Live data from Hacker News

Google serving sponsored link to Homebrew site clone with malware

twitter.com

11–20 of 31 posts

Re: Google serving sponsored link to Homebrew site clone with malware

#11
post #9

How is it possible that in this screenshot, the URL shown on the sponsored result / ad is " https://www.brew.sh "? Can a Google search ad display a different value there than the actual origin of the page?

Yes! This is working as intended, because it earns more money.

Re: Google serving sponsored link to Homebrew site clone with malware

#12

Earlier quoted context omitted.

Apparently, it was collecting passwords from victim machines. So, step one would be to remove everything the script put onto your machine. Step two would be to change your passwords.

Step 3 should probably be reinstalling the OS, and restoring data from backup (ideally from before the malicious version was installed).

And install ublock origin going forward.

Re: Google serving sponsored link to Homebrew site clone with malware

#13
post #9

How is it possible that in this screenshot, the URL shown on the sponsored result / ad is " https://www.brew.sh "? Can a Google search ad display a different value there than the actual origin of the page?

It's explained in replies to the tweet, Google apparently lets you specify a "display URL", that's updated immediately but only verified within 24h for trusted accounts. (https://eligrey.com/blog/link-fraud/)

Re: Google serving sponsored link to Homebrew site clone with malware

#14
I don't get what non-malicious reason there would be for not automatically verifying domain ownership of display urls as an advertising network. The advertiser is highly likely to already have a Search Console account in which they'd have had to verify it, and URL verification is easily done by all kinds of systems via meta tags, CNAME or TXT entries, etc. Why not for ads?

Re: Google serving sponsored link to Homebrew site clone with malware

#16
post #13
post #9

How is it possible that in this screenshot, the URL shown on the sponsored result / ad is " https://www.brew.sh "? Can a Google search ad display a different value there than the actual origin of the page?

It's explained in replies to the tweet, Google apparently lets you specify a "display URL", that's updated immediately but only verified within 24h for trusted accounts. ( https://eligrey.com/blog/link-fraud/ )

Ah thank you! Replies are not visible without a Twitter account so I didn't see that.

Seems like an absolutely terrible idea.

Re: Google serving sponsored link to Homebrew site clone with malware

#17
post #9

How is it possible that in this screenshot, the URL shown on the sponsored result / ad is " https://www.brew.sh "? Can a Google search ad display a different value there than the actual origin of the page?

I think this came up before in the context of scammy Google ads. Apparently you can set any vanity URL you like to be displayed, which indeed seems like the perfect invitation for scammers if it works without any restrictions.

Presumably it's so you see the nice destination URL, and not the link tracking URL.

Re: Google serving sponsored link to Homebrew site clone with malware

#18

Earlier quoted context omitted.

I think this came up before in the context of scammy Google ads. Apparently you can set any vanity URL you like to be displayed, which indeed seems like the perfect invitation for scammers if it works without any restrictions.

Presumably it's so you see the nice destination URL, and not the link tracking URL.

The intent is clear, yes. But given how well-known this problem is by now, I would expect a company of the size of Google to have a practical solution to combat this sort of scam, e.g. requiring that the vanity URL points to page containing a specific advertiser ID in the HTML source, or that the canonical URL of the URL with tracking parameters points to the vanity URL, etc...

There's so many solutions to this problem that allow vanity URLs to continue to work. Google just doesn't care.

Re: Google serving sponsored link to Homebrew site clone with malware

#19
post #14

I don't get what non-malicious reason there would be for not automatically verifying domain ownership of display urls as an advertising network. The advertiser is highly likely to already have a Search Console account in which they'd have had to verify it, and URL verification is easily done by all kinds of systems via meta tags, CNAME or TXT entries, etc. Why not for ads?

Well… marketing and web development are often at war with one another inside individual organizations.

And the person running the ads almost never has domain-verification authority.

So Google doesn’t want to introduce a major barrier to accept money. I think that makes sense without being malicious.

Re: Google serving sponsored link to Homebrew site clone with malware

#20
Ugh, I've seen this before with Todoist. I got as far as downloading the app package before realizing it was spelt incorrectly, and so was the domain. (Though the domain was correct in the ad, and the ad was identical to the actual search result below it.)

It has to be deliberate by Google at this point.

Post reply on HN