Google's Kenyan ripoff?
boingboing.net
boingboing.net
Oh, malarky.
Here. I set up a page at http://lab2.gibsonandlily.com/google.html
Then I ran it through google translation services. Here is the result in apache's log:
74.125.16.18 - - [13/Jan/2012:10:45:37 -0600] "GET /google.html HTTP/1.1" 200 327 "http://translate.google.com/translate_p?hl=en&sl=fr&... "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.75 Safari/535.7,gzip(gfe)
Look familiar? This one is tossing up windows NT, which is strange, but it doesn't seem like a stretch that some of the machines at google for stuff like this are running linux.
The scam here isn't being done by google, it's just a run-of-the-mill scammer scamming and using google's name.
Dearest mocotality. Turning on referals in apache logs and you'll see where on google this is coming from (if you care to).
Here is how:
in: /etc/apache2/apache2.conf (or whereever your apache configuration sits) change the "Logformat" option to the following:
LogFormat "%h %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined
and then use option:
CustomLog /var/log/apache2/access_log combined
(or whatever log path you want).
edit: to be clear, I'm not saying that they're using google translate, just demonstrating that "It came from a google IP!" reveals approximately nothing.
edit2: it was pointed out in another thread that google is probably forwarding my user agent to the site that is being translated. This makes perfect sense (duh!) and closes the loop on the story. The scammers are using linux, which is consistent with both networks that they were seeing in their logs.
edit: source is in boingboing article
The majority of comments, including the top rated one, were extremely dismissive, e.g., "malarky", and glossed or contorted the facts repeatedly to make it seem as though scammers could have easily been responsible for the evidence trail. It was always beyond unlikely that scammers could have access to a a Google corporate headquarters IP. Nor is, as was claimed in the BoingBoing comments, spoofing IP addresses something that can done without some vanishingly unlikely access to Internet infrastructure.
Did you read your gp? http://news.ycombinator.com/item?id=3461252 Google Translate seems to explain this pretty well.
The "evidence against google" here was razor thin, and we still haven't actually seen anything damning, just a sortof generic "we're looking into it and are pre-emtively sorry for what happened".
The last paragraph from the report [emphasis mine]:
The conclusion is hard to escape: Google -- or people working on its behalf, with its knowledge and cooperation -- took the numbers of tens of thousands of Kenyan businesses from Mocality's database, then fraudulently solicited money from them by claiming to be in a joint venture with Mocality. This seems to me to be outright criminal activity, and Google has a lot of explaining to do.
The paragraph from a Google VP [emphasis mine]:
We were mortified to learn that a team of people working on a Google project improperly used Mocality’s data and misrepresented our relationship with Mocality to encourage customers to create new websites. We’ve already unreservedly apologised to Mocality. We’re still investigating exactly how this happened, and as soon as we have all the facts, we’ll be taking the appropriate action with the people involved.
Looks like the conclusion Cory found hard to escape was exactly the right conclusion.
With all due respect to Doctorow, many on HN know quite a lot more about how the internet works than he does.
I know at least two ways to make arbitrary requests from a Google IP that haven't been mentioned on the comments to this story, and I don't claim any mad hackerz skillz.
I think the evidence pointed towards Google being responsible, and that's what I said. But I, and many others said to wait before drawing a final conclusion. I think that that's a reasonable approach.
It makes one wonder if people in the search term can manually mess around with the results to promote their own interests.
https://plus.google.com/u/0/115264064268941645500/posts/WfAL...
Have a look at: http://blog.mocality.co.ke/2012/01/13/google-what-were-you-t...
It says: "OMG!!!!! We received a call on the office line (the one listed on Mocality) from India stating that they were offering website services. I think the guy on phone was Deepak or something (it sounded almost like a scam) the guy said he was from Google Kenya blah blah, we refused the offer as we already have a site. Then few days ago I was just searching our page when I stumbled upon our site on .kbo.co.ke site…I mailed them n told them to take it down! aaaaaaaarg!!!!!!"
--- This is one of the small businesses contacted by 'Google'. SO it seems that after they got the call, they later saw their business website put up on kbo.co.ke (which is Google owned).
Doesn't this sound like further proof that this is Google sanctioned?
Kbo.ke publicly advertises web hosting for free, and by the sounds of it might be automatically populating the listings. So its a reasonable assumption that someone trying to charge Ks 200 per month for their[?] web hosting service might be aware of the potential to exploit Kbo's existence but isn't acting with their blessing...
I haven't checked, but it might be beneficial for Google to come out and say that they will never work with businesses directly to increase their online exposure outside of allowing the business to buy ad space through their official self-serve Adwords platform.
These new accesses were coming directly from Google’s network.
The IP address 74.125.63.33 made 17,645 requests (15,554 to BusinessProfile.aspx). Activity really kicked off on 22 December 2011, with 8 different user agents mostly running Chrome on Linux: The top 3 are :
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/16.0.912.63 Safari/535.7 11249 64.268982
Mozilla/5.0 (Ubuntu; X11; Linux x86_64; rv:9.0.1) Gecko/20100101 Firefox/9.0.1 4247 24.264412
Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.2 (KHTML, like Gecko) Ubuntu/10.04 Chromium/15.0.874.106 Chrome/15.0.874.106 Safari/535.2 1000 5.713306
Search for “tag=mo.request 74.125.63.33″ from 20 December 2011 to 9 January 2012. Found 17,049 requestsOf course, if it is corporate strategy, I suppose the big G could always get an employee to take the fall and tar them as a "loose cannon" for press purposes, but I guess I'm still clinging to the shards of "Don't Be Evil".
As for the corporate behemoth themselves, if they wanted a better directory of Kenyan businesses, then buying Mocality would hardly dent their acquisitions budget. It would certainly be a far more effective way of obtaining it than manual browsing and data collection via call centre operatives' personal gmail addresses. The idea the world's largest provider of free internet connectivity is looking to branch out into paid webhosting in LEDCs doesn't pass the smell test either.
I wonder though if the GAE data center (or part of it) is in Google HQ.
Moreover, as someone (EDIT: the article's author) mentioned in the comments of the article When an IP address registered to Google HQ's internal network is fed a unique phone number, and one hour later that phone number rings from someone who claims to represent Google, and repeats fraudulent claims that have been made for months from entities selling a Google product (that has no affiliate program), it is reasonable to infer that this is taking place with Google's cooperation.
Which is indeed suspect.
EDIT: as this comment below shows, it cannot be GAE: http://news.ycombinator.com/item?id=3460663
[1] http://wiki.opensocial.org/index.php?title=Introduction_to_m...
My bet? Google's statement will blame some third party contractors or a miscommunication. Massive damage control and fire fighting for the rest of the day.
The article is implying that the IP range was one that has been officially used by Google for international business in the past, making it the smoking gun in their accusation.
http://code.google.com/p/googleappengine/issues/detail?id=34...
Whether it's the work of rogue employees or a third party, we'll see.
for what it's worth, after i moved, google maps still showed that my old address was where my business was located. i filled out a short form saying it was not accurate any longer. there was no other contact information on the form, so i could have been anyone telling google a business had moved.
about a week later i received a call at my business number from an indian-sounding man asking if my company was no longer at my previous address. i could barely understand him, but he didn't say he was with google and once i confirmed that my business had moved, he hung up. shortly after that, my company was taken off of google maps.
so google is using manual labor, and they had to have done at least enough research to get my business phone number.
http://www.npr.org/blogs/library/2009/04/the_granting_of_pat...
What should Google do?
Obviously they shouldn't dodge the responsibility, but also they should try and repair the damage somehow.
What is an appropriate course of action for them? Paying damages? Transferring customers?
I can't think of any good options, really.
http://tech.slashdot.org/story/07/04/08/1824210/google-faces...
http://www.pcworld.com/article/130502/google_admits_using_ou...
I'm unclear what you are saying - do you expect perfection from Google? I don't - mistakes happen. But I do expect them to fix things when they do something wrong.
I see this as the exact type of situation that, in the past, Apple has taken its time to respond to.
Rather than move in haste and make a misstatement, it's better to gather all the facts and be fully prepared for all of the obvious questions than to have to go back and restate something later on.
For those unfamiliar, Cory Doctorow is a professional writer of fiction. Like my favorite sci fi authors, he crafts stories about an "imagine if these conditions were true, how would that world work" starting point. His selection in news carries a similar bent, he likes a news story that would be interesting if true. It's generally best to enjoy them as that.
Take a moment, imagine a world where Google actually does this, then remember that it is probably fiction and get on with life until you see the story reappear with journalistic research behind it.
Edit: I see Mr. Doctorow updated with a note that he contacted google and google is preparing a response. +1 for journalism.
Someone fraudulently representing Mocality attempted to start a joint Google-Mocality venture. Google was misled, and no one at Mocality was aware of the fraud, meaning neither party is guilty.
Happens all the time with (semi-)legitimate firms acting as Adsense or Facebook Ads brokers. They often pull bait and switch tactics after you said you'd think about it.
You mean the User-Agent? It's referenced all over mocality's blog post http://blog.mocality.co.ke/2012/01/13/google-what-were-you-t...
Will be interesting to see which news outlets will ride along with it for cheap thrills ("Goolge might be involved in a scam" etc). My guess is: most of them.
The ripoff can be if google was trying to use their name which would effectively be phishing. I don't see them really pushing hard on that accusation.
Of course there are a dozen Google services that could let you serve a webpage from some Google IP, so router-level spoofing seems a bit farfetched for this scenario.
Pretty damn hard http://jobsearch.monster.com/search/sysadmin-on-the-backbone...