See the instructions here: https://support.google.com/webmasters/answer/6347750?hl=en
See the instructions here: https://support.google.com/webmasters/answer/6347750?hl=en
In our case, Google's search console shows clearly what subdomain was guilty of the issue and that subdomain has been cleared now. Just really want to expedite the review process since Google's safe browsing has decided to block the entire domain instead of the offending subdomain :-/
I've submitted a review but they do say that reviews related to malware take a few days to process. This is a little hard to be honest given that it's not even our site that is hosting the malware. It was a page linking to google drive which is where the malware actually is hosted.
Hoping we get a response soon. Appreciate the supportive chime in.
This does, unfortunately, seem to be the right call. There's no way to differentiate between the subdomain user being malicious, the domain owner being malicious, or the domain owner getting hacked. The only granularity of data available is that something under the start.page domain was distributing malware, so it makes sense to quarantine the whole domain.
I hope this gets resolved quickly! I think the response is likely the correct one though.
It's not fair to smaller and newer players, but it's perfectly rational and isn't a uniquely special feature of Google.
If that rationale were valid, it would apply to everyone, including google.
If the rationale does not apply to google, then it does not apply to anyone else.
Please gooogle (if they let you) the concept "double standard".
We can argue about whether this is fair to small players, but it's hardly self-dealing for Google to include themselves in their list of high-profile content hosters, and there are very rational reasons for maintaining such a list.
Try googling the "Golden Rule" and you'll find a version that says "they who have the gold make the rules".
If there’s a risk that each time that happens the entire domain could be blocked, that’s a lot of risk to try and mitigate. Especially seeing that many of the bigger providers also struggle to mitigate this kind of content despite having technical teams that are larger by an order of magnitude (or more).
Or, you know, take into account the number of subdomains serving malware relative to the total number of subdomain.
1 out of 1000’s seems unfair reason. If it was 10’s or 100’s of subdomains out of 1000, then it makes more sense to punish the whole domain. But when it’s just a few, blocking the individual subdomains would be the better way.
If safe browsing only blocked the subdomain when you have a certain threshold of "safe" subdomains, then attackers would just have a sufficient number of "safe" subdomains.
Also how do you set the threshold? It's dependent on the market that the subdomain hosting provider targets, it's dependent on how good their moderation is, it's dependent on how quickly they get indexed, all sorts.
Any solution needs to work for the case of malicious users, and needs to work at a scale of billions of pages, i.e. you can't use any human review or non-machine-identifiable information.
If a website has a.example.com, b.example.com, foo.example.com, baz.example.com and they serve malware on baz, I’m saying put that subdomain on the bad list. If they serve malware from many subdomains, block the whole domain.
The issue is that Google blocked a whole domain for just one bad subdomain. That seems too strict, and is very sad for all of the users of that domain.
At least when done at the domain level there's a cost involved for getting a new domain, which disincentivises the creation of many malware hosting domains.