Live data from Hacker News

Google Ad Disguising Itself as www.gimp.org

old.reddit.com

221–230 of 230 posts

Re: Google Ad Disguising Itself as www.gimp.org

#221
post #64

In this particular case, I suspect a trademark complaint against Google would make sense. Google misrepresented the ad as the product of the Gimp project, and were paid as a result. They usually use an "obeying the law would not scale" type argument in court, but that would clearly be bullshit in this case. They have a business relationship with the ad buyer, and should have verified their affiliation with gimp.org.…

> Also, a simple string match on the URL would expose the attempted fraud on Google's end. I feel like your general argument is proving too much: Google clearly indicated this is an Ad, and you couldn’t reasonably hold Google or any other publisher of ads responsible for every claim made in every ad. However, I agree that the domain part is troubling, and even seems like a potentially misleading representation by Goo…

> and you couldn’t reasonably hold Google or any other publisher of ads responsible for every claim made in every ad.

Why not?

Re: Google Ad Disguising Itself as www.gimp.org

#222

Earlier quoted context omitted.

Turns out uBlock Origin is the best anti-malware software there is. For some reason friends and family just don't seem to get malware anymore after I installed it on their browsers.

As soon as you realize how much of Google's bottom line is scam and malware distribution, it becomes really hard to view the company as anything but crooks. Google's other big line of business is shaking down businesses for cash by selling the top result for someone's own brand name unless they're paid for protection.

Oh it gets worse: Google has the gall position themselves on the authority on malware on the web [0], which they of course do with the same dedication to quality and support that they are known for in their other offerings. So they distribute malware themselves while defaming others with accusations of distributing malware.

[0] https://safebrowsing.google.com/

Re: Google Ad Disguising Itself as www.gimp.org

#223
post #152

Earlier quoted context omitted.

I am confident even Google fails to understand how much of their own business is scams and malware.

This is not merely rhetorical. Nvidia, for example, was caught hard during the first cryptocurrency bust... and the second.

Were they caught hard or did they have a relatively small oversupply after milking the demand for as long as possible?

Re: Google Ad Disguising Itself as www.gimp.org

#224

Earlier quoted context omitted.

It's not enough. I used to always skip the ad of the canonical site I was looking for to avoid incurring them a cost when I knew what I was searching for. But it's often no longer possible. The actual search reasult you want is the ad and the link is no longer duplicated in the organic search results. So you have to click the ad.

you also have the option to not use Google and use DuckDuckGo or Bing instead

> You also have the option to not use [ad-funded search engine #1] and use [ad-funded search engine #2] or [ad-funded search engine #3] instead.

Re: Google Ad Disguising Itself as www.gimp.org

#225
post #93
post #30

Earlier quoted context omitted.

Put the checksums in a separate system such as the DNS. Use DNSSEC on your domains. Manage your DNS system as an isolated system (don't mix your HTTP/Email/Other stuff with your DNS provider). Now, users may verify the downloads you provide at your website by getting checksums from the DNS. DANE may be of interest here as well: https://www.infoblox.com/dns-security-resource-center/dns-se...

How does DNSSEC help here at all? We're talking about the security of checksums of data on pages. DNSSEC only addresses the name lookup.

[deleted]

Re: Google Ad Disguising Itself as www.gimp.org

#226
post #185

Does anyone have a copy of the exe? Would love to poke it for research. Edit: Here be dragons. Found a source: https://old.reddit.com/r/GIMP/comments/ygbr4o/dangerous_goog...

If anyone is mildly curious but doesn't want the actual EXE, here's the VirusTotal analysis: https://www.virustotal.com/gui/file/acea176b67cb7c77dfd0780f...

That is a lot of red but don't be fooled - it doesn't actually say anything. Those are mostly generic machine-learning results which are prone to false positives which neither the AV vendors nor the operator of VirusTotal (surprise: it's Google again) care to do anything about.

Of course whoever went to the trouble to create the scam sites and ads probably also did modify the executables in some malicious way.

Re: Google Ad Disguising Itself as www.gimp.org

#227
post #179

This has been happening to a smaller project I am affiliated with for years . You can report it to Google - typically they ignore the reports. Occasionally they'll remove the offending ad, but they are just replaced with more ads the following day. I don't think it's preventable.

It is with a trademark lawsuit. You don't need to fight, you just need to file the lawsuit.

> a smaller project

Filing a lawsuit is not something within reach of most smaller projects.

Re: Google Ad Disguising Itself as www.gimp.org

#228

Scammers also create ads with fake support contact phone numbers for businesses. People call the scammers and they act like the company and run their scam. Google also allows many deceptive AdSense ads, I constantly have to block ads that run on my website that are nothing but a big "Download Now" button which lead to some malware.

Another variation is for scammers to update the number on google maps to their premium number. Calling it still forwards to the real call center. You can often spot people complaining about a free call to X org costing them hundreds of dollars in google reviews of the company.

Re: Google Ad Disguising Itself as www.gimp.org

#229
post #34

EDIT: There is definitely a mismatch between the display URL and the landing page URL. It's not clear to me how that can happen; for example https://www.youtube.com/watch?v=jx-gl6K2zQw shows that only the display path can be edited (not the domain), consistently with the wording on https://support.google.com/google-ads/answer/2616010 and https://support.google.com/google-ads/answer/2375287 . On the other hand, https:…

Update: It used to be possible to set the Display URL field to an arbitrary value, see for example https://www.youtube.com/watch?v=AQFR8eJlYxQ&t=100 (2015). Maybe it's still possible somehow.

Re: Google Ad Disguising Itself as www.gimp.org

#230

Earlier quoted context omitted.

> Also, a simple string match on the URL would expose the attempted fraud on Google's end. I feel like your general argument is proving too much: Google clearly indicated this is an Ad, and you couldn’t reasonably hold Google or any other publisher of ads responsible for every claim made in every ad. However, I agree that the domain part is troubling, and even seems like a potentially misleading representation by Goo…

> and you couldn’t reasonably hold Google or any other publisher of ads responsible for every claim made in every ad. Why not?

This simply ends advertising, and publishing generally. I’m not saying that gross negligence is okay, but I don’t think verifying every claim is a reasonable standard (it would be impossible).
Post reply on HN