Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

171–180 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#171

I remember when several years ago I typed "download Flash" in Russian Google, there were non-official sites in top results. Now Adobe's site is the first result. Also I tried to experiment a little. If I type "download flash player" in Russian, official Adobe site is only on the 3rd position [1]. The first and second results are "adobe-flash-player.ru.softonic.com". [1] https://www.google.com/search?q=%D1%81%D0%BA%D0…

Flash is malware anyway.

Re: Bing has been serving up malicious Google Chrome ads for months

#172
post #97
post #38

Earlier quoted context omitted.

Perhaps the ad was using one of the Google redirect tricks? There’s a few google.com endpoints (if I recall) that you can abuse to redirect to arbitrary URLs.

At first I suspected this as well, but apparently it was a link to itracking[.]services and Bing pre-resolved the redirect chain. You can spoof any domain you want in Bing Ads without needing an open redirect.

> You can spoof any domain you want in Bing Ads without needing an open redirect.

Is that a bug or a feature? It seems like the kind of thing that could erode user trust

Re: Bing has been serving up malicious Google Chrome ads for months

#173
post #172
post #97

Earlier quoted context omitted.

At first I suspected this as well, but apparently it was a link to itracking[.]services and Bing pre-resolved the redirect chain. You can spoof any domain you want in Bing Ads without needing an open redirect.

> You can spoof any domain you want in Bing Ads without needing an open redirect. Is that a bug or a feature? It seems like the kind of thing that could erode user trust

It's a feature, Google allows the same. Basically advertisers want to set the links to be tracking links and stuff which may be through third parties which then redirect to their site.

So both ad services allow the advertiser to display one URL while directing users to another.

Re: Bing has been serving up malicious Google Chrome ads for months

#174

Earlier quoted context omitted.

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

I hear your intended point, but the question was "how else..." which your answer didn't address. "Simply visit..." implies use of a browser, and for a new Win10 machine that browser will be Edge.

Sure. But searching bing is not needed.

Re: Bing has been serving up malicious Google Chrome ads for months

#175

Earlier quoted context omitted.

> Googling debian google chrome results in instructions for getting chrome on debian. Yes. I know. I'm not picking on debian specifically here, fedora's dnf doesn't help you install chrome either. My point is rather the following: The GP asserts that the way to find (and subsequently install) software is "apt search `software`" and that way breaks down on exactly the piece of software that the article is about. You h…

GP's solution is valid for the majority of software - at least the sort of software that us HN folk probably use. Unfortunately Google Chrome is a bad example here as it's not available in most repos (since it's closed source).

> GP's solution is valid for the majority of software - at least the sort of software that us HN folk probably use.

That’s a bold statement to make, especially since a single piece of malicious software is sufficient. And yes, I want chrome. I need chrome. I need to test stuff on chrome.

Re: Bing has been serving up malicious Google Chrome ads for months

#176
post #172

Earlier quoted context omitted.

> You can spoof any domain you want in Bing Ads without needing an open redirect. Is that a bug or a feature? It seems like the kind of thing that could erode user trust

It's a feature, Google allows the same. Basically advertisers want to set the links to be tracking links and stuff which may be through third parties which then redirect to their site. So both ad services allow the advertiser to display one URL while directing users to another.

Surely they're doing some verification to ensure that either the redirect lands on the advertised TLD, or alternatively that you're at least "in control" of the TLD you're advertising as (similar to GAnalytics verification -- via meta tag, DNS txt entry, etc)?

Re: Bing has been serving up malicious Google Chrome ads for months

#177

Earlier quoted context omitted.

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

This is a tangent/pile-on, but this is not the only dark pattern google engages in. I absolutely do not want YouTube Red. Any software that respects the user would let you dismiss the offer with an option for “do not ask me again.” And yet, because the software is not respecting the user, YouTube asks me ad nauseum if I want to upgrade to YouTube Red. No. I do not. But I don’t get an option for no. There is something…

Try buying a Nest camera and NOT buying their "Nest Aware" subscription. You'll be stuck with a massive bar on the bottom of your camera web views -- cannot be dismissed: https://imgur.com/a/iR5C9bH

Their support team responds to (numerous) requests from multiple users about it saying roughly "cannot be disabled without buying but we'll let engineering dept. know you want that". Yeah, right, like it's an engineering problem.

Worse yet -- if you have >1 Nest camera, and you DO pay for Nest Aware on some but not all of them, the banner still shows up on any camera views you aren't subscribing for.

It's really crappy because the bottom bar is a fixed height, so if you shrink the browser window it can easily take up >=50% of your viewport. Absolutely absurd -- only option once you have their hardware is to use a plugin/bookmarklet to kill the nag bar's CSS. =(

Re: Bing has been serving up malicious Google Chrome ads for months

#178

Have to say, I was looking for a way to get away from Google, and I found that Duckduckgo's results didn't work for me. Bing, though, does the job nicely.

+1 here. I switched to Bing back in April when a Google algorithm update really trashed Google's results for me (it felt like I'd suddenly gone back to the days of Altavista & HotBot). At first my switch to Bing was out of spite, but 6 months later I'm still using Bing & I love it. I really like how it breaks out code snippets for StackOverflow results, for instance.

So it's frustrating to see Bing hurt their reputation with something as stupid as this. If Microsoft want more people to switch, they've got to be at 100% in all areas, they can't afford to let Bing Ads ruin the whole service.

Re: Bing has been serving up malicious Google Chrome ads for months

#179

Earlier quoted context omitted.

Nowadays it's impossible to support the creators you enjoy online by whitelisting ads without exposing your device to multiple megabytes of untrusted, vulnerability-filled JS and iFrames with links off to malware sites. I think that the sponsorship model many YouTubers use these days works really well, because there isn't any code involved that I have to run.

I don't remember "untrusted JS" being any sort of problem in the last, say, 10 years? Now I'm sure you can dig up some vulnerabilities, and a select few of them may even had (remote) exploits. But I've never run into any problems, and I'm not especially careful, have been around the seedy underbelly of the web, and don't run any anti-virus. Just not clicking on any .exe that suddenly downloads seems to be enough. Bei…

Not "JS vulnerabilities", but things that waste memory & cpu cycles and in worst case exploit your PC for things like bitcoin mining.

Also consider that most browser vulnerabilities -- not "JS vulnerabilities" -- are virtually impossible to exploit without JS.

Re: Bing has been serving up malicious Google Chrome ads for months

#180
post #129

Earlier quoted context omitted.

There was a short time about seven years ago when Google was returning a malicious link for Blizard's BattleNet. Had my WoW creds stolen and I wasn't what you would call naive on a computer.

That sucks. I know it's a tired point, but it nevertheless amuses me that someone would search for BattleNet. The name is literally the domain name: battle.net.

This is not a very clever point. Plenty of things used to be caller "somethingnet" in order to advertise their ties with the internet. It was never about a tld. Kind of like how having "block" or "chain" in your app's name makes you "cool" nowadays.
Post reply on HN