My experience being blocked by Google Safe Browsing (2022)
brennan.io
brennan.io
Maybe its some kind of a Stockholm Syndrome variant of people using Chrome, but its definitely not healthy.
I don't actually believe that it has blocked that many people from being phished, and I doubt that all the entries on that list are malicious. It seems like a system that was designed by someone to simply get a pat on the back and a promotion, and then not touched again.
The point of hosting yourself, and not making another facebook/youtube page, or discord server, is really to be free of their terms, control, etc. Your browser itself blocking self hosted sites is such a malicious attack of that.
So this is a harsh punishment to all good people, and very weak punishment to all scammers and spammers.
I personally don't agree with, as I think modern browsers (not just Chrome) already do way too much handholding to a point that neutrality is inevitably lost.
I would go even further and say I don't like ideas like Firefox's/Brave's "Enhanced Tracking Protection" which blocks certain services with a handpick ruleset. Don't get me wrong, I block these trackers myself in uBlock Origin, but I don't like idea that a browser maintains an arbitrary list itself of what to block for the users.
The primary difference is in the messaging. Tracking protection is an opt-in feature, so the user is always aware of it. Additionally, at least in the forms I've encountered it, it doesn't outright prevent you from navigating to a website. At worst it breaks some sites, and you disable it, it's sitting right there in your browser navigation bar. Don't agree with some block? Overriding it is a click away.
Meanwhile, safebrowsing doesn't announce itself anywhere except when it hits you in the face with a giant red screen, specifically designed to inspire a sense of fear/dread. Override buttons are intentionally not outright presented to the user, and the toggles to completely disable the feature are tucked deep into advanced features where no muggle may reach.
It may sound stupid but this simple difference in optics radically changes the effect such a "manual blacklisting" feature has on its users. That said I agree it'd be nice to have more control over the tracking protection feature in firefox, e.g. by allowing custom lists, like uBlock does.
Yeah I don't mean they're the same thing.
I just don't like either (hence "go even further").
The data says the opposite, the safe browsing list is very effective* which is why many other browsers and systems use the same list to block malicious pages.
Google publishes data about the frequency of warnings displayed too: https://transparencyreport.google.com/safe-browsing/overview
* Of course it could be better.
Yes, blocking sites on a blocklist works very well. Whether those sites are legit or not doesnt matter at that point, to them, as they assume they all are malicious.
Do you see what I mean?
The fact that there was one false positive does not imply there are no true positives.
Google crawls malware on sites all the time: https://security.googleblog.com/2009/10/show-me-malware.html...
about:config is also walled off in every mobile Firefox build except Nightly - and even then, the "safe browsing" keys toggle back every time the app restarts.
Android WebView listens to the safe browsing list too, so you can have native apps open up with blood-red warning screens which is very uncomfortable on mobile.
Don't think I've ever seen a GSB warning page that _wasn't_ a false-positive. Google also still links out to https://www.stopbadware.org/ on some of their GSB webpages, even though the site has been dead for ages.
It has the feel of a system staffed _exclusively_ by robots. This isn't necessarily a bad thing (Google does an overall good job) but it has its blind spots for sure.
Self-hosters getting sucker punched offline for a day or two isn't the worst (it happened to me just the other week). I get it, overall it's probably worth the collateral. I also get that mobile should _probably_ be protected more aggressively. But if you are on Android, I don't think there's any way to meaningfully disable it unless you are root.
Firefox has no warranty to void. The warning message they make you view the first time you try to use about:config is simply lying to you. You might say "Oh well it's a well intentioned lie", but it's still a lie and there is no reason for this lie to even exist. The warning could be worded without this lie. It could simply say "You might break stuff if you continue" and that would be true enough and still scare off people who don't know what they're doing. So why the hell are they lying?
Here is a screenshot: https://i.imgur.com/RYPhiSe.png
This is Firefox 111.0.1 on Kubuntu.
The biggest influence are trusted security groups, where security teams of influential websites who trust each other can push or remove websites from these lists without any vetting from anyone.
This is also from there that you can download and share lists of unhashed passwords with e-mails (you know this warning "This password has likely been compromised", they need to source it from somewhere).
If the owner of a website complains, he is never going to win the appeal against a member of the special group.
So it's a very (useful and important) political game once your website becomes large.
This is also where you can informally directly communicate with agencies like FBI.
You (or anyone else) can get such a list (no emails, weak hashing better thought of as obfuscation) from Pwned Passwords[1]. (There used to be direct download links usable without the tricky downloader tool for pre-2022 archives on that page, but not anymore, huh. Take this[2,3].)
[1] https://haveibeenpwned.com/Passwords
[2] https://archive.org/details/pwned-passwords-version-8
[3] magnet:?xt=urn:btih:f9690a02f1accebbee2190b82cfee7b6968d384c&dn=pwned-passwords-sha1-ordered-by-hash-v8.7z
Sneak in your competitor onto this list and they'll lose all of their traffic for as long as it takes them to convince someone at Google they've made a mistake.
It does work. You claim it doesn't because you think the resultant state of affairs is intolerable, but to subsequently claim it "doesn't work" because you don't like the outcome is simply wrong. You might as well claim that allowing people to buy pointy kitchen knives "doesn't work" because sometimes people stab each other and you think murders are simply intolerable. But the reality is that allowing people to have pointy knives even though some people get hurt does work, even though it doesn't produce an outcome the hypothetical you are happy with.
The problem with "think of the children" style arguments is they are always unbounded, and there is always something more controlling than what we're doing presently that could obstensibly make children even safer. Why not have browsers ship a whitelist of trusted websites, and forbid all others? That would be even safer, and if you oppose this then you're not thinking of the children. In fact I find the present state of affairs with bad websites being blacklisted simply intolerable, new malicious websites are permitted by default and that just doesn't work!
I think that regular people having unrestricted access to enriched plutonium also to have intolerable outcomes. Even if some people would be able to handle the substance safely (both to themselves and others), the ones that don't or can't will cause intolerable outcomes. And yes, this is a 'think of the children' style argument. I don't want the children (or adults) to get radiation sickness. My hot take here is that it would be bad.
The vast majority of people, when they want to visit a website, go to Google, type in the name of the website, hit search, then click the top result.
Address bar? WTF is an address? WTF is a bar?
When the vast majority of people access websites through google.com, Google already decides where the people go.
Let's also not forget tech enthusiasts and professionals all advise using 8.8.8.8. Guess what: Google literally owns your DNS requests.
yes, it's true that google has a lot of power
google will remove you from that database fo bad websites but many other crap antivirus/security software will not automatically refresh it. So you will get report from customer A that the website is not safe, you then have to ask for what security program they use, then you need to find the form on those people website , it is not easy since a big securityu company might have different websites and support pages for different stuff so you need to find the right one to submit a form or open a ticket.
And one of this big security companies(unfortunately I do not remember which of them) had a bug on their form, when you submit it it would show an error, and that was for a few weeks.
If anyone works at this "security" companies, make the fuck sure that adding some website on the list should be as easy to also remove it from the list. if you use Google lists to add a site then use same fucking list to remove them, and make a fucking form that works.
You don't have to switch to a browser that ignores standard security mitigations. Just pick a different port for your service.
[0] I just tested Chrome, Firefox, and Safari.
[1] https://fetch.spec.whatwg.org/#bad-port
Always after sufficient investigation I find that the server has been broken into and there are some malicious PHP files sitting in some directory named '.system' or something similar.
Either that or the site allows user uploads and some user has uploaded some malicious JavaScript crypto miner or something.
On a mastodon server, it is hard to check all the content posted by all the users... But I'd bet somewhere there is something malicious that safebrowsing detected.
Some variants of this use cookies to only serve the redirect on the first click from Google, so if you're like "weird" and try again, everything looks fine the second time.
You can see the problem if you curl such a URL with Google as the referrer.
>Maybe I would feel better if there had been more transparency in the process. I was left to guess what Google thought was deceptive about my site.
https://law.hofstra.edu/pdf/academics/journals/lawreview/lrv...
However, if they detect you doing dodgy things like trying to cloak from their scanner (eg. giving bad content when given a browser user agent from a home internet IP range, but not when scanned by googlebot from a google datacenter), then they won't give the URL because that would leak what IP range they scan from to detect such cloaking.
I didn't realise Google safe browsing extended beyond google products. In a way, it makes me think about what other products have ties in to google.
https://news.ycombinator.com/item?id=33526893 ("Google Safe Browsing is blocking small Mastodon servers (snake.club)", 52 comments)
What if one doesn't want to forfeit their personal info to Google and sign / agree to to their policies and TOS?
The other stuff the author does with Google Search Console isn't necessary to get delisted.
Ah and sometimes they block scams.
Disabling it is behind dark patterns.
https://developers.google.com/safe-browsing/v4#update-api-v4
Literally 5 seconds on your favorite search engine could have stopped you from embaressing yourself.
https://www.google.com/chrome/privacy/whitepaper.html#malwar...
There's also a handful of other things they will send in the name of safe browsing, should they be enabled (I don't know if any are defaults): https://www.google.com/chrome/privacy/
(There are other similar mechanisms in Chrome as well, but it's not called Safe Browsing).
Mastodon is often used to distribute illegal content. If you self host you need to be ready to deal with this stuff. Like with self hosted SMTP server.
Not saying it is good or bad, just reality!
I'd agree with you if it had thousands of users, but not when the user count is 8. If you have 8 users on your SMTP server, damn easy to know with certainty if any of them did anything that might be considered malicious.
Law enforcement makes no difference between proxying, caching and storing indefinitely. At least not during all the steps that precede your hardware being seized.
Super easy to check every outbound click, every post published, every post received... Everything.