Hacker News new | ask | show | jobs
by jcrawfordor 1401 days ago
should? probably. But I also get, from a capitalist perspective, why they don't: they probably get enough "we swear our website is actually fine" tickets each day that they would need a sizable dedicated team to offer that kind of assistance. I don't think any of the browser vendors, Google and Mozilla included, will go to any real effort to help the reporter. At least I haven't seen them do so. I think they take the view, and I don't totally blame them, that securing your website is your problem, and they aren't going to offer security consulting for free.
2 comments

They're already checking where the malware is when reviewing a report or unlisting request. The email template would need exactly one value: the URL they found.

Likely they already store this info somewhere so that the next time anyone reviews the domain, the reviewer cannot overlook it. In that case, the system could be completely automated, sending the info to the hostmaster or tech-c of the domain or something.

If they provided proof they wouldn't get "we swear our website is actually fine" tickets. Or if they did, it would be easy to resolve them: Post the proof.

If you launch a product that targets other businesses and has the capability of destroying them, you better take responsibility for that.