Google and Paint.NET need to stop misleading users (2013)
jasonlefkowitz.net
jasonlefkowitz.net
Where is the 3-strikes policy in the ad space? Google is so eager to punish its Youtube streamers for running questionably offensive content, and yet it continues to let advertising scum like this run rampant across its ecosystem.
Youtube streamers are not cients, they are content creators. Just like newspaper sites, the average email user, or, in this case, paint.net.
Google can afford to treat content creators poorly, but they won't slight real clients : people actually paying them money. No matter how scummy these are.
1. The misleading download button Google ad.
2. After clicking the ad they ask the user to install their extension from the Google Chrome Web Store [1].
3. After installation, the extension replaces new tab page with their own which includes a "custom" search engine "Enhanced by Google" [2].
4. PROFIT!!!? They make money when the user clicks a Google ad in their search results on that new tab page.
I'm not sure how it's worth it for Google because with the extension installed they are sharing part of their search results revenue with the owner of the extension compared to the users directly using the Google search when there is no extension to "hijack" it.
From the users perspective: Sure, it's not a ransomware level malware but it's still a PUP and the users are annoyed that they were "tricked" into installing it and their new tab page has been changed, as it can be seen in almost all of the reviews for their chrome extension, and almost all the first page google result for "EasyPDFCombine" is about how to remove this "virus".
It's the same decade old trick from the same company: Mindspark aka MyWebSearch aka Ask Toolbar and many more names.
[1] https://chrome.google.com/webstore/detail/easypdfcombine/kpo...
And my guess is youtubers make up such a small slice of revenue that the threat of lawsuits outweighs the convenience of the customer.
The incentives seem perfectly aligned... the advertiser doubtlessly doesn't care about whether it's a scrupulous ad or not. Paint.NET authors make money, and Google makes money.
Heck, Google likes to brag about how Chromebooks don't get viruses. Distributing viruses for Windows PCs only helps their bottom line. (You'll also notice that Windows support-related search queries have malicious ads, and no ads display at all for Chromebook or Google support-related search queries.)
1. A not-my-problem mentality at Google
2. Google is trying to replace human intelligence with AI pseudo-intelligence which has turned out to be really really easy to fool
I believe it's actually a combination of the two and it scares the crap out of me thinking these guys want to create self driving (and flying!) cars.
If the damage it causes them, both in profit and image, is not very large then it might very well not be worth it to risk setting a precedent than Google is responsible for policing their ads. It is exactly the scenario they were caught in with YouTube, and becoming the police there didn't help them at all compared to the previous status quo.
Of course that's the good scenario, the bad one would be that Google, being of a size and importance that can be called a monopoly in the Internet ad space, would be violating these "fraudsters" rights since technically what they do may not be breaking any laws, which would lead to this becoming a precedent and all the others who currently try to keep themselves mostly clean in their ads would be vindicated to go evil too.
I'm not saying these are the real reasons, but again if the damage and risk they represent is insignificantly small relative to the whole, why would Google risk opening that can of worms.
Screenshot taken 2 minutes ago: http://i.imgur.com/FOcB46m.png
Technically, this latest initiative actually makes sense.
But, manufacturers still want to sell new devices, and carriers want to move them, with mark-up. And there's no dis-incentive to this "abandon and re-sell" incentive.
And mostly, Google doesn't stick with things, any more.
Color me skeptical. Time to go and "Download" me a new phone...
----
P.S. I don't begrudge the Paint.NET developers recompense for their work. Although, as I recall, it originally came out of the University of Washington, presumably with some funding behind it (many years ago, and perhaps no more).
I've used it, upon occasion, and it's a very good substitute for everyday "photo-shopping", as it were.
But the ads, as described/demonstrated, sure seem to be at odds with the old "do no evil" or whatever it was. Loading grandma up ('Download! HERE!') with 5 "toolbars" and nag-ware? Bad Google.
> choco install paint.net
Unfortunately, while that allows me to never see fake download-button ads when pulling down software for my machine, one place it's still a nightmare in is the world of getting minecraft mods installed on a kid's computer. Picking out the real download link from among all the fake ads is sometimes a real challenge.The stars are aligned against you on this:
1) impatient kid who wants his mod working,
2) unfamiliar territory for you,
3) the timing for these things is ALWAYS wrong, you've probably got pressing household matters to attend to or another kid wanting your attention,
4) a couple of more points I forgot.
Worse, they've got fairly effective adblock detection.
those that can't, can be usually found on this site with their official download site linked [2]
[1] https://minecraft.curseforge.com/ [2] https://bot.notenoughmods.com/
Does that launcher ask for the username and password?
That's a pretty lousy message to be teaching mostly children about password security.
Google knows the ad link. Google can crawl the target page / file. If it's an installer, Google can run it in a VM and note what ends up being installed.
If you can't pull a clear "this is crapware" signal out of that, then their ML is a lot less advanced than it seems.
And if they can, then just automatically put a stronger visual border around it with something like "This is an advertisement" in bold. Then let advertisers sort it out. Google penalizes SEO they disagree with all the time, and people stop doing it because they don't want to take the hit.
And I'm pretty sure it is (image recognition) and they don't... so... advertising buys trump "don't be evil."
Google's CEO declared it's "AI first" and they developed TensorFlow. If they wanted to, they could have easily prevented those ads from entering their network.
But yes, if they wanted to, they can divert their more advanced ML teams to tackle specific issues like this first and get it done. I really doubt this is a high priority issue for them.
Google has machine learning technology that automatically reads street address numbers on houses, regardless of angle, color, size, focus, or typeface.
Using the same type of algorithm to answer "does this ad have anything that looks like a button in it?" is relatively simple by at least two orders of magnitude.
So rather than it being "easy" in some absolute sense, what's meant here is that it is easy compared to similar tasks that we already know Google does routinely and has largely automated.
- Is this a download page?
- Does this ad contain a button-like image with the word "Download" on it?
Presumably the people creating these ads are specifically targeting pages with the word "download" in to create this confusion, it doesn't seem like rocket science for Google to apply the exact same rules.
And changing the images to evade the algorithm would also directly affect how likely they are to trick people, so it's win/win?
Most non developers would be served perfectly fine with a locked down OS.
You can even search for Windows drivers and instead of getting drivers from the manufacturer, you end up with malware from a third party site.
What do most non devs gain by an "open system" that a well functioning App Store that forces apps to be sandboxed where the user has to grant permissions individually to apps?
It's like adding regexp to have one more problem.
Compare that to distributing apps on the internet where you have to trust each software provider with your credit card credentials and even if you do trust the vendor, there is a certain amount of friction just entering your payment information all over the internet.
I much prefer handling all of my subscriptions through iTunes even for services that use other places like Hulu, Netflix, and PluralSight.
Did you ever try to distribute a mobile J2ME app on mobile before the Apple and Google app stores? I know indie PC developers love Steam.
I'm very hestitant to download random software on Windows because of crapware/malware. I'll download iOS apps with abandon from the shadiest developers because I know they can't really do that much harm.
However I believe good package formats and OS-level checks can get us there without compromising my private informations to a third party in the process.
The "third party" I'm more concerned about is the random app developer. iOS prevents random developers from having access to files, the camera, the microphone, my music library, my location, contacts, my browsing history,using cellular data, draining my battery by processing in the background, etc. without me giving explicit permission.
Even ad blockers on iOS don't have access to my browsing history and you can disable third party keyboards from having network access.
Furthermore, you may not allow such an app to access your privacy, but Apple itself is above the permission and will happily gather all kinds of data about you, with your implied consent (after all you DID buy a tapped piece of hardware). That's Siri and every remote Apple service for starters, and god knows what else in their closed source shiny software.
The random developer is the least of my concerns.
Now a truly open model where people can enforce torch apps cannot ask for ridiculous permissions, that's better. Enforced by enough parties that nobody can pull the blanket.
Companies should be held responsible for the ads they distribute, it's the only way to make them care enough to vet the ads they push.
There doesn't seem to be an option for "this ad is a huge DOWNLOAD link directly above the actual download link on a page that offers to help me download software." I did try filling out the form at https://support.google.com/adsense/troubleshooter/1190500 with this info, though. There was no way to indicate with a screenshot in that form exactly what the bad ad was.
1) Not interested in this ad 2) Seen this ad multiple times 3) Ad is inappropriate 4) Ad covered content
I chose 3 for all of them, but I'd argue that 4 would also fit somewhat.
A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware.
So I asked them to be careful to ensure the download site is correct and left them to it.
I came back to find they had downloaded some other crapware.
I checked the search results. The ENTIRE first one and a half page of results were advertisements for versions of crapware which may or may not have been Chromium or Chrome lookalikes with lots of malware.
Heck, you could probably even automate that process with Google's technology. If OCR technology can identify captchas, it can probably identify button shapes in images or text that looks like program information.
Nevermind, the right thing to do would be to ban these kinds of ads outright, but we can't count on them to do that now, can we?
I guess Google is too busy dealing with "fake news" and paint.net can't give up that sweet ad money.
And I just checked myself and confirmed the continuing existence of very similar ads.
So it is still relevant. But how these ads are able to pass through AdWords review.
This is a little shady, but all the units are clearly labeled as ads. I have a hard time getting as worked up over this as the author does. Paint.NET is a free product, what do you expect?
If so, I disagree. Those icons are not visible enough, and are hard for many users to click without accidentally clicking the ad instead.
When I go to the site the ads aren't even "download" style ones like those in the screenshots, just normal banner ads.
All well and good until they unwittingly become part of a botnet and start attacking the rest of us...