Google Safe Browsing is blocking small Mastodon servers
snake.club
snake.club
Meanwhile, it's truly incredible how fully my site is now blocked off from the world. Firefox Android won't even let me access it, while Chrome hides the click-through underneath the "details" button. My friends who use the site are understandably concerned, but there's not much I can do. It's crazy how a false positive in one centralized system can impact my little piece of the fediverse.
> Now that you know you’re up against an automated policy enforcement AI, your goal is to look as much as possible like the training data. Unfortunately, this can be easier said than done since we do not have access to the training data.
> All is not lost, however. You have actionable info in the simple fact that what your app looks like now is not acceptable.
https://blog.pushbullet.com/2022/10/27/how-we-became-the-wor...
I still see an exclamation mark in mobile Chrome, but it looks like the big scary red interstitial is gone from most browsers I've seen. Perhaps it was enough different people reporting false positive? Or maybe a re-scan or manual action. Unclear but it's appreciated. Wish there was more transparency (ironic given the "transparencyreport" subdomain that URL is hosted at).
To me there's also some irony to the name "Google Safe Browsing", because IMHO that is an oxymoron -- browsing with Chrome is never "safe" for you because of the inherent/persistent violations of your privacy.
> not only because I assume they involve sending every URL I access to some kind of checking service
This isn't even remotely close to true.
> but also because I don't trust Google or Mozilla (or any other corporate software vendor) to be the arbiter of what makes a site "trustworthy"
Maybe you're a genius that can navigate the web with ease, but the reality is this feature has probably stopped millions or even billions of malware downloads and/or phishing attempts.
> Further, maybe I wouldn't have to worry so much about whether I can "trust a website" if they would stop turning their web browsers into full-blown operating systems?
Safe browsing is more about stopping people from accidentally downloading malware or falling for a phish, and very little about exploits in the browser itself which are few and far between.
https://security.googleblog.com/2022/08/how-hash-based-safe-...
https://security.googleblog.com/2020/05/enhanced-safe-browsi...
I'm not saying Google's Safe Browsing feature is immune to criticism, but when someone posts such blatantly false information it discredits everything else they have to say on the topic.
The Chromium project's Safe Browsing code is open source: https://source.chromium.org/chromium/chromium/src/+/main:com...
Of course given your "threat model" you are probably going to assume what's shipped in Chrome could be different from the open source code, but hey you are free to believe in whatever falsehoods you choose to believe in.
Just not in the way you are arguing about.
Also, even if you are using Chrome with the default search settings, there are lots of cases where it would matter. I suspect people would care a lot more about Google logging the URL for their Amazon search for <embarrassing thing they purchase> than when they typed `amazon.com` in their URL bar to get to Amazon.
Right, I'm sure the "Safe Browsing" stuff has prevented downloads of .exes that the user never would have run anyways (but I digress). Regardless, I still am not going to rely on shareholder-driven megacorps to decide what sites I can trust or not. They have proven they are not trustworthy themselves. To start, Google does things like hiding portions of the URL of the website you're on[0], making the web browsing experience even more opaque than it already is for the average user. In fact, Google has even engaged in phishing-like behaviour themselves, replacing an original website with their own AMP version, while showing the original URL[1].
Of course, this is all without even touching on the shocking depth of surveillance/tracking undertaken by Google.
Regarding exploits in the browser iself, in fact, the extremely massive surface area of web browser software is indeed absolutely a vector for malware. In this sense, Safe Browsing is a solution to a problem browser vendors created by nearly turning the web browser into an OS. By April this year, Chrome had already hit its third zero-day exploit[2] affecting its billions of users. By last month, it had hit its seventh[3]. Basically every month or two there's a new actively-exploited vulnerability in Chrome that may very well allow malware to be installed on your system by simply visiting a web page. If only trying to read some text on a website didn't mean risking having my home network turned into a botnet, or getting ransomware-locked...
[0] https://www.bleepingcomputer.com/news/google/google-chrome-h...
[1] https://www.androidpolice.com/2019/04/16/amp-pages-will-now-...
[2] https://www.forbes.com/sites/gordonkelly/2022/04/16/google-c...
[3] https://www.forbes.com/sites/daveywinder/2022/10/28/emergenc...
The reason for these UI changes is very simple: signaling secure vs insecure via a single character in a string that is meaningless to most people makes it essentially useless. Similarly making "secure" websites get a padlock is not helpful - it's essentially the same as a car engine light, except the engine light is surrounded by a dozen other lights, and it turns off when there's a problem. Unending amounts of research show that that kind of design means people will not notice problems.
This is not to say Google is a shining example of privacy engineering (see their core business model), but you're being incredibly dismissive of the work that their chrome and browser privacy engineering teams do.
IMO when a browser vendor does something like this, I'm not in a rush to sit there and read all their blog posts and give huge consideration to yet another megacorp imposing their will upon me. I just don't want my URL hidden, and I will definitely turn off features like this where possible. (n.b. I don't use Chrome, so its irrelevant for me)
Interesting. http "not secure", but I bet every piece of malware delivered to a user's machine via browser exploit was delivered on an https URL...
BTW, you make some assertions about the feature being more useful for average users -- can you provide any links/documents about this? I am very skeptical, though you are under no obligation to convince me (don't spend the time finding link(s) unless you specifically feel like it). I'd be curious, because I even feel doubtful that there's any solid measurement indicating hiding part of the URL has actually benefited anyone.
If you want to be a provider of url blocking you do the following:
1. Compile a list of "unsafe" urls (malware, phishing, cookie clicker, etc)
2. Generate a SHA256 hash of every url in (1)
3. Truncate those hashes to 32 bits (Because there are a lot of them :( )
4. Publish that list
If you're writing a client that wants to use these providers you do this: 1. Download the list published above
2. Before you load a url calculate a SHA256 hash of that url
3. Truncate that hash to 32 bits
4. Check your giant list of hashes to see if there's a collision.
5. If there is no collision you're done, and carry on the load as usual; otherwise
6. Ask the source of step 1 to give you the full set of hashes corresponding to the prefix from (3)
7. See if the hash from (2) is in the full hashes you get in (6).
8. If there is no collision then load the url, otherwise display scary warnings.
You can see that at no point does the url being checked go in either direction.Is it worth all this trouble just to get a Nx space saving?
Because if you just published the 256-bit hashes directly, you could skip the following steps entirely:
> 6. Ask the source of step 1 to give you the full set of hashes corresponding to the prefix from (3) > 7. See if the hash from (2) is in the full hashes you get in (6).
which are the parts that require an actual network call, infrastructure costs, and privacy issues. Speaking of which:
> You can see that at no point does the url being checked go in either direction.
You're not sending the whole URL, but in step (6) you're still telling the source that you're visiting a website belonging to a particular subset of hashes, hashes which the source knows the plaintext of.
I guess the question is exactly how large the set of 'unsafe' urls is. If it's merely in the billions, then (a) truncating the hashes will only get you a roughly ~4x space saving and (b) the 32-bit hashes you send will almost uniquely identify the website you tried to visit. If it's in the trillions, then it makes more sense.
Is there anything else on the entire internet so centralized?
This is quite similar to sending the url. Like there might only be a single site with that hash. Or there might be a handful of which one is far more likely than the others because it has 1000x their dau.
There are obviously ways that you could improve the privacy aspects of this - you could have two versions of the database hashing urls with slightly different initial conditions. A client can keep one up to date and only fetch the other when the get a collision. Assuming SHA256 is pretty good then we can just multiply the false positive probabilities (I think?).
And alternative would be for the client to request multiple regions at a time.
> has been reported as a deceptive site and has been blocked based on your security preferences.
I checked its settings page and saw no such preference, and about:config is a blank page there. So where is this alleged preference?
It's a product design failure to say "blocked because your configuration says so!" and then hide it from settings.
As for why they disabled it, no clue. Just bitter, disdainful speculation.
My server hosted at home got flagged. After 2 weeks of submitting appeals every 3-4 days it was finally reviewed and the flag was removed.
How did we let megacorps have so much control over who can access our websites?!
I turned off "Fraudulent Website Warning" in Settings and then I was able to access your site.