Live data from Hacker News

Google-hosted malvertising leads to fake Keepass site that looks genuine

arstechnica.com

31–40 of 197 posts

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#31
post #11
post #4

Can you prosecute Google for spreading viruses and helping criminals?

That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…

The malicious website is published on google dot com. It's not unreasonable to require that a website doesn't publish obvious scams. Of course, "obvious" is hard to define precisely.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#32

I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.

When I saw the screenshot the only thing I thought was "damn I should clean that dirt off my monitor". If I didn't have uBo I'd 100% fall for that.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#33

Punycode is of questionable use anyway. Granted I'm mostly looking into this from a primary latin alphabet perspective, but for the various non-latin alphabet sites I've browsed over the past decade all of them just stuck to regular ASCII domains. (Heck you see this even with usernames on websites that allowed Unicode to be used; most non-latin alphabet users will still stick to the Latin alphabet for usernames.) The…

I fully support national languages, ASCII is not suitable for a huge part of mankind. But it's obvious that Unicode as it is is not suitable for security critical applications. Myself, speaking several European languages, I need less than 10 Unicode characters (each of them actually still 8 bit ISO 8859-15 codes). Well, need and need, most of the sites don't even register a punycode domain, but some uglified ASCII version of their name.

As a practical step browsers should ask the user whether they want to allow URLs in a certain language the first time a non-ASCII character is entered. With just one or a couple of languages allowed, the attack surface would be drastically reduced for most users.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#34
While there's no foolproof way to detect scams like these, there are some proactive steps we can take:

1. Always type in URLs manually when downloading critical software to bypass the potential risks from ads.

2. Make use of browser plugins that identify malicious websites or unverified SSL/TLS certificates.

3. Before making any downloads, inspect the TLS certificate of the website by clicking on the padlock icon next to the URL bar. Look for inconsistencies like a different company name or issue date.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#35
post #10

1) Use an ad blocker, always. 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this? 3) IDN shouldn't be enabled by default.

> 2) In advertisements, Google shouldn't allow the advertiser to modify the domain that is displayed. Really, why do they even do this?

Because advertisers usually want to send links to a tracker site of their own first so that they can verify if their numbers match up with what Google reports.

No one trusts anyone in the advertising space, and for good reasons. Advertising has always been a space filled to the brim with crooks and fraudsters.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#36
post #11
post #4

Can you prosecute Google for spreading viruses and helping criminals?

That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world. Effectively you want Google to be the law enforcement corporation and not your government thus massively expanding…

> That would make Google responsible for the work of police - you're saying that Google should be actively trying to identify "criminals" (by whatever definitnion of whatever state in US or even their legal departmeny - quotes deliberate) and prevent them from being able to do business in modern web world.

Google is a company that nets 60 billion $ a year in profits. They can afford hiring a few thousand people to manually vet ads before they go out, and they should.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#38

I consider myself a security-conscious person and I'm not sure I would've spotted this. Another reason to use uBo with zero regrets.

What is uBo?

Haven't seen it mentioned yet: uBlock Origin.

Re: Google-hosted malvertising leads to fake Keepass site that looks genuine

#40

Punycode is of questionable use anyway. Granted I'm mostly looking into this from a primary latin alphabet perspective, but for the various non-latin alphabet sites I've browsed over the past decade all of them just stuck to regular ASCII domains. (Heck you see this even with usernames on websites that allowed Unicode to be used; most non-latin alphabet users will still stick to the Latin alphabet for usernames.) The…

I live in a non-english speaking country, technically we do have non-ascii domains, but they're very rare, absolute majority of websites use latin letters.

Though I think there's nothing wrong with punycode with dedicated first-level domains. like кремль.рф (does not exist, but I'm too lazy to find one).

Post reply on HN