Live data from Hacker News

Google Ad Disguising Itself as www.gimp.org

old.reddit.com

61–70 of 230 posts

Re: Google Ad Disguising Itself as www.gimp.org

#61

This is also a huge issue with Blender and pops up on /r/blender from time to time. (Here's a few random recent examples: https://redd.it/xxkx5s https://redd.it/vvrxko https://redd.it/xwkky8 https://redd.it/vuqu1r ) Ad networks and content providers get up in arms over widespread ad blocking but then allow stuff like this through.

Turns out uBlock Origin is the best anti-malware software there is. For some reason friends and family just don't seem to get malware anymore after I installed it on their browsers.

As soon as you realize how much of Google's bottom line is scam and malware distribution, it becomes really hard to view the company as anything but crooks.

Google's other big line of business is shaking down businesses for cash by selling the top result for someone's own brand name unless they're paid for protection.

Re: Google Ad Disguising Itself as www.gimp.org

#62
post #14

IMO checksums more or less offer a false sense of security for users if they're stored/shared on the same page/domain as the download, since it'd be trivial for a bad actor to change them if the files are compromised. Linux mint, for example, the attacker updated the checksums for the ISOs on the page when it was compromised https://www.infoworld.com/article/3036178/lesson-from-linux-... I don't really have a solid s…

OpenPGP signing keys have similar problems. Web of Trust is useless if you don't know any developers to begin with, dates on public keys can be forged, and false signatures can be forged by creating a large number of other false keys. False keys can be made more misleading using 32-bit short Key ID collision (and don't blame OpenPGP for this, OpenPGP is notorious for its complexity but at least it tried, meanwhile al…

> Surprisingly, I think no attacker has ever forged a OpenPGP signature in a real-world security incident, likely because there's a lack of overlap between crypto nerds and crackers.

I suspect in the real world almost nobody validates PGP keys of software downloads manually. They might do it automatically (for example via a Linux package manager), which a fake key wouldn't fool. Thus, faking the key isn't necessary because 99% of users that could be fooled won't bother checking.

Re: Google Ad Disguising Itself as www.gimp.org

#63

Earlier quoted context omitted.

Yeah Google Ads lies about the destination URL, it always has. Which is why the correct choice is to consider Google Ad links malicious by default. There's actually no way to be sure where clicking them will send you, and tons of fraudsters have put scam ads with the official legit domain listed. I've seen both Amazon and Best Buy URLs on scam ads.

The entire hackjacking of the URLs needs to stop. It is destroying the web. From Safari hiding the full path in the browser in the name of "minimalism" to AMP and all the other bullshit. URLs are sacred. Please don't fuck with them. Please.

[deleted]

Re: Google Ad Disguising Itself as www.gimp.org

#64
In this particular case, I suspect a trademark complaint against Google would make sense.

Google misrepresented the ad as the product of the Gimp project, and were paid as a result. They usually use an "obeying the law would not scale" type argument in court, but that would clearly be bullshit in this case. They have a business relationship with the ad buyer, and should have verified their affiliation with gimp.org. Also, a simple string match on the URL would expose the attempted fraud on Google's end.

I'm not sure how to check if Gimp is a registered trademark in the US. This page kind of implies it might be (or that the author of the page does not understand trademarks):

https://www.gimp.org/about/selling.html

Re: Google Ad Disguising Itself as www.gimp.org

#65
post #14

IMO checksums more or less offer a false sense of security for users if they're stored/shared on the same page/domain as the download, since it'd be trivial for a bad actor to change them if the files are compromised. Linux mint, for example, the attacker updated the checksums for the ISOs on the page when it was compromised https://www.infoworld.com/article/3036178/lesson-from-linux-... I don't really have a solid s…

OpenPGP signing keys have similar problems. Web of Trust is useless if you don't know any developers to begin with, dates on public keys can be forged, and false signatures can be forged by creating a large number of other false keys. False keys can be made more misleading using 32-bit short Key ID collision (and don't blame OpenPGP for this, OpenPGP is notorious for its complexity but at least it tried, meanwhile al…

The big advantage of an OpenPGP signature over a checksum/hash is that you only have to verify the identity once. The identity can be used to verify the signatures of an unlimited number of files. That is as opposed to requiring each file to have a separate checksum/hash. Much more opportunity for deception on the smaller scale.

A perhaps less appreciated advantage is that in practice the identities are stored offline with each entity that will be verifying the signatures. So an attacker has to justify the use of the new identity to what would normally be a large number of entities. That might explain why that sort of attack is so rare.

Re: Google Ad Disguising Itself as www.gimp.org

#66

Earlier quoted context omitted.

Turns out uBlock Origin is the best anti-malware software there is. For some reason friends and family just don't seem to get malware anymore after I installed it on their browsers.

As soon as you realize how much of Google's bottom line is scam and malware distribution, it becomes really hard to view the company as anything but crooks. Google's other big line of business is shaking down businesses for cash by selling the top result for someone's own brand name unless they're paid for protection.

Even if ads were 100% legit verified links, they would still be scams. Advertising is inherently untrustworthy. Why do people trust anything a corporation says about their own products? In the best case scenario, they're highlighting the pros and omitting the cons. Usually they're just straight up lying.

I want real opinions written by real people with no conflict of interest. People who are't getting paid by the corporation.

Re: Google Ad Disguising Itself as www.gimp.org

#67
post #34

EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287 . On the other hand, https:…

Yeah Google Ads lies about the destination URL, it always has. Which is why the correct choice is to consider Google Ad links malicious by default. There's actually no way to be sure where clicking them will send you, and tons of fraudsters have put scam ads with the official legit domain listed. I've seen both Amazon and Best Buy URLs on scam ads.

This is possible with all advertiser platforms, they dont validate for your domain and will happily link to any domain.

Re: Google Ad Disguising Itself as www.gimp.org

#68
Ad-blocking just shows how "the digital naive divide" evolved without them.

I can't say enough nice things about gl.inet deviced and switched to a cellular model when ad-blocking on a 4G ipad was too much trouble.

I orginally setup a Spitz gl-x750v2 and removed the ec25-af lte and put it in an external enclosure and move it between better spec'd gl.inet routers to run adguard home.

"Halt" is a good browser on IOS to block all YT ads, but a portable router workes well with a dedicated sim or tethering a phone.

Ads are soooooo 1980's TV :p

Re: Google Ad Disguising Itself as www.gimp.org

#69

Remind me why Google even allows ads in rank 1 on brand terms? I remember when "don't be evil" Google would talk about how ads are in a different color on the right sidebar.

Not only do they allow it, they actively encourage it. They tell businesses that it's really important to buy ad space on searches for your own brand name so that a competitor doesn't. The way they say it really comes off like a protection racket. "Nice number one spot for searches for your brand name you have there, would be a shame if anything were to happen to it." They make people feel better about it by giving a…

I noticed this on the App Store the other day. I searched for YouTube and the first result was TikTok.

Re: Google Ad Disguising Itself as www.gimp.org

#70
post #14

IMO checksums more or less offer a false sense of security for users if they're stored/shared on the same page/domain as the download, since it'd be trivial for a bad actor to change them if the files are compromised. Linux mint, for example, the attacker updated the checksums for the ISOs on the page when it was compromised https://www.infoworld.com/article/3036178/lesson-from-linux-... I don't really have a solid s…

> it'd be trivial for a bad actor to change them if the files are compromised.

But it's trivial for responsible members of an organization to set-up a continuous, automated verification of the checksums listed on a web page. It wouldn't be practical to do that with the ISOs, directly.

Of course if the organization is lazy or incompetent, and chooses not to do so, then they have only themselves to blame. But if you fail to compare your downloaded files to the listed checksums, that's all on you.

Post reply on HN