The use of "storage.googleapis.com" is probably because it's an "authority" domain that apps can't easily ban without side effects. Buckets can typically be used as a static site host where u can host a client side redirect, depending on how you set it up you can make it almost impossible for an app to ban a campaign in real time.
This has some good uses, by the way! VPNs and news websites that are blocked in Russia use it to either mirror content or redirect to the newest version.
Almost unbelievable that they allow this - except of course they do, because scamware makes a ton of money via in-app purchase, and Apple gets 30%, so of course they do. I'm sure people will come out of the woodwork now to white knight for Apple and spin this somehow. But anything that offends their business model can be removed in minutes, while software that by its title violates the App Store rules is just here indefinitely.
How does Apple allow this? Here I thought the App Store was supposedly superior to the Android eco-system and that's why Apple justified the insane 30% tax on developers back then
At this point it must be intentional that there's always something uncanny about these fake pages. That google logo is so old that if I see it I immediately know to get out of there.
So I find it fascinating how there's always the odd typo, the old logo, the impossible combination of iPhone needing an antivirus, etc and I refuse to believe is incompetence.
Entirely intentional because they want to filter out anyone who can see how scammy it looks, so they don't waste their time. This is bulk spam stuff. If they are actually targeting you, it will look very real.
Blackhole is the name of one of the services used in display-time malicious content filtering.
I’m guessing the urls in that db were either generating a ton of backend load, so they were pushed to devices, or perhaps are customized on a per user basis for some reason
Serve it with content-type set to text/plain and browsers won't try to render it. You can try a random html file on github. If you click raw it'll get rendered as text.
> If storage.googleapis.com weren't operated by Google, the domain would be blocked by Google's "Safe Browsing" long time ago.
Not true. You just need to make it an eTLD by adding it to the public suffix list. Only subdomains of domains on the PSL can be marked by Google’s Safe Browsing.
I thought this was going to be about how links have become harder and harder to follow on Insta. The login walls got progressively stronger (it feels like) and now it's just hard blocked
Sorry, Zuck. Not signing up for Insta, though you probably made a shadow profile of me
I tried visiting that link on my device, and after many redirects and uBO warning screens, I ended up on an AI content farm in my native language, Swedish.
With default uBlock Origin filters on mobile Firefox, all Medium blogs show up as a blank page. Which in this day and age is akin to saying that the page is utterly broken.
written-beyond|16 days ago
Waiting for the next part!
0______0|16 days ago
ghxst|16 days ago
notpushkin|16 days ago
samename|16 days ago
xp84|16 days ago
ronsor|16 days ago
krackers|16 days ago
halapro|16 days ago
wongmjane|16 days ago
That’s probably “Family of Apps” instead, referring to the family of apps that Meta owns (e.g. IG, FB, WhatsApp, etc)
hdjY28|16 days ago
neya|16 days ago
conception|16 days ago
amne|16 days ago
So I find it fascinating how there's always the odd typo, the old logo, the impossible combination of iPhone needing an antivirus, etc and I refuse to believe is incompetence.
flomo|16 days ago
efilife|16 days ago
Weird
ckwalsh|16 days ago
I’m guessing the urls in that db were either generating a ton of backend load, so they were pushed to devices, or perhaps are customized on a per user basis for some reason
est|16 days ago
CORS? sec-fetch-dest, sec-fetch-mode and sec-fetch-site ?
If storage.googleapis.com weren't operated by Google, the domain would be blocked by Google's "Safe Browsing" long time ago.
gruez|16 days ago
kccqzy|16 days ago
Not true. You just need to make it an eTLD by adding it to the public suffix list. Only subdomains of domains on the PSL can be marked by Google’s Safe Browsing.
selridge|16 days ago
mmsc|16 days ago
paulpauper|16 days ago
Facebook was known to aggressively filter URLs too if posted too often.
alex1138|16 days ago
Sorry, Zuck. Not signing up for Insta, though you probably made a shadow profile of me
regenschutz|16 days ago
hypertexthero|16 days ago
Should HN allow links to sites that break the back button, like all Meta sites (Ig, Fb, etc)?
unknown|18 days ago
[deleted]
j1elo|16 days ago
numpad0|16 days ago
unknown|16 days ago
[deleted]
throwaway290|16 days ago
should App Store platform fees fund getting this stuff banned?