ampproject / ampproject/amphtml

Implementation of an AMP Cache Removal Feature for Enhanced Security against Illegal Content on Compromised Sites

Open
#39,704 10 comments 0 reactions 1 assignee Claimed by @erwinmombay View on GitHub
Stale Type: Feature Request
Dominant language
JavaScript
Stars
14.9k
Forks
4.1k
PR merge metrics
No merged PRs in 30d

Description

### Description

I am reaching out as a representative of the ANTI ONLINE GAMBLING team from Pelita Bangsa University, working in collaboration with the Ministry of Communication and Information Technology of Indonesia. We've been tackling the issue of governmental and educational sites hijacked for illegal gambling, with over 701 such instances identified as of December 19, 2023.

The misuse of AMP by these hacked sites is alarming, as AMP pages remain active in Google's cache even after the primary sites are taken down. This creates a false impression that the sites are still legitimate, misleading citizens and damaging the credibility of our institutions. The AMP pages are effectively aiding hackers by staying accessible via Google SERPs despite site suspension, takedowns, and error statuses like 404 and 403.

Our efforts to combat this, including reporting to hosting services, direct communication with site owners, and using Google’s content removal service, have yielded limited success. The process is slow, manual, and often hindered by the hackers' persistent access to the Google Search Console of the affected sites.

**Proposed Feature:**
I urge the AMPdev team to consider a feature that mirrors the functionality of Google's content removal tool but is specifically designed for AMP pages. When a site is confirmed to be inactive or compromised, a swift review process should follow, leading to the disconnection of its AMP cache within 24 hours. This would prevent the AMP version of the site from being served to users, thereby protecting them from fraudulent or harmful content.

### Alternatives Considered

Current methods, including Google's removal tool, are not fully equipped to address the specific challenges posed by AMP pages. The proposed feature would fill this gap, providing a targeted and streamlined solution for AMP cache issues related to security breaches.

### Additional Context

This feature is crucial not just for Indonesia but for any country facing similar challenges. It would significantly improve the security and trustworthiness of the AMP ecosystem, ensuring that AMP continues to serve its purpose without being exploited by malicious actors.

I am willing to provide further information and collaborate closely with the AMPdev team to see this feature implemented. My contact is jefry.mey.sendy@mhs.pelitabangsa.ac.id (JEFRY MEY SENDY).

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.