Comment by lionkor

3 years ago

I feel the "i want my friends and family to be safe" is similar to the "but think of the kids!" excuse.

Maybe its some kind of a Stockholm Syndrome variant of people using Chrome, but its definitely not healthy.

I don't actually believe that it has blocked that many people from being phished, and I doubt that all the entries on that list are malicious. It seems like a system that was designed by someone to simply get a pat on the back and a promotion, and then not touched again.

The point of hosting yourself, and not making another facebook/youtube page, or discord server, is really to be free of their terms, control, etc. Your browser itself blocking self hosted sites is such a malicious attack of that.

The consensus, even among tech people, seems to be that this is a good thing. Sure, lots do argue it shouldn't be maintained by Google, but ultimately such list itself is fine.

I personally don't agree with, as I think modern browsers (not just Chrome) already do way too much handholding to a point that neutrality is inevitably lost.

I would go even further and say I don't like ideas like Firefox's/Brave's "Enhanced Tracking Protection" which blocks certain services with a handpick ruleset. Don't get me wrong, I block these trackers myself in uBlock Origin, but I don't like idea that a browser maintains an arbitrary list itself of what to block for the users.

  • >I would go even further and say I don't like ideas like Firefox's/Brave's "Enhanced Tracking Protection" which blocks certain services with a handpick ruleset. Don't get me wrong, I block these trackers myself in uBlock Origin, but I don't like idea that a browser maintains an arbitrary list itself of what to block for the users.

    The primary difference is in the messaging. Tracking protection is an opt-in feature, so the user is always aware of it. Additionally, at least in the forms I've encountered it, it doesn't outright prevent you from navigating to a website. At worst it breaks some sites, and you disable it, it's sitting right there in your browser navigation bar. Don't agree with some block? Overriding it is a click away.

    Meanwhile, safebrowsing doesn't announce itself anywhere except when it hits you in the face with a giant red screen, specifically designed to inspire a sense of fear/dread. Override buttons are intentionally not outright presented to the user, and the toggles to completely disable the feature are tucked deep into advanced features where no muggle may reach.

    It may sound stupid but this simple difference in optics radically changes the effect such a "manual blacklisting" feature has on its users. That said I agree it'd be nice to have more control over the tracking protection feature in firefox, e.g. by allowing custom lists, like uBlock does.

    • > The primary difference is

      Yeah I don't mean they're the same thing.

      I just don't like either (hence "go even further").

> I don't actually believe that it has blocked that many people from being phished

The data says the opposite, the safe browsing list is very effective* which is why many other browsers and systems use the same list to block malicious pages.

Google publishes data about the frequency of warnings displayed too: https://transparencyreport.google.com/safe-browsing/overview

* Of course it could be better.

  • Very effective at... what? I mean, they seem to not be able to tell the difference between a legit mastodon instance and a phishing site, so why would they suddenly be able to tell if it effectively blocked a site that was actually malicious?

    Yes, blocking sites on a blocklist works very well. Whether those sites are legit or not doesnt matter at that point, to them, as they assume they all are malicious.

    Do you see what I mean?

I often click links on phishing mails I get just for fun, and more often than not they result in webpages being blocked by Chrome. Anecdotal, but there you go.

  • This is a bit dangerous because of zero-days. If you do this in a throw-away isolated virtual machine, this is probably safe.

    • Very much true. It's almost always a specific type of phishing that tries to get me to enter bank credentials, usually not really serving malware. But you make a good point.

  • You shouldn't, the links usually have unique data embedded and it will confirm your email as a valid target for future attacks. You are basically adding a "real mailbox with an active, gullible user" tag to your email in the spammers list.

The strange thing about SSL is that it is meant for strangers. If a group knows each other a self signed certificate can be safer because the group controls the certificate. I always assumed the push for SSL everywhere was to institutionalize man in the middle attacks.

Some things are worth protecting against, but most of the blocking I've seen has beeen sites that just don't conform with google's prefences. Given that there is a conflict between google's preferences and mine, there is a problem.

Good points. Malicious actors doing actual abuse can just rinse and repeat with new domain names.

  • Malicious actors can easily change domains, legitimate businesses can't.

    So this is a harsh punishment to all good people, and very weak punishment to all scammers and spammers.

    • Especially relevant when you consider the organic search traffic legitimate webmasters may rely upon, vs. the email campaigns or even paid traffic bad actors can quickly spin up.