Live data from Hacker News

Google will warn users when sites contain social engineering ads

techcrunch.com

31–40 of 92 posts

Re: Google will warn users when sites contain social engineering ads

#31
post #18
post #9

Earlier quoted context omitted.

IIRC, you have to auth to Tinder with a FB account. Not saying that nothing shady is happening, because I believe it is, but note that there are hundreds of ways for a company like FB to connect the dots. Post locations, event invitations, friends of friends, searches, ads/trackers, even your behavior/patterns on the site. The only real options, IMO, are to delete FB or accept the uphill battle.

IIRC, you have to auth to Tinder with a FB account. Wow. Just wow. That seems like such a horrifically bad idea. The worlds represented by FB and Tinder are almost diametrically opposed and I imagine that people who use both would never want any mixing. We are one FB bug away from some serious embarrassment.

Mind-boggling indeed. I guess you could do worse by using your FB auth on Ashley Madison, but not by much.

> We are one FB bug away from some serious embarrassment.

FB has been squirreling away phone and credit card numbers for awhile, along with DoBs, family members, birth cities, and pet names (i.e. "answers to common security challenge questions"). I wouldn't be surprised if a lot of this information has already been stolen, and is being used for things worth more than a bit of embarrassment.

Re: Google will warn users when sites contain social engineering ads

#33
post #21
post #15

Most people don't realize that Google's "Safe Browser" sends via Chrome & Firefox the URL of ever single URL you visit to Google; as far as I'm able to tell.

No, it doesn't. https://feeding.cloud.geek.nz/posts/how-safe-browsing-works-...

I've seen requests passed to Google, which is how I noticed it in the first place.

This source appears to show at least for downloads the browser is sending data to the API: "From Firefox 32 on, downloads are checked against the local list and a remote list if the local list does not return a hit."

SOURCE: http://www.ghacks.net/2014/07/23/prevent-firefox-sending-dow...

Re: Google will warn users when sites contain social engineering ads

#34
post #6

And Google's own Adwords ads looking more an more like organic search results and pushing the organic results further down the page isn't social engineering at all, right?

What's interesting is that this is moving more and more in the direction of the tried and trusted legacy yellow pages phonebook model. In that model you got a free listing in a category or two but had to pay to get either additional listings (in other categories) or for an advertisement (of various sizes) in order to get phone calls. The rationale (in addition to making money obviously) was that there had to be a way…

Google got the entire search business (including from those yellow pages) exactly because it wasn't a yellow pages company.

It showed people what they wanted to see, while other companies were focusing on what they were paid to show.

Re: Google will warn users when sites contain social engineering ads

#35
It's worth remembering that this is the pain point Adsense and Adwords originally solved for by only allowing a title, 2 lines of text, and a URL. And they did it so well they disrupted/killed a mutli-billion dollar industry of online flash ads practically overnight.

And then they become that problem by taking on flash ads a few years ago.

Re: Google will warn users when sites contain social engineering ads

#36
post #18
post #9

Earlier quoted context omitted.

IIRC, you have to auth to Tinder with a FB account. Not saying that nothing shady is happening, because I believe it is, but note that there are hundreds of ways for a company like FB to connect the dots. Post locations, event invitations, friends of friends, searches, ads/trackers, even your behavior/patterns on the site. The only real options, IMO, are to delete FB or accept the uphill battle.

IIRC, you have to auth to Tinder with a FB account. Wow. Just wow. That seems like such a horrifically bad idea. The worlds represented by FB and Tinder are almost diametrically opposed and I imagine that people who use both would never want any mixing. We are one FB bug away from some serious embarrassment.

Fun fact:

Tinder (as of my last login last year) displays an user liked pages along with their interests and then only their first name so that there is some "privacy".

I used to put all that data through Facebook Graph search and it would get me their full name and contact information, which in turn would lead me to their email address, which would lead me to their addresses or phone number.

Fun, fun time. It's a good thing that I am not the kind of person who would abuse of such things.

Re: Google will warn users when sites contain social engineering ads

#38
post #22

From the article: "Others pretend to be “Download” or “Play” buttons, as if clicking them would provide access to the video content or stream the user had wanted. " These are actively being served through Google Adsense, right now. Here's a few example, live sites, where I see "Download" buttons in an ad, in a context that would be confusing. http://www.getpaint.net/index.html http://downloads.tomsguide.com/PaintNET,…

Where do you see the button the www.getpaint.net? This is all I see and it looks legit [1]

[1] http://imgur.com/S8iV9cX

Re: Google will warn users when sites contain social engineering ads

#39
post #22

From the article: "Others pretend to be “Download” or “Play” buttons, as if clicking them would provide access to the video content or stream the user had wanted. " These are actively being served through Google Adsense, right now. Here's a few example, live sites, where I see "Download" buttons in an ad, in a context that would be confusing. http://www.getpaint.net/index.html http://downloads.tomsguide.com/PaintNET,…

> These are actively being served through Google Adsense, right now.

There should be a button to report them. Please report them.

Post reply on HN