Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

11–20 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#11
post #4

Can you prosecute Google for spreading viruses and helping criminals?

That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world.

Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding their power and reach.

Why would you want that? (And that also goes for people who want Apple to replace their government at law enforcement).

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#12
Interesting, chrome indeed shows it in the url bar as ķeepass[.]info, but with FF I get xn--eepass-vbb[.]info, is this something I changed or a different default?

edit: As someone mentioned further down, it’s an about:config setting for network.IDN_show_punycode

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#14

I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.

What is uBo?

uBlock Origin, the best adblocker, and only full-featured on FF (but still better than the rest on the adtech browser):

https://github.com/gorhill/uBlock

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#15

I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.

What is uBo?

uBlock Origin, the gold standard when it comes to ad and tracker blocking.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#17

I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.

What is uBo?

uBlock Origin: https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#18
post #11
post #4

Can you prosecute Google for spreading viruses and helping criminals?

That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…

> Why would you want that?

If someone were to stand outside holding a big banner advertising something malicious/illegal they'll be in legal trouble pretty quickly, which I think is fair.

Why shouldn't Google be held to the same standard?

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#19

I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.

What is uBo?

Someone saving themselves 3 keypresses, approximately 1.5 seconds effort and causing a flurry of unneccesary replies.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#20

Interesting, chrome indeed shows it in the url bar as ķeepass[.]info, but with FF I get xn--eepass-vbb[.]info, is this something I changed or a different default? edit: As someone mentioned further down, it’s an about:config setting for network.IDN_show_punycode

The TLD registries are supposed to each have defined rules for IDN which can prohibit abuses and to police the use of your service. If you operate the registry for say, Switzerland, it makes sense to allow what Swiss and maybe German people would want, then forbid everything else.

But if you operate .COM or .INFO or .FREE-MONEY or whatever, your goal isn't to help anybody it's to obtain the most money possible without anybody senior going to jail. Crooks want to pay you money to help them target victims? Yes please.

So in practice the browser vendors have to cook up heuristics to try to guess whether the IDN is a trick and in this case I'd guess Chrome's heuristic didn't consider this a problem whereas Mozilla's did. I believe Mozilla were so exasperated by the IDN abuses at these registries they may have just switched off IDN rendering for the entire registries affected which is thorough.

Post reply on HN