Google marked https://old.reddit.com/r/programming/ as unsafe
transparencyreport.google.com
transparencyreport.google.com
A few years ago it marked my company's entire domain as unsafe without any reason. Any human would have been able to tell the flag was incorrect, but "algorithm says no".
There is no team in Google to escalate to, no team managing this service, and no way to get an incorrect flag lifted in anything like an acceptable timeframe.
In the meantime, Gmail just silently decided to drop any email I either sent or received that mentioned my own domain name. I didn't know my customers were notifying us of the problem, and they weren't getting any of my updates. It was horrific. Our production service was down for ~ 3 days whilst Google just sat on their hands and refused to do anything about it. We were running a highly visible citizen-facing service for the UK Government and Google didn't care they'd broken it for everyone.
This runaway bot is a menace to the web and I refuse to give Google any more money until they've demonstrated they can run this responsibly.
There is a question to be asked of where does one draw the line about policing stuff that happens in virtual reality. Are we to start prosecuting people for espionage and insider trading in Eve Online too? Can we punish the church because God isn't answering my prayers in a timely manner?
(I don't think regulation is the answer. They had their 15 minutes of fame; it's time for everybody to form a new clique and cut Google out of it-- just like the Twitter exodus.)
The majority of economic value creation over the long run happens on the internet, it’s high time to adjust the laws to match physical reality.
You can’t just randomly discriminate against people in the physical worlds too.
Youtube and Gmail spring to mind, though there seems to be a resurgence of people moving away from Gmail these days (my perception anyway).
Since Google wanted to be a monopoly in various markets so badly, they should be required to serve those markets properly.
Like, with customer service / support, and similar. "You won! Here are the consequences..."
It's a shame the push a while ago for them to be regulated like a utility didn't succeed.
They owe it to society to manage what they've built in a fair and attentive fashion, or to give it up to someone who will, for the public good.
Define "acceptable timeframe"
Ideally they'd have an SLA measured in hours, the lower the better. Like 1. Because the consequences of their bot flagging a domain are so severe, both in terms of availability and in reputational damage.
If you're about to submit commercially sensitive information to a company providing a service on behalf of your government and instead you see a massive red screen that screams of dire consequences of using that site, how likely would you go back and try again later? They need to be damned sure they're right, and to provide a quick way to resolve false flags.
Instead the only answer I got from Google was "lol, no".
>A [low] false positive rate does not a bad tool make.
It does, if your tool fails to address the issue of false positives to the satisfaction of the people you harm with them, and especially if it fails to provide a quick, easy, direct line to humans, to deal with false positives
obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!”
if you can't resolve the negative externalities of your service to the satisfaction of the people you're harming with them, don't roll out the service
That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost.
You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist? That means a significantly higher amount of people getting significantly more inconvenienced than some false positives cause.
> if you can't resolve the negative externalities of your service to the satisfaction of the people you're harming with them, don't roll out the service
Case study of letting the perfect become the enemy of the good.
that's the thing: they don't. both co-exist, and you must address the negative externalities individually, vs. saying "well we think we do more good so suck it, too bad" to the people you harm.
> You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist?
the alternative could be a meteor hitting the planet, that doesn't justify your creating new negative externalities and unleashing them on the world with no reasonable recourse for the people you harm
indeed, your stated excuse for wrongdoing is a case study in letting the ends justify the means
you also neglect the many other alternatives, one of which is properly staffing and funding enough humans to deal with the harm you're inflicting on other people, and providing easy access to them from the people you've harmed, and scaling your service up only so long as you can support that proper level of staffing
Either you have no clue how much phish there really is or you know exactly. In both cases it sucks to be you.
> you also neglect the many other alternatives, one of which is properly staffing and funding enough humans to deal with the harm you're inflicting on other people, and providing easy access to them from the people you've harmed, and scaling your service up only so long as you can support that proper level of staffing
Sure, you're free to pay for an antivirus product that does the same and you can contact them.
It's thankfully not up to you to decide if people want to be inconvenienced or protected by what Google offers for free.
this is disingenuous: sure, you could, but no amount of antivirus can stop google from blocking customers or potential customers from seeing you without either of your informed, affirmative consent
in any case, thankfully your opinions that the ends justify the means (and also justify easily avoidable negative externalities), and that the lack of recourse available to the people you harm is somehow justified (unspecified how), seems to be the exception among people, rather than the norm
one wishes google actually cared what people thought, rather than professing to know better than them what's best, and directing them through the service without their informed, affirmative consent
No amount of Google will stop an antivirus from doing the same without your consent. What's your point? Anti-phish solutions must have the site owners' consent? Don't be ridiculous.
- google could harm people less by providing recourse to the people they harm, but instead chooses not to;
- your suggestion that those harmed by google "just use another antivirus software" is irrelevant and doesn't apply here;
- market forces would not, in fact, be involved here;
- disabling Google's opt-out-only service is more than trivial for the average user; and
- google exploits this non-triviality by making the service opt-out, vs opt-in with informed consent.
> No amount of Google will stop an antivirus from doing the same without your consent.
I wish this didn't need to be explicitly specified, but "someone else could harm people" isn't a defense for google actively harming people
if that happened, and the antivirus company was in google's place, and they also failed to provide recourse to the people they were harming with their negative externalities, that would also be bad, just like it is now bad that google is actually doing it
so, what exactly is your point here in trying to justify google harming people via negative externalities while at the same time totally failing to offer proper recourse to them, when google has the option of harming people less, and chooses to avoid that option?
A statistical inevitability is a defense for something. The world doesn't have perfect things.
Stop trying to frame something bad just because it isn't perfect. If you manage to stop that, then it would be possible to have a constructive discussion.
no it isn't, and also being screwed over by the leading search provider isn't a statistical inevitably anyways
> Stop trying to frame something bad just because it isn't perfect. If you manage to stop that, then it would be possible to have a constructive discussion.
stop trying to justify the means with the ends, more specifically trying to justify google actively harming people (sorry to break the news to you, but harming people IS bad), just because they also happened to do a good thing, when they have the non-mutually-exclusive option to harm people less, and instead choose to avoid that option
if you manage to stop that, then it would be possible to have a constructive discussion about how google can harm people less, since currently it seems like you're okay with google actively harming people any amount less than or equal to the amount of "good" they claim to do (with the determination made by you personally, natch), even when they could choose not to
If you think it's possible to be 100% accurate detecting phish then I've got a bridge to sell you.
even if that were true, it simply isn't a defense for google choosing to actively harm people: "google was going to screw over this site sooner or later, so you can't get mad at them for doing it now."
like, is that supposed to make google look better? It really doesn't.
There would be a full investigation as to how and why this happened and someone somewhere would be held accountable.
Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.
A more apt comparison would be with seatbelts or airbags.
> Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.
The market forces are sufficient. If the FP rate climbs too high more people will disable the feature, easy.
Try explaining that to people who lost tens of thousands of dollars or more in missed transactions due to Google's fuckups. I'm sure they will be consoled that one day if the right fairy farts in the right direction google will stop screwing people over in this particular way.
Inevitably anti-phish solutions end up with false positives, but it's utterly out of the question and silly to ask everyone to stand down defenceless.
I get that it's a service.
I don't get how not having human intervention available to fix it when it goes wrong is defendable business practices.
So do AV vendors. What specifically makes it not okay for Google? Have you tried delisting a website from other vendors' products? Microsoft SafeScreen?
If you want to hate on Google doing (or not doing) something, do it based on criteria that can actually be fulfilled.
your repeated attempts to deflect to literally anything except google's wrongdoing makes it seem like you think google should receive special treatment versus the others you're deflecting to
if not, then take your issues with others up with others, or perhaps in a discussion about others, rather than in a discussion about google's wrongdoing, which we can discuss here
I'm trying to give you a chance to ground this discussion in unbiased reality
so far you're dead-stuck on defending google's decisions to harm people, but you've still failed to articulate a valid defense for it ("they also did good thing" is not a valid defense)
you're making the discussion (which, remember: is about google's wrongdoing) ridiculous and useless by refusing to discuss the topic and instead attacking people who do for "hating on google" or whatever other paranoid persecution fantasies you dream up
if you don't like people discussing the harms google is doing to people, why even join a discussion which is literally about that, and why attack people for discussing it? why not just move onto the next topic whose very existence doesn't personally offend you, and leave everyone here alone?
If they're not one of those 4, then they are lamentably pathetic wasting their time like this.
do you have any evidence this is true? it seems like a hypothesis that you totally made up just now
it's hard to even imagine the feedback loop that would convince the average user to enter their browser settings and change one of them just to view a website for a product they're interested in but google wrongly blocked them from seeing
indeed, if it were so easy to convince a user to do so, google could make the feature opt-in, with informed consent that the feature might wrongly block them from seeing sites they want to see, letting the user decide for themselves if they want to enable it
no, it seems common sense that they'd just move onto another website/product, and market forces would never actually come into play
One of too many to list: https://archive.is/jvJhl
Be sure to claim domain ownership in the Google search console. If there is a flag of some sort, it will show up there. And you can address it there.
I worked for a financial services company where this happened. The public-facing .com domain was set up first, before I got there. Later, I added the .net domain behind zero trust to serve as our entry point for internal apps. Google marked the .net as a phishing domain. Verifying ownership of both under the same google search console account and then contesting the flag got it removed.
My domain ownership was already registered even before it was flagged. I _think_ it was the search console I used to request a review of the flag. But it still took that long to resolve.
This wasn't an issue of not realising what had happened for 3 days, it was 3 days after letting Google know they'd got it wrong. And spending hours on the phone to anyone I could get hold of to try to escalate etc.
If you've already verified your domains in the search console it is one click to add them. https://postmaster.google.com/
The flag was raised against web content on our domain - it claimed our online demo was a phishing site - not on use or content of our email.
obviously the biggest issue described in the above post is the lack of humans in the loop
And since that was attached to his business domain, it fucked with his business website too.
https://forum.level1techs.com/t/google-now-considers-looking...
Today... Google flags my domains as "unsafe" at least 3 times a year (For deceptive login forms - apparently having the gall to host tooling like bookstack/jellyfin/mealie is "deceptive" because they... ask for my login info? I don't fucking know, google won't tell me why they flag it)
They are about as locked down as you can get - 100% A scores on securityheaders.com - traffic monitoring so I know nothing untowards is happening. I don't see any particular or unusual traffic before they flag me.
But just hosting the login is enough - apparently I'm unsafe in Google's eyes. I spam the misdetected link, and 2 months later the unsafe warning pops off.
...only to show up again 6 to 8 weeks later. Rinse and repeat.
My opinion of Google today? Google can get fucked. I want the company to die. I want them out of browsers, I want them out of phones, I want this fucking ad company to get the fuck off my internet.
> Advisory provided by Google Safe Browsing.
Firefox clearly says it is using Google.
// dont send urs to whoever to decide if they are "safe"
user_pref("browser.safebrowsing.malware.enabled", false);
user_pref("browser.safebrowsing.enabled", false);
user_pref("browser.safebrowsing.malware.enabled", false);
user_pref("browser.safebrowsing.phishing.enabled", false);
user_pref("browser.safebrowsing.downloads.enabled", false);
user_pref("browser.safebrowsing.downloads.remote.block_potentially_unwanted", false);
user_pref("browser.safebrowsing.downloads.remote.block_uncommon", false);
user_pref("browser.safebrowsing.downloads.remote.block_dangerous", false);
user_pref("browser.safebrowsing.downloads.remote.block_dangerous_host", false);
// disable binaries NOT in local lists being checked by Google (real-time checking)
user_pref("browser.safebrowsing.downloads.remote.enabled", false);
user_pref("browser.safebrowsing.downloads.remote.url", "");
// disable reporting URLs/
user_pref("browser.safebrowsing.provider.google.reportURL", "");
user_pref("browser.safebrowsing.reportPhishURL", "");
user_pref("browser.safebrowsing.provider.google4.reportURL", ""); // (FF50+)
user_pref("browser.safebrowsing.provider.google.reportMalwareMistakeURL", ""); // (FF54+)
user_pref("browser.safebrowsing.provider.google.reportPhishMistakeURL", ""); // (FF54+)
user_pref("browser.safebrowsing.provider.google4.reportMalwareMistakeURL", ""); // (FF54+)
user_pref("browser.safebrowsing.provider.google4.reportPhishMistakeURL", ""); // (FF54+)
// disable Mozilla's blocklist for known Flash tracking/fingerprinting
user_pref("browser.safebrowsing.blockedURIs.enabled", false);
user_pref("browser.download.manager.scanWhenDone", false);
// may only affect windows, but disable mircosoft family safety MiTM
user_pref("security.family_safety.mode", 0);https://www.reddit.com/r/programming/comments/15pxt76/why_ha...
works great, with the old look. Just set preferences!
... yes it is. It's still up and running at the moment.
You want to use the "old" look, cool. Log in and set preferences.