Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

91–100 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#91
post #74

Earlier quoted context omitted.

weird because the keepass example, on chrome + android, looks exactly like a regular k in the address bar.

>looks exactly like a regular k in the address bar. Because there's a quick 302 redirect from "ķeepass.info" to "keepass.info" : Chrome F12 Dev Tools network trace: https://imgur.com/a/vrxjsUV Whether that redirect was there at the time of the Arstechnica article, I don't know. EDIT ADD: around 12:57 UTC, the 302 redirect was changed to a Youtube video: https://imgur.com/a/TtLxafP (Somebody is apparently having fun t…

Well that's good news, I was a little worried that it would be impossible to tell on mobile

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#92
post #79
post #53

Earlier quoted context omitted.

Can you somehow quantify it or is it your gut feeling? Any articles out there? I don't know if they catch small fish as in this example, it just isn't in the news. The bigger fish happens to be in the news, like shutting down international scam call center - 2 in LV, 1 in LT. Video from police cam if anyone wants to see smashing windows: https://www.vp.gov.lv/lv/jaunums/verieniga-starptautiska-ope... We are also bein…

At least for Russia itself there's plenty of articles about it. Here's one: https://krebsonsecurity.com/2021/05/try-this-one-weird-trick... > In Russia, for example, authorities there generally will not initiate a cybercrime investigation against one of their own unless a company or individual within the country’s borders files an official complaint as a victim.

> Eastern European countries, including Ukraine and Russia.

Okay, the term is used in geographical context and not geopolitical.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#93

Earlier quoted context omitted.

>Advertising has always been a space filled to the brim with crooks and fraudsters. If I ever work at a cubicle, I will hang this sentence on a large frame over my desk, then stay silent and stare every time someone comes and complains about my ad blockers.

Unless you're working at an adtech company, why would anyone complain about your ad blockers at work? Or even notice?

There was a brief period in my tech history where I viewed adblockers as "somewhat immoral."

I am waaay past that now.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#94
post #2

One solution to mitigate malverising is as transparency. Each as should contain the legal contact details (company name, country) of the advertiser. It does not solve the issue fully, but consumers will surely avoid East European suspicious companies advertising. It will also make it easier for the security researchers to track down bad actors and will bring some liability to the ad platform (Google). Facebook alread…

That would cost Google and Facebook revenue.

They are not going to do it unless a government makes them do it, or if the legal liability risk is too great.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#95

Another reason to use ublock origin / Brave shields. Thanks for another article to send the adblocker complainers. THIS shit is what is killing the net, not adblock users.

Yeah. I was briefly an adblock complainer, but I have swung so far to the other side I can't even see my old high horse, and not just because of ad served malware.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#97
post #11
post #4

Can you prosecute Google for spreading viruses and helping criminals?

That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…

Google is effectively a giant mall, and mall owners sure as heck police their stores by actively trying to identify criminal storefronts.

Google doesn't have to do this because they are anticompetitive.

The root problem here is that Google shouldn't be in this position where we are talking about them acting as law enforcement, and a business getting banned by Google is akin to getting ejected from society.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#98
post #11

Earlier quoted context omitted.

That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…

> Why would you want that? If someone were to stand outside holding a big banner advertising something malicious/illegal they'll be in legal trouble pretty quickly, which I think is fair. Why shouldn't Google be held to the same standard?

"If someone were to stand outside holding a big banner advertising something malicious/illegal they'll be in legal trouble pretty quickly, which I think is fair."

For the most part, you would not. While it is not protected by the first amendment in the US to advertise illegal products, it is also not particularly restricted in most of the US.

To whit: If you hold up a big banner saying "fentanyl sale - 30 cents per gram", you would not have committed a crime or an actionable legal tort in most places.

The thing that is actionable everywhere is deceptive/fraudulent/misleading advertising.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#100

Earlier quoted context omitted.

Right now, using curl, [ķ]eepass.info redirects to xn--eepass-vbb.info and consequently that redirects to official domain keepass.info.

So it might be triggering on certain UAs

It's sending me to a rickroll now (Youtube).
Post reply on HN