Live data from Hacker News

Google and Paint.NET need to stop misleading users (2013)

jasonlefkowitz.net

81–90 of 109 posts

Re: Google and Paint.NET need to stop misleading users (2013)

#81
post #67
post #63

Earlier quoted context omitted.

I was going to say - obviously the author of this post hasn't looked for Minecraft mods, because there the problem is far worse.

is it? 99% of the mods nowadays can be downloaded from Curse [1] without any ads and for easy mod management you can even install their launcher those that can't, can be usually found on this site with their official download site linked [2] [1] https://minecraft.curseforge.com/ [2] https://bot.notenoughmods.com/

Or FeedTheBeast

Re: Google and Paint.NET need to stop misleading users (2013)

#82
The Bing search engine is about as bad.

A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware.

So I asked them to be careful to ensure the download site is correct and left them to it.

I came back to find they had downloaded some other crapware.

I checked the search results. The ENTIRE first one and a half page of results were advertisements for versions of crapware which may or may not have been Chromium or Chrome lookalikes with lots of malware.

Re: Google and Paint.NET need to stop misleading users (2013)

#83

Earlier quoted context omitted.

You could've at least visited the website. They are NOT clearly labeled as ads. https://www.getpaint.net/index.html

wcummings might mean the tiny grey-and-blue icons in the top right of each unit. If so, I disagree. Those icons are not visible enough, and are hard for many users to click without accidentally clicking the ad instead.

Indeed. Little icons inside the square can also be imitated by ads and do something quite different.

Re: Google and Paint.NET need to stop misleading users (2013)

#84

Everyone seems to give Google the benefit of the doubt here. Is it possible they aren't doing anything because they are making lots of money from this ethical grey area? The incentives seem perfectly aligned... the advertiser doubtlessly doesn't care about whether it's a scrupulous ad or not. Paint.NET authors make money, and Google makes money.

This is entirely it. It's not nearly offensive enough to get the "you're putting racist ads on my page" level of public uproar for them to do anything about it. And distributing malware is incredibly profitable. They simply have no incentive to stop. And trying to moderate it would cost them money, both in terms of effort to review ad submissions, and lost revenue from the ads themselves.

Heck, Google likes to brag about how Chromebooks don't get viruses. Distributing viruses for Windows PCs only helps their bottom line. (You'll also notice that Windows support-related search queries have malicious ads, and no ads display at all for Chromebook or Google support-related search queries.)

Re: Google and Paint.NET need to stop misleading users (2013)

#85
post #8

I'm curious why these ads are even allowed to get through the network in the first place. Is there just NO content reviewing taking place? That's seems negligent on Google's part. There is no reason for an ad like that to exist on any webpage, period. It should have been blocked at the source. Where is the 3-strikes policy in the ad space? Google is so eager to punish its Youtube streamers for running questionably of…

And one of the download button ads that I just checked (EasyPDFCombine) is "getting trough" 3 separate Google "reviews" if I understand correctly how this scheme works:

1. The misleading download button Google ad.

2. After clicking the ad they ask the user to install their extension from the Google Chrome Web Store [1].

3. After installation, the extension replaces new tab page with their own which includes a "custom" search engine "Enhanced by Google" [2].

4. PROFIT!!!? They make money when the user clicks a Google ad in their search results on that new tab page.

I'm not sure how it's worth it for Google because with the extension installed they are sharing part of their search results revenue with the owner of the extension compared to the users directly using the Google search when there is no extension to "hijack" it.

From the users perspective: Sure, it's not a ransomware level malware but it's still a PUP and the users are annoyed that they were "tricked" into installing it and their new tab page has been changed, as it can be seen in almost all of the reviews for their chrome extension, and almost all the first page google result for "EasyPDFCombine" is about how to remove this "virus".

It's the same decade old trick from the same company: Mindspark aka MyWebSearch aka Ask Toolbar and many more names.

[1] https://chrome.google.com/webstore/detail/easypdfcombine/kpo...

[2] http://hp.myway.com/portal/ttab02/index.html

Re: Google and Paint.NET need to stop misleading users (2013)

#87
post #54

And as unpopular as the idea is with geeks, I think this illustrates the need for a "walled gardened" for the majority of users where each app is sandboxxed. Something like this couldn't happen on iOS, ChromeOS or Windows 10s. Most non developers would be served perfectly fine with a locked down OS.

What it illustrates the need for is understanding why you're receiving things (which is a pretty vital outside of software, too). If you pay for your product then you won't see phishing on the download page. If it's a subscription fee, then they're going to make it difficult to abandon or switch away from. And if it's "free", then who knows what's going on - maybe the product will wantonly encourage spending money (a…

Look at all of the open source software that is there for the common good, but is still hijacked with crapware by places like SourceForge and Download.com.

You can even search for Windows drivers and instead of getting drivers from the manufacturer, you end up with malware from a third party site.

Re: Google and Paint.NET need to stop misleading users (2013)

#88
post #77
post #29

Earlier quoted context omitted.

I can't believe Google couldn't categoricatically add context to these type of ads if they really cared. Google knows the ad link. Google can crawl the target page / file. If it's an installer, Google can run it in a VM and note what ends up being installed. If you can't pull a clear "this is crapware" signal out of that, then their ML is a lot less advanced than it seems. And if they can, then just automatically put…

They would care if thousands of organisations pulled their advertising over it.

I really wish this were the case. It would be nice if more organizations were more action oriented against malvertisement. I seem to recall there was one blog / news site that got rid of Google Adsense from their website here on HN not over a year ago, and I'm sure others have. It's really sad that Google doesn't put any effort (that we know, though we would see less of this) against these advertisements.

Re: Google and Paint.NET need to stop misleading users (2013)

#90

I don't think 2013 article is still relevant today.

It's still relevant. I took this screenshot a few seconds ago: https://i.imgur.com/6LoQ3TW.png

Today I visited the site again and now it started to show me the same download ads.

So it is still relevant. But how these ads are able to pass through AdWords review.

Post reply on HN