4 ms·
Thanks for the really useful tip to look into Chrome's debug log. First of all we see that this so called phishing detection filter's code is found at http://s
by miomyosky 13y ago
Thanks for the really useful tip to look into Chrome's debug log.
First of all we see that this so called phishing detection filter's code is found at
http://src.chromium.org/svn/trunk/src/chrome/renderer/safe_browsing/ http://src.chromium.org/svn/trunk/src/chrome/renderer/safe_b...
Second, this code and the logic it employs is really bull.
The world wide web is not a kiddie playground especially for a browser, and especially for a plugin whose's job is to detect phishing.
The way Chrome's anti-phishing works is to use several foolish measures that mean nothing in the real world and then 'punish' and push websites into oblivion when someone crosses these arbitrary sets of rules.
The way the plugin appears to work is to look at various things
* The type of URL (IP vs domainname, number of subdomains, size of the subdomain names, the strings in the Path URL)
* Whether the page contains form data
* Whether the page contains password input box
* Whether the page contains checkboxes/radio boxes
* Whether the page text contains some terms (in this case 'connexion')
* Whether page has links/images to other domains
and so on.
None of these are ANY indication of phishing behavior and if this set of quackery based logic is what we see from Google Chrome, where else can we go to really feel safe and protected?
- hiddenfeatures 13y agoAs much as I can understand you being upset that Chrome shows a warning for your site, I don't think that the approach they are using is unreasonable. I'd take bets that those criteria show a correlation to phishy sites. Especially if you combine those metrics together. Is it perfect? No. Does it produce false positives? Yes. Is it beneficial on average? I think so. PS: Since you have found the relevant file in the open source project (or 'kiddie playground' - as you like to call it), why don't you supply a superior implementation with less "foolish" measures?
- Filecloud 13y agoYou are trivializing the underlying issue here. If the same thing happened in a physical world it will be a high profile public defamation case. Browser is the window through people sees the world. That’s the reality we live in. In our target market, Google chrome holds 40% market share. Because of its stupid categorization, in one stroke Google harmed our reputation and the reputation of companies we serve. It is not a simple browser compatibility issue. Google chrome is telling the world our software is phishing software while we are not. What is the recourse here? We don’t care what Chrome’s algorithms are. But the results are not factual and it harms our business. "One cannot escape saying hey that is our algorithm. We don’t do evil…" Remember.
- hiddenfeatures 13y agoBelieve me, I am empathetic to the pain this is causing you. I can understand the anger you are feeling. But I don't think that I am trivializing things. The fact is, that phishing sites are causing a real pain (as in millions of dollars lost by the victims, hundreds of thousands of computers becoming zombies, etc). All major browsers are trying to mitigate these risks by implementing phishing & malware filters. None of these implementations are perfect (you probably know a bit or two about bugs in software development). But on average these filters have a positive ROI - especially for the target market (which is Joe WebUser and sadly NOT your company - or mine for that matter). The costs of a false positive ("I'll go & find that information on another site") far outweigh the costs of a false negative ("I put my login+password into this legitimate looking website and now I can no longer access PayPal").
- miomyosky 13y agoMy point is that with an browser (similar to an OS), they cannot take things lightly and flag things left and right based on "heuristics". With great power comes great responsibility. My point is that if you are going to design a system to identify bad websites it better be fail safe otherwise it is going to cause a lot of hurt. The message shown in the browser for a phishing warning is the same as when a website has an invalid SSL certificate. The first is vaguely accurate, the latter is 100% accurate and no one is going to argue if the warning is needed. Both show the mind chilling warning no sane user will click through. I am more interested in removing the phishing filter than in writing a phishing filter. Anyways, with a 'closed' server component also in the mix, what option is there to provide any implementation. IMHO, I think that doing things for the 'benefit of most' will lead to eroded freedoms for all over time. PS: 'Supply a better implementation' is not an answer to writing poor code and hoisting on the world.
- markshepard 13y ago@hiddenfeatures Yes. Lets apply this everywhere. Lets electrocute folks based on "heuristics" because there are no other way to find out "bad guys". It is nice to act as an arbiter and spout philosophy isn't it? If you really do think that there is no other better way then I guess there is no more point arguing about this.
- mayanksinghal 13y agoOr let everything go through until and unless we are 100% certain that it shouldn't. Like, if someone is pointing a gun at you, do not duck because there is a chance he/she will miss. Because you know, exaggeration is truly a great tactic to convince other stakeholders.
- markshepard 13y agoEven though this looks like a troll attempt, lets try this. The problem is 1. No clarity on what constitutes a problem. 2. No way to officially contact to clear up a problem resulting in possible irreparable loss of business. So, if you insist on interesting and orthogonal "analogies".. please carry on.
- mayanksinghal 13y agoI was NOT trolling. I was pointing out that (A) Exaggeration is not a great debating tactic, in your case it was a clear slippery slope argument (B) It will not help in convincing the other stakeholders into being empathetic with your situation because you equated them to mindless psychopaths. > So, if you insist on interesting and orthogonal "analogies".. please carry on. If it was not clear, I was trying to describe a possible issue with you "lets apply this everywhere" argument. The two arguments you just put forward, are nowhere close to what you said in the comment I replied to. Yes, there are issues with the current implementation of it, which is very similar to how spam detection/prevention systems work at the moment. Yes, there can be improvements to it. There can be improvements to everything. Yes there is high chance of false negatives in the current system, but this is a problem where false positives can be just as disastrous. If we cannot agree with that, then do not think it is worth continuing this discussion. Now if you check the top comment on the thread, I believe the communication channels have already been set. They did not work for you as promptly as you would want them to, that's a different issue. But there definitely exists an official contact to clear up the problem - your colleague seems to be aware of it. The lack of clarity of the reasons has been marked as intentional and has been discussed elsewhere on the thread. It was poor of me to use snark instead of clearly stating my stance, but the stupidity of analogy that you are blaming me for, is not much different from what I was trying to mock.