Live data from Hacker News

Google Ad Disguising Itself as www.gimp.org

old.reddit.com

71–80 of 230 posts

Re: Google Ad Disguising Itself as www.gimp.org

#71

Earlier quoted context omitted.

OpenPGP signing keys have similar problems. Web of Trust is useless if you don't know any developers to begin with, dates on public keys can be forged, and false signatures can be forged by creating a large number of other false keys. False keys can be made more misleading using 32-bit short Key ID collision (and don't blame OpenPGP for this, OpenPGP is notorious for its complexity but at least it tried, meanwhile al…

> Surprisingly, I think no attacker has ever forged a OpenPGP signature in a real-world security incident, likely because there's a lack of overlap between crypto nerds and crackers. I suspect in the real world almost nobody validates PGP keys of software downloads manually. They might do it automatically (for example via a Linux package manager), which a fake key wouldn't fool. Thus, faking the key isn't necessary b…

The 1% that do verify it would report the issue and alert others.

Re: Google Ad Disguising Itself as www.gimp.org

#72

Not to defend Google but this has been against Ad Words terms for as long as I can remember. It’s surprising they found a way to evade auto detection for this.

> against Ad Words terms Oh great, they'll get their account closed and need to make another one to continue scamming people. How about Google fixes this by displaying the URL that the ad actually goes to? Of course they don't want to do this because the URL with all of the tracking parameters looks ugly and it would hurt conversion rates. $$$ > user safety.

It's kind of crazy when they could just extract the domain name, or provide options for how much of the url you want (domain? subdomain? path? ...)

Re: Google Ad Disguising Itself as www.gimp.org

#73

Earlier quoted context omitted.

As soon as you realize how much of Google's bottom line is scam and malware distribution, it becomes really hard to view the company as anything but crooks. Google's other big line of business is shaking down businesses for cash by selling the top result for someone's own brand name unless they're paid for protection.

Even if ads were 100% legit verified links, they would still be scams. Advertising is inherently untrustworthy. Why do people trust anything a corporation says about their own products? In the best case scenario, they're highlighting the pros and omitting the cons. Usually they're just straight up lying. I want real opinions written by real people with no conflict of interest. People who are't getting paid by the cor…

I agree, but the fact that even if you hold the view that ads are beneficial to society, Google is still a bad actor and a net negative to all of us, is particularly noteworthy. We all pay for Google via folks paying ransoms and other scams, having to indirectly pay for high ad budgets every company has to pay off Google to avoid their own search result being squatted by a competitor, etc. There is no company on the planet that the world would benefit more from being shut down.

Re: Google Ad Disguising Itself as www.gimp.org

#74
post #64

In this particular case, I suspect a trademark complaint against Google would make sense. Google misrepresented the ad as the product of the Gimp project, and were paid as a result. They usually use an "obeying the law would not scale" type argument in court, but that would clearly be bullshit in this case. They have a business relationship with the ad buyer, and should have verified their affiliation with gimp.org.…

> obeying the law would not scale

I don't know why, but that sentence terrifies me. It's like the silicon valley version of a dystopia.

Re: Google Ad Disguising Itself as www.gimp.org

#75
post #40
post #21

Earlier quoted context omitted.

Yeah, blocking ads quickly became security improvement...

Always was. Does anyone remember the defacto original ad-blockers that blocking popups were? Firefox was marketed with this feature. It is basically a condom for the Internet. It makes maintenance for family computers much easier.

> Does anyone remember the defacto original ad-blockers that blocking popups were?

I was using the Internet Junkbuster (and later: Privoxy) in the mid-90s, many years before that. https://web.archive.org/web/19961222061917/http://www.junkbu...

Of course, back then you could just disable javascript in your web browser to protect yourself from malicious sites and annyances, and practically all sites would work perfectly fine.

Re: Google Ad Disguising Itself as www.gimp.org

#76

Earlier quoted context omitted.

Yeah Google Ads lies about the destination URL, it always has. Which is why the correct choice is to consider Google Ad links malicious by default. There's actually no way to be sure where clicking them will send you, and tons of fraudsters have put scam ads with the official legit domain listed. I've seen both Amazon and Best Buy URLs on scam ads.

This is possible with all advertiser platforms, they dont validate for your domain and will happily link to any domain.

Just to avoid no confusion, the issue here is that the URL displayed in the ad (and also when hovering over it) has a different domain from the page the user lands on when they actually click the ad. It's not about whether the advertiser owns the domain.

Re: Google Ad Disguising Itself as www.gimp.org

#78
post #30
post #14

IMO checksums more or less offer a false sense of security for users if they're stored/shared on the same page/domain as the download, since it'd be trivial for a bad actor to change them if the files are compromised. Linux mint, for example, the attacker updated the checksums for the ISOs on the page when it was compromised https://www.infoworld.com/article/3036178/lesson-from-linux-... I don't really have a solid s…

Put the checksums in a separate system such as the DNS. Use DNSSEC on your domains. Manage your DNS system as an isolated system (don't mix your HTTP/Email/Other stuff with your DNS provider). Now, users may verify the downloads you provide at your website by getting checksums from the DNS. DANE may be of interest here as well: https://www.infoblox.com/dns-security-resource-center/dns-se...

Is there any tooling around this?

In particular, it's crazy that I can't just stick a public key for my email address in the DNS record for my domain, and have email auto E2E encrypt to it.

(No, that wouldn't scale for gmail, but they could do a two level thing, where the gmail key signs the public key for each mailbox -- assuming people bothered to set up their own keys, or that gmail just silently opted them in to server side encryption.)

Re: Google Ad Disguising Itself as www.gimp.org

#79
Why is this allowed? I know Google will do anything for money, but why is Google allowed to signpost a link to gimp.org which actually takes you to g--imp.org (sanitised)?

I mean, if nothing else, how do they not share the liability for damages done by the spyware they're literally promoting? For the businesses squatting on the names of more notable ones? AdWords goes too far.

Re: Google Ad Disguising Itself as www.gimp.org

#80

Earlier quoted context omitted.

As soon as you realize how much of Google's bottom line is scam and malware distribution, it becomes really hard to view the company as anything but crooks. Google's other big line of business is shaking down businesses for cash by selling the top result for someone's own brand name unless they're paid for protection.

Even if ads were 100% legit verified links, they would still be scams. Advertising is inherently untrustworthy. Why do people trust anything a corporation says about their own products? In the best case scenario, they're highlighting the pros and omitting the cons. Usually they're just straight up lying. I want real opinions written by real people with no conflict of interest. People who are't getting paid by the cor…

Why is this getting downvoted?
Post reply on HN