Live data from Hacker News

No More Deceptive Download Buttons

googleonlinesecurity.blogspot.com

111–120 of 263 posts

Re: No More Deceptive Download Buttons

#111
post #24

Perhaps now that Google has taken steps to block websites that display these ads, Google should take steps to stop accepting these ads onto their network in the first place. Most of the time when I see those DOWNLOAD/PLAY buttons, they're hosted on doubleclick.

I'm not sure they need to. Google's approach here tackles the problem of these ads being created from an economic direction: if nobody is seeing these ads, they won't make any CPM money any more, so their creators will stop running them. That's a much more sensible approach than doing what you're suggesting—trying to catch specific instances of people doing something nefarious that makes them money. That just causes…

You're aware that people view websites through browsers which don't run Google's safe browsing software, right? How is leaving them to get tricked into downloading malware (served via Google) "more sensible"?

Re: No More Deceptive Download Buttons

#112

I'm surprised of the negativity towards this action, but I guess I shouldn't be. A lot of you are in a very different situation than me and this will affect you directly. However, warning people away from being potentially tricked by these deceptive ads is a very good thing. Tons of sites out there that turn a blind eye to such ads and that's bad. Yes, there will be some unfortunate pain for sites that responsibly at…

> I'm surprised of the negativity towards this action

Its pretty basic. A lot of people are not happy that Google is serving these ads that they are telling you they will stop at the browser-level with a warning that makes the site owner look guilty. They want Google's Ad network to stop serving the ads in the first place.

Re: No More Deceptive Download Buttons

#113

Earlier quoted context omitted.

It also happens when one department is perceived as an "expense" like IT or R&D, and starts pushing against "revenue-generating" departments like sales. Of course, all components of a properly-functioning organization are revenue-generating. An idealized business in some respects would be people giving you money with no money being spent. Everyone knows that's not how the world works, but it's awfully hard to justify…

These are very good questions. I have wondered the same for a long time. Can anybody shed some light on this?

There are a lot of pieces to that puzzle. One of them is a stock program that basically guarantees the investors have a voice, but zero actual steering capacity for the company, coupled with a CEO who wants to take risks, coupled with a company track record of risks paying off in bizarrely outsized ways just often enough to keep investors hungry for the stock in spite of the fact that ownership of the stock grants them no control.

In short, the company's founders have the ability to steer where the company's money goes, nobody has the authority to tell them otherwise, and so far benevolent dictatorship is working. To give a concrete contrasting example, Apple ousted Steve Jobs when his leadership became fiscally risky; because of Alphabet's stock structure, there's no legal way for holders to directly oust Larry Page.

Re: No More Deceptive Download Buttons

#114

As I write this, the ranking of the comments here is... strange. Those who see this as being yet another way of Google using their power to manipulate what people see on the Internet are being heavily downvoted, while those agreeing with the practice are not? That doesn't feel like HN to me. I'm in the former group. This mollycoddling is just going to lead to more users who can't decide for themselves whether somethi…

As an experienced user, when I'm looking for some semi-obscure Windows program, I still do have problems distinguishing legit download links from this. Perhaps I'm too used to the radical method "just select what you want from the repository, and it will be installed automagically;" in other words, one of the issues here is nonexistent install management in Windows (party like it's 1998!), forcing users to run this g…

Hovering the link to check the URL is a good old trick. Well until browsers start to hide that as well.

Re: No More Deceptive Download Buttons

#115
post #53
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

Firstly, this will work on ad networks other than Google, so it''s more broad reaching than anything they could do just within AdSense. This is good. Secondly, and arguably more importantly, the way to stop these adverts is for them to cost the advertiser (in either money or time) without giving them the reward of revenue. If the ads stop working then people won't have a reason to make them. By stopping the ads in Ad…

"more broad reaching than anything they could do just within AdSense"

... as long as you don't care about browsers which don't run Google's Safe Browsing service.

You know another way to stop these ads? Make available an advertising network which doesn't serve them. Website owners who don't want to install malware on their users' computers - which is probably most of us - would prefer that network to the others. As-is, with even Google's network serving up malicious ads, the choice for a website that wants to run display ads appears to be either build out a sales team & manage inventory itself, or accept that some percentage of its users will get scammed.

Re: No More Deceptive Download Buttons

#116
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

I agree, I have a personal blog and wanted to experiment with ads, so I put AdSense up there. I reported the "Download" ones but just kept getting more, so i finally removed the ads.

Re: No More Deceptive Download Buttons

#117
So who decides what to flag? Is google analyzing the behavior of chrome users and then automatically flags websites? Or can users flag websites? I disabled "Automatically report details of possible security incidents to Google" and "Protect you and your device from dangerous sites" in the settings, will my chrome browser still report these websites (in case it ever did)?

Re: No More Deceptive Download Buttons

#118

I'm surprised of the negativity towards this action, but I guess I shouldn't be. A lot of you are in a very different situation than me and this will affect you directly. However, warning people away from being potentially tricked by these deceptive ads is a very good thing. Tons of sites out there that turn a blind eye to such ads and that's bad. Yes, there will be some unfortunate pain for sites that responsibly at…

> I'm surprised of the negativity towards this action Its pretty basic. A lot of people are not happy that Google is serving these ads that they are telling you they will stop at the browser-level with a warning that makes the site owner look guilty. They want Google's Ad network to stop serving the ads in the first place.

Thanks for that.

So can anyone point me to an ad served by Google that is as bad as the examples in the blog post? I thought Google had previously cracked down on such ads from the serving side too, although less deceptive ones were still allowed, no? I'm happy to be better informed!

Re: No More Deceptive Download Buttons

#119
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

Exactly this. Ads served through Adsense are flooded with these. We have spent countless hours trying to block all of them but they just pop up again under a different domain. So is Google going to punish publishers who are using Adsense if these ads come through Adsense?

Re: No More Deceptive Download Buttons

#120
post #109
post #35

Earlier quoted context omitted.

The little X button in the top right corner of Google display ads already performs this function, no?

I tried to flag a deceptive "Start Download" ad of this kind by clicking on this button a few days ago (which appeared on a site I run, annoyingly). The form I was required to fill out needed me to say where the link in the ad took me. So I"m supposed to click on the link in an ad which is pretty plainly attempting to install some kind of malware, in order to be able to report it? I'm supposed to either be 100% confi…

I just tried it on the getpaint.net site (mentioned elsewhere itt) and it only had an option box set with three options: inappropriate, repetitive, irrelevant.

But you could just right click and copy the ad link. The link would point to the ad network (e.g. googleads.g.doubleclick.net/aclk), but it would be better than nothing. Also, many ads include a domain, sometimes in a tooltip, and usually just the tld, but again, better than nothing.

Post reply on HN