Live data from Hacker News

No More Deceptive Download Buttons

googleonlinesecurity.blogspot.com

241–250 of 263 posts

Re: No More Deceptive Download Buttons

#241
post #228

Earlier quoted context omitted.

Yes. To date, Android has generated $31 billion in revenue and $22 billion in net profit. http://www.bloomberg.com/news/articles/2016-01-21/google-s-a...

Counting web ads served to users as revenue generated by the computer's operating system is ludicrous. Oracle is trying to misrepresent the amount of money made so they can sue for damages. The numbers are BS.

> Counting web ads served to users as revenue generated by the computer's operating system is ludicrous.

Why? Isn't that precisely why Google invested so much in Android?

Re: No More Deceptive Download Buttons

#242
post #238

Earlier quoted context omitted.

I've actually built an advertising network[1] that is not focused on serving display ads, but linking to content directly in images. Video demo: https://www.youtube.com/watch?v=8GfKBvs53Ss The thought is that if "advertising" is actually a feature of a website, then it solves the problem of users trying to avoid being shown ads. If you could hover your mouse over an object on any image on the internet and be taken di…

This is the first ad platform I've seen that is innovative in a good way, instead of the usual remarketing/tracking/native/data whatever bullshit. Seriously, awesome idea and execution. Have you gotten any press for this?

No press, just a reddit post[1]. Do you know anyone? :)

[1] https://www.reddit.com/r/Entrepreneur/comments/43qnen/if_you...

Re: No More Deceptive Download Buttons

#243

Earlier quoted context omitted.

I've actually built an advertising network[1] that is not focused on serving display ads, but linking to content directly in images. Video demo: https://www.youtube.com/watch?v=8GfKBvs53Ss The thought is that if "advertising" is actually a feature of a website, then it solves the problem of users trying to avoid being shown ads. If you could hover your mouse over an object on any image on the internet and be taken di…

That's pretty good. The issue I have with it is that without this prior knowledge, I can't tell what will happen when I click - the URL isn't informative, and there's no alt-text.

What would you like to see it do? I've been thinking of tons of different ways of displaying that to a user, but I figured I'd just put it out there and see what people suggested.

Re: No More Deceptive Download Buttons

#244

Earlier quoted context omitted.

Sure, this is fine, but Google seems to plan to block sites which show malicious ads served by Google 's AdSense. That's idiotic. This is the second case in a month of Google punishing web publishers for using Google products. (The previous case was Google punishing non-https search results, when in fact many of Google's own web publishing tools don't support https.)

And I'm willing to bet Google will make a special exception for itself. I actually posted a screenshot on my G+ page yesterday of the most recent fake download button I saw online... On a YouTube banner ad, served by Google AdSense.

Do they have a history of making exceptions for themselves? If not, then you winning this bet will be quite a big deal - it'll show them as anti-competitive. They'd be forcing customers to use their AdSense product instead of just-as-good competitors.

Maybe they'll just give this "malvertising" detection software to AdSense who can then filter their own content before it hits websites. I'd be more willing to bet this will be the beginning of Adsense cleaning itself up than what you suggest.

Re: No More Deceptive Download Buttons

#245

Earlier quoted context omitted.

Sure, this is fine, but Google seems to plan to block sites which show malicious ads served by Google 's AdSense. That's idiotic. This is the second case in a month of Google punishing web publishers for using Google products. (The previous case was Google punishing non-https search results, when in fact many of Google's own web publishing tools don't support https.)

And I'm willing to bet Google will make a special exception for itself. I actually posted a screenshot on my G+ page yesterday of the most recent fake download button I saw online... On a YouTube banner ad, served by Google AdSense.

[deleted]

Re: No More Deceptive Download Buttons

#246

Earlier quoted context omitted.

I'm not sure if you know what the "first amendment" is. I'll tell you what it isn't, it's not a magical trump card that lets you say whatever you want.

http://searchengineland.com/another-court-affirms-googles-fi... That seems to be how Google is (successfully) using it.

That's a VERY different situation. Google is claiming there that (essentially) they have the right to put sites in whatever order they want, and US courts are extremely sympathetic to that argument.

Here the issue is that Google is making direct, verbal claims about other sites. That's not to say Google couldn't come up with a strategy to win in court, but the strategy would have to differ markedly.

Re: No More Deceptive Download Buttons

#247

Perhaps now that Google has taken steps to block websites that display these ads, Google should take steps to stop accepting these ads onto their network in the first place. Most of the time when I see those DOWNLOAD/PLAY buttons, they're hosted on doubleclick.

Admob too serves similar Ads: "Your phone is infected, click here to install Clean Master..."

Re: No More Deceptive Download Buttons

#248
post #114

Earlier quoted context omitted.

As an experienced user, when I'm looking for some semi-obscure Windows program, I still do have problems distinguishing legit download links from this. Perhaps I'm too used to the radical method "just select what you want from the repository, and it will be installed automagically;" in other words, one of the issues here is nonexistent install management in Windows (party like it's 1998!), forcing users to run this g…

Hovering the link to check the URL is a good old trick. Well until browsers start to hide that as well.

Nice try, but no, that's a broken old trick. window.status is gone for exactly this reason, but things like onclick="this.href=http://evilsite.example/" (or even onclick="window.location=http://somewhereelse.evil.example/;return false") still work (link shows a benign location, but it's changed to a malicious one when you click).

Re: No More Deceptive Download Buttons

#249
post #32
post #7

Earlier quoted context omitted.

I remember a few years ago AdSense was showing a lot of fake Download buttons (and users would complain about it). I haven't seen them recently, though, so I hope that means they've fixed that problem.

I just checked and the download page on getpaint.net still has a deceptive "Start Download" AdSense ad. That site came to mind because, a few months ago, I tried to be charitable and disabled ad blocking for a few days. That was the site where I decided enough was enough and started blocking again.

You're not being charitable disabling your ad blocking. You're just perpetuating a system where egregious invasion of privacy is 'the deal' for using the internet. I understand that some sites might struggle for income without advertising but if they want me to view their ads they had better find some partners who don't stalk me across the web.

Re: No More Deceptive Download Buttons

#250
post #148

This "Google Safe Browsing" initiative seriously worries me. It's effectively some unknown, mysterious, un-contactable set of AI algorithms/people/who knows what controlling the internet because Google owns everyone's browser. One of my websites got tagged as "Dangerous" and having "harmful programs" despite having nothing of the sort. My guess is a silly hiccup of their neural network algorithms. And I have absolute…

Yes, there's good reason why I'm posting this from https://www.palemoon.org/ which is Firefox without the politics - Chrome is too intrusive and non-transparent about its intrusion to boot.

How do they fund their security patches?
Post reply on HN