5 ms·
I have had a Google sheet I created years ago and edit periodically that has also been flagged but not removed. It has a number of URLs. I suppose it's possible
by computer23 4y ago
I have had a Google sheet I created years ago and edit periodically that has also been flagged but not removed. It has a number of URLs. I suppose it's possible at least one of the URLs is no longer legitimate.
There is a yellow banner "This file looks suspicious.
It might be used to steal your personal information" and an option to "Request a review".
It also says "This file can still be viewed, edited, and shared, but users will see a warning that alerts them that the content may be harmful. These restrictions were put in place because this content violates Google Drive's Phishing policy."
There is no indication of why the file was flagged.
Despite my concerns about a human looking at my personal file, I bit the bullet and clicked review several times but the banner remains after several months. Google support hasn't been helpful even though I'm a paid user.
I have now received 5 emails from "Google Drive Safety" notifying me of this alleged violation.
- bsedlm 4y agowhy assume that the review would be done by a human? I'd wager the "reviewer" it's merely a more computationally expensive process
- powerhour 4y agoHumans are involved at some point, if only while developing the software or writing up the spec. They ought to figure out how to do better.
- bsedlm 4y agobut ultimately, the "executives" making the decisions of what software to develop, which bugs to hunt, and so on, are all basing their decisions on data, reports, and many sorts of 'metrics'. Additionally, I suppose in a company as big as Google, all this decision making is backed by written communications. All this written stuff is subject to legal scrutiny. All must abide by 'approved' rules, guidelines, etc.. Squinting a little bit (maybe some may need to squint harder) it's clear that in the end everything is being done according to a computational (written) process. this is essentially what 'skynet' (from the terminator) or the matrix actually means. if every human involved is following data and written guidelines, the decisions are being made by a computer program running across many hundreds of humans pushing "paper" around.
- computer23 4y agoI suppose you're right that it doesn't explicitly say a human is doing the review. It says: Review process If you think this is an error, or if you've modified the file to comply with Google Drive's Terms of Service, you can request a review. 1. Your file will be reviewed This file will remain restricted during the review. 2. A decision will be made If the file is found to be safe, all restrictions will be removed and you’ll be able to use and share it with others. If it's found to be unsafe, the restrictions will remain in place.
- ttgurney 4y agoI find this kind of language positively disgusting: > Your file will be reviewed > A decision will be made > If the file is found to be... > ... restrictions will be removed ... It is the archetypical "mistakes were made". Note the constant use of passive voice, intended to hide the actor, and to keep you from even thinking about who is doing these things and thus who is responsible. By the way, no better is the most likely alternative "Google will review...". I'll leave deducing the reasons why as an exercise for the reader.
- coliveira 4y agoGoogle has created the idea that "an algorithm is responsible" for something. This is never the case. An algorithm is programed by human beings, therefore the humans who created and approved the algorithm are responsible for its decisions. It is just a form of hiding their intent under the disguise of an algorithmic intelligence. I'm pretty sure that if something is bad for Google, it will not be approved despite what "the algorithm" thinks.
- deltree7 4y agoThis is spoken by someone who is really clueless about AI and Machine Learning
- Schroedingersat 4y agoOr someone who understands that it's not magic, and there's still humans choosing the dataset, labelling the data and picking the loss function. This is exactly the kind of gaslighting GP was talking about. Just because there are more edge cases where the human has no idea what their algorithm does, doesn't absolve them of responsibility. You don't get to go free after running a bunch of pedestrians over by claiming you were too drunk to know where the road was or which direction your car would turn when you moved the wheel. If I put a running metal lathe in a kindergarten, I don't get to throw my hands up and say 'you clearly don't understand machining' when some children get dismembered.
- anonporridge 4y agoHow do you define 'expensive'? Because if it's measured in watt hours, this computational process is almost certainly drastically cheaper than using humans to do the same work, especially if you account for 20+ years of unprofitable training time per compute unit and 76% weekly downtime even at peak productivity.
- ASalazarMX 4y agoI think parent comment mean "a longer automated check than the one that flagged the content". I think he meant no human would make the call, but another routine.
- deleted 4y ago[deleted]
- nimbius 4y agoscrew this technocratic neofeudalist garbage. ive been encrypting my entire google drive for a while now for exactly this kind of overreach in the past. https://dev.to/petarov/store-encrypted-files-in-google-drive-3d62 https://dev.to/petarov/store-encrypted-files-in-google-drive...
- jug 4y agoI can also recommend Cryptomator (F/OSS) for this client-side encryption, which also supports other services than Google Drive. https://cryptomator.org https://cryptomator.org
- balderdash 4y agoAnd at least on iOS it works nicely with the native file system
- kup0 4y agoOh wow, I didn't realize it worked seamlessly with file systems like this. Definitely considering this now.
- cmroanirgo 4y agoHow have I not heard of this? Doing a quick HN search I see it's been posted multiple times over the years, but with minimal uptake. https://hn.algolia.com/?q=https%3A%2F%2Fcryptomator.org%2F https://hn.algolia.com/?q=https%3A%2F%2Fcryptomator.org%2F Perhaps the problem is that the privacy conscious have already deplatformed & do their own syncing to private cloud, whereas the others are still using the platform & don't care as much. I'm in the first group, but have become increasingly weary of keeping servers online (I self host everything) & I'm see a lot of promising results in Crytomator... but there's one inevitable gotcha: those very platforms can cut you off at some point in the future. So, you'll need to multi sync across multiple platforms for redundancy. That said, cryptomator looks good!
- hoppyhoppy2 4y agorclone is good too, particularly for people using the command line, and supports client-side encryption. https://rclone.org/ https://rclone.org/
- curiousgeorgio 4y ago> It has a number of URLs. I suppose it's possible at least one of the URLs is no longer legitimate. > "These restrictions were put in place because this content violates Google Drive's Phishing policy." > There is no indication of why the file was flagged. Isn't your answer in the warning (albeit lacking some specificity)? If you have a bunch of URLs in there and admit not knowing about their legitimacy, it seems reasonable that at least one of them matches a database of known phishing URLs. Isn't it also reasonable to expect (and in many cases want) a company hosting publicly-shared files to notify users when content matches some heuristics for unsafe content, especially given the prevalence of phishing attempts? That said, there may still be a case to argue that the review process, heuristic, lack of transparency, and other implementation details are flawed. But I don't have a problem with them posting a warning message on content that looks suspicious. Complete removal, on the other hand (as in the case of OP) is another story, especially given Google's laughable process (or lack thereof) for appealing such cases.
- rsync 4y agoWhat, pray tell, is a “legitimate” url ? What is wrong with a list of phishing urls ? Sounds simultaneously useful and innocuous to me …
- curiousgeorgio 4y agoYou're right - a URL is either a technically valid URL or it isn't, but in this context, we're clearly talking about links to phishing sites (or not). As someone who operates a service that allows people to create and share lists of links on a public site, I can tell you from experience that it's not as innocuous as you might think. Scammers routinely use a trusted domain to host a link to their malicious final destination since the initial, trusted domain in often the one given the most scrutiny (e.g., from an email). It sounds silly to more technical users who understand how the web works, but unfortunately it's effective and super popular in phishing campaigns. To your point, yes - a list of phishing URLs would be useful in a lot of cases, but it's difficult for automated tools to tell the difference between those legitimate use cases and the much more common cases used for phishing, so they err on the side of caution. As mentioned, the human review / appeal process surely has room for improvement.
- kypro 4y agoIf I were you I'd back the whole of your Google account up ASAP. It wouldn't be unheard of for Google to suspend your entire account for a violation on a single product.
- mr90210 4y agoYikes
- raxxorraxor 4y agoFar more scary is that Google already has automated systems to classify content and probably very closely works with government to keep a close eye on citizen.