Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

151–160 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#151
post #2

One solution to mitigate malverising is as transparency. Each as should contain the legal contact details (company name, country) of the advertiser. It does not solve the issue fully, but consumers will surely avoid East European suspicious companies advertising. It will also make it easier for the security researchers to track down bad actors and will bring some liability to the ad platform (Google). Facebook alread…

That would cost Google and Facebook revenue. They are not going to do it unless a government makes them do it, or if the legal liability risk is too great.

This is why punitive damages were invented: companies who didn't want to do the right thing because of money would be made to pay even more than if they had done the right thing in the first place.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#152

"the company has said it promptly removes fraudulent ads as soon as possible after they’re reported" If they wanted to be part of the solution they'd vet the ads before they're made public. But that doesn't scale, and so people get scammed and society suffers and Google makes more money than it knows what to do with. Pretty fair trade...? As others have said in one way or another, blocking internet advertising is par…

>"the company has said it promptly removes fraudulent ads as soon as possible after they’re reported"

Same issue from a year ago, looks to be the same prexix on the domain name as well.

https://www.bleepingcomputer.com/news/security/google-ad-for...

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#154

Earlier quoted context omitted.

I guess it's a fine line. If Google starts pre screening ads and then bans somewhat legit ads - which may or may not look as legit - then we will see reports about them. Moderation is a tough problem to solve. We want convenience with the right stuff, and strong blocks with even slightly shady stuff. They are bound to miss a thing or two. Question here is that is this an edge case or a prominent one (as in do they ha…

I think you're giving them an unnecessary pass, the incentives are completely in their favor: don't screen ads, make money off ads that are frauds, scams, age-inappropriate, etc... wait for "someone" to report those ads as such; meanwhile, keep making money off them, and the scammers/frauds/etc keep making marks. The human-friendly way would be to screen ads before airing them, which means hiring teams to do the scre…

I think I probably am giving them an unnecessary pass. There is another case in the below links about FB ads where Facebook banned an advertiser's account because of usage of words "panda" and "python".

While that case is unrelated, if someone prescreens the ads without having the required context, (let's be real here, it would be reviewed by someone in Philippines or India, not USA) they are likely to block stuff they do not understand but told to err on the side of the caution - which is what you presumably want to avoid the cases as in this title.

> the rejection can be appealed upon which another person will deal with the rejection review process

It still requires someone to have context about what you are running an advert on. Still hard to find, still not as reliable, and would either end up blocking many legit ads, or passing some objectionable ads. It does not just hurt their bottomline, but the bottomline of every good faith advertiser on the network.

I agree that just reporting post seeing the ad is a poor feedback mechanism. Maybe some sort of AI. They do verify advertisers though as they say. Maybe that should be more stringent.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#155

Another reason to use ublock origin / Brave shields. Thanks for another article to send the adblocker complainers. THIS shit is what is killing the net, not adblock users.

Yeah. I was briefly an adblock complainer, but I have swung so far to the other side I can't even see my old high horse, and not just because of ad served malware.

Ads have broken an unwritten contract with the general public. They by this unwritten contract must be for legitimate products not scams. They must be things that I do not find offensive. This is an unwritten contract because there are other evil things that I have not thought of that they must not do.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#156

Earlier quoted context omitted.

Also the , may be somewhat obscured by link underlining, which additions atop a letter would not be.

Modern typography in Firefox and Edge (I can't speak to Chrome as I don't have it installed) has actually done a great job of skipping underlines across descenders of all sorts (as proper underlining is supposed to do).

http://test.xn--ifa.test

Ah, funny. HN renders the ķ as punycode in urls. In the interest of sharing negative results, I leave this here.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#157
See: https://keepass.info/integrity.html (you may want to manually type it into the address bar...) and download their PGP keys. That way you can verify KeePass downloads using their signatures, which you can save and sign with your own key to really verify the paranoid way. If you ever land on a bad download site, you'll know something's up after you verify and it doesn't match.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#158

Earlier quoted context omitted.

To be even more frank, Google's search capabilities diminished around late 2000s early 2010s for me. I used to be able to write out anything verbatim and find it. Now I can't even get the double quotes trick to work properly. Google's strengths have been slowly crippled for years. Windows has a similar problem: marketing / ads is ruining an otherwise decent product.

I don't know if it still works, but plus triple double quotes used to work as a verbatim match. Iirc I picked it up here when they broke double quote search a while back (which they fixed at some point). But last I checked, +"""search phrase""" works

A tip I saw here a couple of weeks ago that restored some quality to searches was to, after searching, open the drop-down menu from “Tools”, select “all results” and then “verbatim”.

I do all of my searches in incognito so sadly I don’t know if the options is remembered or not.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#159
post #67

That's a neat trick. I can imagine getting caught by this if I saw the link in non-ad context. The attackers made a smart choice here. Usual Unicode substitutions are something I've learned to spot, because the substituted letters look off , even if a tiny bit. But here? I didn't notice the dot under "k" even with an arrow pointing at it, because to me, it looked like a tiny speck of dust or dirt on the monitor . $de…

I would have fallen like you. But because I use dark mode / a dark theme, this is displayed as a white dot on a black background and does not look like dust on my screen. I clearly see it. It is a white light-emitting pixel, not mistaken with a light-blocking speck of dust similar to a black pixel. I had never imagined dark mode as a security enhancement :)

I have a lamp above my monitor, so the dust on it is illuminated making the dark mode version less noticeable

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#160

Earlier quoted context omitted.

But we need these alphabets to allow people of various culture to be able to have url in their native language, and I'm not sure how browser could help disambiguate all the possible Unicode symbol, afaik while there are some font to make each symbol as distinct as possible (I think they are used in licence plate), none of them support all of Unicode. Also, while I can agree that url are "security-critical", the same…

> But we need these alphabets to allow people of various culture to be able to have url in their native language Those of them who want to accept the security risk that comes with that should have the option to turn it on, but it shouldn't be on by default for the rest of us.

sure, it can be done, but is not a solution to the problem as it will still leave a lot of people vulnerable. We, probably, need to rethink how we handle identity on the web but is a hard problem to solve
Post reply on HN