Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

131–140 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#131
post #96

What can I as a user even do to protect myself from this? Like what is the best practice for finding the official website of some organization in a high stakes situation?

Always check URL, and never use browser that hide URL or show unicode in an URL string I suppose.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#132
post #10

1) Use an ad blocker, always. 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? 3) IDN shouldn't be enabled by default.

4) Use a different search engine. I use search.brave.com myself.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#133
post #103

While Google is waging war against adblockers on YouTube they are once again showing they absolutely cannot be trusted with the responsibility of showing safe ads. That, and them showing war videos in ads to little kids.

Im constantly reporting ads that are inappropriate, scams, or flat out illegal, usually they are back within a week or two, if they even get removed at all. My favorites are the dumb-brick phone charger that "magic defrags your phone", and the micro-ghost pistol.

I noticed some fake reviews for a business on Google Maps recently. They were giving high ratings praising the service they received yesterday etc. I knew these were fake because the business has been closed for renovations for months. I tried to report them but Google only allows specific options, like “offensive language.” I tried their “spam” or “unrelated to this business” option, but they went nowhere. Not surprising since there’s no ability to write in additional information in your report.

It seems Google doesn’t want to receive feedback if it affects their bottom line.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#134
post #121
post #103

Earlier quoted context omitted.

Im constantly reporting ads that are inappropriate, scams, or flat out illegal, usually they are back within a week or two, if they even get removed at all. My favorites are the dumb-brick phone charger that "magic defrags your phone", and the micro-ghost pistol.

I see so many binary options scam ads on YouTube, often with a very poorly deepfaked Elon Musk as a spokesman. Google never takes them down. Maybe I should start reporting them to the securities regulator in my province instead - binary options were banned in Canada a few years ago as they are a haven for scammers and con artists. That might get better results.

I recently resolved a long standing issue with Loblaws by working with the Competition Bureau. It takes a long time though. Maybe that will help

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#136

"The ads were paid for by an outfit called Digital Eagle, which the transparency page says is an advertiser whose identity has been verified by Google." OF COURSE they were verified by Google. Google verifies identity by accepting money. Give them money, and you're verified. "Google representatives didn’t immediately respond to an email" Are there real humans at Google who actually answer email? I haven't seen a resp…

To be even more frank, Google's search capabilities diminished around late 2000s early 2010s for me. I used to be able to write out anything verbatim and find it. Now I can't even get the double quotes trick to work properly. Google's strengths have been slowly crippled for years.

Windows has a similar problem: marketing / ads is ruining an otherwise decent product.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#137
post #128

Earlier quoted context omitted.

"Advertising malware is not legit business." Sure. I"m pointing out this simple sort of "they can easily afford to do x" is usually nonsense. I haven't commented at all on what the result should be (not allowed to do it or whatever), simply that the math that it would be simple to fix is wrong. If we are going to argue about things in a useful way, we should avoid random assertions without data that don't really adva…

Sorry, but that is most fanboyish thing ever. If Google cannot handle their ad business, when there are too many customers, then stop taking new customers. Very simple. But taking money from criminals is very profitable and that is the reason. Edit: Checked DannyBee profile: "I manage developer workflow tools and services at Google" That explains why he is defending Google's scammy behaviours.

Ah, i see we've moved onto ad-hominen attacks and dismissal rather than engaging for real. That certainly may feel good, but it changes nothing about the argument?

This sort of dismissal based on who you work for is both childish, and unproductive to a real discussion. Similar to the "most fanboyish thing ever" comment, which, honestly, if telling someone their totally unsourced math and claim is wrong, by providing data and real math, is the most fanboyish thing you've ever seen, then i think you are very lucky in what you see ;)

Beyond that, i'll repeat what I said - i simply pointed out the assertion and math is wrong. That is all. You are the one claiming i am defending anything, beyond that, at all. I was very careful about not defending anything, and in fact said i'm open to all sorts of views about what to do about it.

Maybe you should re-read what i wrote, and point out any point where i did anything but show that the claim made was wrong, and the math was wrong?

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#138
post #115
post #47

Earlier quoted context omitted.

The first "punycode attacks" were using letters that were completely indistinguishable from the "real" ones (e.g. by using Cyrillic letters). I guess the assumption is that the user would be able to identify any letters with diacritics (even if they're indistinguishable from specks of dust on your screen) and avoid them - after all, you wouldn't go to "göogle.com" either?

As a german I wouldn't go to göogle.com. If my native language didn't include ö? Then that might be a speck of dust to me as well. A safer approach would be to only ever show a user the characters they expect to see (and are familiar with), e.g. based on their language setting. Assuming that every language has a finite list of characters used in its written form such a whitelist approach should be possible and much b…

I don't think it's that easy. Most people A) use english as their system language, because troubleshooting menus / error messages in foreign languages is a nightmare, and B) my mom would not notice the difference between google and göogle.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#139
post #103

Earlier quoted context omitted.

Im constantly reporting ads that are inappropriate, scams, or flat out illegal, usually they are back within a week or two, if they even get removed at all. My favorites are the dumb-brick phone charger that "magic defrags your phone", and the micro-ghost pistol.

I did so too. Only that often, that I'm no longer able to report any ads at all.

If you can, you should escalate with google support. Thats pretty bullshit that they expect users to report ads, but penalize them for doing so.

I pay, and if they cut me off for helping do their job, I'd be livid. Maybe being a paying customer is the reason they haven't blocked me yet

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#140
post #128

Earlier quoted context omitted.

Sorry, but that is most fanboyish thing ever. If Google cannot handle their ad business, when there are too many customers, then stop taking new customers. Very simple. But taking money from criminals is very profitable and that is the reason. Edit: Checked DannyBee profile: "I manage developer workflow tools and services at Google" That explains why he is defending Google's scammy behaviours.

Ah, i see we've moved onto ad-hominen attacks and dismissal rather than engaging for real. That certainly may feel good, but it changes nothing about the argument? This sort of dismissal based on who you work for is both childish, and unproductive to a real discussion. Similar to the "most fanboyish thing ever" comment, which, honestly, if telling someone their totally unsourced math and claim is wrong, by providing…

Your math is wrong because you say that Google spends 0 dollars at the moment to fight scam ads.

If it is true, then Google execs should be in jail right now.

And proves point again that Google does not care about filtering content and it is profitable to accept money from criminals.

Ofcourse if your paycheck depends of criminals money then it is very dumb to share that profit to hire more people to fight malware content.

In my country there are many Google scam ads which feature local celebrities/doctors, but it is impossible to remove those ads, because Google never removes them. Zero response from Google. Even Police cannot help because nobody from Google responses.

So I guess it is intentional to spread those spam ads.

Even if users report those ads, Google 99% of time never takes an action to remove spam ads.

With few thousand people you can remove those reported ads...

Post reply on HN