Live data from Hacker News

Until further notice, think twice before using Google to download software

arstechnica.com

221–230 of 242 posts

Re: Until further notice, think twice before using Google to download software

#221
Who search for installers on web should know about winget, scoop or chocolatey.

https://winget.run/

https://scoop.sh/

https://chocolatey.org/

For those who don't like command line, there is WingetUI: https://github.com/marticliment/WingetUI

We should abandon old, inefficient and now dangerous habits.

Re: Until further notice, think twice before using Google to download software

#222
post #7

The malvertisement thing has become real bad. The other day I had a problem so I used chrome, where I unfortunately hadn't installed an add blocker yet. I searched for my bank (I know, I should have put the URL in directly, but I was being lazy since it was a new chrome install and I didn't have the url in my history yet). I hit the first link, logged in (my password manager would have saved me here, but again it was…

This is why the appeal-to-ethics argument against adblocking holds no weight with me. Yes, maybe I stole $0.0001 from the publisher by not looking at an advert. But I also didn't have my bank password stolen and my files cryptolockered. It's a small price to pay for security.

The other appeal-to-ethics argument is that major advertising networks should not (ever) do business with malware companies, scammers, and bad actors. Their ethical responsibility of doing their business, which they profit from, is at the very least some form of due diligence on who they form business relationships with.

Ethics is a two-way street.

Re: Until further notice, think twice before using Google to download software

#223
post #56
post #25

Earlier quoted context omitted.

The search results are not the problem. The ads are. Ads are placed above search results, so users are more likely to be mislead by them. Installing an ad blocker removes the misleading ads, leaving only the legitimate search results.

Not entirely, unfortunately, at least on my experience. Putting the keyword "download" after the name of software, ebooks, or music will lead into weird websites that distribute malware, and they rank very high. I just tried searching for an old Game Programming book I happen to have. There's two piracy sites, then one site with a "Download" button that gives me a DMG with an executable. Those are above Archive.org,…

that's slightly different.

piracy is a known vector for distributing malware.

this is more for general searches or software with no paid option.

google should deindex scam sites, but this is easier said than done. however they should NEVER have paid ads for malware as they're directly profiting from malware

Re: Until further notice, think twice before using Google to download software

#225
post #7

The malvertisement thing has become real bad. The other day I had a problem so I used chrome, where I unfortunately hadn't installed an add blocker yet. I searched for my bank (I know, I should have put the URL in directly, but I was being lazy since it was a new chrome install and I didn't have the url in my history yet). I hit the first link, logged in (my password manager would have saved me here, but again it was…

This is why the appeal-to-ethics argument against adblocking holds no weight with me. Yes, maybe I stole $0.0001 from the publisher by not looking at an advert. But I also didn't have my bank password stolen and my files cryptolockered. It's a small price to pay for security.

That doesn’t help. My mom downloaded malware when she was searching for a printer driver. It was organic search and not an ad.

It’s about time for her to upgrade anyway. I’m going to encourage her to get a new $599 Mac Mini. Yes I know there is nothing inherently more secure about the Mac than your typical Windows computer besides perhaps code signing. But isn’t targeted as heavily.

Re: Until further notice, think twice before using Google to download software

#226
post #98

Earlier quoted context omitted.

And governments are doing their best to break the app stores, destroying even the basic safely mechanisms such stores can offer. This should be taken as instructive, but is ignored by most.

What a strange argument - with this they're actually opening the market to stores that will ensure secure products like F-Droid with their guarantee for opensource. If anything, the current situation where BOTH Apple and Google store are ridden with malware and poor software doesn't work. We didn't fix SourceForge problems by allowing a megacorp to kill all competition and enshrine that cesspool, but by creating new…

There is very little outright, break the sandbox malware available for iOS.

Re: Until further notice, think twice before using Google to download software

#229
post #190

Earlier quoted context omitted.

No, I checked for that multiple times as I was around when that happened. It was an ad served up directly by Google that lead to a phishing website and phone numbers on it. His filter bubble is very different from mine, and it's clear that the peddlers of malware and scams use ad targeting to hit the elderly with ads that try to take advantage of them. This is a major downside of ad targeting: they're more effective…

I increasingly believe that there are no legitimate uses of micro-targeted ads and only harmful ones. The only real distinction is whether or not it is harmful to the target (user), the advertiser (failed impressions), and/or the advertisement network (Google allowing malware companies to spend pennies on the dollar to sell bad software malware launchers in turn makes Google look bad). Micro-targeting may go down as…

I agree on that point. I believe that micro-targeting of ads is how harmful content (outright scams as well as conspiracy theories and other misinformation) is able to get promoted in ways that allow it to proliferate which was not possible in the past. My theory is that back when TV stations and newspapers were locally owned, editorial staff filtered out the extreme and harmful content as a means to protect their own reputation. Being trustworthy was important if the owner was an active member in the community. If you wanted to promote conspiracy theories, the reasonable people who saw those ads would complain about them and go to the editors and owners of the content delivery platforms to get those ads pulled. The whole system was self regulating in a way that online platforms have made impossible.

As ownership of content platforms is disconnected from local communities, it becomes more profitable to engage in exploitative behaviour that would not be acceptable on a local scale. Computers simply don't care if you trust them or not, and we the programmers have yet to make that an important factor in how platforms decide which content is promoted to end users.

I have no idea how to improve this situation outside of legislation by our governments.

Re: Until further notice, think twice before using Google to download software

#230
post #190

Earlier quoted context omitted.

No, I checked for that multiple times as I was around when that happened. It was an ad served up directly by Google that lead to a phishing website and phone numbers on it. His filter bubble is very different from mine, and it's clear that the peddlers of malware and scams use ad targeting to hit the elderly with ads that try to take advantage of them. This is a major downside of ad targeting: they're more effective…

You gave me a fantastic insight Ive been wondering why a loved one is constantly getting phishing emails. Ive been fighting a losing battle using email filters to contain the phishing fraud emails. Your post gave me the idea to clean up his browsing caches. Thank you

Just login to your own Google account on their device. =-) That'll result in some pretty dramatic changes in the content they see (and probably you too as things get blended over time).
Post reply on HN