack-a-mole. Every update of chrome can potentially change their "heuristic" that thinks it has "found" a phishing attack.. and we have to scramble to see what the heck caused it and fix it. This would be funny if it wasn't so detrimental to a business. I will get the dev to recreate this on dev1 and post it.
- markshepard 13y agoIt shows up now on Version 27.0.1453.116
- blauwbilgorgel 13y agoNo warning on 28.0.1500.63 m and 30.0.1552.0 canary either.
- deleted 13y ago[deleted]
- pyvek 13y agoI opened http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html (URL in your screenshot) in Chrome (latest) but I'm not getting any phishing warning.
- deleted 13y ago[deleted]
- driverdan 13y agoSame here, latest Chrome 28 beta.
- vigneshv_psg 13y agoSame here. I'm in Chrome 28 beta.
- Filecloud 13y agoThe issue is much more complex. It appears in the latest live production version. if any of you are part of Google chrome team we can show you.
- ctz 13y agoI opened the same URL and did get a phishing warning. Version 27.0.1453.116 m on Windows 7 x64.
- swalkergibson 13y agoI received the warning. Chrome 26.
- markshepard 13y agoIt has now been patched to throw the error. It shows up now on Version 27.0.1453.116
- mjcohen 13y agoNo warning with Version 27.0.1453.110
- 13y ago
- grey-area 13y agoDo you have an example page where this happens, like a demo login page? If so it'd be a good idea to post it as at the moment there's no way for us to see what you see and no way for people to help you work out what is wrong.
- markshepard 13y agoWhile I think chrome having strong anti fraud protection built in is nice, the fact that there is no way to understand what constitutes "correct behavior" and no clear way to get clarification is appalling. It is essentially engineering how things should be developed, which still could be tolerable if there are guidelines. If an average user sees a red page indicating risk to a page, then that site/page is essentially killed.
- mgevans 13y agoI just ran into this with some pages in our product as well. If you run Chrome with '--enable-logging --v=2' the chrome_debug.log will contain messages from the phishing classifier (search for 'phishing_classifier'). I was able to tweak the wording on the page to drop the score below 0.5, but there are other features that may be causing your problem. You may need to restart the browser between edits, as it seems to cache the classifier results by URL. It also skips classification for hosts with private IPs, I had to jump through some hoops to test.
- Terretta 13y agoFor offering a concrete self-help approach among a sea of speculation, and sharing that text on the page changes classification score -- I hope you get upvoted more.
- markshepard 13y agoVery nice! This will actually be very helpful in tracking this. Thank you.
- markshepard 13y agoHere is the output snippet. Basically some "algorithm" thinks it has found phishyness with some score above 0.5 and flags it. No clue as to what caused it (We know that it can be triggered by simply changing the name of the "Login" button to "Connexion"!! Must be nice to dream up some "algorithm" and push it out.. sigh [5570:1799:0701/133949:VERBOSE1:client_side_detection_host.cc(221)] Instruct renderer to start phishing detection for URL: http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html [5579:1799:0701/133949:VERBOSE2:phishing_classifier_delegate.cc(238)] Not starting classification, no Scorer created. [5579:1799:0701/133950:VERBOSE2:phishing_classifier_delegate.cc(238)] Not starting classification, no Scorer created. [5570:1799:0701/133954:VERBOSE2:client_side_detection_service.cc(255)] Sending phishing model to RenderProcessHost @0x7aa18a00 [5570:1799:0701/133954:VERBOSE2:client_side_detection_service.cc(255)] Sending phishing model to RenderProcessHost @0x8043d620 [5579:1799:0701/133954:VERBOSE2:phishing_classifier_delegate.cc(283)] Starting classification for http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: UrlTld=com = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageImgOtherDomainFreq = 0 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: UrlOtherHostToken=dev1 = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: UrlPathToken=html = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageLinkDomain=tonido.com = 1 [5574:1799:0701/133954:VERBOSE2:phishing_classifier_delegate.cc(275)] Not starting classification, last url from browser is , last finished load is chrome-extension://jpjpnpmbddbjkfaccnmhnkdgjideieim/background.html [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: UrlPathToken=core = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageTerm=password = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageHasTextInputs = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageExternalLinksFreq = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageHasPswdInputs = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageSecureLinksFreq = 0 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageTerm=connexion = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: UrlDomain=codelathe = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: UrlPathToken=index = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageTerm=account = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageHasForms = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageNumScriptTags>1 = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier.cc(192)] Feature: PageNumScriptTags>6 = 1 [5579:1799:0701/133954:VERBOSE2:phishing_classifier_delegate.cc(211)] Phishy verdict = 1 score = 0.548927 [5570:1799:0701/133954:VERBOSE2:client_side_detection_host.cc(447)] Feature extraction done (success:1) for URL: http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html. Start sending client phishing request. [5570:1799:0701/133954:VERBOSE2:client_side_detection_host.cc(415)] Received server phishing verdict for URL:http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html is_phishing:1 [5570:1799:0701/133954:VERBOSE2:client_side_detection_service.cc(255)] Sending phishing model to RenderProcessHost @0x802b7ff0 [5580:1799:0701/133954:VERBOSE2:phishing_classifier_delegate.cc(259)] Toplevel URL is unchanged, not starting classification.
- Filecloud 13y agoA request to YC mods. It seems like this post is getting flagged. This issue is really a big risk for our startup and we will appreciate if you allow the post to get the visibility it deserves.
- olalonde 13y agoIf you are lucky, Matt Cutts (https://news.ycombinator.com/user?id=Matt_Cutts https://news.ycombinator.com/user?id=Matt_Cutts) will read this and investigate with the Chrome team.
- daave 13y agoI work at Google but not on this product.. so I escalated your issue to the team that works on the anti-phishing classifier. They're looking into it now, and put you on a temporary whitelist in the mean time (should take effect within 30 mins).
- miomyosky 13y agoIt would be nice if the antiphishing filter also gave some good way for web developers to figure out why this happened and what to do to correct this.
- packetslave 13y agoThis is harder to do than you'd think, without also giving the bad guys a cookbook for "here's how to avoid detection"
- Filecloud 13y agoThank you so much. Much appreciated. We will be more than happy to provide additional information or even access to the server if needed.
- Filecloud 13y agoJust one more thing. Since our product is self-hosted by our customers under their own domain, white listing just our development domain is unlikely to help our cause.
- ISL 13y agoIn fact, whitelisting would tend to hurt your debugging efforts.
- markshepard 13y agoThe whitelisting already active for this domain now. Trace showing server overriding the "Phishyness" verdict of the client [5760:1799:0701/150256:VERBOSE2:phishing_classifier_delegate.cc(211)] Phishy verdict = 1 score = 0.548927 [5751:1799:0701/150256:VERBOSE2:client_side_detection_host.cc(447)] Feature extraction done (success:1) for URL: http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html. Start sending client phishing request. [5751:1799:0701/150256:VERBOSE2:client_side_detection_host.cc(415)] Received server phishing verdict for URL:http://dev1.codelathe.com/ui/core/index.html http://dev1.codelathe.com/ui/core/index.html is_phishing:0
- minm 13y agoWondering. what kind of phishing score Google chrome phishing classifier will allocate for pages with Google Ad words? Any idea?