On the Google Webmaster Central blog, Ben asked why sites with malware aren't removed from search results.
Users often use Google to search for sites they already know about. Urls are hard to remember but users can remember a couple of search terms and use those instead - like "barak obama" or "john mccain". If a user typed either of those queries, they'd expect the candidate's official site to rank near the top. But malware can strike any website: big or small; Democrat or Republican; corporation, government or private citizen. If Google removed the candidate's website from search results, there would be a lot of confused users. (1)
By leaving the website in the search results and placing a warning on it, users can find what they are looking for but know that visiting the website may be dangerous.
(1) I am not suggesting that either candidate's website has ever had malware. It's just an example.
Update: Yes, yes, I misspelled "Barack". Fortunately, Google still finds the right site: http://www.google.com/search?q=barak+obama
Why are you reading this? Go outside. Do something meaningful with your life.
Monday, November 3, 2008
Sunday, November 2, 2008
Information
Webmasters often ask why Google can't give more information about malware on websites. A couple of factors come into play.
Google's automated scanners only see the end result of the infection. They have no way of knowing how or exactly when the malicious content was added to a website. There are many ways it could have happened, from sql injection to stolen passwords. The automated scanners just know the bad content is there now.
To some extent, the success of Google's automated scanners relies on the secrecy of the methods used. The team has published malware papers (like Ghost in the Browser [pdf]) that include overviews of the system. But we're uncomfortable publishing any more detail because malware authors can read that information too. We've observed malware trying to hide from our automated systems and a large part of my job is tweaking the system to adapt to new types of malware. Staying on top of what malware is doing isn't easy and providing exact descriptions of the scanners and what they detect would make it impossible.
Earlier this year Google released the Safe Browsing diagnostic page which list general information about what Google's automated scanners found on a website. Some webmasters have found that information helpful in cleaning up their site. Hopefully we can find other ways to share information with webmasters without compromising the success of the scanning system. If you've got specific ideas, please let me know!
Google's automated scanners only see the end result of the infection. They have no way of knowing how or exactly when the malicious content was added to a website. There are many ways it could have happened, from sql injection to stolen passwords. The automated scanners just know the bad content is there now.
To some extent, the success of Google's automated scanners relies on the secrecy of the methods used. The team has published malware papers (like Ghost in the Browser [pdf]) that include overviews of the system. But we're uncomfortable publishing any more detail because malware authors can read that information too. We've observed malware trying to hide from our automated systems and a large part of my job is tweaking the system to adapt to new types of malware. Staying on top of what malware is doing isn't easy and providing exact descriptions of the scanners and what they detect would make it impossible.
Earlier this year Google released the Safe Browsing diagnostic page which list general information about what Google's automated scanners found on a website. Some webmasters have found that information helpful in cleaning up their site. Hopefully we can find other ways to share information with webmasters without compromising the success of the scanning system. If you've got specific ideas, please let me know!
Sunday, October 26, 2008
Bowling
On Friday we went bowling for a friend's birthday. I hadn't been bowling in about 15 years. Several things were surprising. First, Google had the address wrong - it's 1205 Wellington, not 1025 - I've filed a bug. Second, the shoes were both comfortable and stylish - they had an embroidered "Rental" on the side - I almost stole them.
But the automatic scoring system fascinated me most. It detected which pins were down and calculated scores - players didn't need to do anything. Each lane had their own computer screen. You could manually override incorrect score - of course, none of us knew how to score anyway. Here's a blurry photo.

It's an old system - probably programmed by one or two people 20 years ago. It must be cool for them to know that their software is still chugging along. It was a good system - as players were added the height of the rows changed. There were awesome multi-coloured ASCII art animations when someone got a strike, spare or gutter-ball.
The system was from Mendes, a now defunct Quebec company. They built the software and the pin mechanisms. YouTube has a very cool video of the pin mechanism.
For the observant, yes, that's 5-pin bowling - a truly Canadian game.
But the automatic scoring system fascinated me most. It detected which pins were down and calculated scores - players didn't need to do anything. Each lane had their own computer screen. You could manually override incorrect score - of course, none of us knew how to score anyway. Here's a blurry photo.

It's an old system - probably programmed by one or two people 20 years ago. It must be cool for them to know that their software is still chugging along. It was a good system - as players were added the height of the rows changed. There were awesome multi-coloured ASCII art animations when someone got a strike, spare or gutter-ball.
The system was from Mendes, a now defunct Quebec company. They built the software and the pin mechanisms. YouTube has a very cool video of the pin mechanism.
For the observant, yes, that's 5-pin bowling - a truly Canadian game.
Friday, October 24, 2008
Google Blogs
I've just published a post about malware on Google's Online Security Blog and cross-posted to Google's Webmaster Central Blog. Avid readers (all 5 of you) will recognize the content as being adapted from a few earlier posts on this blog: "This site may harm your computer", Advance Warning, and How long does a review take?
A new point in that post is about Google's new notifications to webmasters with hackable servers. The best type of malware warning is one you get before you've been infected! Hopefully webmasters will find those notification useful and the team building them will be able to expand the program.
A new point in that post is about Google's new notifications to webmasters with hackable servers. The best type of malware warning is one you get before you've been infected! Hopefully webmasters will find those notification useful and the team building them will be able to expand the program.
Wednesday, October 22, 2008
Android G1 Phone in Canada on Rogers
Update: Also see my recent Nexus One in Canada post.
Getting the G1 working in Canada on Rogers' GSM network isn't hard, but you won't be able to use a true 3G connection - you'll only get an EDGE connection. For me, that's good enough and I love the phone. I've never owned an iPhone so I'll leave the iPhone vs G1 debate to others.
You'll need an unlocked phone. Apparently T-Mobile will unlock any phone for any customer who has been with T-Mobile at least 3 months. Of course, someone will write an unlocking program so new customers don't have to wait 3 months. You may also be able to buy an unlocked G1 from non-T-Mobile sources.
Put a Rogers SIM card into the G1 phone. You should have an iPhone/SmartPhone data plan with Rogers - the Blackberry plan won't work (at least not with these instructions). When I called to switch my plan I said that I had an iPhone - no point in confusing the operator. With the SIM in place you should have voice connectivity right away.
To get data working, go to Settings | Wireless controls | Mobile networks | Access Point Names. You'll see a long list of T-Mobile networks. Press the menu button, select New APN, then modify these values:
- Name: Rogers
- APN: internet.com
- Username: wapuser1
- Password: wap
- MCC: 302 - should be preset correctly
- MNC: 72 - should be preset correctly
Browsing, email, video and SMS works, but I haven't been able to get MMS working. It may be that my Rogers plan isn't configured for MMS. I think the below settings should work - if you find they do work or what to change to make them work, please let me know. Create a New APN and set these values:
- Name: Rogers MMS
- APN: media.com
- Username: media
- Password: mda01
- Server: 172.25.0.107 - or maybe this should be * - I've tried both
- MMSC: http://mms.gprs.rogers.com
- APN type: mms
I discovered a good Rogers developer document [pdf]. It's targeted at developers building applications for the Rogers network, but lists everything needed to get non-Rogers hardware connected. The first few pages are also a good overview of GSM/GPRS/EDGE, UMTS/HSPA, 3G, etc.
Update: To clarify, an EDGE connection is usually slower than a 3G connection. I say "usually" because it depends on a ton of network factors.
Update: If you have a G1 with a T-Mobile plan, you can bring it to Canada and it will just work, including data. You'll be roaming on Rogers network and you'll be charged whatever T-Mobile's roaming rates are, but no additional configuration is needed.
Update: Make sure to check out the comments for lots of other settings that work, including on some other Canadian carriers.
Subscribe to:
Posts (Atom)
