upvote
> These scammers usually do IP address checks to check for residential IP before showing the scam, and some also do some basic fingerprinting checks, so that is how they get past detection.

Same issue with spam sms in my country: I think they geo-locate it so submitting the link to safe browsing project takes way too long

reply
Yep. I Agree. I believe it's a question of economics, not technical challenges.

Google is absolutely smart enough to make these attacks un-economical. IMO they are unwilling to incur the loss in revenue this would involve (false positives, banned resellers etc).

reply
Another major issue is google safe browsing whitelists many of these subdomains that the attackers like to host their scam pages on.

As a result, even though "Enhanced" safe browsing can use Gemini Nano to do client side detection of scams and then flag it in google safe browsing for everyone, the entire domain and all subdomains are whitelisted, so that detection never seems to actually fire. https://blog.google/security/using-ai-to-stop-tech-support-s...

I'm not sure which domains this applies to, but it seems to apply to most of the domains that these scammers actually like to use.

reply