Comment by arnaudsm
3 years ago
Yikes, giving Google the power to block any website to the majority of humankind may not be the best idea.
3 years ago
Yikes, giving Google the power to block any website to the majority of humankind may not be the best idea.
What's even worse is that Firefox, Safari, Vivaldi, Brave, Instagram, other Google services (like Gmail and Search) all rely on this list in some capacity, though their delivery method may differ. It's got far bigger reach than Chromium alone.
Sneak in your competitor onto this list and they'll lose all of their traffic for as long as it takes them to convince someone at Google they've made a mistake.
Even worse, the data is crowd sourced. I've been playing whack-a-mole with this service for over a year now. Strongly suspecting that this is negative SEO. It is temporarily unblocked, then in the next week the entire domain is re-flagged.
Yes and no, the public crowdsourcing is only a part.
The biggest influence are trusted security groups, where security teams of influential websites who trust each other can push or remove websites from these lists without any vetting from anyone.
This is also from there that you can download and share lists of unhashed passwords with e-mails (you know this warning "This password has likely been compromised", they need to source it from somewhere).
If the owner of a website complains, he is never going to win the appeal against a member of the special group.
So it's a very (useful and important) political game once your website becomes large.
This is also where you can informally directly communicate with agencies like FBI.
> This is also from there that you can download list of unhashed passwords with e-mails (you know this warning "This password has likely been compromised", they need to source it from somewhere).
You (or anyone else) can get such a list (no emails, weak hashing better thought of as obfuscation) from Pwned Passwords[1]. (There used to be direct download links usable without the tricky downloader tool for pre-2022 archives on that page, but not anymore, huh. Take this[2,3].)
[1] https://haveibeenpwned.com/Passwords
[2] https://archive.org/details/pwned-passwords-version-8
[3] magnet:?xt=urn:btih:f9690a02f1accebbee2190b82cfee7b6968d384c&dn=pwned-passwords-sha1-ordered-by-hash-v8.7z
I agree, but also what's the alternative. A complete free-for-all doesn't work because malicious actors be malicious and a majority of users aren't competent to protect themselves against such threats. So we need something, if not google, then it would be something else. We can't trust private corporations because of potential for conflicts of interests (between users and profit motives) and we don't seem to want to trust government bodies to do this because then it would be censorship (conflict between users and political motives). What else is there?
> A complete free-for-all doesn't work because malicious actors be malicious and a majority of users aren't competent to protect themselves against such threats.
It does work. You claim it doesn't because you think the resultant state of affairs is intolerable, but to subsequently claim it "doesn't work" because you don't like the outcome is simply wrong. You might as well claim that allowing people to buy pointy kitchen knives "doesn't work" because sometimes people stab each other and you think murders are simply intolerable. But the reality is that allowing people to have pointy knives even though some people get hurt does work, even though it doesn't produce an outcome the hypothetical you are happy with.
The problem with "think of the children" style arguments is they are always unbounded, and there is always something more controlling than what we're doing presently that could obstensibly make children even safer. Why not have browsers ship a whitelist of trusted websites, and forbid all others? That would be even safer, and if you oppose this then you're not thinking of the children. In fact I find the present state of affairs with bad websites being blacklisted simply intolerable, new malicious websites are permitted by default and that just doesn't work!
Well of course when I said "it doesn't work" I meant that I found the outcome intolerable. That outcome being a majority of users being vulnerable to malicious attacks with a whole host of real world bad consequences for them.
I think that regular people having unrestricted access to enriched plutonium also to have intolerable outcomes. Even if some people would be able to handle the substance safely (both to themselves and others), the ones that don't or can't will cause intolerable outcomes. And yes, this is a 'think of the children' style argument. I don't want the children (or adults) to get radiation sickness. My hot take here is that it would be bad.
Let's be real here: Google doesn't need a "safe browsing" list to control website access.
The vast majority of people, when they want to visit a website, go to Google, type in the name of the website, hit search, then click the top result.
Address bar? WTF is an address? WTF is a bar?
When the vast majority of people access websites through google.com, Google already decides where the people go.
Let's also not forget tech enthusiasts and professionals all advise using 8.8.8.8. Guess what: Google literally owns your DNS requests.
there's an enormous difference between people not being able to find a site they don't know about and breaking bookmarks and existing links
yes, it's true that google has a lot of power