Live data from Hacker News

Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

techcrunch.com

11–20 of 156 posts

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#11
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

You can't trust open source repos either; you can only verify them.

And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies?

I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see crap you don't want being included as a means to funnel users into commercial channels.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#12
post #7
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

You can't trust anybody except for open source repositories. Like Sourceforge? http://blog.gluster.org/2013/08/how-far-the-once-mighty-sour...

Ah yes sourceforge. How far the mighty have fallen.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#14
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

> You can't trust anybody except for open source repositories. Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.

Well, that depends if you read that has a "repository of open source software" or a "repository that is open source". Sourceforge doesn't qualify as the latter.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#15
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

> You can't trust anybody except for open source repositories. Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.

He didn't say all open source is trustworthy, only that closed source is not. And Sourceforge, the repository itself is not open source.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#16
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…

Yes, that's an excellent point, I highly doubt anybody verifies what they install end-to-end. We all put a lot of trust in reputations and a couple of checksums.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#18

Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229

This, right here, is why I have no qualms installing Adblock Edge and insisting that my parents (and anyone else who isn't very tech-savvy) do the same.

It's not about not wanting to support independent bloggers. It's about making sure that unsuspecting users don't accidentally download malware when they're doing something mundane like downloading their web browser.

In the age of the web, Adblock is the new anti-virus.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#20

Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229

Absolutely. Though they're apparently changing their policy sometime this month to require ads advertising downloads be that apps' "primary download source".
Post reply on HN