Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
21–30 of 156 posts
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#22Do these injectors work with https (ssl) sites? Where in the web page fetch/render process does this occur?
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#23You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.
> There are whole companies dedicated to this concept of piggy-backing junk. ... including a YC company called InstallMonetizer: https://news.ycombinator.com/item?id=5092711
Downvoters are invited to explain what's wrong with this comment, I see installmonetizer as one of the low points in the history of YC and watsi as the high point, possibly the high point in VC investing in the last decade or more.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#24Earlier quoted context omitted.
You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…
Yes, that's an excellent point, I highly doubt anybody verifies what they install end-to-end. We all put a lot of trust in reputations and a couple of checksums.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#25Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
Your rant is outdated. This is what "download firefox" looks like now: http://i.imgur.com/dG7wONC.png
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#26Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
Your rant is outdated. This is what "download firefox" looks like now: http://i.imgur.com/dG7wONC.png
It looks more like the OP's version to me, including 'softonic' as the third linked one. The top two are mozilla's (and I use an ad blocker so I don't see the ad).
On Chrome the first 6 links are mozilla's then the 'download sites' start.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#27Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#28Earlier quoted context omitted.
Your rant is outdated. This is what "download firefox" looks like now: http://i.imgur.com/dG7wONC.png
For you. It looks more like the OP's version to me, including 'softonic' as the third linked one. The top two are mozilla's (and I use an ad blocker so I don't see the ad). On Chrome the first 6 links are mozilla's then the 'download sites' start.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#29You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.
You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…
The only practical solution I can see is proper sandboxing of applications so you don't need to trust them in the first place.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#30 "It’s also worth noting that ad networks often also don’t know that their ads are being used in this way."
So, ad networks don't know about a source that hits them with the 5% of the total throughput of Google's sites? Yeah right.