Live data from Hacker News

Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

techcrunch.com

81–90 of 156 posts

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#81

I googled for "Open Office download" on a family's computer and went with the first download -- download.com or cnet, I think. It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site. It was scary, being a technical professional,…

CNET.com and Download.com are both part of CBS Interactive (CNET Networks was a publicly traded company and was bought by CBS in 2008).

I worked at CBS Interactive when the Download.com installer/adware controversy erupted: http://insecure.org/news/download-com-fiasco.html

As you might expect, it was controversial inside the company as well. I guess things haven't changed after I left.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#82
post #39

Browsing sites on my Android phone is the worst. I frequently get re-directed right off the page to either Google Play to install some dodgy app, or some site that tries to download the APK directly.

This happens a lot on iOS too - even some respectable sites have ads that open the App Store without any user intervention. I'm not sure why Apple allows this.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#83

Do these injectors work with https (ssl) sites? Where in the web page fetch/render process does this occur?

Not unless they do something incredibly stupid like install a certificate authority and hijack every SSL session. [1]

[1]: http://en.wikipedia.org/wiki/Superfish#Lenovo_security_incid...

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#84
post #7
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

You can't trust anybody except for open source repositories. Like Sourceforge? http://blog.gluster.org/2013/08/how-far-the-once-mighty-sour...

I read the gp comment as something like a distribution repository. Apt-get or perhaps like brew on Mac OS and so on. Checksummed binaries and a single source for each machine.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#85
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

>You can't trust anybody except for open source repositories.

That is patently false.

Established profitable companies in a market with multiple competitors usually do not fuck with their customers, if they charge up-front for their product/service.

On the other hand, companies that give away stuff for "free" have to find unique ways to pay the bills (be it hosting fees, or hardware costs, or developer time, etc). In recent years the most common way is to create some way to essentially trick people into clicking ads.

Open Source repositories have not found any long term sustainable method to get compensated for their hosting fees or hardware costs. At the moment, they are run on donations - mostly from commercial vendors, universities and the like. At some point in the future, lets say if 500 million desktop users all start using those repositories, there will come a time when that cost is going to stick out on a balance sheet. I hope that they figure out a way to get paid for their efforts by then.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#86

I googled for "Open Office download" on a family's computer and went with the first download -- download.com or cnet, I think. It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site. It was scary, being a technical professional,…

I go to Wikipedia nowadays to find a project's official URL. Not foolproof but better than Google.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#87
Ad injection can cause other problems, too, especially when combined with people whose understanding of technology is lacking.

A few years back I got a job to do a wordpress site for a client. However, I wasn't dealing directly with the client, I signed on through a friend who was a fellow staff member of a forum I frequented. He agreed to create their site despite the fact that he was almost entirely technologically illiterate. His skills were at the 'barely read email' and 'be puzzled by OSX window decorations' sort of level. So, I agreed to do the job.

After working on the site for a couple of weeks, one day I received a call from him. He was quite upset as he was seeing porn ads and random nonsense characters on the blog. I investigated and found no trace of ads or foreign code, using several devices and several separate Internet connections. However he could see the ads on multiple devices in his house. Attempts to get him to try another Internet connection like his phone service were unsuccessful. I was pretty sure there was nothing wrong with the site, which was hosted on my VPS along with a couple of other sites that had no sign of issues. However he grew progressively more worried that the client would see these ads on the page, which was live for some reason. I even engaged the help of 20 or so people from the forum to check and they all agreed that no porn ads were visible to them. However this just upset my friend more as he felt embarrassed, but still convinced there was a problem. I suspected he had a virus on the systems at his house (all Apple...) or his router. It ended up with me being banned from his forum and being forced to quit the job... Before finally someone reset his router and the porn ads disappeared.

So, content appearing from unknown sources has definitely caused me problems in the past.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#88

Well maybe they should stop allowing download sites that offer ad infected downloads to buy the top spots on the google search results page? https://i.imgur.com/Ote9c2k.png Adwords is probably one of the main infection vectors for malware these days. Previous rant: https://news.ycombinator.com/item?id=8879229

Adwords has had a policy against ads for malware for many years now. (I helped develop an earlier version of that policy.) But it's not entirely effective. Unreviewed ads, poorly reviewed ads, and ads for sites that just barely skirt the boundaries of being malware are all regular problems. For some historical perspective, here's a 2007 article: http://www.infoworld.com/article/2663560/application-develop...

As recently as a year ago, even "google chrome" turned up an adware ad as the first "result" in a Google search:

https://twitter.com/mbrubeck/status/459715935272566784

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#89
post #67
post #60

Earlier quoted context omitted.

(google search, youtube, bing search - all use late load javascript to get misclicks). Of course, go back a year or so and everyone was screaming at ad providers for using blocking JavaScript.

And what is stopping them from having the placeholders a specific size, instead of expanding them when the javascript finally loads/starts up? If that sort of thing was unfeasible to do then fine, I'll give you your point. But they have no excuse. So they're either just too lazy to do it properly (and enjoy the nice mis-clicks on ads) or they just like the mis-clicks on ads and did it purposefully.

I'm not familiar with the systems, but I imagine that not knowing the eventual size of the ad would prohibit that. Or the fact that you'd have to have the user insert some HTML alongside your currently very simple entry.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#90
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

You can't trust open source repos either; you can only verify them. And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies? I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see cra…

I haven't done this in most cases, but for some systems this is a practical action to take (embedded system, minimal software, security sensitive). The reality is any modern OS + apps for "basic" functions is far too complex and has too many SLOC in too many disparate languages for any one person to be able to reliably verify it all. Knowing that the very simple basic functionality of all the code you plan to run on an embedded device is secure though is still an achievable objective.
Post reply on HN