Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

161–170 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#161

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

Toward the end of the article, he asks the question, "Or is it?". That is an ongoing issue with Bing.

Re: Bing has been serving up malicious Google Chrome ads for months

#162
post #135

Earlier quoted context omitted.

I mean, you could guess. The name even hints at it for anyone aware of the `.net` tld. That's not a great solution, since many people are barely aware what at url is, but I think it should still be one that you and I (as people who are) use. Similarly the article is fixed by guessing that google chrome is probably at chrome.google.com (also chrome.com), firefox is probably at firefox.com, cnn is probably at cnn.com,…

> I mean, you could guess. The name even hints at it for anyone aware of the `.net` tld. Which also risks ending up on the wrong site (e.g. Steam is not at Steam.com). I'd trust Google to know the correct URL more than my guess.

Steam isn't at steam.com, but there also isn't a phishing site for steam at steam.com, and if there was you can bet that valve would do something about it.

Basically I'm trading Google/Bing and ads known to be malicious, for ICANN/registrars, self interested companies, and a reasonably functional "legal" system. Edit: And less tracking, and faster access to websites.

Re: Bing has been serving up malicious Google Chrome ads for months

#163
post #22

Earlier quoted context omitted.

> The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. I think you're slicing this too thinly. This has everything to do with Edge, which is purposely configured to use a search engine that creates a liability for users. I would agree that "stop using Edge to download Chrome" is not useful and probably clickbait-y. A…

Microsoft could just as well ship Firefox with Bing as the default search. The problem is Bing.

Except that Firefox blocked the site in question.

Re: Bing has been serving up malicious Google Chrome ads for months

#165
post #164

The real problem here is that a system allows users to install unsigned software.

From the article: >>> The download itself is called "ChromeSetup.exe," but examining the digital signature reveals "Alpha Criteria Ltd." >>>

It was signed, but most users won't catch that it's signed by the wrong party.

Re: Bing has been serving up malicious Google Chrome ads for months

#166
post #163

Earlier quoted context omitted.

Microsoft could just as well ship Firefox with Bing as the default search. The problem is Bing.

Except that Firefox blocked the site in question.

Does Edge not use the same safe browsing filters? I thought they were shared by all major browsers.

Re: Bing has been serving up malicious Google Chrome ads for months

#167
I mentioned this in a comment over a year ago in a story about paint.net.

https://news.ycombinator.com/item?id=14338174

> The Bing search engine is about as bad. A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware.

So I asked them to be careful to ensure the download site is correct and left them to it.

I came back to find they had downloaded some other crapware.

I checked the search results. The ENTIRE first one and a half page of results were advertisements for versions of crapware which may or may not have been Chromium or Chrome lookalikes with lots of malware.

Re: Bing has been serving up malicious Google Chrome ads for months

#169

Using browsers to download software should never have become the standard practice... Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.

Both windows and mac have built in app stores which are the equivalent of package managers.

But package managers can also have lookalike names. Npm and pip has had a few famous misspelled common packages that contained malware instead. Those are more open than apt or the big app stores but even on Google play you will find tons of lookalikes.

This whole incident just shows you should never just search for anything by name and pick the first good looking result. You really have to verify the source regardless of which search engine you are using. What I very much dislike is companies who refer to their own app in the app store only by name and then you when you search you get 10 results which all look equally shady. And because they outsourced the app development the publisher doesn't even match. Place a god damn link or show the unique package name on your websitr instead.

Re: Bing has been serving up malicious Google Chrome ads for months

#170

Earlier quoted context omitted.

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

I'm not a fan of the tactic either but MS does the same thing all the time. Also FF, Chrome and Safari ARE upgrades to Edge/IE by any reasonable metric. You've probably never had to write a non-trivial cross browser app. Try it and then let's see how you feel.

Chrome isn’t an upgrade to edge anymore. Chrome is the new ie6. But I’m on FF now so I don’t care.
Post reply on HN