Live data from Hacker News

No More Deceptive Download Buttons

googleonlinesecurity.blogspot.com

221–230 of 263 posts

Re: No More Deceptive Download Buttons

#222
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

[deleted]

Re: No More Deceptive Download Buttons

#223
post #148

This "Google Safe Browsing" initiative seriously worries me. It's effectively some unknown, mysterious, un-contactable set of AI algorithms/people/who knows what controlling the internet because Google owns everyone's browser. One of my websites got tagged as "Dangerous" and having "harmful programs" despite having nothing of the sort. My guess is a silly hiccup of their neural network algorithms. And I have absolute…

Yes, there's good reason why I'm posting this from https://www.palemoon.org/ which is Firefox without the politics - Chrome is too intrusive and non-transparent about its intrusion to boot.

Firefox uses Google Safe Browsing, like Opera and Safari.

Re: No More Deceptive Download Buttons

#224
post #9

This is a joke right ? We run Adsense display ads on our site and have to spend significant time every day reviewing and blocking new ads which try to use these deceptive practices. Since Google clearly has the tech to detect this they should be implementing it at source on the advertisers (malvertisers). Instead they are pushing this down to the publishers and hitting them with penalties. It's a clever ploy in some…

Fits with Google: free consumer services (paid for by advertisers); and Google gets the highest price possible by letting advertisers fight it out in real time (the other advertisers are the bad guys... but Google gets the money).

Re: No More Deceptive Download Buttons

#225
post #111
post #24

Earlier quoted context omitted.

I'm not sure they need to. Google's approach here tackles the problem of these ads being created from an economic direction: if nobody is seeing these ads, they won't make any CPM money any more, so their creators will stop running them. That's a much more sensible approach than doing what you're suggesting—trying to catch specific instances of people doing something nefarious that makes them money. That just causes…

You're aware that people view websites through browsers which don't run Google's safe browsing software, right? How is leaving them to get tricked into downloading malware (served via Google) "more sensible"?

You're not "leaving them"; making the ROI for an ad 30% lower (given a 30% Chrome install-base) is usually enough to make the advertiser give up on that ad, because they could instead be running an ad that converts ~90% as well and not losing 30% of their impressions in the process.

Now, the advertisers who only run these mal-ads will stick around and continue running them. They're also the ones who would fight tooth-and-nail to make their mal-ads more clever, instead of giving up and switching to regular ads; so they're exactly the ones Google will have a hard time discouraging at the ad-network level.

My hope for those is that other browsers simply copy Google's strategy here. If Chrome, Firefox, and IE all do this, there's pretty much no point in running these ads any more.

Re: No More Deceptive Download Buttons

#226
post #33

Earlier quoted context omitted.

You don't actually have to go that far; there are plenty of Chrome settings controlled by command-line options, and that's usually safe enough—it's actually really hard for malware to "sneak in" command-line options (if the user is a regular user, while the the Chrome shortcuts in the Start Menu et al were installed under elevation, which is the usual case.) There's a command-line option to Chrome that entirely disab…

> (if the user is a regular user, while the the Chrome shortcuts in the Start Menu et al were installed under elevation, which is the usual case.) Nope. Windows allows deletion of "protected" shortcuts e.g. from your desktop and launch bar.

You mean shortcuts placed in the All Users Desktop/QuickLaunch/StartMenu folders? (I'm guessing it's just "hiding" them with a Desktop.ini entry, rather than truly deleting them?)

That's probably fine, actually, as long as the user (i.e. malware) isn't allowed to create their own shortcuts to replace the deleted ones. I assume there's a GPO to disable the per-user Desktop/QuickLaunch/StartMenu folders, so that only the results from the All Users ones show up?

Re: No More Deceptive Download Buttons

#227
post #129

Earlier quoted context omitted.

Most websites seem not to care about the content they deliver to their visitors. When I visit xyz.com, it is xyz.com's job to ensure that it doesn't deliver to me malicious content. I have zero sympathy for xyz.com telling me that it's not their problem, they serve 3rd party ads and if these ads are malicious it's the fault of these advertisers not their.

Sure, this is fine, but Google seems to plan to block sites which show malicious ads served by Google 's AdSense. That's idiotic. This is the second case in a month of Google punishing web publishers for using Google products. (The previous case was Google punishing non-https search results, when in fact many of Google's own web publishing tools don't support https.)

And I'm willing to bet Google will make a special exception for itself. I actually posted a screenshot on my G+ page yesterday of the most recent fake download button I saw online... On a YouTube banner ad, served by Google AdSense.

Re: No More Deceptive Download Buttons

#228

Earlier quoted context omitted.

Didn't Oracle reveal recently (maybe I'm totally misremembering this) that Google receives a shitload of revenue via Android?

Yes. To date, Android has generated $31 billion in revenue and $22 billion in net profit. http://www.bloomberg.com/news/articles/2016-01-21/google-s-a...

Counting web ads served to users as revenue generated by the computer's operating system is ludicrous. Oracle is trying to misrepresent the amount of money made so they can sue for damages. The numbers are BS.

Re: No More Deceptive Download Buttons

#229
post #15

I will take programs like this seriously when Google stops bundling Chrome installer with unrelated software like Adobe Flash.

Flash is unrelated to a web browser? I mean I hate flash as much as the next guy... but how can Flash not be related to a browser?

Chrome has Flash built-in. Shipping Chrome with Flash is inane, because if you install Chrome, you don't need Flash. o_o

Re: No More Deceptive Download Buttons

#230
post #15

I will take programs like this seriously when Google stops bundling Chrome installer with unrelated software like Adobe Flash.

Adobe Flash is a browser plugin. Chrome is a browser. How are they unrelated?

Chrome doesn't use/work with the Flash browser plugin.
Post reply on HN