Live data from Hacker News

Bing has been serving up malicious Google Chrome ads for months

forbes.com

231–240 of 249 posts

Re: Bing has been serving up malicious Google Chrome ads for months

#231
post #220

Earlier quoted context omitted.

Disclaimer: I'm the author/maintainer for AppGet [0]. What you explained here is one of the main selling points (as in convincing, appget is completely free) for appget. AppGet pretty much automates what you explained here and more. We automatically download and validate SHA256 of downloads (We have a strict policy of only allowing releases from the official source) All package info that is used to install applicatio…

Is there a readme on the website, github, or elsewhere? Do you have a plan to monetize AppGet?

you can read the documentation at https://docs.appget.net

As far as monetization, we do have plans for a paid offering, internally we are calling it "AppGet for Fleets" it'll be to manage/monitor app installation on a group of computers remotely using a hosted dashboard (SaaS offering).

AppGet as you see today and all of its stand-alone features will remain free and opensource.

Re: Bing has been serving up malicious Google Chrome ads for months

#232
post #129

Earlier quoted context omitted.

There was a short time about seven years ago when Google was returning a malicious link for Blizard's BattleNet. Had my WoW creds stolen and I wasn't what you would call naive on a computer.

That sucks. I know it's a tired point, but it nevertheless amuses me that someone would search for BattleNet. The name is literally the domain name: battle.net.

This was soon after the switch to battle.net and I may not have realized that the address was actually 'battle.net'. I don't remember. Honestly, I still search from time to time even when I know the address (didn't back then) because sometimes it's fast, and sometimes it's just muscle memory.

Re: Bing has been serving up malicious Google Chrome ads for months

#233
post #135

Earlier quoted context omitted.

I mean, you could guess. The name even hints at it for anyone aware of the `.net` tld. That's not a great solution, since many people are barely aware what at url is, but I think it should still be one that you and I (as people who are) use. Similarly the article is fixed by guessing that google chrome is probably at chrome.google.com (also chrome.com), firefox is probably at firefox.com, cnn is probably at cnn.com,…

That .com trick works mostly if you are american going on american websites mostly. You seem to be unaware of other tlds.

Point of interest: Chinese websites are expected to use the .com TLD. China technically has its own TLD, .cn, but using it is not normal.

.com is pronounced 网 wǎng, "net", which doesn't leave much conceptual space for other TLDs.

Re: Bing has been serving up malicious Google Chrome ads for months

#234
post #39

Earlier quoted context omitted.

Ok, we've changed the title to the subtitle.

I suspect that as a general matter, headlines are attention-catching gimmicks and subtitles are more likely to proper titles for an article.

Yes, that's quite right.

Re: Bing has been serving up malicious Google Chrome ads for months

#235

Call me paranoid, but every time I install software on Windows [1] I do the following dance: 1. Search for the name of the software on Google [2]. 2. Open link to software in separate tab. 3. Open Wikipedia link (usually on the same SERP) for software in separate tab. 4. Compare domain name from direct link with the domain name from the Wikipedia article. 5. Open another tab and type domain name manually. 6. Find dow…

I do a simplified version of it:

1. Search for the name of software on Google.

2. See if something looking like a site for the product shows up.

3a. If a product site shows up, I take a careful look around, and if it feels legit, I manually find the download link and use it.

3b. If a SourceForge link shows up, I proceed to the download. This is rare, but some program authors don't bother setting up their own sites, and I'm yet to see a malicious SF repo.

This is less secure than your procedure, but worked well enough so far.

Re: Bing has been serving up malicious Google Chrome ads for months

#236

Earlier quoted context omitted.

No. Ubuntu makes private package archives (PPAs) very simple to use; many packages are available from the maintainer’s PPA. There are many alternative repositories for essentially all distorts today; snaps and flatpaks are indeed not yet polished enough, but they are much better and easier for 99% of users than tarballs, so calling tarballs a “best case scenario” is, in my opinion, wrong.

And how are PPAs fundamentally different from downloading a Windows installer from the Internet? If I download the installer from the maintainer's site, there's 0 risk (assuming HTTPS). And the site giving the PPA link is just as likely to be a phishing site as the the one serving some exe. Except browsers will sometimes warn on strange executables, whereas none do on misleading PPA links.

Moving the goal posts much?

You were complaining tarballs are the “best case” and are not good enough because they’re too hard for regular users.

PPA is as easy as windows downloads; it updates the same way as the main system unlike windows; and it always go through ununtu’s Servers which makes it somewhat more monitorable. But that’s a new discussion.

Re: Bing has been serving up malicious Google Chrome ads for months

#237
post #129

Earlier quoted context omitted.

There was a short time about seven years ago when Google was returning a malicious link for Blizard's BattleNet. Had my WoW creds stolen and I wasn't what you would call naive on a computer.

That sucks. I know it's a tired point, but it nevertheless amuses me that someone would search for BattleNet. The name is literally the domain name: battle.net.

That's not an assumption you can make in general. For example, paint.net is not found at paint.net.

Re: Bing has been serving up malicious Google Chrome ads for months

#238
post #51

.. and that's why running an ad-blocker these days is not even a moral question; It's proper hygiene. I don't eat without washing my hands first, and I don't browse without an ad blocker.

I'm with you on that, but in this specific case people are using Edge exactly once on a new machine in order to download Google Chrome. It's reasonable to assume they aren't going to bother installing an ad blocker on Edge for this use.

Pretty sure malwarebytes would catch this. Or any AV.

Malware like this targets the lowest hanging fruit I guess.

Re: Bing has been serving up malicious Google Chrome ads for months

#239

I mentioned this in a comment over a year ago in a story about paint.net. https://news.ycombinator.com/item?id=14338174 > The Bing search engine is about as bad. A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware. So I asked them to be careful to ensure the download site is correct and left them to it. I came back…

I've just checked on bing with IE and the first results are:

- ad by Google for Google Chrome - ad by Mozilla for Firefox - 2 result on Google's site - one download site (didn't check if it's crapware) - two wikipedia links - the same ads at the tops

Re: Bing has been serving up malicious Google Chrome ads for months

#240

Call me paranoid, but every time I install software on Windows [1] I do the following dance: 1. Search for the name of the software on Google [2]. 2. Open link to software in separate tab. 3. Open Wikipedia link (usually on the same SERP) for software in separate tab. 4. Compare domain name from direct link with the domain name from the Wikipedia article. 5. Open another tab and type domain name manually. 6. Find dow…

I would also add:

7. Scan installation package using VirusTotal (Ignore ClamAV and Chinese A/V results).

Post reply on HN