Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

151–160 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#151
post #138

Earlier quoted context omitted.

There was a short time about seven years ago when Google was returning a malicious link for Blizard's BattleNet. Had my WoW creds stolen and I wasn't what you would call naive on a computer.

It is important to remember that phishing works against even experienced and savvy users who know about phishing, and that effective countermeasures for these types of attacks do not include “replace users with smarter users”.

Perhaps it's time for software companies to invest in human genetic engineering, to improve the next generation of users.

Re: Bing has been serving up malicious Google Chrome ads for months

#152

Earlier quoted context omitted.

I'm not a fan of the tactic either but MS does the same thing all the time. Also FF, Chrome and Safari ARE upgrades to Edge/IE by any reasonable metric. You've probably never had to write a non-trivial cross browser app. Try it and then let's see how you feel.

I don’t use Edge, but it’s unfair to characterize Edge as a “downgrade” for all people. The average user cares much more about being able to annotate webpages (for example) than having access to the latest web standard. So the “upgrade” you’re talking about is only from the point of view of the web developer, which is usually the wrong way to think about this kind of stuff. If you go far enough along the path of prio…

>The average user cares much more about being able to annotate webpages

You grossly overestimate what the average user wants to do. The average user doesn't even know the difference between browsers, rarely (if ever) uses bookmarks, and considers printing a web page an advanced task.

Annotating webpages is something that a tiny sliver of power users will use.

Re: Bing has been serving up malicious Google Chrome ads for months

#153

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

I hear your intended point, but the question was "how else..." which your answer didn't address. "Simply visit..." implies use of a browser, and for a new Win10 machine that browser will be Edge.

Re: Bing has been serving up malicious Google Chrome ads for months

#155

Earlier quoted context omitted.

Browsers are banned from the Windows Store. For 'security' reasons. It's tricky to get win32 apps in general into it, too.

No they aren't, the UC Browser is listed in the Windows store (third most popular mobile browser in the world,) along with some others. Microsoft has been very willing to help companies list Win32 apps in the Windows store, especially large ones.

Interesting. But I think UC Browser is special by being sort of a thin client. The store policy is quite clear: "Apps that browse the web must use the appropriate HTML and JavaScript engines provided by the Windows Platform."

For general win32 apps I do think the situation has improved since I last looked.

Re: Bing has been serving up malicious Google Chrome ads for months

#156

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

Compared to edge, calling it an "upgrade" isn't really lying.

Re: Bing has been serving up malicious Google Chrome ads for months

#157

Earlier quoted context omitted.

I spent some time trying to understand googles ads and seo structure for a project, as a sysadmin. My conclusion was the reason greyhat and blackhat techniques werent dealt with was because they make too much money from it... I wrote a big report on it, but that was the gist. Im sure the same is true of MS et al.

If the report is public, would you link it?

Its not, sorry, I dont even have a personal copy, but it could be worth redoing it publicly on my own.

Re: Bing has been serving up malicious Google Chrome ads for months

#158
post #135
post #132

Earlier quoted context omitted.

Ok but there's no way to know that without searching. Unless you have one of these https://mobile.twitter.com/PulpLibrarian/status/844278365590...

I mean, you could guess. The name even hints at it for anyone aware of the `.net` tld. That's not a great solution, since many people are barely aware what at url is, but I think it should still be one that you and I (as people who are) use. Similarly the article is fixed by guessing that google chrome is probably at chrome.google.com (also chrome.com), firefox is probably at firefox.com, cnn is probably at cnn.com,…

> I mean, you could guess. The name even hints at it for anyone aware of the `.net` tld.

Which also risks ending up on the wrong site (e.g. Steam is not at Steam.com). I'd trust Google to know the correct URL more than my guess.

Re: Bing has been serving up malicious Google Chrome ads for months

#159

Earlier quoted context omitted.

So how does that prevent a malicious PPA or repo that the attacker could push up in the search rankings? Just like the attacker here pushed up a malicious download page in the search rankings?

It doesn't in this case, however you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website. The security of the package repository system falls down when people add apt signing keys that are untrusted/unverified, which is what happens when you add a ppa in Ubuntu.

> you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website.

We're sort of in a loop here -- how can I know what is the official Chromium website?

Re: Bing has been serving up malicious Google Chrome ads for months

#160
I usually use ninite to set up first time downloads, it's great because you can just run it again every couple weeks to make sure all your software is up to date.

It avoids using malicious options accidentally and it also means I don't need to go through each installer. Plus I can just send the file to friends and family when they get a new comp.

edit: just wondering why people disagree with this idea?

Post reply on HN