Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

221–230 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#221

It's possible to install Google Chrome on a Windows box with chocolatey, the Windows answer to apt and brew. But, still, Microsoft's browsers still aren't good. In my workplace (where we do some complex cross-browser work) they're an enormous nuisance to development and QA. I wish Edge were far better than IE, but they're both quirky. Firefox and Google Chrome ordinarily work predictably. Safari has a few quirks, Edg…

Chocolatey is very handy but has a few warts. It can't tell if the underlying app has self-updated. When Chrome autoupdates after choco install, the next time you run a choco upgrade, it will unnecessarily upgrade Chrome again.

take a look at appget, we use windows itself as the source of truth. so even if an app self updates, or you have installed the app manually or even using chocolate, appget will know the _currently_ installed version.

also, we don't run some random PowerShell script written by god-knows-who on your machine. All installs are driven by pure data, so the only thing you need to trust is the appget client itself.

e.g. https://github.com/appget/appget.packages/blob/master/manife...

Re: Bing has been serving up malicious Google Chrome ads for months

#222

Using browsers to download software should never have become the standard practice... Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.

I've been trying to solve this for windows,

take a look at https://appget.net if you use windows.

Re: Bing has been serving up malicious Google Chrome ads for months

#223

Earlier quoted context omitted.

It doesn't in this case, however you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website. The security of the package repository system falls down when people add apt signing keys that are untrusted/unverified, which is what happens when you add a ppa in Ubuntu.

> you can determine that the chromium-team ppa is the official one in Ubuntu by following links from the Chromium website. We're sort of in a loop here -- how can I know what is the official Chromium website?

> We're sort of in a loop here

Yeah, unfortunately that's what verifying the legitimacy of the chromium-team Ubuntu ppa requires...

Anyway, there are two quick ways I found:

* Go to chrome://settings/help and see the link to Chromium.org (but obviously this doesn't work if you don't have Chrome already)

* At the bottom of google.com/chrome there is a link to Chromium.org

Re: Bing has been serving up malicious Google Chrome ads for months

#224

Earlier quoted context omitted.

I remember having great fun some years ago when my friend's Internet Explorer somehow broke in the Win95/98/ME days. So I tried to guess ftp servers from the DOS prompt. I think I managed to connect to ftp://ftp.opera.com and install Opera. Update: looks like it still works today. Anyone looking for a 2004 BeOS version?

You could just get a free AOL cd at the gas station, it included Internet Explorer.

Maybe in USA.

Re: Bing has been serving up malicious Google Chrome ads for months

#225
post #220

Call me paranoid, but every time I install software on Windows [1] I do the following dance: 1. Search for the name of the software on Google [2]. 2. Open link to software in separate tab. 3. Open Wikipedia link (usually on the same SERP) for software in separate tab. 4. Compare domain name from direct link with the domain name from the Wikipedia article. 5. Open another tab and type domain name manually. 6. Find dow…

Disclaimer: I'm the author/maintainer for AppGet [0]. What you explained here is one of the main selling points (as in convincing, appget is completely free) for appget. AppGet pretty much automates what you explained here and more. We automatically download and validate SHA256 of downloads (We have a strict policy of only allowing releases from the official source) All package info that is used to install applicatio…

Is there a readme on the website, github, or elsewhere? Do you have a plan to monetize AppGet?

Re: Bing has been serving up malicious Google Chrome ads for months

#226

I mentioned this in a comment over a year ago in a story about paint.net. https://news.ycombinator.com/item?id=14338174 > The Bing search engine is about as bad. A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware. So I asked them to be careful to ensure the download site is correct and left them to it. I came back…

This is exacltly what you would get if you'd deliberately moved all links to the legitimate site way down. Maybe because it's your competition?

Or if Bing was more susceptible to spam and abuse than Google

Re: Bing has been serving up malicious Google Chrome ads for months

#227
post #127

Earlier quoted context omitted.

Package managers are a fundamentally flawed concept: You depend on your distro mantainers to package what you need to install. If it isn't packaged, best case scenario is you get a tarball, which is already too hard for 99% of computer users. Snaps and Flatpaks are still too unpolished. Getting all your user applications (DAW, IDE, etc) from your OS developer (instead of getting it from the application developer) is…

No. Ubuntu makes private package archives (PPAs) very simple to use; many packages are available from the maintainer’s PPA. There are many alternative repositories for essentially all distorts today; snaps and flatpaks are indeed not yet polished enough, but they are much better and easier for 99% of users than tarballs, so calling tarballs a “best case scenario” is, in my opinion, wrong.

And how are PPAs fundamentally different from downloading a Windows installer from the Internet? If I download the installer from the maintainer's site, there's 0 risk (assuming HTTPS). And the site giving the PPA link is just as likely to be a phishing site as the the one serving some exe. Except browsers will sometimes warn on strange executables, whereas none do on misleading PPA links.

Re: Bing has been serving up malicious Google Chrome ads for months

#228

Call me paranoid, but every time I install software on Windows [1] I do the following dance: 1. Search for the name of the software on Google [2]. 2. Open link to software in separate tab. 3. Open Wikipedia link (usually on the same SERP) for software in separate tab. 4. Compare domain name from direct link with the domain name from the Wikipedia article. 5. Open another tab and type domain name manually. 6. Find dow…

I use ninite.com to achieve the same thing with less pain. The downside of my approach will only be revealed if ninite.com for some reason goes dark or to the dark side. I hope it doesn't happen and that if it does happen I hear about in time to transition to your approach!

Re: Bing has been serving up malicious Google Chrome ads for months

#229

I mentioned this in a comment over a year ago in a story about paint.net. https://news.ycombinator.com/item?id=14338174 > The Bing search engine is about as bad. A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware. So I asked them to be careful to ensure the download site is correct and left them to it. I came back…

It‘s kinda sad that there‘s currently no more intuitive, built-in, simple and elegant better way to do that.

(I know of thousands (if not infinitely) more complex ones so please don‘t start on them)

It must be as simple as „google that and press install“. Everything requiring an install has a huge negative attached, but the worst is if they google for the tool you use to then type in ... . Maybe make the tool the start page and train them to press the startpage-button first every time you tell them to „google sth“.

You‘ll miss a business model though incase you don‘t want to show links to crapware like certain others.

Or maybe just make DuckDuckGo the startpage?

Re: Bing has been serving up malicious Google Chrome ads for months

#230
post #185

Earlier quoted context omitted.

Me too. I've made at least $50 in amazon gift cards from bing rewards.

I made $0 in Amazon gift cards from DDG, but I did retain my privacy. If you got $50 in gift cards from Microsoft, you can be sure they profited more than $50 from you.

You can't be sure of that. It could be a loss leader to get people off Google. That said they are hoping that eventually they'll profit more than $50 from you.
Post reply on HN