Define "acceptable timeframe"
Define "acceptable timeframe"
Ideally they'd have an SLA measured in hours, the lower the better. Like 1. Because the consequences of their bot flagging a domain are so severe, both in terms of availability and in reputational damage.
If you're about to submit commercially sensitive information to a company providing a service on behalf of your government and instead you see a massive red screen that screams of dire consequences of using that site, how likely would you go back and try again later? They need to be damned sure they're right, and to provide a quick way to resolve false flags.
Instead the only answer I got from Google was "lol, no".
>A [low] false positive rate does not a bad tool make.
It does, if your tool fails to address the issue of false positives to the satisfaction of the people you harm with them, and especially if it fails to provide a quick, easy, direct line to humans, to deal with false positives
obviously it's not acceptable to screw people over and justify it by saying "we're not screwing over everybody, and look, we're doing good stuff, too!”
if you can't resolve the negative externalities of your service to the satisfaction of the people you're harming with them, don't roll out the service
That's the thing, the benefits immensely outweigh the small negatives. Small inconvenience from even tens of thousands of false positives out of tens of billions site visits is such a small cost.
You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist? That means a significantly higher amount of people getting significantly more inconvenienced than some false positives cause.
> if you can't resolve the negative externalities of your service to the satisfaction of the people you're harming with them, don't roll out the service
Case study of letting the perfect become the enemy of the good.
that's the thing: they don't. both co-exist, and you must address the negative externalities individually, vs. saying "well we think we do more good so suck it, too bad" to the people you harm.
> You do understand that the alternative would be most phishing sites remaining active for days, if not months, if this service didn't exist?
the alternative could be a meteor hitting the planet, that doesn't justify your creating new negative externalities and unleashing them on the world with no reasonable recourse for the people you harm
indeed, your stated excuse for wrongdoing is a case study in letting the ends justify the means
you also neglect the many other alternatives, one of which is properly staffing and funding enough humans to deal with the harm you're inflicting on other people, and providing easy access to them from the people you've harmed, and scaling your service up only so long as you can support that proper level of staffing
Either you have no clue how much phish there really is or you know exactly. In both cases it sucks to be you.
> you also neglect the many other alternatives, one of which is properly staffing and funding enough humans to deal with the harm you're inflicting on other people, and providing easy access to them from the people you've harmed, and scaling your service up only so long as you can support that proper level of staffing
Sure, you're free to pay for an antivirus product that does the same and you can contact them.
It's thankfully not up to you to decide if people want to be inconvenienced or protected by what Google offers for free.
this is disingenuous: sure, you could, but no amount of antivirus can stop google from blocking customers or potential customers from seeing you without either of your informed, affirmative consent
in any case, thankfully your opinions that the ends justify the means (and also justify easily avoidable negative externalities), and that the lack of recourse available to the people you harm is somehow justified (unspecified how), seems to be the exception among people, rather than the norm
one wishes google actually cared what people thought, rather than professing to know better than them what's best, and directing them through the service without their informed, affirmative consent
No amount of Google will stop an antivirus from doing the same without your consent. What's your point? Anti-phish solutions must have the site owners' consent? Don't be ridiculous.
- google could harm people less by providing recourse to the people they harm, but instead chooses not to;
- your suggestion that those harmed by google "just use another antivirus software" is irrelevant and doesn't apply here;
- market forces would not, in fact, be involved here;
- disabling Google's opt-out-only service is more than trivial for the average user; and
- google exploits this non-triviality by making the service opt-out, vs opt-in with informed consent.
> No amount of Google will stop an antivirus from doing the same without your consent.
I wish this didn't need to be explicitly specified, but "someone else could harm people" isn't a defense for google actively harming people
if that happened, and the antivirus company was in google's place, and they also failed to provide recourse to the people they were harming with their negative externalities, that would also be bad, just like it is now bad that google is actually doing it
so, what exactly is your point here in trying to justify google harming people via negative externalities while at the same time totally failing to offer proper recourse to them, when google has the option of harming people less, and chooses to avoid that option?
A statistical inevitability is a defense for something. The world doesn't have perfect things.
Stop trying to frame something bad just because it isn't perfect. If you manage to stop that, then it would be possible to have a constructive discussion.
no it isn't, and also being screwed over by the leading search provider isn't a statistical inevitably anyways
> Stop trying to frame something bad just because it isn't perfect. If you manage to stop that, then it would be possible to have a constructive discussion.
stop trying to justify the means with the ends, more specifically trying to justify google actively harming people (sorry to break the news to you, but harming people IS bad), just because they also happened to do a good thing, when they have the non-mutually-exclusive option to harm people less, and instead choose to avoid that option
if you manage to stop that, then it would be possible to have a constructive discussion about how google can harm people less, since currently it seems like you're okay with google actively harming people any amount less than or equal to the amount of "good" they claim to do (with the determination made by you personally, natch), even when they could choose not to
If you think it's possible to be 100% accurate detecting phish then I've got a bridge to sell you.
even if that were true, it simply isn't a defense for google choosing to actively harm people: "google was going to screw over this site sooner or later, so you can't get mad at them for doing it now."
like, is that supposed to make google look better? It really doesn't.
There would be a full investigation as to how and why this happened and someone somewhere would be held accountable.
Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.
A more apt comparison would be with seatbelts or airbags.
> Google in its current form is immune to the consequences of the decisions of its robots, and that is not acceptable.
The market forces are sufficient. If the FP rate climbs too high more people will disable the feature, easy.
Try explaining that to people who lost tens of thousands of dollars or more in missed transactions due to Google's fuckups. I'm sure they will be consoled that one day if the right fairy farts in the right direction google will stop screwing people over in this particular way.
Inevitably anti-phish solutions end up with false positives, but it's utterly out of the question and silly to ask everyone to stand down defenceless.
I get that it's a service.
I don't get how not having human intervention available to fix it when it goes wrong is defendable business practices.
So do AV vendors. What specifically makes it not okay for Google? Have you tried delisting a website from other vendors' products? Microsoft SafeScreen?
If you want to hate on Google doing (or not doing) something, do it based on criteria that can actually be fulfilled.
your repeated attempts to deflect to literally anything except google's wrongdoing makes it seem like you think google should receive special treatment versus the others you're deflecting to
if not, then take your issues with others up with others, or perhaps in a discussion about others, rather than in a discussion about google's wrongdoing, which we can discuss here
I'm trying to give you a chance to ground this discussion in unbiased reality
so far you're dead-stuck on defending google's decisions to harm people, but you've still failed to articulate a valid defense for it ("they also did good thing" is not a valid defense)
you're making the discussion (which, remember: is about google's wrongdoing) ridiculous and useless by refusing to discuss the topic and instead attacking people who do for "hating on google" or whatever other paranoid persecution fantasies you dream up
if you don't like people discussing the harms google is doing to people, why even join a discussion which is literally about that, and why attack people for discussing it? why not just move onto the next topic whose very existence doesn't personally offend you, and leave everyone here alone?
If they're not one of those 4, then they are lamentably pathetic wasting their time like this.
do you have any evidence this is true? it seems like a hypothesis that you totally made up just now
it's hard to even imagine the feedback loop that would convince the average user to enter their browser settings and change one of them just to view a website for a product they're interested in but google wrongly blocked them from seeing
indeed, if it were so easy to convince a user to do so, google could make the feature opt-in, with informed consent that the feature might wrongly block them from seeing sites they want to see, letting the user decide for themselves if they want to enable it
no, it seems common sense that they'd just move onto another website/product, and market forces would never actually come into play