Live data from Hacker News

Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

techcrunch.com

61–70 of 156 posts

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#61
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

> You can't trust anybody except for open source repositories. Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.

"You can't trust anybody outside of group X" does not imply "You can trust everybody inside of group X".

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#63
I googled for "Open Office download" on a family's computer and went with the first download -- download.com or cnet, I think.

It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site.

It was scary, being a technical professional, and executing adware(malware?) installer while trying to install an open-source alternative to the most popular word-processor for a less-than-savvy family member.

It was the top result on Google at the time.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#64

Earlier quoted context omitted.

You also need to verify that the binary you run is the same source code and be able to identify malware in source code that may be very well hidden. This isn't remotely practical and for even simple software. The only practical solution I can see is proper sandboxing of applications so you don't need to trust them in the first place.

That's probably where we're headed. Hypervisors running single-application kernels talking via message passing over some networking protocol to display servers and other virtualized hardware.

Am I the only one who thinks this reality sucks? Everything locked down, no way to tweak or repurpose any of your software. I know, there are bad actors out there, etc. but shouldn't there be a limit for destroying utility of things in the name of security?

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#65
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…

Actually, I do trust them and I do not verify them. So far I have had only good experiences.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#66

Earlier quoted context omitted.

This, right here, is why I have no qualms installing Adblock Edge and insisting that my parents (and anyone else who isn't very tech-savvy) do the same. It's not about not wanting to support independent bloggers. It's about making sure that unsuspecting users don't accidentally download malware when they're doing something mundane like downloading their web browser . In the age of the web, Adblock is the new anti-vir…

It's definitely the people who are least inclined to install an ad blocker that could use it most. On the other hand, it takes a long time, but they do learn to be more cynical about the Internet if they're exposed to its raw state.

It takes less than sixty seconds and requires nothing more than installing a browser extension.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#67
post #60
post #38

Earlier quoted context omitted.

It's the 30 second youtube ads that finally got me to install adblock again after 3 years without. Also the javascript late load "oops click" tricks they're pulling to scam advertisers now (google search, youtube, bing search - all use late load javascript to get misclicks).

(google search, youtube, bing search - all use late load javascript to get misclicks). Of course, go back a year or so and everyone was screaming at ad providers for using blocking JavaScript.

And what is stopping them from having the placeholders a specific size, instead of expanding them when the javascript finally loads/starts up? If that sort of thing was unfeasible to do then fine, I'll give you your point. But they have no excuse. So they're either just too lazy to do it properly (and enjoy the nice mis-clicks on ads) or they just like the mis-clicks on ads and did it purposefully.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#68

Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229

Adwords has had a policy against ads for malware for many years now. (I helped develop an earlier version of that policy.) But it's not entirely effective. Unreviewed ads, poorly reviewed ads, and ads for sites that just barely skirt the boundaries of being malware are all regular problems. For some historical perspective, here's a 2007 article: http://www.infoworld.com/article/2663560/application-develop...

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#69

Earlier quoted context omitted.

It's definitely the people who are least inclined to install an ad blocker that could use it most. On the other hand, it takes a long time, but they do learn to be more cynical about the Internet if they're exposed to its raw state.

It takes less than sixty seconds and requires nothing more than installing a browser extension.

The people who most need to do this don't know what a "browser" is, much less an "extension".

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#70

Earlier quoted context omitted.

> You can't trust anybody except for open source repositories. Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.

"You can't trust anybody outside of group X" does not imply "You can trust everybody inside of group X".

True, but then that is not what he said, you conveniently reworded it ;)
Post reply on HN