Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

41–50 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#41
post #2

Bing makes it clear when a site is promoted by prepending "ad" to the search result. Other search engines such as DuckDuckGo and Google do the same. It is near impossible for Bing to manually review every advert so perhaps it would be beneficial for search engines to provide a way for users to report rouge promoted links, similar to how YouTube allows you to report its sidebar ads.

>It is near impossible for Bing to manually review every advert

I don't agree with this. Reviewing ads should be a straight forward process, much more so than reviewing an app submission. Plus, obvious issues can easily be automated, reducing the load of manual reviews.

Re: Bing has been serving up malicious Google Chrome ads for months

#42
post #17
post #2

Bing makes it clear when a site is promoted by prepending "ad" to the search result. Other search engines such as DuckDuckGo and Google do the same. It is near impossible for Bing to manually review every advert so perhaps it would be beneficial for search engines to provide a way for users to report rouge promoted links, similar to how YouTube allows you to report its sidebar ads.

> Bing makes it clear when a site is promoted by prepending "ad" to the search result. Other search engines such as DuckDuckGo and Google do the same. They very specifically do not make it clear, they (and I mean all of them) intend to make sponsored results look as identical as possible to organic results to improve the likelihood that you'll click them. They only have subtle markings showing that they're ads becaus…

>the Bing ad shows the domain as `google.com

There's a reason for this - ad tracking for conversion, performance or even to make sure the advertising network is honest. The ad tracking domain is not always the same as destination domain.

AFAIK, this problem seems easily solved.

All Ms has to do is flag ads whose displayed URL do not match the final URL for manual review. Or simply ban it.

Re: Bing has been serving up malicious Google Chrome ads for months

#43

Using browsers to download software should never have become the standard practice... Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.

True, this was one of the things that originally appealed to me about Linux. But on a for-profit operating system this turns into an "app store" which gets to pick which software is and isn't allowed, while taking a 30% cut of the profits.

Re: Bing has been serving up malicious Google Chrome ads for months

#44

Earlier quoted context omitted.

Given the malware Google's ads also ship, which Googlers here on HN have tried to have removed only to return an hour later, suffice to say malicious ads are an industry pervasive problem, and the solution is to kill the online advertising market. Aggressively. In fact, when I tried to look for a specific class of malicious ads (looking for "mapquest") recently, DuckDuckGo was even as bad as Google, it was Bing who g…

Just FYI, that ad you're talking about appears to really, truly be gone now. Im not sure why it reappeared, but I didn't need to take any other action for it to be removed.

FYI, just screenshot after reading this comment: https://imgur.com/a/zZCcXc2

Malicious ads pretending to be MapQuest remain alive and well. After pausing my Pi-hole, I can confirm that it refuses to actually provide directions when asked, and promptly tries to add an extension to my web browser.

Part of the problem with ad platforms like these (including Bing's), is even if you report one and take it down, it's trivial for the same people to stand up the same website on a different cloud server with a slightly different domain name and do it again.

Notes:

- My sole extension not made by Mozilla itself is the EFF's Privacy Badger. I also use Firefox Multi-Account Containers and the Facebook Container, both first party.

- Do recall that advertisers can target users by a variety of variables (browser, location, etc.), your ad experience does not reflect everyone else's ad experience.

Re: Bing has been serving up malicious Google Chrome ads for months

#45

Earlier quoted context omitted.

Just FYI, that ad you're talking about appears to really, truly be gone now. Im not sure why it reappeared, but I didn't need to take any other action for it to be removed.

FYI, just screenshot after reading this comment: https://imgur.com/a/zZCcXc2 Malicious ads pretending to be MapQuest remain alive and well. After pausing my Pi-hole, I can confirm that it refuses to actually provide directions when asked, and promptly tries to add an extension to my web browser. Part of the problem with ad platforms like these (including Bing's), is even if you report one and take it down, it's trivi…

That's very peculiar. I was running in incognito with no adblock, and checked across multiple devices and multiple internet connections, so you seem to be uniquely affected.

Re: Bing has been serving up malicious Google Chrome ads for months

#46

Perhaps since MS makes only a tiny minority of their income from ads they can ship an effective adblocker with their default browser. It could be great opportunity to lead the market in a customer friendly way.

All of bing's revenue comes from ads. Somehow I don't think Microsoft is planning on disabling bing ads in the Windows default browser.

Re: Bing has been serving up malicious Google Chrome ads for months

#47

Earlier quoted context omitted.

apt search chrome. Good luck with that on a default Debian install.

Debian prioritizes being open source over being user friendly. Googling debian google chrome results in instructions for getting chrome on debian. I have 3 different distros installed on 3 different computers. Chrome is listed on all app searches.

> Googling debian google chrome results in instructions for getting chrome on debian.

Yes. I know. I'm not picking on debian specifically here, fedora's dnf doesn't help you install chrome either.

My point is rather the following: The GP asserts that the way to find (and subsequently install) software is "apt search `software`" and that way breaks down on exactly the piece of software that the article is about. You have to google instructions and then install either the .deb or add googles repo. And that's where the attacker could just as well insert an ad pointing you to a malicious repo. Just as the attacker currently points people to a malicious download. So the GPs solution isn't a solution at all. Not to this problem.

Re: Bing has been serving up malicious Google Chrome ads for months

#48

Earlier quoted context omitted.

apt search chrome. Good luck with that on a default Debian install.

chromium-browser is the one. Although on Ubuntu it's in the Universe repository, so you have to add the chromium-team ppa in order to get on-time updates. I will admit that Chrome/Chromium is one of the few things you can't easily get from the repos, on Ubuntu at least.

So how does that prevent a malicious PPA or repo that the attacker could push up in the search rankings? Just like the attacker here pushed up a malicious download page in the search rankings?

Re: Bing has been serving up malicious Google Chrome ads for months

#49

Earlier quoted context omitted.

FYI, just screenshot after reading this comment: https://imgur.com/a/zZCcXc2 Malicious ads pretending to be MapQuest remain alive and well. After pausing my Pi-hole, I can confirm that it refuses to actually provide directions when asked, and promptly tries to add an extension to my web browser. Part of the problem with ad platforms like these (including Bing's), is even if you report one and take it down, it's trivi…

That's very peculiar. I was running in incognito with no adblock, and checked across multiple devices and multiple internet connections, so you seem to be uniquely affected.

That's not peculiar at all. Different people see different ads, individual ads run out of budget, new ads are added, and so on.

Re: Bing has been serving up malicious Google Chrome ads for months

#50
post #22

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

> The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. I think you're slicing this too thinly. This has everything to do with Edge, which is purposely configured to use a search engine that creates a liability for users. I would agree that "stop using Edge to download Chrome" is not useful and probably clickbait-y. A…

this same thing happened to my older co-worker who was using chrome and google to get firefox and he downloaded it from a top ad link that was a malware'd firefox...
Post reply on HN