Earlier quoted context omitted.
There was a short time about seven years ago when Google was returning a malicious link for Blizard's BattleNet. Had my WoW creds stolen and I wasn't what you would call naive on a computer.
It is important to remember that phishing works against even experienced and savvy users who know about phishing, and that effective countermeasures for these types of attacks do not include “replace users with smarter users”.
Bing has been serving up malicious Google Chrome ads for months
151–160 of 249 posts
Re: Bing has been serving up malicious Google Chrome ads for months
#152Earlier quoted context omitted.
I'm not a fan of the tactic either but MS does the same thing all the time. Also FF, Chrome and Safari ARE upgrades to Edge/IE by any reasonable metric. You've probably never had to write a non-trivial cross browser app. Try it and then let's see how you feel.
I don’t use Edge, but it’s unfair to characterize Edge as a “downgrade” for all people. The average user cares much more about being able to annotate webpages (for example) than having access to the latest web standard. So the “upgrade” you’re talking about is only from the point of view of the web developer, which is usually the wrong way to think about this kind of stuff. If you go far enough along the path of prio…
You grossly overestimate what the average user wants to do. The average user doesn't even know the difference between browsers, rarely (if ever) uses bookmarks, and considers printing a web page an advanced task.
Annotating webpages is something that a tiny sliver of power users will use.
Re: Bing has been serving up malicious Google Chrome ads for months
#153The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…
> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?
Re: Bing has been serving up malicious Google Chrome ads for months
#154Re: Bing has been serving up malicious Google Chrome ads for months
#155Earlier quoted context omitted.
Browsers are banned from the Windows Store. For 'security' reasons. It's tricky to get win32 apps in general into it, too.
No they aren't, the UC Browser is listed in the Windows store (third most popular mobile browser in the world,) along with some others. Microsoft has been very willing to help companies list Win32 apps in the Windows store, especially large ones.
For general win32 apps I do think the situation has improved since I last looked.
Re: Bing has been serving up malicious Google Chrome ads for months
#156The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…
> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?
Re: Bing has been serving up malicious Google Chrome ads for months
#157Earlier quoted context omitted.
I spent some time trying to understand googles ads and seo structure for a project, as a sysadmin. My conclusion was the reason greyhat and blackhat techniques werent dealt with was because they make too much money from it... I wrote a big report on it, but that was the gist. Im sure the same is true of MS et al.
If the report is public, would you link it?
Re: Bing has been serving up malicious Google Chrome ads for months
#158Earlier quoted context omitted.
Ok but there's no way to know that without searching. Unless you have one of these https://mobile.twitter.com/PulpLibrarian/status/844278365590...
I mean, you could guess. The name even hints at it for anyone aware of the `.net` tld. That's not a great solution, since many people are barely aware what at url is, but I think it should still be one that you and I (as people who are) use. Similarly the article is fixed by guessing that google chrome is probably at chrome.google.com (also chrome.com), firefox is probably at firefox.com, cnn is probably at cnn.com,…
Which also risks ending up on the wrong site (e.g. Steam is not at Steam.com). I'd trust Google to know the correct URL more than my guess.
Re: Bing has been serving up malicious Google Chrome ads for months
#159Earlier quoted context omitted.
So how does that prevent a malicious PPA or repo that the attacker could push up in the search rankings? Just like the attacker here pushed up a malicious download page in the search rankings?
It doesn't in this case, however you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website. The security of the package repository system falls down when people add apt signing keys that are untrusted/unverified, which is what happens when you add a ppa in Ubuntu.
We're sort of in a loop here -- how can I know what is the official Chromium website?
Re: Bing has been serving up malicious Google Chrome ads for months
#160It avoids using malicious options accidentally and it also means I don't need to go through each installer. Plus I can just send the file to friends and family when they get a new comp.
edit: just wondering why people disagree with this idea?