Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

191–200 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#191

Earlier quoted context omitted.

It's a feature, Google allows the same. Basically advertisers want to set the links to be tracking links and stuff which may be through third parties which then redirect to their site. So both ad services allow the advertiser to display one URL while directing users to another.

Surely they're doing some verification to ensure that either the redirect lands on the advertised TLD, or alternatively that you're at least "in control" of the TLD you're advertising as (similar to GAnalytics verification -- via meta tag, DNS txt entry, etc)?

Google does.

Re: Bing has been serving up malicious Google Chrome ads for months

#192
Call me paranoid, but every time I install software on Windows [1] I do the following dance:

1. Search for the name of the software on Google [2].

2. Open link to software in separate tab.

3. Open Wikipedia link (usually on the same SERP) for software in separate tab.

4. Compare domain name from direct link with the domain name from the Wikipedia article.

5. Open another tab and type domain name manually.

6. Find download link manually on domain[3].

I do this since a family member got burned badly by a malicious OpenOffice install many years ago.

[1] Sometimes I do it on Mac too, because the App Store has it's own issues (e.g. upgrades are often cheaper if you buy software directly). On any other system I use the package manager. All of this makes the effort bearable because I only have to do it rarely.

[2] I'm usually on DuckDuckGo, but for this I always used Google. The reason is that I had hope that they'd remove malicious results quicker. It's manual work after all and Google has more resources. This whole thread makes me doubt though.

[3] I'd do this anyway because I usually don't want to install the version that is automatically suggested, but decide myself which specific version I want to install. Most of the time the reason is the language.

Re: Bing has been serving up malicious Google Chrome ads for months

#193
post #126
post #43

Earlier quoted context omitted.

True, this was one of the things that originally appealed to me about Linux. But on a for-profit operating system this turns into an "app store" which gets to pick which software is and isn't allowed, while taking a 30% cut of the profits.

As if distro mantainers didn't get to pick which software is and isn't allowed.

Sure they do, and there's usually an official first-party process to add repositories not approved by the distro maintainer. As far as I am aware neither the microsoft nor the apple app stores allow this.

Re: Bing has been serving up malicious Google Chrome ads for months

#194

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

I don't agree with you that the article is "deceptive clickbait". What is true though, whoever uses Bing for searches instead of Google gets served by subpar search results, hence the chances are great to get served malware. That is common knowledge today. Who uses Bing anyway, even on Edge? That's what the article gets wrong.

Re: Bing has been serving up malicious Google Chrome ads for months

#195

Call me paranoid, but every time I install software on Windows [1] I do the following dance: 1. Search for the name of the software on Google [2]. 2. Open link to software in separate tab. 3. Open Wikipedia link (usually on the same SERP) for software in separate tab. 4. Compare domain name from direct link with the domain name from the Wikipedia article. 5. Open another tab and type domain name manually. 6. Find dow…

> 5. Open another tab and type domain name manually.

I think this point is vulnerable to typosquatting and could actually reduces the overall security of your approach. I would say if the Wikipedia link matches the search engine link you are good to go.

Re: Bing has been serving up malicious Google Chrome ads for months

#196

The title of this article is deceptive clickbait.[1] The problem has nothing to do with the Edge browser, it has to do with search results returned by Bing, which happens to be Edge's default search engine. If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? So "stop using Edge to download Chrome" is not useful advice. Better advice…

I remember having great fun some years ago when my friend's Internet Explorer somehow broke in the Win95/98/ME days. So I tried to guess ftp servers from the DOS prompt. I think I managed to connect to ftp://ftp.opera.com and install Opera. Update: looks like it still works today. Anyone looking for a 2004 BeOS version?

You could just get a free AOL cd at the gas station, it included Internet Explorer.

Re: Bing has been serving up malicious Google Chrome ads for months

#197

Call me paranoid, but every time I install software on Windows [1] I do the following dance: 1. Search for the name of the software on Google [2]. 2. Open link to software in separate tab. 3. Open Wikipedia link (usually on the same SERP) for software in separate tab. 4. Compare domain name from direct link with the domain name from the Wikipedia article. 5. Open another tab and type domain name manually. 6. Find dow…

> 5. Open another tab and type domain name manually. I think this point is vulnerable to typosquatting and could actually reduces the overall security of your approach. I would say if the Wikipedia link matches the search engine link you are good to go.

My reasoning is that someone could change the Wikipedia link to a look-alike domain and that this could easily go unnoticed for some time. Even if the domains visually match they don't need to be identical (Unicode Confusables [1]), but the plain ASCII version that I can type on my keyboard is probably the right one.

[1] http://unicode.org/cldr/utility/confusables.jsp

Re: Bing has been serving up malicious Google Chrome ads for months

#198

Earlier quoted context omitted.

> If you have a new Windows 10 PC and want to download Chrome, how else could you do it besides "using Microsoft Edge to download Chrome"? Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome. My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?

This is a tangent/pile-on, but this is not the only dark pattern google engages in. I absolutely do not want YouTube Red. Any software that respects the user would let you dismiss the offer with an option for “do not ask me again.” And yet, because the software is not respecting the user, YouTube asks me ad nauseum if I want to upgrade to YouTube Red. No. I do not. But I don’t get an option for no. There is something…

Tangential on top of the pile-on: when using a "not-logged into google services browser that is not Chrome" the Google captchas produced are at times never ending for me (i.e. I will never spot enough traffic lights and cars for them to let me past). Would be interested in whether others have had similar experiences?

Re: Bing has been serving up malicious Google Chrome ads for months

#199

I mentioned this in a comment over a year ago in a story about paint.net. https://news.ycombinator.com/item?id=14338174 > The Bing search engine is about as bad. A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware. So I asked them to be careful to ensure the download site is correct and left them to it. I came back…

This is exacltly what you would get if you'd deliberately moved all links to the legitimate site way down. Maybe because it's your competition?

Re: Bing has been serving up malicious Google Chrome ads for months

#200
I often dig into phishing and malware spam I receive, reporting it to the abuse@ address for the sending network, and reporting any links hosting malware.

I frequently come across malware hosted on onedrive and I've stopped bothering to try to report it, its still there months later and I've never received a response from Microsoft.

Post reply on HN