Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
gomox
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
16 ms
·
181.
▲
by
gomox
6y ago
Author here. Nothing was fixed, and the blacklist entry was cleared upon requesting a review, with no explanation.
182.
▲
by
gomox
6y ago
I am not misunderstanding anything, the fact that Google's own legitimate emails are flagged as phishing by their own filters is pretty telling about the reliability of the whole thing. The fact that you can come up with a plausible e
183.
▲
by
gomox
6y ago
Author here. I blocked the message in the screenshot because I narrated the first incident, but took screenshots during the second one, so the redacted part was referencing the first one in which, as described, our domain was cleared withou
184.
▲
by
gomox
6y ago
Author here. This is fascinating because I figured Google would definitely not ban cloudfront.net entirely and that's why they blacklisted the subdomain, but had this been hosted on our actual company domain, would we have been spared?
185.
▲
by
gomox
6y ago
This Cloudfront URL is not a customer visible URL, it's just referenced for some static assets (images/JS/CSS). The warning is shown instead of the actual SaaS app that is hosted on a "proper" domain, effectively ta
186.
▲
by
gomox
6y ago
It's only more secure from Google's blacklist hammer. No significant security is introduced by splitting our company's properties into a myriad of separate domains. This type of incident can be a deadly blow to a B2B SaaS com
187.
▲
by
gomox
6y ago
Is there a problem with doing it? I don't see how that would have helped in this case (if anything, it might have made things worse if Google decided to ban the 1st level domain, which they certainly won't do for Cloudfront.net).
188.
▲
by
gomox
6y ago
Not really, we own the entire Cloudfront subdomain, and Google is wise enough to not ban cloudfront.net entirely (now that would be an interesting day on the internet!). Having a CNAME in front wouldn't have made any difference.
189.
▲
by
gomox
6y ago
We spend a nice buck on Google Ads but the impact of getting your SLA-sensitive SaaS app blocked from the Internet is not compatible with reaching out to "someone who might know someone" at a 100K employee company.
190.
▲
by
gomox
6y ago
There is the expected privacy-surrendering API in which you send all your URLs to Google, and a more defensible one in which you download some sort of database to then query locally: https://developers.google.com/safe-browsi
191.
▲
by
gomox
6y ago
Author here. Yes, "serve" is the correct interpretation. It is not clear how Google gets ahold of offending URLs within blacklisted domains (like the article says, there were no offending URLs provided to us). Theories: * Obtained
192.
▲
by
gomox
6y ago
Author here - I haven't signed up for Medium's "pay the author" thing, which I think should make my content free to read and paywall free, is that not the case for you?
193.
▲
by
gomox
6y ago
Author here. The impacted domain was a Cloudfront CDN subdomain with random characters in it, not company.com (thankfully!). I doubt anyone signs up for Search Console on that type of domain that they don't even really own.
194.
▲
by
gomox
6y ago
Yes, this was a massive headache and we got very lucky with the timing of the incident and the blast radius of the system in question. I can't really say the issue is fixed so much as it is mitigated, hence the writeup to gain some awa
195.
▲
by
gomox
6y ago
Author here. I think it's too late in the cycle for that. This list is too widespread and anyone that is banned from it needs to immediately work around the issue somehow, therefore reducing the visibility of the problems.
196.
▲
by
gomox
6y ago
Author here. The second time around, the review confirmation email took around 12 hours to get to us.
197.
▲
by
gomox
6y ago
If your systems have any number of nines in their SLA, drafting a letter to Google's legal department is not a viable strategy.
198.
▲
by
gomox
6y ago
Author here. I'm not sure exactly how they actually decide to flag. Alternatively, Amazon might somehow be reporting files in S3 onto the Google blacklist. It would seem surprising, but it's the other possibility.
199.
▲
by
gomox
6y ago
Author here. It's not really rhetoric, I wrote the post because it's downright scary that your business of over 10 years can vanish in a puff of smoke because Google didn't bother to require an offending URL field in an inter
200.
▲
by
gomox
6y ago
Author here. The scary bit is that the blacklist is enforced client side in Chrome and other programs. Our servers and systems were running just fine when this happened, but if Google Chrome refuses to open your website, you're still d
201.
▲
by
gomox
6y ago
Author here. I don't think it's malice on their part, but their hammer is too big to be wielded so carelessly.
202.
▲
by
gomox
6y ago
Author here. That was exactly our situation with the impacted systems. We got lucky with the fast "review" and it happened late enough in the day that only PST customers were impacted meaningully. But still, quite frightening, hen
203.
▲
by
gomox
6y ago
Author here. That is definitely a good idea, and I recommend it. But that should not be the main takeaway. In our particular case, that was not found to be the problem (we think it was some sort of false positive), and there are valid reaso
204.
▲
by
gomox
6y ago
They don't even validate that blacklist entries actually contain an offending URL in the report. That's how much they care.
205.
▲
Google Safe Browsing can kill a startup
(gomox.medium.com)
1714 points
by
gomox
6y ago
|
543 comments
206.
▲
by
gomox
6y ago
There's a very strong point to be made that shorts in a rigged market are not a good idea, because squeezing the shorts is easy for the money printers (who plausibly have visibility over the liquidation price points), whereas the odds
207.
▲
by
gomox
6y ago
Lol. I hold precisely 0 BNB, and never did. These guys are execution masters, and the proof is in the pudding.
208.
▲
by
gomox
6y ago
Also Binance is quite simply a better exchange. It works flawlessly even when the market is hot. The quality of what they've developed and the speed at which they did it makes the average silicon valley team look like 7 year olds.
209.
▲
by
gomox
6y ago
Telegram
210.
▲
by
gomox
6y ago
3x the collateral, not 3x your yearly income.
More ›