Live data from Hacker News

Google will warn users when sites contain social engineering ads

techcrunch.com

21–30 of 92 posts

Re: Google will warn users when sites contain social engineering ads

#21
post #15

Most people don't realize that Google's "Safe Browser" sends via Chrome & Firefox the URL of ever single URL you visit to Google; as far as I'm able to tell.

No, it doesn't. https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...

Re: Google will warn users when sites contain social engineering ads

#22
From the article: "Others pretend to be “Download” or “Play” buttons, as if clicking them would provide access to the video content or stream the user had wanted. "

These are actively being served through Google Adsense, right now.

Here's a few example, live sites, where I see "Download" buttons in an ad, in a context that would be confusing.

http://www.getpaint.net/index.html

http://downloads.tomsguide.com/PaintNET,0301-4883.html

http://filehippo.com/download_paint.net/

Re: Google will warn users when sites contain social engineering ads

#23
post #9

From Wikipedia[0]: > Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional "con" in that it is often one of many steps in a more complex fraud scheme. Honest question: When you tak…

IIRC, you have to auth to Tinder with a FB account. Not saying that nothing shady is happening, because I believe it is, but note that there are hundreds of ways for a company like FB to connect the dots. Post locations, event invitations, friends of friends, searches, ads/trackers, even your behavior/patterns on the site. The only real options, IMO, are to delete FB or accept the uphill battle.

This is correct, however, the exchange of phone number has to be parsed through the text exchanges on the app (regex dashes and 10-11 digits....simple yet creepy), validated with an actual person (no fake numbers!), and Facebook needs permission from tinder to process such information.

As developers this isn't hard to implement, but it is a bit extreme.

There is also the question of business contacts, whom I have only had connection with via Voice Call and Text message (no external app and permissions given), showing up in my feed. Of course, this could be permission given on THEIR side that is reciprocating on my end, but again, this implementation is also extreme (ly possible).

Re: Google will warn users when sites contain social engineering ads

#24
post #14
post #2

The only time I have been bothered with these kind of ads, is when DoubleClick serves me those on my Android. DoubleClick certainly is not the worst offender of this, but they are the biggest player. Is Google going to block/penalize the sites of their own customers? That would feel weird. Is Google going to block/penalize the sites of their competitors? That would also feel weird.

Usually the burden to approve an Ad is on the network that hosts/serve the Ad. Google does require approval for all Ads you want to serve to Google Search or Google Display Network, as well as Ads you want to sell through Doubleclick Ad Exchange. Doubleclick is actually a suite of different applications. I suppose you mean DFP (Doubleclick for Publishers). This is a google product but it doesn't necessarily display a…

Google partners with these other networks (like Advertising.com and AppNexus). In the end it is their DFP .js code that invokes malicious ads/redirects. I blame the last in the chain, and I do not think that is unfair.

Not all ads on adSense are reviewed. Or, if they are, the reviewers are doing a poor job. Locally, and on mobile devices, I get adSense ads like: "Your device has a virus. Click here to download our anti-virus software for 4.99$." Then the page shows the "404 broken robot"-graphic (it is an ad on adSense network, which spoofs Google, and scares you into downloading a paid, probably worthless, virus-scanner).

I've reported numerous ads to Google over the years: Some competitors who were not playing by the rules, but also redirects to porn websites and the (locally) infamous: Your Whatsapp has expired! Enter your phone number, so we can mine that, and charge you weekly for a fake app.

> I suppose they might block sites that use DFP to serve ads from other networks they can't vet and don't go through good review and were detected to contain bad Ads.

Likely, but this seems weird (fix/penalize DFP partner networks first, don't penalize your users for using your own product). Also from a competitor sense: I am all for protection of users (use an adblocker!), but it does not feel right that a company with the resources of Google, finally manages to rid their own network of these malicious ads (let's say for sake of argument they have), then immediately puts the ban-hammer on their less resourceful competitor networks. Perhaps that is a side-effect of owning both analytics, the ad networks, and the browser people use to view those ads.

Re: Google will warn users when sites contain social engineering ads

#25
post #18
post #9

Earlier quoted context omitted.

IIRC, you have to auth to Tinder with a FB account. Not saying that nothing shady is happening, because I believe it is, but note that there are hundreds of ways for a company like FB to connect the dots. Post locations, event invitations, friends of friends, searches, ads/trackers, even your behavior/patterns on the site. The only real options, IMO, are to delete FB or accept the uphill battle.

IIRC, you have to auth to Tinder with a FB account. Wow. Just wow. That seems like such a horrifically bad idea. The worlds represented by FB and Tinder are almost diametrically opposed and I imagine that people who use both would never want any mixing. We are one FB bug away from some serious embarrassment.

I believe part of what I'm seeing is a facebook bug. Namely, they are supposed to see me show up on Facebook, having given FB permission to peruse their contacts, but I'm not supposed to see them, if that makes any sense (permissions granted, and what not).

Re: Google will warn users when sites contain social engineering ads

#26

What about on their own sites? Like YouTube? Yesterday I just saw a banner ad on a YouTube music video - from Google AdWords - that was alerting me I may need some "Drivers" for my machine and I should get them from some suspicious company called TechSoft or RealSoft or something like that. It was the "dying car alarm drops a sick beat" extended remix if that's of any interest. I did take a screenshot but don't have…

I regularly see ads during Youtube videos for what I would assume to be malware -- "driver updates" and the ilk. It would be nice if Google would get their own house in order.

Re: Google will warn users when sites contain social engineering ads

#27

What about on their own sites? Like YouTube? Yesterday I just saw a banner ad on a YouTube music video - from Google AdWords - that was alerting me I may need some "Drivers" for my machine and I should get them from some suspicious company called TechSoft or RealSoft or something like that. It was the "dying car alarm drops a sick beat" extended remix if that's of any interest. I did take a screenshot but don't have…

I regularly see ads during Youtube videos for what I would assume to be malware -- "driver updates" and the ilk. It would be nice if Google would get their own house in order.

Why should Google get it's house in order? The best part about being a monopoly is everyone has to deal with you whether they like it or not. ;)

And they can punish other people's websites for having malicious ads, including Google-sourced malicious ads, because that totally solves the problem!

This comment was thick with sarcasm.

Re: Google will warn users when sites contain social engineering ads

#29
Well I block ads on my desktop so I'm not really seeing fake "download" buttons that often. On the other end what really bothers me on mobile (using the latest chrome) is ads automatically redirecting me to another site, happens quite regularly when I browse Google news. I don't really know if those ads use an exploit of some sort or if they consider I've clicked the ad when I only tried scrolling the page with my finger but that should clearly be checked. And it happens on well known newspapers websites, not that I was browsing some obscure shady part of the web...

Re: Google will warn users when sites contain social engineering ads

#30
post #16

>[Update: Google published this news today on its corporate blog, but this was previously announced earlier this year. We’ve asked Google to clarify why it was republished, if that was in error, or if it represents any changes since the first announcement.] This was previously discussed at https://news.ycombinator.com/item?id=11032270 .

The actual news is this: https://security.googleblog.com/2016/04/improvements-to-safe...

Google's expanded it from just protecting users to also notify the network admin via https://security.googleblog.com/2010/09/safe-browsing-alerts...

(The "notify the AS owner" service existed before, but now it also notifies about social engineering content.)

[/end doing job of reporter who should have done it themselves.]

Post reply on HN