> 3.) Fictitious Domain Considerations: As you may know, domains that has ".web" have faced issues related to fictitious domain name usage. While ".one" is not ".web" the combination of the subdomain and TLD triggers similar security protocols.
This is an LLM response. It's the classic pattern where the LLM says something completely unrelated to the topic at hand, realizes that it doesn't have a backspace key, and tries to hedge it in.
StilesCrisis 11 hours ago [-]
Has anyone ever tried giving LLMs a backspace? I have long wondered if their responses could be better if they had the ability to correct earlier parts of their text. Imagine how much harder it would be for us to write coherently with no backspace!
kangalioo 10 hours ago [-]
Thinking mode is exactly this. The LLM is allowed to dump thoughts, correcting itself along the way, and only surfaces the cleaned-up final answer to the user
krautsauer 9 hours ago [-]
It's not exactly this. It's something like it. But it's not a token that erases a previous token. Not that I know how that would work or how you'd get training data (edit histories of internet comments seem too few).
(You could have a token that hides previous tokens, but that'd be rather closer to CoT.)
dpkirchner 9 hours ago [-]
You could burn a few tokens by prompting the LLM to summarize the omit all of the "wrong" answers (where it overrode itself), after the user accepts the response. It'd probably reduce token use in the end, especially for long sessions.
Aissen 8 hours ago [-]
I'm not sure how that would work. You'd need to be able to reverse the operations in the KV cache, and I'm not sure if it's doable or not. And then you'd need to pick another path, or "rebalance" the probabilities or you'd go the same token path. CoT is probably easier to implement (but not necessarily better).
StilesCrisis 7 hours ago [-]
You could set up checkpoints where you store off the current state, and roll back to those checkpoints?
Aissen 7 hours ago [-]
Definitely, this is the easy "bruteforce" way, but it would require more memory, and would not resolve the second part of the problem (i.e "how to pick a better path").
Aissen 5 hours ago [-]
I'm not an LLM engineer, but I just got an idea of how it could work, combining CoT + checkpoints :
- use checkpoints to save KV cache before trigger CoT
- trigger CoT, save result as a summary
- go back to previous checkpoint
- instead of generating tokens, add result of CoT summary as input tokens
- continue normally
For the price of twice the KV cache memory, the context stays perpetually small, allowing smarter sessions. You can even apply that continually by summarizing tool calls, etc.
This idea is free.
I'm not sure it's that advantageous though: it consumes more memory, and the sessions are already quite long at 1M+ tokens. One would need to run the economics down, and just test if the shorter sessions are actually smarter with the continuous summarization.
gspr 9 hours ago [-]
Backtracking, of sorts. The LLM descends a seemingly fruitful path, and all of a sudden that path seems less so. So you backtrack a few tokens ("erasing"/"undoing") and resample the probability distribution a bit back in the stream.
zarzavat 9 hours ago [-]
ChatGPT does this. It will present an initial response, then change its mind partway through the thinking process and present a different response.
StilesCrisis 8 hours ago [-]
Oh wow, I'd like to see this. Any prompt which reliably triggers it? (Seahorse emoji comes to mind!)
deaton 8 hours ago [-]
Copilot does this too, kinda. It will give an initial response, realize that it might tangentially criticize Microsoft, then change that response to a refusal.
StilesCrisis 7 hours ago [-]
That's not a backspace, that's just a nanny filter. I think all bigco LLMs have something similar. e.g. Claude obviously uses this to prevent Fable from doing security work.
kevin_thibedeau 8 hours ago [-]
Chatgpt will erase text it wants to censor if you get near sensitive topics.
StilesCrisis 7 hours ago [-]
What sort of prompt would exercise this?
kevin_thibedeau 6 hours ago [-]
I inquired into a court case against a police officer who committed a sex crime. I only wanted to know the disposition of the case with no details. It briefly spit out a response involving the victim and wiped it away with a refusal to answer more questions. This was a year ago and the behavior may have changed by now.
StilesCrisis 5 hours ago [-]
That's just a standard nanny filter. The filter realized it was in the process of saying "sexual assault" or the like, and just shut the conversation down.
Chu4eeno 11 hours ago [-]
Yes, it was invented by an anonymous user on 4chan in the early 2020s, then sanitized by a Google paper some years later as CoT (chain of thought) or thinking tags, where the model iterates on its own before writing a final response.
All models do it now.
natpalmer1776 17 hours ago [-]
There needs to be a Hanlon’s razor but for suspecting something is LLM generated. The typo and grammar mistakes in the response lead me to think it’s a human, but no way to really know.
embedding-shape 13 hours ago [-]
> The typo and grammar mistakes in the response lead me to think it’s a human
People using LLMs to "spam" slop already caught up on this sentiment and are purposefully introducing grammar and spelling mistakes in the outputs now. I'm not saying yay/nay in this particular case, just sharing what I've seen in the wild. If a company get complaints that customer support is too robotic after starting to use LLMs for it, making it more concise and introducing subtle mistakes are two surefire approaches they'd get recommended.
neuroticnews25 11 hours ago [-]
I refuse to believe there are actual human beings so blatantly splitting a single concept into three artificial points.
lbriner 7 hours ago [-]
Been happening for years. You are not talking to a Developer but someone employed to do "support" who 1) might not know much or 2) think they know a lot but they don't 3) can't tell you the actual reason so try and BS an answer that will make you go away.
pwdisswordfishq 11 hours ago [-]
There needs to be a Grey's law but for suspecting something is LLM generated.
Matheus28 17 hours ago [-]
I GUARANTEE that was written by AI. This type of slop is unmistakable
FeepingCreature 14 hours ago [-]
Strongly doubt that a LLM would say "domains that has .web". Maybe it's a human paraphrasing a LLM.
cube00 13 hours ago [-]
For what it's worth and I know it can't be trusted, one of the AI detectors reported that sentence as "Your most AI sentences"
In this case, the combination of "web" and ".one" triggers these security measures.
It also flagged the whole email as 100% AI.
Traubenfuchs 9 hours ago [-]
To do this you need to run
hallucinated command
but wait, this command only existe for aws cli, not for oracle cli, so you need to run
actual command
Regularly happens to me in chatgpt.
chrisjj 10 hours ago [-]
Plus the idiot bot has confabulated a subdomain.
iamtedd 7 hours ago [-]
Why did you post the exact same comment three hours before this one?
chrisjj 13 hours ago [-]
Plus this idiot bot has confabulated a subdomain.
raverbashing 15 hours ago [-]
This doesn't make sense, even if the LLM had access to the source code
But yeah I kinda understand why would they want to block stuff with 'web'
lr0 13 hours ago [-]
I had a similar experience with Google's support this year when I logged to my older Google account from a new device, and I was automatically logged out from everywhere, when I was trying to login again it asked me to provide an OTP, when I asked the form to send me the OTP, it said that I've done so many attempts.
Later, I learnt that this is actually very common problem, if you see the "Me too" count on the Google Community Help, it's about 20K (https://support.google.com/accounts/thread/52598991/my-gmail...) users, that's a huge amount of false positives that Google refuses to care enough about to make a change in their automated account process, which they keep bringing up when users complain, they say the process is automated and nothing could be done about it (well, you are a tech company, can't you like change the code or something?). Unironically I had to wait uncertainly for a week then try, which did not work (same too many attempts), then after two weeks, then after couple of months, until I just gave up and created a new account. After 4 months I was able to finally login again.
FireBeyond 5 hours ago [-]
I'm now at the point where I cannot create a new Google account as my phone number "has been used too many times".
chadgpt3 11 hours ago [-]
Since "me too" begins with "me", support staff couldn't see it, and assumed it was just one product (human) having the issue.
an0malous 23 hours ago [-]
My business Workspace account got suspended recently, no reason given, can’t even login to contact support. I’m a solo user so I only had one admin account and that was the one locked out. There was just one text field to submit an appeal, so I did. I never got any email confirmation or tracking number for my appeal, it’s been a week now with no contact from Google. This happened about a week after they charged my credit card for the subscription.
I’m now in the process of switching to Fastmail. Google doesn’t give a shit about anything besides for their golden goose, I would encourage everyone to move away from their services before they just screw you with no warning or recourse just because they can.
an0malous 23 hours ago [-]
I’m also worried that this is just the future of SaaS where everything is a Kafkaesque nightmare of automated processes no one even understands anymore, and even these incidents are lost in so much complexity the businesses either don’t care or don’t even know it’s happening.
anonzzzies 18 hours ago [-]
It already is, that’s why I prefer companies I can physically visit. My hosting, email, payments for my company are now places I can reach within hours and just have a chat. In person, people are a lot less nasty and they cannot yet (…) fob me off with an AI.
hansvm 7 hours ago [-]
To be fair, the last time I had an issue with Google I just drove up to the Googleplex, and the front desk was very helpful routing me to the right real person. Proper support otherwise was impossible.
anonzzzies 7 hours ago [-]
Little sad it is like that, but at least local vendors have a chance now again. If they don't want to become 'the biggest' / make 'trillions', then you good service and 100k clients works fine too.
Gareth321 13 hours ago [-]
I think the AI dystopia will save us from the SaaS dystopia and ultimately win.
Dark patterns? AI doesn't care about dark patterns. It will instantly navigate around them.
10% annual price increases for absolutely no reason? No problem! Just build a replacement. 98% of SaaS applications out there no longer have a moat. My friend just contracted out a CRM replacement for Salesforce for a small company for $65k. He built it in a few days for a few hundred dollars. Obviously it's much less feature rich, but this company never used 99% of the features in Salesforce anyway. If anything, a light weight and bespoke CRM was what they always needed and wanted anyway. SaaS just wasn't viable for bespoke.
Ads killing the experience? AI will hunt down every explicit and hidden ad and eradicate it. The entire ad model is about to die.
EvanAnderson 21 hours ago [-]
That's pretty much the way the work did now if you're dealing with the "right" companies. The future isn't evenly distributed.
bell-cot 11 hours ago [-]
Is this particular problem really SaaS behavior, or is it "market share too large to care" behavior?
pnw 23 hours ago [-]
I ditched Google Workspace for Proton earlier this year and haven't looked back. Yes, the Proton apps don't integrate with everything and E2E encrypted data isn't as accessible as the data held in Google apps, but that's a bonus at this point.
Some people understand that there is naunce in the world. This is literally just the view of a single sponsor.
The way everyone gets so up-in-arms about the political views of a person three levels detached from the company is insane.
"Oh no, an individual with different views than me offhandedly mentioned Proton, the horror! I can't possibly differentiate between the views of a company and a separate individual!
Let's go grandstand about canceling our service and discouraging others from signing up because a random person thinks differently than me, and talked about the company."
evulhotdog 21 hours ago [-]
I believe when the views of that person who has influence on the product, and it does not align with the services they say they desire to provide, it’s an issue.
It also can purely be choosing to not support an organization that doesn’t align with your world view. The money in our pockets is the power to change things.
pitched 21 hours ago [-]
If I’m reading this right, it was a failure at due diligence before sponsoring a YouTube channel. That doesn’t sound at all like what you wrote so maybe you could expand on what the controversy was?
NietTim 13 hours ago [-]
Admitted it was a mistake, fixed it. Meanwhile google is actively platforming and funding the far right, and has no issue with it. What is the issue with Proton here exactly? This is a complete nothing burger.
Gareth321 13 hours ago [-]
Thankfully you have a domain you can switch. I feel bad for people with Gmail addresses who are really fucked when they're banned.
cube00 13 hours ago [-]
So much for my theory that they only did this to personal accounts. Although I guess I shouldn't be surprised, they do it to paid Google One accounts too [1]
I have the same issue but just for Google Cloud thankfully. Never got a response when I filled in the text field. When I contacted support they kept asking me do go to things in the Google Cloud dashboard (that I was banned from). Then eventually the person said they'd escalate and I'd get an email but I never got anything. Maybe I'll try calling a sales number.
cube00 13 hours ago [-]
> Maybe I'll try calling a sales number.
It's your sign to move on, there are hundreds of other cloud providers who will actually provide meaningful human support because they need your business unlike Google.
dabbz 17 hours ago [-]
Yea I really resonated with the messaging and mission of Migadu. Super reliable hosting. Have had it for nearly 5 years now. (of course now that I recommend it, I bet they're going to have an outage...)
phyzome 21 hours ago [-]
Dispute the credit card charge and you might be able to get in touch with someone.
Kwpolska 14 hours ago [-]
Or get your personal Google account permanently banned.
cube00 13 hours ago [-]
Exactly, if you think charging back against Google will result in a human reaching out to actually resolve the problem you are sorely mistaken.
danlugo92 22 hours ago [-]
I switched over to Zoho, has a lot of the same tools (mail/users/office) but UI is much more tech-y / old-school it e.g. more dense. Gets to the point.
I also use it with my own domain registered outside Zoho, so Zoho cannot actually lock me out of my email ever, only the data they host, though this is true for external domains in Google Workspace also.
2Gkashmiri 20 hours ago [-]
I got into self hosting in 2021.
A cheap 2.5Gb how from racknerd, $20-22/year, + domain.
It's been as smooth sailing as any other email provider.
Very satisfied.
Try it
hansvm 7 hours ago [-]
I can give racknerd a +1 by the way (compute rental in my case, not email). Prices are good, machines are machines, support exists and is helpful even for off-the-beaten-path issues, and so far they still exist despite seemingly being a small player. I'd use them again (I don't have many points of comparison though, so take this review with a grain of salt).
Schiendelman 16 hours ago [-]
How do you back up? What stack are you using?
cube00 13 hours ago [-]
Not OP but I backup with a scheduled rclone to B2 and rsync to my local storage at home so I have the required three copies.
I use the Maildir format so each message is its own file making it atomic.
baybal2 10 hours ago [-]
[dead]
dmd 1 days ago [-]
I get this sort of thing constantly because my domain, 3e.org, which I have had for 30 years, is apparently impossible. It's either too short to be real, or starts with a number (obviously impossible).
And like the author, 90% of the time I can just disable their front-end validation and go on my merry way.
jofzar 19 hours ago [-]
My friend has a short last name, and they still have many websites be like "must be longer then 3 letter"
eco 17 hours ago [-]
I was trying to activate Zelle with my bank and since Zelle is used for scams so often I had to do a bunch of identity verification steps while on the phone with my bank.
One of them was to submit a photo of my drivers license. After I did that it OCRed out some details and prepopulated a form with my information. Hitting submit gave me an error saying to use my full middle name, not an initial. My full middle name is a single letter though.
The person on the phone with my bank had no idea what to do and just kept asking me try again.
I busted out my elite hacker skills though and added a space to the end of the middle name field and was able to steal my own identity.
debugnik 10 hours ago [-]
> My full middle name is a single letter though.
I guess you could follow the Simpsons joke and spell the letter's name. I'm adding this one to my personal list of falsehoods programmers believe about names.
dprkh 18 hours ago [-]
Has your friend tried clearing their cookies?
sebmellen 18 hours ago [-]
Super cool website btw.. cheers!
lstodd 4 hours ago [-]
ahaha I still remember when 3com forced icann to allow leading numbers and that was some shitstorm
allarm 3 hours ago [-]
Huh? From RFC1123:
<quote>
2.1 Host Names and Numbers
The syntax of a legal Internet host name was specified in RFC-952 [DNS:4]. One aspect of host name syntax is hereby changed: the restriction on the first character is relaxed to allow either a letter or a digit. Host software MUST support this more liberal syntax.
</quote>
It's from 1989. ICANN was founded in 1998.
ivan_gammel 1 days ago [-]
Smells like „product engineering“. So a product or an engineering lead gets a task to reduce risks of specific abuse by preventing someone from sending email from yahoo or web.de clone. As a quick solution they add this filter without „overthinking“ it. The impact is low, a few customers in a million, so its stupidity gets unnoticed and, once first complaint reaches them, quietly deprioritized to death. Removing it is cheap: the justification for taking that work is likely the show stopper. Google is an old large corp that hires and fires at a scale. Owning removal of abuse filter to increase revenue by Planck-sized amount is an impossible thing.
TLDRisk 24 hours ago [-]
> Just for context, this is a premium domain with a very high premium renewal fee, no history of abuse obviously.
The registry premium domains on the new TLDs have several issues. The biggest IMO is a lack of price protection. Non-premium domains at least get the cohort based protection from section 2.10c of the registry agreement.
So, in addition to being treated as a 2nd rate domain, there’s nothing stopping the registry from cranking up the price if a domain gets popular. I don’t think it’s ever happened, but have never found contractual terms that forbid it.
I made a website about it a while ago after a registry reclassified one of my domains from standard to premium.
All more reason to stick with standard TLDs like .com, .org, .net, and your country’s TLD when you can.
sebmellen 18 hours ago [-]
Do you have a list of TLDs that don’t charge for premium domains? E.g. I have never seen a Registry Premium .com domain.
TLDRisk 11 hours ago [-]
Both .com and .net are price controlled. I think for the rest of the gTLDs it would be allowed. There’s a lot of nuance to it. The registry agreement never mentions premium domains, only pricing rules, so being accurate about the rules takes a long explanation. That’s why I made the site I linked.
chadgpt3 10 hours ago [-]
We really need to replace ICANN.
sam_lowry_ 1 days ago [-]
The end is really hilarious. Google had a stupid frontend-only validation, it seems.
chmod775 1 days ago [-]
Since Google themselves claim that's a security check, there's a bug bounty here.
The author of that article missed their chance making Google eat their words.
tzs 8 hours ago [-]
Or he missed the chance to get Google to move that check to the back end and then when it is time to renew find out that he cannot, if he’s lucky enough for it to not break earlier.
pigbearpig 22 hours ago [-]
I was under the impression Google engineers went through a rigorous hiring process, yet this is the sort of thing you get from lowest bidder consultants who have inexperienced devs.
anon48293 18 hours ago [-]
Nah Google and Microsoft have been offshoring to India for years. And sorry, but the developers there suck.
twostorytower 21 hours ago [-]
All that leetcode, whiteboarding, and Googly-style interview questions just to put front-end validation for security.
zerocrates 16 hours ago [-]
This seems like something more intended to avoid a bunch of pointless attempted signups from people who don't understand what having a domain means who then won't be able to do the later step where you verify that you actually own it.
A client-side check's not so unreasonable for that kind of thing.
Of course then you still want the list to be accurate and/or actually have some working support flow that results in an overzealous filter getting fixed. The code suggests that they do or did have a process at some point: the list of specific domains is an override that allows domains that would otherwise match one of the regexes and get blocked.
chadgpt3 10 hours ago [-]
Yeah but they said it was important security.
anilakar 17 hours ago [-]
Google has a computer making decisions that affect humans, and then they then have humans defending the decisions a computer did. We live in a dystopia. I hope "Karen" sees the irony in the day job she is doing.
A COMPUTER CAN NEVER BE HELD ACCOUNTABLE. THEREFORE A COMPUTER MUST NEVER MAKE A MANAGEMENT DECISION.
—IBM, 1979
Maxion 15 hours ago [-]
Technically not allowed in the EU. Will probably take several more years before they get fined a few hundred million again.
anilakar 15 hours ago [-]
Google will present multipe bogus reasons, such as:
1) it is not automated
2) the user consented
3) subjecting oneself to automated processing is a hard requirement
while in reality
1) a human rubberstamping the decision does not make it non-automated
2) coerced or forced consent via ToS and a checkbox is not consent
3) automated processing is not a requirement, just a business decision.
qingcharles 1 days ago [-]
I use a .one for a project where it makes perfect sense. Brevo, who are a huge email delivery platform, told me they don't support signing up with a .one domain. Fortunately, after a couple of weeks going back-and-forth one of their developers eventually saw sense and fixed it.
Sadly, with Google, I don't think you'll ever get the issue that far up the chain.
hkt 19 hours ago [-]
I've got a .email domain which various UK based retailers insist isn't a real domain from which email can be sent. I've been trying to convince Argos that it is real for about seven years.
To their credit, my building society actually took it all on board and fixed their system within a few months. To my incredible surprise, so did a major insurer.
dannyw 18 hours ago [-]
It probably made its way onto a Jira backlog somewhere, and some engineer thankfully took it as a 1 story point task.
corint 13 hours ago [-]
I wonder whether you could use GDPR to force compliance with this. You have the right to correct the record, after all.
hkt 8 hours ago [-]
Somehow I suspect GDPR isn't engaged there as they forbid the creation of an account in the first place, so they don't store the data. Maybe I could create an account with a different email address and try it then.
dutchCourage 1 days ago [-]
Since the author asked about Alice: it was an Internet provider in France in the early 2000's.
Some domains in that list are truly ancient. That was a trip down memory lane.
kome 15 hours ago [-]
same in italy btw, it was an italian provider with some european presence, since then they rebranded (several times actually)
petepete 1 days ago [-]
Just wait for someone at Google to read this post and then block the domain retrospectively.
llacb47 1 days ago [-]
And ban their entire Google account
qingcharles 1 days ago [-]
And delete all their data.
sunaookami 1 days ago [-]
*make it hidden, they will of course keep the data for themselves :)
f4c39012 16 hours ago [-]
I'd recommend not coming up with inventive fixes like this. There's a non-zero chance that check is in some server-side validation that you can't work around, and one day something you rely on becomes unrecoverable. Take it as a sign that it won't always work
otto23 8 hours ago [-]
Alice once was one of Germany's biggest DSL providers started 1995. Haven't heard of that brand for about a decade.
A quick websearch leads to an obviously still existing webmail service.
samlinnfer 17 hours ago [-]
>write an entire blog post ranting about how the company that runs the product doesn't give a shit and has terrible support
>signs up for it anyway
Why?
NewJazz 7 hours ago [-]
Notice how they were going to go to Microsoft next?
Clearly a masochist.
el1s7 7 hours ago [-]
sunk cost fallacy I guess
anon48293 8 hours ago [-]
With how many products Google suddenly retires, and how they often just ban or remove accounts without any sort of support, it’s mind boggling to me that anybody still considers to use any Google service honestly.
Well, apart from search and advertisement, maybe.
cube00 1 days ago [-]
If you could just change your company's domain name that'd be swell!
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
ValentineC 20 hours ago [-]
Google would rather cheap out on offshore support than waste their engineers' time talking to real customers.
Plus, any entity large enough probably has some kind of account manager or contact in Google that could hopefully escalate to the right person.
soraminazuki 21 hours ago [-]
As usual, this is more than just an honest mistake from Google. Not only is the given justification complete gibberish, it has AI written all over it. They have zero respect for users and it shows.
tomasphan 19 hours ago [-]
User != customer
jeroenhd 16 hours ago [-]
I can only presume this regex is there because Google had to block various scammers trying to use email hosting donain names when novel TLDs came onto the market. You can try to manage gmail.zip or outlook.mov but Google will probably flag you as a scammer if you try to email from them. Just because web.de isn't well-known outside of German circles doesn't mean the risk doesn't exist. These email providers, especially the ones hosted by Microsoft, have a history of buying multiple TLDs to offer users a localised email domain.
Blocking a second level domain like the Ukranians tried to use is surprising, though. I guess it's to prevent domains like outlook.co.uk or something like that?
These regexes were put there for a reason so I doubt they'll get removed, but if they fix their frontend-only detection script you're going to be locked out of your domain some day if you force your way through their checks. Seems awfully risky.
chinathrow 16 hours ago [-]
Thw regex on the frontend only makes zero sense though.
fillthegap 1 days ago [-]
I think ditching google would've been a better choice.
necovek 24 hours ago [-]
Well, if the alternative was going to be Microsoft 365... not so sure :)
soraminazuki 21 hours ago [-]
Or just ditch both. These companies have nothing but contempt for their users and signing up for their services is just asking for trouble. There are alternatives for email and whatever else is needed from these services.
23 hours ago [-]
fg137 20 hours ago [-]
> I was about to ditch Google completely and head over to Microsoft
That is the obvious thing to do. Don't understand why you even waste time there. You are digging a deeper hole for yourself.
If they cannot even provide proper support for sign up, what will happen when your account gets disabled for no obvious reason, and you potentially lose years of emails?
sandeepkd 23 hours ago [-]
the last paragraph was probably most important one here, and the lesson is If you truly want to enforce a validation then it has to be in the backend, the client side validation is just additional luxury if you can afford it.
On a different note, the validations were added for genuine reasons and most likely there would be some discussions/debate on the scope/cost/benefits. I would imagine if some one were to do it a a business seriously then they would have some way to override it on use case basis.
alibarber 15 hours ago [-]
In this case I think the validation is the next step when they ask you to set up a DNS record on the domain you typed in, and have their system match it.
Obviously if you typed Outlook.com this would be a challenge for you.
Unfortunately that may mean a support ticket and explanation and whatnot, and wasted time. Charitably, it might even mean the customer experiencing friction and going to another provider.
So in this case, front ending it seems to make a bit of sense, it’s just really clumsily done.
sikozu 1 days ago [-]
This was a fun read. Absolutely baffling behaviour from Google.
fg137 20 hours ago [-]
Not baffling at all. Google could not care less about individual users. (lots of horror stories about account getting disabled here and on reddit.) They only care about large enterprise customers. Not even the smaller ones, only the largest. Speaking from first hand experience.
jeroenhd 16 hours ago [-]
A division of the Ukranian government seems to come pretty close to a "large enterprise".
Maybe there are politics involved, but fixing a broken regex seems well worth the time to convince a foreign government to rely on your tech.
Of course, the support request never reached anyone who knows what a regex is, so bugs get confused for policy and nobody cares to fix it.
Mashimo 16 hours ago [-]
I get it, they want to stop scammeers to sign up with domains that look close like a real email provider. In this case web.de
bonzini 1 days ago [-]
alice.it is indeed an email provider's domain; based on the code snippet it seems like they are active in other countries.
alice.app however isn't registered anywhere.
11 hours ago [-]
t0mas88 1 days ago [-]
I would hope that somewhere at Google there is a policy that says you can't do anti-fraud and security checks in frontend only...
mikey_p 7 hours ago [-]
But isn't the web so much better now that everything is client side instead of server side?
I still think client side JS apps are the biggest mistake this industry ever made.
mikey_p 7 hours ago [-]
Stuff like this is why I migrated all my services away from Google. I don't do business with people that treat me like shit.
Hitish 8 hours ago [-]
Asking all those hard dsa questions, only to end up skipping server-side validation in one of their most-used products, is honestly unbelievable.
Elliott-Diy 23 hours ago [-]
Crazy that .one gets locked, but .arpa is fully okay.
soraminazuki 21 hours ago [-]
That's not going to pass the domain ownership validation though.
One time in college I bypassed client-side validation to order a burrito in a slightly earlier pickup window. More recently, I unhid html elements for features that were "disabled" on an ISP provided router.
You can query an LLM for "a bookmarklet to show hidden elements and enable disabled inputs".
jd3 20 hours ago [-]
Google Workspace has one of the most perplexing interfaces I've ever had the displeasure of getting to know and use.
Namely, it seems impossible to archive users despite the fact that we have a business account and have already archived numerous former employees.
mdrzn 14 hours ago [-]
"I was curious what would happen if I disabled this function, so I did, and I was happy to find out that once disabled, I was able to continue the sign-up process for my domain successfully. That means that this was only a frontend validation, not a server-side one."
This is so stupid.
torh 6 hours ago [-]
I love client side validation.
xlmnxp 15 hours ago [-]
Better then my email invalidate most email checks because it 5 characters wide
wodenokoto 19 hours ago [-]
I was about to say that the response was pretty clear, e.g, “your domain sounds like spam”, and you can’t give a more clear reasoning for “exactly why” than any other spam filter can give you an “exactly why reason”.
But then I saw the work around at it turned out it was just incompetence compounding.
yieldcrv 1 days ago [-]
ooof that's bad, all levels of support missed the frontend validation and blamed you and an opaque non-existent process instead
xyst 23 hours ago [-]
The engineer that implemented this probably used it to justify promotion.
"Reduced fraudulent signups by <made up metric>. Reduce business risk exposure."
Google engineering has certainly taken a nosedive.
1 days ago [-]
spl757 23 hours ago [-]
that's a trip. nice catch!
mpalczewski 1 days ago [-]
I wonder how this list ended up being created anyway. Was it a long standing issue, or just some ai slop? web.com, web.org, web.net don't look like an email provider.
layer8 24 hours ago [-]
The rationale probably was that end users primarily identify the email provider by the subdomain, not the TLD, and therefore to prevent spoofing they block all domains where the subdomain corresponds to an email provider, regardless of the TLD. Like, they don’t want to allow gmail.<anything>, and the same for all other email providers they know of.
mh- 1 days ago [-]
web.net, at least, absolutely is an email provider.
0x073 1 days ago [-]
web.de is also a big email provider in Germany.
brewmarche 23 hours ago [-]
Yes and gmx (listed next to it) as well, and I’m pretty sure that gmx offered/offers multiples TLDs (gmx.net, gmx.de, gmx.at, …)
I think the same goes for Alice (big ISP, offering mail addresses, in multiple countries)
It looks like some of these wildcards are for mail providers who use multiple TLDs.
mpalczewski 1 days ago [-]
fair enough. at least not primarily an email provider. so if they offer any email.
nom 23 hours ago [-]
scroll through a list of known email providers and you will notice they registered tlds for the countries they operate in, very typical for the old ones like yahoo yandex Freemail Hotmail etcpp
web.de is an oldschool German provider, as is gmx.de (and .at, .fr, .com, ...)
the regex smells like an inexperienced developer trying to be clever
croes 22 hours ago [-]
Or an pretty old regex from before all those new TLDs
suzuki_yuya 6 hours ago [-]
[dead]
baptistemicl 12 hours ago [-]
[flagged]
avazhi 17 hours ago [-]
If you use a whacky domain name suffix I dunno what else you expect.
Act unconventional and you’ll encounter various inconveniences for doing so, which applies to the real world, too.
sethaurus 13 hours ago [-]
Google sells (and also owns) domains with exotic TLDs. It's reasonable to expect them to get handled gracefully.
And as the article explains, it was the prefix (web.*) and not the suffix (one.*) which turned out to be tripping their validation rules.
Doctor_Fegg 11 hours ago [-]
That’s right, you should do the conventional thing by using gmail, and then you’ll never encounter any difficulties because Google never make capricious decisions like (checks notes) blocking access from certain paying customers using a half-arsed regex.
Rendered at 22:27:26 GMT+0000 (Coordinated Universal Time) with Vercel.
This is an LLM response. It's the classic pattern where the LLM says something completely unrelated to the topic at hand, realizes that it doesn't have a backspace key, and tries to hedge it in.
(You could have a token that hides previous tokens, but that'd be rather closer to CoT.)
- use checkpoints to save KV cache before trigger CoT
- trigger CoT, save result as a summary
- go back to previous checkpoint
- instead of generating tokens, add result of CoT summary as input tokens
- continue normally
For the price of twice the KV cache memory, the context stays perpetually small, allowing smarter sessions. You can even apply that continually by summarizing tool calls, etc.
This idea is free.
I'm not sure it's that advantageous though: it consumes more memory, and the sessions are already quite long at 1M+ tokens. One would need to run the economics down, and just test if the shorter sessions are actually smarter with the continuous summarization.
All models do it now.
People using LLMs to "spam" slop already caught up on this sentiment and are purposefully introducing grammar and spelling mistakes in the outputs now. I'm not saying yay/nay in this particular case, just sharing what I've seen in the wild. If a company get complaints that customer support is too robotic after starting to use LLMs for it, making it more concise and introducing subtle mistakes are two surefire approaches they'd get recommended.
In this case, the combination of "web" and ".one" triggers these security measures.
It also flagged the whole email as 100% AI.
But yeah I kinda understand why would they want to block stuff with 'web'
Later, I learnt that this is actually very common problem, if you see the "Me too" count on the Google Community Help, it's about 20K (https://support.google.com/accounts/thread/52598991/my-gmail...) users, that's a huge amount of false positives that Google refuses to care enough about to make a change in their automated account process, which they keep bringing up when users complain, they say the process is automated and nothing could be done about it (well, you are a tech company, can't you like change the code or something?). Unironically I had to wait uncertainly for a week then try, which did not work (same too many attempts), then after two weeks, then after couple of months, until I just gave up and created a new account. After 4 months I was able to finally login again.
I’m now in the process of switching to Fastmail. Google doesn’t give a shit about anything besides for their golden goose, I would encourage everyone to move away from their services before they just screw you with no warning or recourse just because they can.
Dark patterns? AI doesn't care about dark patterns. It will instantly navigate around them.
10% annual price increases for absolutely no reason? No problem! Just build a replacement. 98% of SaaS applications out there no longer have a moat. My friend just contracted out a CRM replacement for Salesforce for a small company for $65k. He built it in a few days for a few hundred dollars. Obviously it's much less feature rich, but this company never used 99% of the features in Salesforce anyway. If anything, a light weight and bespoke CRM was what they always needed and wanted anyway. SaaS just wasn't viable for bespoke.
Ads killing the experience? AI will hunt down every explicit and hidden ad and eradicate it. The entire ad model is about to die.
The way everyone gets so up-in-arms about the political views of a person three levels detached from the company is insane.
"Oh no, an individual with different views than me offhandedly mentioned Proton, the horror! I can't possibly differentiate between the views of a company and a separate individual!
Let's go grandstand about canceling our service and discouraging others from signing up because a random person thinks differently than me, and talked about the company."
It also can purely be choosing to not support an organization that doesn’t align with your world view. The money in our pockets is the power to change things.
[1]: https://support.google.com/accounts/thread/117103497/i-m-loc...
It's your sign to move on, there are hundreds of other cloud providers who will actually provide meaningful human support because they need your business unlike Google.
I also use it with my own domain registered outside Zoho, so Zoho cannot actually lock me out of my email ever, only the data they host, though this is true for external domains in Google Workspace also.
A cheap 2.5Gb how from racknerd, $20-22/year, + domain.
It's been as smooth sailing as any other email provider.
Very satisfied.
Try it
I use the Maildir format so each message is its own file making it atomic.
And like the author, 90% of the time I can just disable their front-end validation and go on my merry way.
One of them was to submit a photo of my drivers license. After I did that it OCRed out some details and prepopulated a form with my information. Hitting submit gave me an error saying to use my full middle name, not an initial. My full middle name is a single letter though.
The person on the phone with my bank had no idea what to do and just kept asking me try again.
I busted out my elite hacker skills though and added a space to the end of the middle name field and was able to steal my own identity.
I guess you could follow the Simpsons joke and spell the letter's name. I'm adding this one to my personal list of falsehoods programmers believe about names.
<quote>
2.1 Host Names and Numbers
</quote>It's from 1989. ICANN was founded in 1998.
The registry premium domains on the new TLDs have several issues. The biggest IMO is a lack of price protection. Non-premium domains at least get the cohort based protection from section 2.10c of the registry agreement.
So, in addition to being treated as a 2nd rate domain, there’s nothing stopping the registry from cranking up the price if a domain gets popular. I don’t think it’s ever happened, but have never found contractual terms that forbid it.
I made a website about it a while ago after a registry reclassified one of my domains from standard to premium.
https://tldrisk.com/beyond-basics/premium-domains/
The author of that article missed their chance making Google eat their words.
A client-side check's not so unreasonable for that kind of thing.
Of course then you still want the list to be accurate and/or actually have some working support flow that results in an overzealous filter getting fixed. The code suggests that they do or did have a process at some point: the list of specific domains is an override that allows domains that would otherwise match one of the regexes and get blocked.
A COMPUTER CAN NEVER BE HELD ACCOUNTABLE. THEREFORE A COMPUTER MUST NEVER MAKE A MANAGEMENT DECISION.
—IBM, 1979
1) it is not automated
2) the user consented
3) subjecting oneself to automated processing is a hard requirement
while in reality
1) a human rubberstamping the decision does not make it non-automated
2) coerced or forced consent via ToS and a checkbox is not consent
3) automated processing is not a requirement, just a business decision.
Sadly, with Google, I don't think you'll ever get the issue that far up the chain.
To their credit, my building society actually took it all on board and fixed their system within a few months. To my incredible surprise, so did a major insurer.
Some domains in that list are truly ancient. That was a trip down memory lane.
>signs up for it anyway
Why?
Clearly a masochist.
Well, apart from search and advertisement, maybe.
Surprising Google is happy to lose a paying company over this.
Although the author is taking quite the risk bypassing Google's validation like that. Not sure I'd be risking my company's workspace to do it in case Google wakes up ban hammer happy one morning.
Plus, any entity large enough probably has some kind of account manager or contact in Google that could hopefully escalate to the right person.
Blocking a second level domain like the Ukranians tried to use is surprising, though. I guess it's to prevent domains like outlook.co.uk or something like that?
These regexes were put there for a reason so I doubt they'll get removed, but if they fix their frontend-only detection script you're going to be locked out of your domain some day if you force your way through their checks. Seems awfully risky.
That is the obvious thing to do. Don't understand why you even waste time there. You are digging a deeper hole for yourself.
If they cannot even provide proper support for sign up, what will happen when your account gets disabled for no obvious reason, and you potentially lose years of emails?
On a different note, the validations were added for genuine reasons and most likely there would be some discussions/debate on the scope/cost/benefits. I would imagine if some one were to do it a a business seriously then they would have some way to override it on use case basis.
Obviously if you typed Outlook.com this would be a challenge for you.
Unfortunately that may mean a support ticket and explanation and whatnot, and wasted time. Charitably, it might even mean the customer experiencing friction and going to another provider.
So in this case, front ending it seems to make a bit of sense, it’s just really clumsily done.
Maybe there are politics involved, but fixing a broken regex seems well worth the time to convince a foreign government to rely on your tech.
Of course, the support request never reached anyone who knows what a regex is, so bugs get confused for policy and nobody cares to fix it.
alice.app however isn't registered anywhere.
I still think client side JS apps are the biggest mistake this industry ever made.
You can query an LLM for "a bookmarklet to show hidden elements and enable disabled inputs".
Namely, it seems impossible to archive users despite the fact that we have a business account and have already archived numerous former employees.
This is so stupid.
But then I saw the work around at it turned out it was just incompetence compounding.
"Reduced fraudulent signups by <made up metric>. Reduce business risk exposure."
Google engineering has certainly taken a nosedive.
I think the same goes for Alice (big ISP, offering mail addresses, in multiple countries)
It looks like some of these wildcards are for mail providers who use multiple TLDs.
web.de is an oldschool German provider, as is gmx.de (and .at, .fr, .com, ...)
the regex smells like an inexperienced developer trying to be clever
Act unconventional and you’ll encounter various inconveniences for doing so, which applies to the real world, too.
And as the article explains, it was the prefix (web.*) and not the suffix (one.*) which turned out to be tripping their validation rules.