Live data from Hacker News

Google AdWords Exploit Seen in the Wild

wp.josh.com

31–40 of 163 posts

Re: Google AdWords Exploit Seen in the Wild

#31
post #11

Earlier quoted context omitted.

If a large brand like Uber wouldn‘t buy (really expensive) keywords like „uber“ some of their rivals like lyft could bid on it. So uber would lose a customer who was really interested in uber to lyft. Exchange company names how you like. Its especially expensive for shops etc. Google will not change any rules to forbid bidding on brand names because they are making a ton of money of it. Think of something like amazon…

They have some rules in place, try bidding on Fortnite.

I imagine that might be in response to the malware advertising that was going on for fortnite a while back, and how quite a large proportion of the players are kids. As a highly visible brand and a highly vulnerable audience, it makes sense for them to focus efforts there and put in special rules.

Re: Google AdWords Exploit Seen in the Wild

#34

Earlier quoted context omitted.

>> Google's algorithms think the users query will be answered by going to that domain That's BS semantics. Their algorithms are based more on the age of your domain and other technicalities, rather than some hypothetical meaning of "search intention". Today you're much more likely to get directed to some SEO-optimised highly monetised blog content because they bought an incredibly old domain name rather than what you…

> Their algorithms are based more on the age of your domain and other technicalities One of which is "dwell time" and another is "bounce rate". Both those correlate highly with how well the site matches the users intention.

And that's why (e-mail, ad, notification, cookie) popups work that great: because the time it takes to actually see the content is increased and thus is the dwell time.

Bounce is mainly irrelevant as we mostly use Google to find a particular page on a website.

Re: Google AdWords Exploit Seen in the Wild

#38

Earlier quoted context omitted.

Bidding on your own company name is very cheap because your site has a very high quality score for that keyword (ie. Google's algorithms think the users query will be answered by going to that domain). A high quality score gives you an effective discount in the ad auction. You might only need to pay $0.01 for that ad, whereas your competitor would need to pay $1

>> Google's algorithms think the users query will be answered by going to that domain That's BS semantics. Their algorithms are based more on the age of your domain and other technicalities, rather than some hypothetical meaning of "search intention". Today you're much more likely to get directed to some SEO-optimised highly monetised blog content because they bought an incredibly old domain name rather than what you…

I think you're speaking to a point the parent wasn't really making. All they're saying is that being known as the canonical source for a brand gives you a steep discount on bidding for that brand name.

We can quibble about the philosophical role of modern search engines I guess, but the basic idea is just that it should be easy to defensively bid on your own thing.

Re: Google AdWords Exploit Seen in the Wild

#39
When I worked at Apple I filed a Radar (bug-report) asking for the mail client to check that, if the text of an tag was a url, that the text matched the href field. What followed, on the Radar, was a lengthy debate about this. If I recall correctly, the people who opposed basically argued that, if this feature was implemented by the mail client, spammers would simply find another way to inject false links. We (those who wanted the feature) lost. But I still think that, any web app that shows "http://whatever" in a link field should ensure that the href field is "http://whatever".

Re: Google AdWords Exploit Seen in the Wild

#40
post #32

Interesting that they go through so much trouble to spoof eBay.com and then not try to collect logins/passwords.

My understanding is that's not the purpose of the obfuscation. The parties doing this don't generally want to hack users or compromise accounts, they want people to go to their site instead of the more recognizable one.

If they start actively phishing users this way they're solidly in illegal hacking territory on a pretty massive scale. What they're currently doing is "only" a "growth hack" to get more people on their site instead of the competitor's site.

Post reply on HN