Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

1–10 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#2
One solution to mitigate malverising is as transparency. Each as should contain the legal contact details (company name, country) of the advertiser. It does not solve the issue fully, but consumers will surely avoid East European suspicious companies advertising. It will also make it easier for the security researchers to track down bad actors and will bring some liability to the ad platform (Google).

Facebook already does this for political ads, so it is doable.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#3
post #2

One solution to mitigate malverising is as transparency. Each as should contain the legal contact details (company name, country) of the advertiser. It does not solve the issue fully, but consumers will surely avoid East European suspicious companies advertising. It will also make it easier for the security researchers to track down bad actors and will bring some liability to the ad platform (Google). Facebook alread…

Or you simply can have a database of all websites' SSL certificates[0] and compare it to the website you are accessing or in this case, compare it to the website that buys ad placement.

[0] https://www.cloudflare.com/learning/ssl/what-is-an-ssl-certi...

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#8
post #2

One solution to mitigate malverising is as transparency. Each as should contain the legal contact details (company name, country) of the advertiser. It does not solve the issue fully, but consumers will surely avoid East European suspicious companies advertising. It will also make it easier for the security researchers to track down bad actors and will bring some liability to the ad platform (Google). Facebook alread…

That would be amazing.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#9
post #2

One solution to mitigate malverising is as transparency. Each as should contain the legal contact details (company name, country) of the advertiser. It does not solve the issue fully, but consumers will surely avoid East European suspicious companies advertising. It will also make it easier for the security researchers to track down bad actors and will bring some liability to the ad platform (Google). Facebook alread…

Why East European are suspicious?

Little xenophobic?

Post reply on HN