You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.
> You can't trust anybody except for open source repositories. Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.
Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
61–70 of 156 posts
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#62Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#63It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site.
It was scary, being a technical professional, and executing adware(malware?) installer while trying to install an open-source alternative to the most popular word-processor for a less-than-savvy family member.
It was the top result on Google at the time.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#64Earlier quoted context omitted.
You also need to verify that the binary you run is the same source code and be able to identify malware in source code that may be very well hidden. This isn't remotely practical and for even simple software. The only practical solution I can see is proper sandboxing of applications so you don't need to trust them in the first place.
That's probably where we're headed. Hypervisors running single-application kernels talking via message passing over some networking protocol to display servers and other virtualized hardware.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#65You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.
You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#66Earlier quoted context omitted.
This, right here, is why I have no qualms installing Adblock Edge and insisting that my parents (and anyone else who isn't very tech-savvy) do the same. It's not about not wanting to support independent bloggers. It's about making sure that unsuspecting users don't accidentally download malware when they're doing something mundane like downloading their web browser . In the age of the web, Adblock is the new anti-vir…
It's definitely the people who are least inclined to install an ad blocker that could use it most. On the other hand, it takes a long time, but they do learn to be more cynical about the Internet if they're exposed to its raw state.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#67Earlier quoted context omitted.
It's the 30 second youtube ads that finally got me to install adblock again after 3 years without. Also the javascript late load "oops click" tricks they're pulling to scam advertisers now (google search, youtube, bing search - all use late load javascript to get misclicks).
(google search, youtube, bing search - all use late load javascript to get misclicks). Of course, go back a year or so and everyone was screaming at ad providers for using blocking JavaScript.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#68Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#69Earlier quoted context omitted.
It's definitely the people who are least inclined to install an ad blocker that could use it most. On the other hand, it takes a long time, but they do learn to be more cynical about the Internet if they're exposed to its raw state.
It takes less than sixty seconds and requires nothing more than installing a browser extension.
Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
#70Earlier quoted context omitted.
> You can't trust anybody except for open source repositories. Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.
"You can't trust anybody outside of group X" does not imply "You can trust everybody inside of group X".