Live data from Hacker News

Google will warn users when sites contain social engineering ads

techcrunch.com

81–90 of 92 posts

Re: Google will warn users when sites contain social engineering ads

#81
post #39
post #22

From the article: "Others pretend to be “Download” or “Play” buttons, as if clicking them would provide access to the video content or stream the user had wanted. " These are actively being served through Google Adsense, right now. Here's a few example, live sites, where I see "Download" buttons in an ad, in a context that would be confusing. http://www.getpaint.net/index.html http://downloads.tomsguide.com/PaintNET,…

> These are actively being served through Google Adsense, right now. There should be a button to report them. Please report them.

Sure! Would you mind fixing my revenue generator for free while you're at it?

Re: Google will warn users when sites contain social engineering ads

#83
post #46
post #39

Earlier quoted context omitted.

> These are actively being served through Google Adsense, right now. There should be a button to report them. Please report them.

Sure. But it's just funny that Google's approach is to mark these sites with big red warnings when Google itself is the source of the actual problem.

The ads are the actual problem. It's entirely possible this is a stopgap solution while they flag the client for manual auditing (or whatever)—manual auditing doesn't scale, so I suspect this is going to be more successful at preventing abuse in the short term.

Re: Google will warn users when sites contain social engineering ads

#84
post #63
post #60

Earlier quoted context omitted.

Yep. But spam detection and flagging is a hard problem. Google tries to detect and flag malicious creatives and stop them from serving, but it's not perfect. (I've touched that subsystem in a past life).

If their system finds a site displaying a misleading ad, and it's a google ad... Why is the action to flag and penalize the site? Why would the action not be "google stops showing that ad"?

Consider the likely interaction: (a) Spammer tries to figure out a twist on the ad that makes it through the inappropriate ad filters. They keep at this until they get an image or wording that works. (b) Slightly different system goes and tries to find malicious sites. It detects a site where the spammer managed (a) successfully, because it uses some different methods of identifying the bad stuff.

I don't find this kind of result surprising at all, particularly given how big Google is. If the site safety team is different from the don't-show-evil-ads team, it's almost an inevitable result, at least, in some point in the evolution of the system(s) and processes involved. It does point out some improvements that are needed.

Re: Google will warn users when sites contain social engineering ads

#86
post #83
post #46

Earlier quoted context omitted.

Sure. But it's just funny that Google's approach is to mark these sites with big red warnings when Google itself is the source of the actual problem.

The ads are the actual problem. It's entirely possible this is a stopgap solution while they flag the client for manual auditing (or whatever)—manual auditing doesn't scale, so I suspect this is going to be more successful at preventing abuse in the short term.

The problem is that Google has built most of it's products and business around the concept that they can automate away manual intervention. I think they are quickly starting to discover how faulty that concept is.

Some of the "AI" startups that mix automated intelligence with human fallback have probably got it much more right: Sometimes, you need people.

Re: Google will warn users when sites contain social engineering ads

#87
post #57

Earlier quoted context omitted.

I see fake download buttons, full screen ads, ads opening new windows/tabs, and ads opening Google play automatically from Adsense on a regular basis. I gave up reporting them years ago. I only see them when using chrome on Android these days. I generally use Firefox with an ad blocker on both windows and Android to combat it. I disable on some sites to support them, donate where I can, subscribe to YouTube red/Googl…

> ads opening Google play automatically from Adsense Are you sure they are ads, and not the site redirecting you based on your useragent? I've had some sites that have apps do that, but I've never had an add automatically direct me to the Play store before.

Yes. I ran into this problem with one of my websites. Turns out, a lot of websites in NL were having the same problem. I guess it's coming through one of the thousands of other advertising networks that are using the Adsense auction.

It's still happening now and then, so Google is fixing the problem in the wrong place.

Re: Google will warn users when sites contain social engineering ads

#88
post #69

Earlier quoted context omitted.

It's really weird that Google isn't dealing with them It's never "weird" for a company to choose not to attack its own revenue base.

Except Google knows that low-quality ads are driving people to ad-blockers

Exactly. Adsense had this problem in the Netherlands and it turned a lot of my visitors to ad blockers, even though advertising on my website was meant to be subtle.

Re: Google will warn users when sites contain social engineering ads

#89
post #35

It's worth remembering that this is the pain point Adsense and Adwords originally solved for by only allowing a title, 2 lines of text, and a URL. And they did it so well they disrupted/killed a mutli-billion dollar industry of online flash ads practically overnight. And then they become that problem by taking on flash ads a few years ago.

It's not a flash ad problem. I have seen auto-expanding ads on Android phones without flash. I'm guessing HTML5 banners with javascript in them, but it's hard to find out if it happens only once every couple of days and only on mobile, where you can't look at the source of all scripts once it happens.

Re: Google will warn users when sites contain social engineering ads

#90
post #84
post #63

Earlier quoted context omitted.

If their system finds a site displaying a misleading ad, and it's a google ad... Why is the action to flag and penalize the site? Why would the action not be "google stops showing that ad"?

Consider the likely interaction: (a) Spammer tries to figure out a twist on the ad that makes it through the inappropriate ad filters. They keep at this until they get an image or wording that works. (b) Slightly different system goes and tries to find malicious sites. It detects a site where the spammer managed (a) successfully, because it uses some different methods of identifying the bad stuff. I don't find this k…

I still don't get it. It's like the city randomly testing drinking fountains for lead, then issuing penalties to businesses, when the city municipal supply is the issue. Sure, shut down the water, but don't penalize victims.

That same scraper that's flagging the site can see the adsense block, see that image url for the offending image is "googlesyndication.com/some/image", etc. As far as I can tell, enough info to map directly back to the entity paying for the ad to show.

Post reply on HN