Live data from Hacker News

No More Deceptive Download Buttons

googleonlinesecurity.blogspot.com

31–40 of 263 posts

Re: No More Deceptive Download Buttons

#31
post #27
post #23

I hope they'll include a "Stop the nanny" flag in chrome://flags as well. I mean you can't even change the new tab page to a custom .html, without Chrome nagging you at every launch if the settings are correct. If you make a manifest.json and load as an unpacked extension, it will moan about that. FFS, I know what you're trying to do with Joe/Jane Noob, but at least give me something to skip that if I know what I'm d…

The hard part here is that, wherever you'd decide to persist a "don't bug me any more about this" flag, malware could also potentially write that same flag to that same place. For example, Windows UAC is frequently set to the "don't bug me about this, just auto-elevate" setting by malware.

> The hard part here is that, wherever you'd decide to persist a "don't bug me any more about this" flag,

Build a new binary - offer users to install a "developer" build of Chrome which is exactly the same as the mainstream "release" build, except it allows disabling the protections.

Re: No More Deceptive Download Buttons

#32
post #7

Perhaps now that Google has taken steps to block websites that display these ads, Google should take steps to stop accepting these ads onto their network in the first place. Most of the time when I see those DOWNLOAD/PLAY buttons, they're hosted on doubleclick.

I remember a few years ago AdSense was showing a lot of fake Download buttons (and users would complain about it). I haven't seen them recently, though, so I hope that means they've fixed that problem.

I just checked and the download page on getpaint.net still has a deceptive "Start Download" AdSense ad. That site came to mind because, a few months ago, I tried to be charitable and disabled ad blocking for a few days. That was the site where I decided enough was enough and started blocking again.

Re: No More Deceptive Download Buttons

#33
post #27

Earlier quoted context omitted.

The hard part here is that, wherever you'd decide to persist a "don't bug me any more about this" flag, malware could also potentially write that same flag to that same place. For example, Windows UAC is frequently set to the "don't bug me about this, just auto-elevate" setting by malware.

> The hard part here is that, wherever you'd decide to persist a "don't bug me any more about this" flag, Build a new binary - offer users to install a "developer" build of Chrome which is exactly the same as the mainstream "release" build, except it allows disabling the protections.

You don't actually have to go that far; there are plenty of Chrome settings controlled by command-line options, and that's usually safe enough—it's actually really hard for malware to "sneak in" command-line options (if the user is a regular user, while the the Chrome shortcuts in the Start Menu et al were installed under elevation, which is the usual case.) There's a command-line option to Chrome that entirely disables the sandboxing protections, for instance.

My distinction was just that there's absolutely no way to have a UI-based mechanism for disabling nags, since behind any UI is a persisted flag. If you're up for editing your shortcuts to add command-line options, that's fine.

Re: No More Deceptive Download Buttons

#34
post #18

Google should detect and block the buttons, not display full-screen warnings. What next? "This site contains controversial views"? Or "Politically incorrect website ahead"?

Google can't block elements on sites it does not control.

Warning users of phishing and warning users of speech that it finds objectionable are 2 different things entirely.

Re: No More Deceptive Download Buttons

#35

Earlier quoted context omitted.

There should be an easy way to flag an ad for inappropriate behaviour (by the user seeing it)

How long would it take before fake "Flag this ad" buttons start appearing on ads?

The little X button in the top right corner of Google display ads already performs this function, no?

Re: No More Deceptive Download Buttons

#37
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

Google doesn't charge for ads, it charges for impressions. If you user doesn't seem it, google doesn't get paid. It also seems like a very different tech than trying to determine what an ad script will actually show a user. So it's not easy as if they can do A they can do B. Still doesn't excuse the fact that they should be doing their best to block those kind of ads in their ad network.

FWIW, "impression" means "request". Who knows what the user saw.

Google AdSense is pay-per-click (or some algorithm, based on clicks against and the subject matter's value). In the context of adware rubbish, we are probably talking about AdSense. So no, Google doesn't pay per impression.

DoubleClick (part of Google for some time) may still offer an impression-based product. My experience of them a few years ago was that they'd negotiate on anything if you have enough traffic to make it worth their time.

Re: No More Deceptive Download Buttons

#38
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

It's a big company, I can imagine the browser guys wanting this but the ad guys saying they "can't" do this and there being a mini-war.

You get the sense that sort of thing happens all the time at microsoft for example, before Ballmer left it felt like the ASP.Net team were pulling in one direction, the Visual Studio team another and the IIS team had gone rabid and were just trying to bite everyone.

It happens when different products have different priorities.

Re: No More Deceptive Download Buttons

#39

Perhaps now that Google has taken steps to block websites that display these ads, Google should take steps to stop accepting these ads onto their network in the first place. Most of the time when I see those DOWNLOAD/PLAY buttons, they're hosted on doubleclick.

I'm not at all against this move from Google - it is good sense. However, to play Devil's advocate, what are the odds this was pushed down by the MPAA/RIAA or similar? This policy more or less directly targets sites that offer free online streaming or torrent downloads of Movies/TV/Music. The sites that wind up with these deceptive ads are typically sites that provide copyrighted content to their users. Again, this i…

Download button ads appear on websites providing useful utilities and in particular Minecraft content and add-ons. I'm having to educate my kids on what is and isn't a real download button. Its a pain in the arse.

I would say it hasn't come from the MPAA or RIAA. These deceptive download buttons appear on a myriad of sites which are not related to streaming/torrenting.

Re: No More Deceptive Download Buttons

#40
post #5

This is really important. One step closer to killing ad tech companies who only make money off my grandma and little brother.

You mean Google? I see a tonne of deceptive advertising propagated by Google's ad network.

No. I mean the companies whose sole business is to get you to download bundled malware, change your search engine, push ads to every site you browse using extensions etc.

Source: I've worked at one of those.

Post reply on HN