'How did Google come to have so much power?'

Advertisement
By Nicole Perlroth, New York Times | Updated: 6 June 2012 12:05 IST
Highlights
  • On New Year’s Day, Robert Epstein woke to nine e-mails from Google. His Web site had been compromised by hackers, Google informed him, and until Dr. Epstein, a psychologist, cleaned up his site, Google would warn any would-be clickers to stay away.
On New Year's Day, Robert Epstein woke to nine e-mails from Google. His Web site had been compromised by hackers, Google informed him, and until Dr. Epstein, a psychologist, cleaned up his site, Google would warn any would-be clickers to stay away.

Their ensuing exchange offers a glimpse into the frustrating nature of Web site infections, which are increasingly widespread but hard to diagnose and cure. Dealing with them, or even dealing with an Internet giant's claim that it has spotted one, can cause even the most sensible people to throw up their hands and seek court injunctions.

Dr. Epstein, a former editor in chief at Psychology Today, says his Web site, which offers free interactive mental health screening tests, can draw up to 5,000 visits a day. Now, four days after Dr. Epstein first heard from Google, a search for his site yields the digital equivalent of a skull and crossbones: "This site may harm your computer," Google warns. Click on the link and another message pops up. This one does not mince words: "Reported Attack Page! This web page at drrobertepstein.com has been reported as an attack page and has been blocked."

Dr. Epstein contacted his Web host and Google. The former could not find any evidence of malware but reset his site's configurations anyway. The latter would respond only in boilerplate. So Dr. Epstein responded to Google's e-mail, this time copying Larry Page, Google's chief executive; David Drummond, Google's legal counsel; Dr. Epstein's congressman; and journalists from The New York Times, The Washington Post, Wired and Newsweek.

"Dear nameless Google worker," Dr. Epstein's e-mail begins. "Your company is continuing -- initially through incompetence and now through negligence and malice -- to do irreparable harm to my good name and reputation."

"I am not a spammer and I do not run 'attack sites,' as you have now been claiming to the world for three days," the e-mail continues. "I demand that you unblock my websites immediately."

Google responded to Dr. Epstein (and the journalists), telling him that it had re-scanned his site and had found it was still infected and still redirecting users to a site known to host malicious code.

"We understand that your site has been compromised against your will, but in the spirit of protecting users, we hope you understand that we will continue to display a warning for as long as we continue to detect malware on your site," it said.

Dr. Epstein says Google's automated crawler is referring to a nonexistent page on his Web site. He now plans to seek a court order forcing Google to remove its warnings.

The fact is, unbeknownst to their owners and administrators, hundreds of millions of Web sites have been programmed to infect visitors with malware. In one month in 2010, Symantec reported seeing 40 million Web attacks, on average, every day.

"Mainstream Web sites are one of the primary ways computers are getting infected," said John Harrison, a project manager at Symantec. "We've seen physicians' Web sites, news sites, even a Fortune 1,000 company infect visitors with malicious code."

Hackers troll the Web using automated software that looks for legitimate Web sites with security weaknesses. Once they find vulnerabilities, they  install  Web attack toolkits or redirect visitors to sites that host malicious code.

"Anyone with a hundred dollars and basic computer skills can use these automated tools," Mr. Harrison said. "They've lowered the barrier to entry, and they are getting harder and harder to track down."

Hackers have become so adept at covering their tracks, Mr. Harrison said, that it's getting more challenging for Web host providers and even skilled security researchers to track them down.

In some cases, hackers will only redirect users to malicious sites if they come to the site through a particular search engine. Or they will serve up malicious code the first time a user clicks on a site and then never attack again, to confuse security experts.

So what can the owner of  an infected Web site do? Mr. Harrison suggests working with the Web host provider, installing updated Internet security software and using stronger administrator passwords.

Having exhausted those options, Dr. Epstein e-mailed Google demanding telephone numbers for Larry Page so he could let Mr. Page know his search engine had made a grave mistake.
"Everything I'm getting back is automated or boilerplate. This is going nowhere," Dr. Epstein said. "How can Google come between an Internet service provider and an end user? How did Google come to have so much power?"

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale
  2. OTT Releases of the Week (Mar 30th - Apr 5th): From Aamir Khan's Sitaare Zameen Par
  3. Infinix Note 60 Pro With Active Matrix Panel to Arrive in India on This Date
  4. OnePlus Nord 6 First Impressions
  5. Honor X80i With MediaTek Dimensity 6500 Elite Chip Launched: See Price
  6. ChatGPT is Now Available in Apple CarPlay, but With Some Limitations
  7. Honor Play 80 Pro With a 7,000mAh Battery Arrives at This Price
  8. Vivo V70 FE Launched in India With 7,000mAh Battery, 200-Megapixel Main Camera
  9. PS Plus Monthly Games for April Revealed
  10. Best Mobiles Under Rs. 30,000 in India
  1. Motorola Signature, Razr 60 Ultra and More Models Now Eligible to Receive Android 17 Beta Updates
  2. ChatGPT App May Soon Get a Custom Share Sheet, File Picker Interface and More UI Changes
  3. OpenAI Brings ChatGPT to Apple CarPlay, but It Cannot Access Navigation and Live Location Data
  4. iPhone 17 Pro Max At Rs. 1,02,900 in Apple 50th Anniversary Sale; iPad, Watch Available With Offers
  5. Google Pixel 11 Pro XL Leaked CAD Renders Reveal Design Identical to Pixel 10 Pro XL
  6. Apple's iPhone 18 Pro Models May Not Arrive in Classic Black Finish Just Like iPhone 17 Pro, Tipster Claims
  7. Oppo F33, Oppo F33 Pro Launch Timeline, Price Range Revealed in New Leak
  8. Capcom Adds Original Versions of Resident Evil 1, 2 and Resident Evil 3 Nemesis to Steam
  9. Google's Next Fitbit Wearable Could Launch Without a Display; Said to Require Paid Subscription
  10. CFTC-FTX Settlement: Former FTX Executive Nishad Singh to Pay $3.7 Million, Faces Trading Ban
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.