Google blocks Twitpic over alleged malware
thenextweb.com
thenextweb.com
We're trying to sort it out but there isn't really any information provided by Google/Chrome to go on. The best "details" they have show that Twitpic has 0 pages with Malware.
Crazy how some automated process at Google can kill an entire site just like that.
http://support.google.com/webmasters/bin/answer.py?hl=en&...
edit: ack. just read his twitter feed and it looks like he's out for a week.
http://safebrowsing.clients.google.com/safebrowsing/diagnost...
What happened when Google visited this site?
Of the 12592 pages we tested on the site over the past 90 days, 31 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2012-12-31, and the last time suspicious content was found on this site was on 2012-12-30. Malicious software includes 13 trojan(s), 4 exploit(s). Successful infection resulted in an average of 8 new process(es) on the target machine.
Malicious software is hosted on 5 domain(s), including mpchester.info/, malatyuhr.com/, iloveeu.info/.
2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including 2upmedia.com/, adexcite.com/.
This site was hosted on 3 network(s) including AS36351 (SOFTLAYER), AS15169 (Google Internet Backbone), AS31815 (MEDIATEMPLE).
Has this site acted as an intermediary resulting in further distribution of malware?
Over the past 90 days, twitpic.com appeared to function as an intermediary for the infection of 1 site(s) including ow.ly/.
Google bases its entire company around automated processes. Sites are made and killed by Google's automated processes every day. If you want to ask Google about it you will be talking to yet another automated process.
The Google Safebrowsing report [1] appears fairly ambiguous though:
"Site is listed as suspicious - visiting this web site may harm your computer (...)"
"Of the 12029 pages we tested on the site over the past 90 days, 0 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2012-12-30, and suspicious content was never found on this site within the past 90 days."
[1] http://safebrowsing.clients.google.com/safebrowsing/diagnost...
And that's all the same to end users. When will the web evolve past these pests?
What likely happened is that one of the 3rd party advertisers on Twitpic delivered ads that contain something classified as malware thus resulting in the entire Twitpic site getting blacklisted.
I am beginning to hope that someone takes google to task and reigns in thier power over the Internet community. No company should have the ability to practically shut down websites at will.
As a HN user you're most likely able to take care of yourself, but the vast majority of people are better off heeding Google's advice.
If it turns out to be true, that's fine. If it's not true, don't you think Google should be held responsible for the damage to their competitor's reputation?
Twitpic is part of the Twitter ecosystem and is such is certainly competitive with Google's social and photo sharing efforts (i.e. Google+ and Picasa)
Being a known distributor of malware (described by Google as: software which causes things like identity theft, financial loss, and permanent file deletion) is a crime.
So yes, they are a competitor, and yes they are being accused of a crime.
I don't doubt for a minute that if someone figured out how to create a twitpic app that could inject malware into the images you shared, they would try really hard to get it on to your phone. How great a coup to have all eleventybillion followers check out your latest 'woah!' picture and spread the malware. Its a primo target.
I'm not defending Google here, I'm just saying that putting malware into images is a primary goal of any number of advanced persistent threat shops. Keep that in mind and make sure you keep an offline MD5 hash of every picture on your web site for validation.
Rather than accusing Twitpic of being "a known distributor of malware", it might be better if the message said something like "The site appears to be infected with malware. This warning will be remain in place until the malware has been removed."
One is an opt-in completely private non-coercive entity, the other uses a gun and has real power over you. Don't like Google, don't use their search or Chrome or Gmail et al., there are plenty of alternatives and your adoption of those would help spur further activity in the way of competition. Don't like homeland security? Tough luck, obey or go to jail.
Try to load the founder's page on Twitter: http://twitter.com/noaheverett
"Danger: Malware Ahead! Google Chrome has blocked access to this page on twitter.com. Content from twitpic.com, a known malware distributor, has been inserted into this web page."
Punishing anti-malware software for false positives may feel like it could be warranted at times (at least in cases of anti-competitive actions or extreme incompetence), but it seems like it would set an extremely poor precedent. Even worse would be someone winning a case like "yes, there was malware, but you should have sent users though anyway."
Which kind of points to the reason why you probably won't see a case like this go far. Whether or not it's bad from the website's point of view, users chose to install a browser that blocks what it thinks are infected sites, and there's still the option (however small or hidden) to click through or disable the warning. There are also tools to figure out why you're blocked (I'm not sure about Microsoft or Opera's system, but I assume so), even if they can be annoyingly slow in internet time.
I don't think there's any more case than suing over a browser displaying a broken lock icon (or not loading a page at all) when you serve content over mixed secure and insecure connections, or warning that a self-signed certificate is untrusted and may be an attempt to hijack and redirect you.
"Danger: Malware Ahead! Content from twitpic.com, a known malware distributor has been inserted into this page. Visiting this page now is very likely to infect your computer with malware.
Malware is malicious software that causes things like identity theft, financial loss, and permanent file deletion."
If this turns out to be a false positive, it certainly looks as though Google has committed a serious act of libel against a competitor by claiming that they are known to be malicious and involved in crime. Furthermore they prevented millions of customers from reaching another competitor (and partner of the first competitor) in order to deliver this message.
There's no mention of the possibility of there being a false positive, or how the conclusion was reached, or the general rate of false positives, or the fact that it's Google's opinion.
The fact that we assume it's an automated detection system doesn't absolve Google of responsibility for what they are communicating and the damage it can do to their competitors reputations.
If it does turn out to be a false positive, will Google contact all the people who saw that message to inform them that they were wrong?
I hope it's not a false positive.
You actually get two slightly different warnings, depending upon whether the content is embedded or not. If you go to Twitpic directly you'll see "Google has blocked access to twitpic.com for now", a generally more gentle warning than the one you cite (which you'll see if you're viewing embedded content instead).
It's interesting there are two warnings, only one of which seems to be potentially libelous (if it was a false positive, which at this point is uncertain, especially if the content came in from an ad network).
I'll take occasional minor shortlived inconveniences over security breaches anyday.
Google can perfectly well block the malware without making such an accusatory statement. It's not a tradeoff, so I don't really know why you are defending them.
Security is a tradeoff, if you do business on the web, deal with it.
Security is sometimes a trade-off but in this case there is no trade-off involved. Google can just as easily block the malware without the potentially defamatory language.
The accuracy of the algorithm is utterly irrelevant.
An accurate and informative statement like:
"Google's Scans detected malware <X>, which is known to do harm <Y> within the past <N> hours at <Z> percent of the pages operated by <COMPANY>. Google recommends that you do not click on this link until this warning is lifted. [Site owners click here for detailed information]"
...would be just as effective.
Scare tactics, especially those that might be laying blame incorrectly, simply breed ignorance, and ignorance is the enemy of security.
That's what you suggested, seems pretty mealy-mouthed to me.
So even by your judgement of what is 'mealy mouthed', an effective and accurate warning is clearly possible. You might not have liked the wording of my first suggestion but that doesn't change the argument.
There is no valid trade-off that requires Google to use accusatory wording in order to protect people from malware. It would clearly be an improvement if their messages were more accurate.
The messages are accurate, Twitpic was unfortunately a distributor of malware. Here's a copy and paste of the current detailed report.
What happened when Google visited this site? Of the 12910 pages we tested on the site over the past 90 days, 31 page(s) resulted in malicious software being downloaded and installed without user consent. The last time Google visited this site was on 2013-01-01, and the last time suspicious content was found on this site was on 2012-12-30. Malicious software includes 13 trojan(s), 4 exploit(s). Successful infection resulted in an average of 8 new process(es) on the target machine.
Malicious software is hosted on 5 domain(s), including mpchester.info/, malatyuhr.com/, iloveeu.info/.
2 domain(s) appear to be functioning as intermediaries for distributing malware to visitors of this site, including 2upmedia.com/, adexcite.com/.
This site was hosted on 3 network(s) including AS36351 (SOFTLAYER), AS15169 (Google Internet Backbone), AS31815 (MEDIATEMPLE).
Has this site acted as an intermediary resulting in further distribution of malware? Over the past 90 days, twitpic.com appeared to function as an intermediary for the infection of 1 site(s) including ow.ly/.
http://safebrowsing.clients.google.com/safebrowsing/diagnost...
I'm not sure why you're placing the business interests of Twitpic over the safety of users, but I disagree with your attitude. I'm done here.
Maybe, but I'm not arguing about the 'strength' of the language. I'm arguing about the accuracy of it.
The messages are accurate, Twitpic was unfortunately a distributor of malware. Here's a copy and paste of the current detailed report.
Actually, this report proves my point. Twitpic is implicated because ad networks they embed have distributed malware.
This is a perfectly good reason for warning people, but it is not justification for calling Twitpic "A known distributor of malware" - a statement which portrays Twitpic as an intentional agent in this.
If I called you "A known distributor of falsehoods", and my evidence was that you made a few mistakes on a math test, and mistyped the a URL in one of your postings, I imagine most people would consider that a misrepresentation, because the phrase "A known distributor" implies agency and intent.
Another analogy would be if a grocery store carried a batch of improperly pasteurized milk from that people got food poisoning from.
Calling the grocery store "A known poisoner" would be an obvious misrepresentation.
In just the same way, Twitpic is not "a known distributor" of malware.
I'm not sure why you're placing the business interests of Twitpic over the safety of users, but I disagree with your attitude.
You are simply misrepresenting my position. You keep making a false dichotomy, as though the users safety and accurate messaging are in conflict with one another. This is not true.
It is perfectly possible for Google to strongly state their opinion about the dangers of clicking through without misrepresenting twitpic.
I think that the communications of those in a position of power should be critiqued, and I think that misleading people 'for their own protection' is almost never justified and certainly shouldn't be casually accepted as a necessary tradeoff.
I disagree with your attitude too, but I guess at least we know where we stand.
You have an exposure risk every time you use the Web; managing that risk is part of what we do as users (and, to a greater degree, as professionals).