Live data from Hacker News

Google AdWords Exploit Seen in the Wild

wp.josh.com

111–120 of 163 posts

Re: Google AdWords Exploit Seen in the Wild

#111

everything on this page boils down to 2 simple things: 1) google ads should verify domain ownership of destination domains (via webmaster tools, etc) 2) google should expand the "feature" of supporting tracker redirects to allow "final" domain owners to disallow the use of interim clicks (so ebay can simply say: "no, I will always go straight to ebay.com, which I own, and any ad that points to me at any step must als…

I assumed this would be the way forward when they introduced Webmaster Tools like a decade ago.

Re: Google AdWords Exploit Seen in the Wild

#112
post #109

As mentioned here https://news.ycombinator.com/item?id=17126218 , this blog's author is an interesting character, a very early pioneer in electronic stock trading infrastructure.

it Is something of note that someone who helped pioneer electronic stock trading is now working in digital advertising (which in many ways is similar to to trading stocks)

There are similarities - but I don't think he works in adtech. (Based on this article, and as far as I can tell.)

Re: Google AdWords Exploit Seen in the Wild

#113

I feel like all the technical arguments here are besides the point. The ad is designed to take you to a page, which tells you a lie, to convince you to give them your money. We already have a legal term for people that make money by misrepresenting something, it's called fraud. Sure, you can tell me it will still be a cat or mouse game and that laws aren't gonna reach into whatever sort of clickfarm network exists fa…

In this case, the technical side is also at fault for allowing this (on every other website (well, aside from Google search results), the status bar shows on hover where you will be taken if you click), but I do agree that we very often talk about the technical aspect and not the legal one.

I don't know any country where anyone goes to the police when they had a malware infection. It's a little like countries where there is no point going to the police for theft: nobody was killed so the police has better things to do. Here too, if you're not a huge corporation with millions in damage, they won't even look at it, even if you supply logs that point to an IP within their jurisdiction. (Example of a few years ago in the Netherlands: employer was hacked, hundreds of customer websites taken offline, IP address came from a home connection in the same city as we were in, police took the report straight to /dev/null...)

The only way to get anything done legally is by starting lawsuits yourself, which doesn't work for criminal cases, but oh-so-conveniently works for online copyright infringement.

Re: Google AdWords Exploit Seen in the Wild

#114
post #78

Earlier quoted context omitted.

> I, personally, would be quite happy for this use case to break. Why? If you don't want to be tracked it is pretty easy to avoid. You should already only be getting/opening emails you care about. Emails you don't care about should be unsubscribed from and reported as spam. Granted that links should only be tracked in email you do care about, why do you not want those people to have the information they need to refin…

> why do you not want those people to have the information they need to refine and improve these emails Well, it comes at the expense of 1) making things slower for me and 2) making it more difficult to discern phishing emails from legitimate ones. I also find it difficult to believe that all of this analytics is actually doing much to inform me about things I care about. > Would you be happy if the email just doesn'…

> 1) making things slower for me and

That is a valid reason, but I suspect the extra delay of 2x your ping when you click on a link and wait for it's target to load is fairly negligible for most people.

> 2) making it more difficult to discern phishing emails from legitimate ones

You shouldn't be relying on link text to discern phishing emails, that is what the client checking SPF records and the user checking the contents of the url bar are for.

> I also find it difficult to believe that all of this analytics is actually doing much to inform me about things I care about.

Why is that? I would think it is pretty obvious how A/B testing click-through rates for emails could easily help make those emails more informative and easier to use.

If the speed cost and privacy loss is not worth it to you, having the actual (non-tracked) URL available in the link text atleast gives users the option to opt out of that tracking.

Re: Google AdWords Exploit Seen in the Wild

#116
That's the kinda stuff that keeps me installing adblockers on computers and phones of relatives that don't know about it.

My aunt's android was slow as hell and had lock screen ads, how is this possible?

Be kind to your relatives, install an adblocker.

Re: Google AdWords Exploit Seen in the Wild

#117

Are there trademark infringement issues here, particular on Google's part? They are getting paid (probably a lot) to display this ad, and are explicitly allowing buyers to lie about their identity. If I were eBay, I'd be getting my lawyers on this immediately. Every dollar getting paid to Google for this ad is a dollar out of my revenue, and a lost customer, and is illegal.

https://www.forbes.com/sites/ericgoldman/2012/10/22/google-d... https://en.m.wikipedia.org/wiki/Rosetta_Stone_Ltd._v._Google... .

Second link is broken, and the first is about a different thing (triggering an ad based on a competitor's trademark).

Pretending to be a competitor clearly violates trademark law. But I somewhat suspect these fraudsters aren't that concerned with trademark law.

Re: Google AdWords Exploit Seen in the Wild

#118
Off-topic but related to the source... I just finished reading Dark Pools, by Scott Patterson, and immediately recognized josh.com as being Josh Levine’s website. He’s portrayed in a very positive light by the book, and he seems like the kind of person who would rather avoid attention from it, but I do want to recommend the book as one of my absolute favorites.

It seems his old site about The Island ECN is archived at http://josh.com/oldindex.htm

Check it out if you have the slightest interest in electronic and high frequency trading!

Re: Google AdWords Exploit Seen in the Wild

#119
post #98
post #76

Earlier quoted context omitted.

At least Thunderbird seems to do that: when an email has an tag with text that looks like a URL but doesn't match the href, it throws the "this email is probably a scam" bar above the message.

...which then marks all these newsletters as scams, since the link usually first points to analytics site?

Sounds to me it’s working as intended.

Re: Google AdWords Exploit Seen in the Wild

#120
post #4

This is an explicit tool in adwords, believe it or not. The feature is intended so that you can have a link "to" http://trackersRus.com/ which forwards to http://ebay.com/ , without the user seeing that bit of ugly. It's been used in campaigns for years, I've reported probably hundreds of these distributing malware.

I wonder why Google doesn’t follow the redirect, and ensure the followed link matches the displayed link?

I get that there’s workarounds like changing the redirect after Google checks it, but there’s solutions to this too (like running checks every so often to ensure the link redirects to the same domain).

Post reply on HN