Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

81–90 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#81

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

>If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Use Edge to download Firefox, and Firefox to download Chrome ;)

Just use ninite

https://ninite.com/

Re: Bing has been serving up malicious Google Chrome ads for months

#82

Earlier quoted context omitted.

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

This is a tangent/pile-on, but this is not the only dark pattern google engages in. I absolutely do not want YouTube Red. Any software that respects the user would let you dismiss the offer with an option for “do not ask me again.” And yet, because the software is not respecting the user, YouTube asks me ad nauseum if I want to upgrade to YouTube Red. No. I do not. But I don’t get an option for no. There is something…

Would you like to try YouTube Red for 30 days?

Re: Bing has been serving up malicious Google Chrome ads for months

#83

I never quite understood the appeal of giving some unknown third-party the right to put links and text and javascript onto your site. It might be labour intensive to have human eyes on every ad that is sold when you're at Google, or even Bing, scale. But it seems a little bit too hands-off, and irresponsible, to take money without vetting the input and then letting every scammer get into that very "blessed" and visib…

I spent some time trying to understand googles ads and seo structure for a project, as a sysadmin. My conclusion was the reason greyhat and blackhat techniques werent dealt with was because they make too much money from it... I wrote a big report on it, but that was the gist. Im sure the same is true of MS et al.

If the report is public, would you link it?

Re: Bing has been serving up malicious Google Chrome ads for months

#84

Using browsers to download software should never have become the standard practice... Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.

The Mac experience is almost identical, except that the App Store has a GUI (although Linux distributions also have those these days, I hear). Apple regularly gets lots of grief here because people have been suspicious they want to shut down distribution outside of the store. I have my doubts that any Linux distribution is capable of auditing every line of every package they distribute, so I think the relative lack o…

> The Mac experience is almost identical

I don't agree. If you search for "chrome" or "firefox", you will get a page full of spammy apps that are anything but what you searched for.

Linux distributions probably don't audit every single line of code in the packages, however this is code written by trusted developers that is mandated to be open source and distributed through official channels.

Getting malware into the package repositories would be very difficult, but it seems that getting a fake Google ad on Bing is very easy, so in my opinion the distribution method makes a big difference.

Re: Bing has been serving up malicious Google Chrome ads for months

#85

Earlier quoted context omitted.

Nowadays it's impossible to support the creators you enjoy online by whitelisting ads without exposing your device to multiple megabytes of untrusted, vulnerability-filled JS and iFrames with links off to malware sites. I think that the sponsorship model many YouTubers use these days works really well, because there isn't any code involved that I have to run.

I don't remember "untrusted JS" being any sort of problem in the last, say, 10 years? Now I'm sure you can dig up some vulnerabilities, and a select few of them may even had (remote) exploits. But I've never run into any problems, and I'm not especially careful, have been around the seedy underbelly of the web, and don't run any anti-virus. Just not clicking on any .exe that suddenly downloads seems to be enough. Bei…

Try visiting a popular tabloid news website and use the dev tools to see where it is loading content from.

The number of horrendous tracking/ads/spam domains you'll see rushing by is unbelievable.

Re: Bing has been serving up malicious Google Chrome ads for months

#86

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

I'm not a fan of the tactic either but MS does the same thing all the time.

Also FF, Chrome and Safari ARE upgrades to Edge/IE by any reasonable metric.

You've probably never had to write a non-trivial cross browser app. Try it and then let's see how you feel.

Re: Bing has been serving up malicious Google Chrome ads for months

#87
post #51

.. and that's why running an ad-blocker these days is not even a moral question; It's proper hygiene. I don't eat without washing my hands first, and I don't browse without an ad blocker.

I'm with you on that, but in this specific case people are using Edge exactly once on a new machine in order to download Google Chrome. It's reasonable to assume they aren't going to bother installing an ad blocker on Edge for this use.

Re: Bing has been serving up malicious Google Chrome ads for months

#88
post #2

Bing makes it clear when a site is promoted by prepending "ad" to the search result. Other search engines such as DuckDuckGo and Google do the same. It is near impossible for Bing to manually review every advert so perhaps it would be beneficial for search engines to provide a way for users to report rouge promoted links, similar to how YouTube allows you to report its sidebar ads.

Google Adwords has the same problem but, um, much bigger. They manage to review ads and mostly prevent malware much more successfully than Bing does.

Re: Bing has been serving up malicious Google Chrome ads for months

#89
Explanation for the spoofed domain name: https://twitter.com/sephr/status/1055751684146655232

Bing can easily fix this domain spoofing vulnerability. I've reported this vulnerability to MSRC previously but received no response.

This is also why open redirects can be so dangerous. Even if this domain spoofing vulnerability is fixed on Bing's end attackers can abuse open redirects to achieve the same result.

Re: Bing has been serving up malicious Google Chrome ads for months

#90

Earlier quoted context omitted.

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

This is a tangent/pile-on, but this is not the only dark pattern google engages in. I absolutely do not want YouTube Red. Any software that respects the user would let you dismiss the offer with an option for “do not ask me again.” And yet, because the software is not respecting the user, YouTube asks me ad nauseum if I want to upgrade to YouTube Red. No. I do not. But I don’t get an option for no. There is something…

YouTube red spam is obnoxious. Same with apps that ask for a review and the options are "not now, or not right now"

I'm never going to leave a review.

Post reply on HN