Can you prosecute Google for spreading viruses and helping criminals?
That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…
Google-hosted malvertising leads to fake Keepass site that looks genuine
31–40 of 197 posts
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#32I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#33Punycode is of questionable use anyway. Granted I'm mostly looking into this from a primary latin alphabet perspective, but for the various non-latin alphabet sites I've browsed over the past decade all of them just stuck to regular ASCII domains. (Heck you see this even with usernames on websites that allowed Unicode to be used; most non-latin alphabet users will still stick to the Latin alphabet for usernames.) The…
As a practical step browsers should ask the user whether they want to allow URLs in a certain language the first time a non-ASCII character is entered. With just one or a couple of languages allowed, the attack surface would be drastically reduced for most users.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#341. Always type in URLs manually when downloading critical software to bypass the potential risks from ads.
2. Make use of browser plugins that identify malicious websites or unverified SSL/TLS certificates.
3. Before making any downloads, inspect the TLS certificate of the website by clicking on the padlock icon next to the URL bar. Look for inconsistencies like a different company name or issue date.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#351) Use an ad blocker, always. 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? 3) IDN shouldn't be enabled by default.
Because advertisers usually want to send links to a tracker site of their own first so that they can verify if their numbers match up with what Google reports.
No one trusts anyone in the advertising space, and for good reasons. Advertising has always been a space filled to the brim with crooks and fraudsters.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#36Can you prosecute Google for spreading viruses and helping criminals?
That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…
Google is a company that nets 60 billion $ a year in profits. They can afford hiring a few thousand people to manually vet ads before they go out, and they should.
Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#37Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#38Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#39Re: Google-hosted malvertising leads to fake Keepass site that looks genuine
#40Punycode is of questionable use anyway. Granted I'm mostly looking into this from a primary latin alphabet perspective, but for the various non-latin alphabet sites I've browsed over the past decade all of them just stuck to regular ASCII domains. (Heck you see this even with usernames on websites that allowed Unicode to be used; most non-latin alphabet users will still stick to the Latin alphabet for usernames.) The…
Though I think there's nothing wrong with punycode with dedicated first-level domains. like кремль.рф (does not exist, but I'm too lazy to find one).