• On CHOW: Groundbreaking hangover cure
January 31, 2009 8:44 AM PST

Google warns entire Internet is malware

by Natalie Weinstein

Updates at 9:10 a.m., 9:45 a.m., 10:30 a.m., 10:40 a.m., 11:25 a.m., and 12:15 p.m. PST: Google's and StopBadware.org's numerous responses added. Rewrites have been made throughout to sum up the issue.

For about an hour on Saturday morning, Google listed every site on the Internet as malware.

After the initial problem was fixed, it took a couple of hours to iron out who actually was to blame--Google or a nonprofit known as StopBadware.org.

Here are Google's results for a search on 'Google' early Saturday morning. Click on image for a larger view.

(Credit: Google, via Friendlybit.com)

TechCrunch and CNET reported around 7 a.m. PST that every site found via Google search was flagged with this message: "This site may harm your computer." As part of Google's malware protection, clicking on a flagged site's link would pull up an additional warning. Although a link could simply be cut and paste, Google's warning was unnerving enough to keep some people from pushing their luck.

Twitter was awash in the news, with thousands of people posting about their kindred experiences on Google search.

In a blog posting just after 9 a.m. PST, Marissa Mayer, Google vice president of search products & user experience, attributed the problem to "human error" and to a URL list provided by StopBadware.org. But about 30 minutes later, a blog posting on StopBadware.org disputed her explanation. An hour after that, Mayer posted Google's mea culpa.

Below is Mayer's 9:02 a.m. PST posting, with her 10:29 a.m. PST update folded in. Her update acknowledges that StopBadware.org did not provide the wrong information and that it was solely Google's fault. In her update, Mayer wrote: "This post was revised as more precise information has become available."

Note: The sentences that Mayer removed in her update are noted with strike-outs and brackets. The sentences she added in her update are in bold. Here is Mayer's explanation:

If you did a Google search between 6:30 a.m. PST and 7:25 a.m. PST this morning, you likely saw that the message "This site may harm your computer" accompanied each and every search result. This was clearly an error, and we are very sorry for the inconvenience caused to our users.

What happened? Very simply, human error. Google flags search results with the message "This site may harm your computer" if the site is known to install malicious software in the background or otherwise surreptitiously. We do this to protect our users against visiting sites that could harm their computers.

[We work with a non-profit called StopBadware.org to get our list of URLs. StopBadware carefully researches each consumer complaint to decide fairly whether that URL belongs on the list. Since each case needs to be individually researched, this list is maintained by humans, not algorithms.]

We maintain a list of such sites through both manual and automated methods. We work with a non-profit called StopBadware.org to come up with criteria for maintaining this list, and to provide simple processes for webmasters to remove their site from the list.

[We periodically receive updates to that list and received one such update to release on the site this morning.]

We periodically update that list and released one such update to the site this morning.

Unfortunately (and here's the human error), the URL of '/' was mistakenly checked in as a value to the file and '/' expands to all URLs. Fortunately, our on-call site reliability team found the problem quickly and reverted the file. Since we push these updates in a staggered and rolling fashion, the errors began appearing between 6:27 a.m. and 6:40 a.m. and began disappearing between 7:10 and 7:25 a.m., so the duration of the problem for any particular user was approximately 40 minutes.

Thanks to our team for their quick work in finding this. And again, our apologies to any of you who were inconvenienced this morning, and to site owners whose pages were incorrectly labelled. We will carefully investigate this incident and put more robust file checks in place to prevent it from happening again.

Mayer's update followed several blog postings from StopBadware.org manager Maxim Weinstein. StopBadware.org, which is coordinated through Harvard's Berkman Center for Internet & Society, doesn't partner only with Google. Its other partners include PayPal, VeriSign, Trend Micro, and Consumer Reports WebWatch.

After Weinstein read Mayer's initial explanation, he asserted that her posting was wrong. At 9:31 a.m. PST, he wrote on the nonprofit's blog:

Google has posted an update on their official blog that erroneously states that Google gets its list of URLs from us. This is not accurate. Google generates its own list of badware URLs, and no data that we generate is supposed to affect the warnings in Google's search listings. We are attempting to work with Google to clarify their statement.

About 10 minutes later, Weinstein updated the post with this:

Google is working on an updated statement. Meanwhile, to clarify some false press reports, it does not appear to be the case that Google has taken down the warnings for legitimately bad sites. We have spot checked a couple known bad sites, and Google is still flagging those sites as bad. i.e., the problem appears to be corrected on their end.

In an e-mail to CNET News at 10:08 a.m. PST, Weinstein reiterated that "Mayer's explanation was inaccurate. She has informed me that Google is working on an updated statement to clarify the facts."

In StopBadware.org's defense, Weinstein added:

Google scans websites to identify sites that may be dangerous to users. When it finds such sites, Google issues warnings in the search results. This morning, they inadvertently added these warnings to nearly all websites, causing user confusion.

StopBadware.org does not provide the data for these warnings. Our role is to use the data provided to us by Google for research/analysis, to support/assist webmasters in cleaning up sites and navigating the review process when their sites are clean, and to provide a third-party review when users hit roadblocks with Google's own process.

Our site was taken down this morning as a result of extremely heavy traffic due to the Google glitch, which led many users to seek additional information. As StopBadware.org is mentioned on the Google warning page that users see when they click on a search result that Google has flagged as bad, many people associated the warnings with us.

In a follow-up e-mail at 11:14 a.m. PST, Weinstein wrote that he was satisfied with Google's corrected response.

"I believe Google's updated statement accurately clarifies that Google does not receive the URL data from us and that we were not involved in this morning's glitch," he wrote.

What a way to start the weekend...

Note: I am in no way related to Maxim Weinstein.

Natalie Weinstein is an associate editor who works out of Austin, Texas. She spent a decade as a reporter and editor in the newspaper industry before joining the CNET News staff in 2000. E-mail Natalie.
Recent posts from Business Tech
Microsoft releases SDK for Facebook
EC formally objects to Oracle buying Sun
Compuware completes Gomez buyout
VMware elevates its desktop virtualization view
PC processor shipments break record
After 5 years, Firefox faces new challenges
Cisco ruffles feathers with new collaboration tools
Nvidia CEO says 'no' to Intel-compatible chip
Add a Comment (Log in or register) (22 Comments)
  • prev
  • 1
  • next
by January 31, 2009 8:59 AM PST
haha, I thought it was just me...thats funny
Reply to this comment
by Hairbawl87 January 31, 2009 1:27 PM PST
I thought the same LOL I was asking myself "Am I doing something wrong?"
by MSSlayer January 31, 2009 3:43 PM PST
Why would you think that? Seems odd to think you are entering queries "wrong'.
by Dylan_Wisor January 31, 2009 9:01 AM PST
Well it's true.
Reply to this comment
by ckurowic January 31, 2009 9:17 AM PST
Seconded.
by afterhours January 31, 2009 11:12 AM PST
ditto --- the web is crap.
by SleepyInKC January 31, 2009 1:01 PM PST
I'm harming your computer right now.
by chuchucuhi January 31, 2009 9:18 AM PST
I thought it was because I had just installed IE8 RC1 and then I tried it in Chrome and FF3...that's when I thought something was up but I hadn't had my morning cup of coffee yet so any sort of reasonable thinking was shot.
Reply to this comment
by crustycracker January 31, 2009 9:43 AM PST
Youtube URLs were not flagged.
Reply to this comment
by Spanwite February 1, 2009 7:04 AM PST
Images search, and with click on the image, same message until Afternoon!
by rapier1 January 31, 2009 12:56 PM PST
These sort of problems are what concern me the most about cloud computing. Its whole other set of failure points add to the chain.
Reply to this comment
by cuwickliffe January 31, 2009 3:12 PM PST
It just happened that I had installed the latest Chrome beta on my netbook and figured something was awry with that. I guess it wasn't just me. What a fiasco though. People like getting all in a tissy even on the weekends ...
Reply to this comment
by askermana271275 January 31, 2009 4:52 PM PST
Darn it I miss all the fun on the web.
Reply to this comment
by firefoxluva95 January 31, 2009 5:21 PM PST
Well you could argue that just by connecting online, you are exposing your computer to the possibility of getting infected. That risk depends on the security and Operating System but there is no absolute 100% security. There may be 99.99% but not 100%. So in a sense, Google was sort of right. Perhaps they were just trying to make a point and there really wasn't an error. It's all a conspiracy I tell you ;).
Reply to this comment
by PhaseDMA January 31, 2009 8:19 PM PST
Is this really news? Not really.
Reply to this comment
by flickrz January 31, 2009 11:35 PM PST
huh....And, it still doesn't show screensavers.com as the bad site that spits malware....
Reply to this comment
by billmosby January 31, 2009 11:36 PM PST
That's funny, I could have sworn that it didn't flag my site as "dangerous". Guess I didn't look closely enough!
Reply to this comment
by winstein February 1, 2009 4:30 AM PST
This is not funny at all. I thought my computer was compromised and that my wife was to blame. Now I have to cook for her for the entire week.
Reply to this comment
by Spanwite February 1, 2009 7:10 AM PST
I assume she cooks for you the rest of the Year :-) Be a Man, you get through this.
by NavalHistory February 1, 2009 4:58 AM PST
Hullo,

I experienced this glitch (http://www.telegraph.co.uk/scienceandtechnology/technology/google/4413065/Millions-hit-by-Google-breakdown.html), and I am very concerned that Google, which is so widely used by millions, report it is a temporary problem. Maybe this is their way of hiding it from the public.

I run www.naval-history.net (nearly 2 million visitors pa). Over the last few weeks I have had two such warnings trying to open my site and I know at least one other visitor has. Ten colleagues I contacted had received no warnings. Of the other 5,000 visitors daily, who can say.

When this first happened yesterday, I contacted the BBC Wales newsdesk thinking this was a major virus attack on Google, to be told my computer had a glitch. It obviously had not. I run Windows on a Mac, and both systems experienced it.

It suggests to me Google either has a potentially major software problem or is undergoing a serious attack.

Can I suggest you keep an eye on this.

Gordon Smith MBA, CEng
Naval-History.Net
Reply to this comment
by winstein February 1, 2009 7:51 AM PST
This is not funny at all. I thought my computer was compromised and that my wife was to blame. Now I have to cook for her for the entire week.
Reply to this comment
by BathroomVanities February 2, 2009 11:15 AM PST
I actually think that the entire Internet IS malware. If it wasn't, I wouldn't have to protect my children from it, would I?
Reply to this comment
(22 Comments)
  • prev
  • 1
  • next
advertisement
Click Here

After 5 years, Firefox faces new challenges

Mozilla helped reshape the Web since releasing Firefox 1.0 five years ago. Now it's got a reawakened Microsoft and Google Chrome to reckon with.

There's a map for that: GPS or smartphone?

Almost every handset comes with mapping software these days, but standalone GPS devices are becoming more affordable than ever.

advertisement

About Business Tech

Your destination for the latest news on enterprise-level information technology, from chip research and server design to software issues including programming, open source and patents.

Add this feed to your online news reader

Business Tech topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right