I Am Security Rotating Header Image

Blocking legitimate sites in real-time

I Ran into this on Slashdot: http://tech.slashdot.org/tech/08/09/21/1827209.shtml. It seems like the Google filter for malicious sites was blocking a whole domain name – including all sub-domains, which happened to be a dynamic DNS provider. A Big false positive, and a big problem to all the legitimate sites that were hosted using this domain. Disclosure – I used to run my personal domain using the services provided by DynDNS as well.

The root of the problem here lies in the concept that someone (even if it’s Google) presumes that providingĀ a list of “bad” sites can be used to provide security to users. It’s just not going to work no matter how fast the list is updated, and no matter how “real-time” the scanning and categorizing of the sites are. Unless the real-time is applied to where it is supposed to be applied – when a user requests content from a site, scanning in real-time the content that this user receives. No more, no less. Remember that content differs from user to user, and malicious code may be delivered to one but not to another user!.

Share:
  • Digg
  • del.icio.us
  • Facebook
  • Twitter
  • LinkedIn
  • Technorati
  • Google Bookmarks
  • email

Related posts:

  1. Blocking Facebook? Not popular, and not effective
  2. Have something to hide? make a lot of noise about it!
  3. The great AV vs. AV debacle starts again?
  4. Google’s “Ghost in a Browser”, WebSense, and more…
  5. IFRAME is a security risk???

Leave a Reply

Powered by WP Hashcash

Get Adobe Flash playerPlugin by wpburn.com wordpress themes