Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

21–30 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#21

This was bing's shit to begin with. Anyway no one ever uses it. This is serious but limited in attack surface I would say. BTW: forbes can fuck off with their auto play videos shit. Even on mobile. Who really thinks this is a good strategy?!!?

No one uses Bing....

except every user of Windows 10 by default

Re: Bing has been serving up malicious Google Chrome ads for months

#22

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

> The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine.

I think you're slicing this too thinly. This has everything to do with Edge, which is purposely configured to use a search engine that creates a liability for users.

I would agree that "stop using Edge to download Chrome" is not useful and probably clickbait-y. A better guide would be "Be careful when downloading a different browser on Windows 10."

Re: Bing has been serving up malicious Google Chrome ads for months

#23

Earlier quoted context omitted.

Given the malware Google's ads also ship, which Googlers here on HN have tried to have removed only to return an hour later, suffice to say malicious ads are an industry pervasive problem, and the solution is to kill the online advertising market. Aggressively. In fact, when I tried to look for a specific class of malicious ads (looking for "mapquest") recently, DuckDuckGo was even as bad as Google, it was Bing who g…

Nowadays it's impossible to support the creators you enjoy online by whitelisting ads without exposing your device to multiple megabytes of untrusted, vulnerability-filled JS and iFrames with links off to malware sites. I think that the sponsorship model many YouTubers use these days works really well, because there isn't any code involved that I have to run.

Yeah, there's a few YouTube creators and a few coders I've added to Patreon from time to time. I'd much rather toss someone a dollar a month than watch a dollar worth of ads, where 70 cents goes to a FAANG company.

Re: Bing has been serving up malicious Google Chrome ads for months

#24
post #2

Bing makes it clear when a site is promoted by prepending "ad" to the search result. Other search engines such as DuckDuckGo and Google do the same. It is near impossible for Bing to manually review every advert so perhaps it would be beneficial for search engines to provide a way for users to report rouge promoted links, similar to how YouTube allows you to report its sidebar ads.

> It is near impossible for Bing to manually review every advert Why? Are there hundreds of ad campaigns being created per second?

It would be possible to handle the quantity of ad campaigns, but not without false positives or missed fraudulent ads.

If you paid a person or a team of people to remove adverts promoting fake websites, the person reviewing the advert would have to understand the product being sold, the company selling the product and the companies real website. For Chrome this may be easy, but for more obscure projects such as a cryptocurrency wallet or email client it'd be hard for a person to distinguish between real and fake continually over the course of an 8 hour work day.

People who are searching for a product already understand that context and so will be able to make a less erroneous judgement on whether a promoted link is real or fake.

Re: Bing has been serving up malicious Google Chrome ads for months

#26

Using browsers to download software should never have become the standard practice... Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.

`apt install this` would be problematic at App Store/Play Store scale, though. I agree that search engines as an intermediary don't do enough to curb confusion, but exploitation of `apt` and other "more stable" distribution channels is prevented not as much by their design superiority than by the risk/reward dynamics of their incentive structures.

Re: Bing has been serving up malicious Google Chrome ads for months

#27
So basically Microsoft's browser isn't even safe to use temporarily to download a real browser. In 2018 can we stop pretending that any web browser is a safe effective way to acquire any software. While it can be done people have been consistently getting pwned for decades now.

Software should be distributed via apps stores. Preferably vetted lists as opposed to free for alls you can post malware to for $25.

Linux has been doing this correctly for a long time. Any time you guys at Microsoft want to rip this off properly would be absolutely fantastic.

Re: Bing has been serving up malicious Google Chrome ads for months

#28
The issue here is a broken functionality that I've reported on before with Google Ads which Bing mirrors: Allowing advertisers to lie about the destination URL of their ads.

Here's a screenshot of the same exploit on Google: https://plus.google.com/u/0/115181074626403443464/posts/fSPm... (The included hijack was blocked as a malicious site on Edge, but wasn't on Chrome.)

Ads should always be forced to display in the URL text the actual URL the ad directs the browser to. Maybe as a side bonus, less tracking URLs will get used to keep it looking cleaner.

Post reply on HN