Facebook incorrectly reports personal blog to DigitalOcean for phishing
social.lol
social.lol
I once had my account with a major cloud provider terminated for "violating our terms of service". After contacting support, they then claimed that someone had gained access to my credentials.
What evidence did they have? None. I just updated a VM's metadata too frequently (about once a minute). This tripped an ML model, which caused them to automatically terminate my account and send an automated email saying that I had been a bad boy.
This took down a key part of my business for about 5 hours (while I navigated my way through layers of customer support and ultimately temporarily moved this functionality to another cloud provider). Customers were not happy.
It took about 2 weeks and multiple support tickets for the full story to come out. I got them to refund a few months of charges (amounted to several hundred dollars at the time) and restore my account. There was never any recognition that they made a mistake.
I get that companies need to resort to automated means to handle fraud or abuse. But they should also own up to it, add some humility in their automated outreach to customers ("our automated system has detected possible X" instead of "you are guilty"), provide clear escalation paths to talk to a human, and provide a way to "shield" your account (identity verification, upfront deposit of $X, etc) that forces them to contact you before any enforcement action.
In my case, I upgraded to a paid support plan ($100+ per month) in the hopes that their system will be a little less trigger happy with my account in the future. I don't use support at all, it's purely a lame form of insurance that may or may not actually protect against anything.
With respect to Facebook: I posted a shop vac last April for $50. I got a message that I was banned from using marketplace for "violating community guidelines."
However, if you believe this happened in error, you could request a review.
So I did! And was denied. I did this process a few more times and each time was denied. Once I requested a review for the third (or fourth?) time, I received a message that said "Unfortunately, your account cannot be reinstated due to violating community guidelines. The review is final."
I have no idea what happened.
So now, I can't use Facebook Marketplace because of some stupid error in their algorithm that can't be ever appealed. Which is a bummer, because I've legitimately found some good electronic finds on there (and have been able to offload things I don't have use for).
Meanwhile, their algorithms for advertising and marketing useless stuff to us are just perfect. A passage from Yuval Noah Harari's book, "Homo Deus: A Brief History of Tomorrow" highlights this:
> A recent study commissioned by Google’s nemesis – Facebook – has indicated that already today the Facebook algorithm is a better judge of human personalities and dispositions than even people’s friends, parents and spouses. The study was conducted on 86,220 volunteers who have a Facebook account and who completed a hundred-item personality questionnaire.
> The Facebook algorithm predicted the volunteers’ answers based on monitoring their Facebook Likes – which webpages, images and clips they tagged with the Like button. The more Likes, the more accurate the predictions. The algorithm’s predictions were compared with those of work colleagues, friends, family members and spouses.
> Amazingly, the algorithm needed a set of only ten Likes in order to outperform the predictions of work colleagues. It needed seventy Likes to outperform friends, 150 Likes to outperform family members and 300 Likes to outperform spouses. In other words, if you happen to have clicked 300 Likes on your Facebook account, the Facebook algorithm can predict your opinions and desires better than your husband or wife!
Additionally, I think there should be a right to download your data after being banned, whether or not the ban was fair.
Vultr has a nasty habit of forwarding these directly to the current holder of the IP address with a dire warning that your account will be shut down within 24h if no action is taken, regardless of the timestamp of the complaint. Abusers just create & destroy servers frequently frequently to acquire fresh IP addresses to host malicious content on. It became a morning routine of copy+pasta responses to these emails to keep the servers online.
https://incident.netcraft.com/3ee0db5c9a6a/
Maybe a little HN kumbaya moment and report this as one?
>appears to be sorted from netcrafts end but how is this okay as a response? fuck you for threatening me with losing my server with 24 hours.
Source: I've filed these before and fuck all happened.
Now if net neutrality had teeth, maybe you could angle that way.
https://en.wikipedia.org/wiki/Actual_malice
https://www.findlaw.com/injury/torts-and-personal-injuries/w...
That's facebook's situation. Even though they've got hundreds of billions and could easily afford to, they don't want to pay humans to verify these things and they know that innocent people are being hurt by their terrible lazy code, they just don't care.
i.e. if you want automated tools for "protection" than they need to "correct" 99.99999% of the time otherwise it's not worth it.
It's a personal blog (which didn't even go down), so the damages are zero or negligible.
And it's probably not defamatory at all, because the bar for what's "reckless disregard" for truthfulness is quite high. "We run a commercial service that identifies malicious websites and 0.01% of them are unintentionally false positives" is not gross negligence.
edit: (To defend myself because I'm getting piled on in votes)—I agree that this shitty behavior, but I just don't agree that there is or should be a legal remedy for it. You all have way too heated hot takes, HN. There's no life-changing injuries here for which five-figure attorneys would be a proportionate investment—this is, no offense, just some blog which did not go down, and everyone will have forgotten all about this by Monday. This is just not the kind of conflict the legal system is meant to resolve!
This trend of hiding behind algorithms and percentage figures needs to stop, yesterday.
I don't see any tangible reputational damages here. No one seems to have read this except Digital Ocean (?)
- "They were falsely accused of engaging in criminal activity"
And Netcraft sincerely believed that this was a criminal-activity website. That is not libel! Untrue statements without malice (or a very severe amount of negligence) are not defamatory in the US. You are allowed to accuse people of things—that is protected speech.
And that matters how? Digital Ocean read the complaint and acted on it, so the reputational damage occurred.
You don't have to make a public article to damage someone's reputation privately.
How much damages is that, in your opinion? How much would OP need to paid to be made whole?
The good thing is, this is very easy to detect when things are hosted on DO.
The bad news is, companies are harsh on DigitalOcean and will have some level of false positives.
What's a solid low cost ($5/month) VPS provider that is below the radar for this kind of broad brush blocking based on guilt by association? Thinking of making a move, but I kind of hate to give up the 15 years of good reputation on my IP address and starting over.
What DO has is some of the best content marketing around (great tutorials on server stuff) and scale. The first attacts beginners (which includes most of the spammers and hackers), the second puts them on people's radar.
it's very, very, very simple to use.
some people can't even navigate AWS or GCP, not to mention that the pricing is unclear as it can be. for people learning by practice it's a nightmare.
Then again I'm sure there's no incentive to improve it, since if for whatever reason you were laid off from AWS... you could have a lucrative consulting gig the next day helping people with the blindingly obvious consumer pain points you refused to resolve.
> "Yeah you won’t figure those APIs out from the documentation. It was on purpose. You have to go buy the book."
If you want to see pieces as you do stuff you can go to the Google Cloud
Some innocents get caught in that crossfire, however.
As far as I can tell, Google Blogger is still a pretty reasonable site for a blog and some static pages. And it’s free. Of course you may not like that option for various other reasons.
They then get caught in the crossfire, but the correct complaint would be to DO not to the people who are taking the relatively reasonable and easy way out of "ban this part of the Internet, it sucks."
1. “Facebook” and “login” in the URL
2. URL redirect
3. “Facebook login”, “password login, “forget password” etc in text body
4. The quoted email from Spotify sounding close (in vector space) to phishing text.
5. A link to Facebook settings, followed by a series of steps; these instructions say to log in to a non-Facebook url using your Facebook email
All of these together was probably enough to hit some threshold. From there the issue was just misaligned personal incentives, all along the chain from engineers at Facebook to Netcraft and Digital Ocean, that leads to false positives being an acceptable outcome.
I wonder if there’s been an uptick in DO-hosted spam, and now some heuristic is being a little too eager with taking down DO content?
DigitalOcean should reach out to Netcraft and decide on a more reasonable minimum enforcement time that is based on Netcraft's actual support throughput capabilities.
This arbitrary choice of a 24 hour time limit hurts their customers. I plan to switch my hosting provider away from DigitalOcean due to this incident.
cloudflare plasted red "DANGER! BAD WEBSITE!!!" banners across my company's website because the morons at netcraft told them it was a "phishing website"
edit: looked like this: https://global.discourse-cdn.com/cloudflare/original/3X/e/9/...
thanks cloudflare for altering my website to tell my customers that I'm trying to phish them and to avoid us because some third party told them that was so
what was the cause of netcraft to sending this to cloudflare?
they found a 20 year old exe that had a link to our website as a string inside the binary
not a binary we had produced, just some random innocent third party program that mentioned us in their about box
if I had could have proven that I'd lost sales/reputation I'd have gone after netcraft and cloudflare for defamation
what use is a DDoS shield if they'll automatically shut down your site if someone sends them an anonymous form saying "they're hosting bad things!!!!"
edit: another guy with the same complaint here: https://community.cloudflare.com/t/cloudflare-mistakenly-fla...
Nobody should have that much power.
To be fair I’m never sure who is imposing the captcha s about things that are alien to my society (traffic lights hanging above lanes, yellow taxis, crossings without flashing amber lights), either cloudflare or google, but I’m certain it’s to continue the adtech economy.
How do you know they added a phishing warning because of something Netcraft told them?
Cloudflare received a phishing report regarding:
mycompany.com
Below is the report we received:
Reporter: Anonymous
Reported URLs:
http://www.mycompany.com/deadlink
Logs or Evidence of Abuse: Hello,
You are currently hosting a site which is associated with an ongoing
malware attack. The malware either communicates with, or is spread
directly by following malicious links:
hxxp://www[.]mycompany[.]com/deadlink [1.2.3.4]
Visit the report below to see details on one of the attachments
associated with this URL or IP address:
https://www.virustotal.com/en/file/12345678/analysis/
More information about the detected issue is provided at
https://incident.netcraft.com/1234/
Would it be possible to have this URL taken down as soon as possible?
Many thanks,
Netcraft
Phone: +44(0)1225 447500
Netcraft Issue Number: 123456
(numbers removed to prevent doxxing)we redirect 404s back to the parent directory
cloudflare used that url on our own website to warn our customers we were "PHISHING!!"
also, you used cloudflare. meh.
Never again with these discount hosts.
Which hosting provider would you use today?
Even when it's working their peering to half the world is absolute shite.
If I had to move, I'd look at BuyVM or Incognet, but I don't really look around until I feel the need.
I confronted Netcraft about it and they just told me that they didn't actually detect anything like criminal activity, but they need to say that or else Amazon won't take their reports seriously. Pretty fucked IMO.
yeah, because their business model is to hope you have very expensive spikes. legitimate or not
[0] - parody microservice in famous skit.
I guess we need to give advance notice to traffic spikes if that is an abnormal historical occurrence for our accounts.
(The maddening thing is that some of the circuit breakers are undocumented).
I haven't done it often, but 100% of the time I've hit "report" on something advocating violence towards a specific individual, the automated response has come back and told me the comment had been reviewed and was within the rules. The most memorable time was a death threat to a politician -- not that I agreed or disagreed with that politician, it was another country where I don't have skin in the game; I was just an onlooker really shocked by violent rhetoric.
Comments sections are shitholes.
Then again, modern moderation is provided by the most bargain basement person or AI capable (and as it moves to AI it will be amusing in a horrifying way how people get around it).
I'm not talking at all about prosecution or legality of speech and its varying definitions under the law (of which I believe German law is more restrictive than here). I'm talking about Facebook interpreting their own rules, which I am pretty sure do not allow threats of violence.
Also, I am in favor of free speech and open political discourse. I am not in favor of saying a politician in a democracy should be murdered. There may be edge cases in the law where that is not considered credible, however, in terms of my own personal ethics it is very unambiguous when that line is crossed, and I think that's true for others.
I had a friend murdered by her boyfriend and because he was black, when the story broke her personal facebook was flooded with racist comments towards her for a while, even years after the incident, one most recently was how she's been "one year clean and sober from mud diving" and hundreds of us have reported those comments for racism and every time Facebook came back saying they don't violate the rules.
But one time I replied to an old lady who was saying bigoted and hateful things towards a trans person with "Thankfully like you, your views will die soon too." and I got 30 day ban for hateful comments.
As you should do. There's no excuse for wishing people dead because you disagree with their beliefs.
As a result I've stopped submitting any reports, and question all FB metrics about active users & account numbers.
Got a big thumbs up from FB though.
any company/person using stats to self promote should always be questioned. of course numbers are going to be rounded and massaged in the direction most rewarding, but the extent of the rounding makes a difference. lots of weasel room available in these types of stats.
#include <don_quixote.jpg>