Bing has been serving up malicious Google Chrome ads for months
forbes.com
forbes.com
https://news.ycombinator.com/item?id=14338174
> The Bing search engine is about as bad. A close friend used IE to get Google Chrome. They clicked the first result and luckily I was able to stop them before starting the install on some crapware.
So I asked them to be careful to ensure the download site is correct and left them to it.
I came back to find they had downloaded some other crapware.
I checked the search results. The ENTIRE first one and a half page of results were advertisements for versions of crapware which may or may not have been Chromium or Chrome lookalikes with lots of malware.
(I know of thousands (if not infinitely) more complex ones so please don‘t start on them)
It must be as simple as „google that and press install“. Everything requiring an install has a huge negative attached, but the worst is if they google for the tool you use to then type in ... . Maybe make the tool the start page and train them to press the startpage-button first every time you tell them to „google sth“.
You‘ll miss a business model though incase you don‘t want to show links to crapware like certain others.
Or maybe just make DuckDuckGo the startpage?
- ad by Google for Google Chrome - ad by Mozilla for Firefox - 2 result on Google's site - one download site (didn't check if it's crapware) - two wikipedia links - the same ads at the tops
1. Search for the name of the software on Google [2].
2. Open link to software in separate tab.
3. Open Wikipedia link (usually on the same SERP) for software in separate tab.
4. Compare domain name from direct link with the domain name from the Wikipedia article.
5. Open another tab and type domain name manually.
6. Find download link manually on domain[3].
I do this since a family member got burned badly by a malicious OpenOffice install many years ago.
[1] Sometimes I do it on Mac too, because the App Store has it's own issues (e.g. upgrades are often cheaper if you buy software directly). On any other system I use the package manager. All of this makes the effort bearable because I only have to do it rarely.
[2] I'm usually on DuckDuckGo, but for this I always used Google. The reason is that I had hope that they'd remove malicious results quicker. It's manual work after all and Google has more resources. This whole thread makes me doubt though.
[3] I'd do this anyway because I usually don't want to install the version that is automatically suggested, but decide myself which specific version I want to install. Most of the time the reason is the language.
I think this point is vulnerable to typosquatting and could actually reduces the overall security of your approach. I would say if the Wikipedia link matches the search engine link you are good to go.
This reminds me of a podcast I listened to last night where a physician explained how to get a flu shot: go to your place of work and do it yourself. Of course she was being sarcastic.
What you explained here is one of the main selling points (as in convincing, appget is completely free) for appget.
AppGet pretty much automates what you explained here and more.
We automatically download and validate SHA256 of downloads (We have a strict policy of only allowing releases from the official source)
All package info that is used to install applications are fully public in our GitHub repository [1] (think homebrew)
Also, for less tech-savvy users, they can install applications through our gallery e.g. https://appget.net/packages/i/chrome using appget as long as they have appget installed on the machine.
[1] https://github.com/appget/appget.packages/tree/master/manife...
As far as monetization, we do have plans for a paid offering, internally we are calling it "AppGet for Fleets" it'll be to manage/monitor app installation on a group of computers remotely using a hosted dashboard (SaaS offering).
AppGet as you see today and all of its stand-alone features will remain free and opensource.
AppGet doesn't use custom scripts on install; everything is defined by data (YAML files). The client uses the data in the manifest and knows how to deal with different installers. This alone makes appget more secure; if you trust the client (it's opensource and managed by the core team) you don't blindly run a PowerShell script as admin on your machine.
Also, adding/updating packages is trivial since all you need to do is update/create a very simple YAML file. Another benefit is we can upgrade the client to better deal with let's say MSI installers, and none of the manifests need to be updated since all the logic is in the client, the manifest only needs to identify itself as MSI.
This also means you can install an app in different interactivity levels, Silent (everything happens in the background), Passive (you see the installer and progress, but you don't have to click next or do anything) or Interactive (appget downloads and validates the installer and just launches it for you, but you can run through the installer and customized it as you see fit)
Our packages are more up-to-date. We have a crawler that checks for updates on regular bases, we use GitHub api, and check vendor sites constantly (over 500K of check events per day). Trivial updates are automatically pushed to the repository, For non-trivial ones the bot automatically creates a pull-request on GitHub to be reviewed by a human. Most cases we pickup updated releases for apps within hours.
AppGet can list, upgrade and uninstall apps that aren't even installed using appget. We check windows installer database as the source of truth. You can download appget right now, run "appget outdated" and I guarantee it'll find outdated apps for you.
I'm sure there are more things, this question comes up a lot, so I'm gonna spend some time and add a page to the documentation just for this.
But your description of AppGet has convinced me to try it out. Thank you!
Edit: There seems to be no obvious way to globally set the install location for apps. This is critical for my setup, I don't install apps in Program Files, because my Windows partition is lean and on an ssd that is shared with other VMs. Apps are installed in another drive location. Is there any way to do this currently?
In the meantime, what you can do as a workaround, is to use `-i` param when installing apps to launch the installer in interactive mode. That will let you run through the installer and customize everything including the install location. I know it's not ideal, but if you want to use appget to automatically download, validate the installers and check for outdated apps, it might be a reasonable work-around.
1. Search for the name of software on Google.
2. See if something looking like a site for the product shows up.
3a. If a product site shows up, I take a careful look around, and if it feels legit, I manually find the download link and use it.
3b. If a SourceForge link shows up, I proceed to the download. This is rare, but some program authors don't bother setting up their own sites, and I'm yet to see a malicious SF repo.
This is less secure than your procedure, but worked well enough so far.
7. Scan installation package using VirusTotal (Ignore ClamAV and Chinese A/V results).
Also I tried to experiment a little. If I type "download flash player" in Russian, official Adobe site is only on the 3rd position [1]. The first and second results are "adobe-flash-player.ru.softonic.com".
[1] https://www.google.com/search?q=%D1%81%D0%BA%D0%B0%D1%87%D0%...
And the problem seems to have been fixed. When I search for chrome download on Bing, the top result is https://www.google.com/chrome.
[1] Successful clickbait, too. Writing an article with "download Chrome" in the title apparently got them the top spot in Bing's "News about Chrome Download", so anyone who searches for "chrome download" will see this article near the top of the search results page. Very clever.
This has everything to do with Edge.
As I noted back in 2017, Edge flagged the destination site as malicious, Chrome did not. Warning on malicious websites is, in fact, done in Edge. But as with Chrome and Firefox, it doesn't catch every one of them.
Which could be faked, as seen in the referenced tweet: https://twitter.com/GabrielLandau/status/1055300918101598208 Yes, they show the word "Ad", alongside the domain name "google.com" - except the user doesn't end up on "google.com".
You can spoof any domain you want in Bing Ads without needing an open redirect.
Is that a bug or a feature? It seems like the kind of thing that could erode user trust
So both ad services allow the advertiser to display one URL while directing users to another.
Though that was 2017, and Google might've improved their protections since then.
I think you're slicing this too thinly. This has everything to do with Edge, which is purposely configured to use a search engine that creates a liability for users.
I would agree that "stop using Edge to download Chrome" is not useful and probably clickbait-y. A better guide would be "Be careful when downloading a different browser on Windows 10."
Because Google Chrome is a greater threat to them than Firefox, so promoting Firefox helps them even if it hurts Edge, as long as it also hurts Chrome.
Also because if they preload Firefox with Bing as the default search engine then Firefox users may leave it that way.
The only thing plausible thing I can think of is hoping to execute another round of embrace extend extinguish on the web, putting other desktop operating systems at a disadvantage. With google chrome's dominance that seems unlikely to work.
If I recall correctly UWP uses Edge's rendering engine (EdgeHTML) and JavaScript engine (Chakra). Edge integration/embeddability is also available to Win32/WPF/WinForms applications past a certain Windows 10 version. It makes some sense for them to develop something they have full control over if they use its technology in other core components/libraries of their operating system.
> This has everything to do with Edge, which is purposely configured to use a search engine that creates a liability for users.
You could say the exact same thing about Chrome and not be lying.
(The obtuseness being likening Google tracking to malware ads)
Simply visit Google.com, Gmail, Youtube or any other Google-site and await the Chrome-spam 100% guaranteed to appear in any browser not Chrome.
My favorite one: “Upgrade your browser”. Not misleading at all, eh? How about “no”?
I'm never going to leave a review.
My review will of course focus mostly on my most recent experience with the app, which was "getting annoyed with an obnoxious pop-up". I hope that this discourages app authors from doing that.
Their support team responds to (numerous) requests from multiple users about it saying roughly "cannot be disabled without buying but we'll let engineering dept. know you want that". Yeah, right, like it's an engineering problem.
Worse yet -- if you have >1 Nest camera, and you DO pay for Nest Aware on some but not all of them, the banner still shows up on any camera views you aren't subscribing for.
It's really crappy because the bottom bar is a fixed height, so if you shrink the browser window it can easily take up >=50% of your viewport. Absolutely absurd -- only option once you have their hardware is to use a plugin/bookmarklet to kill the nag bar's CSS. =(
Also FF, Chrome and Safari ARE upgrades to Edge/IE by any reasonable metric.
You've probably never had to write a non-trivial cross browser app. Try it and then let's see how you feel.
If you say "I upgraded my stereo system", I would consider the chance you meant that to imply you got better versions of the same devices from the same manufacturer to be essentially nil.
I'm that respect, it may seem misleading if you do a lot of work with computer or have for many years, buts maybe it isn't much to a layperson?
I think you either have more respect for manufacturers and how they advertise, or have a higher estimation for people's ability to successfully wade through marketing bullshit than me.
Here's a question, is replacing your stereo cables with gold plated monster cables an "upgrade"? What do you think the average person thinks.
> Chrome and FF are effectively comparable
that depends quite a bit on the criteria used to judge them. If you value your privacy, I don't think the are comparable (as a synonym for similar) at all.
You grossly overestimate what the average user wants to do. The average user doesn't even know the difference between browsers, rarely (if ever) uses bookmarks, and considers printing a web page an advanced task.
Annotating webpages is something that a tiny sliver of power users will use.
Use Edge to download Firefox, and Firefox to download Chrome ;)
So, we just spread the word to use the actual URL when possible (been doing that) instead of search and that chrome.com works for Chrome.
So I tried to guess ftp servers from the DOS prompt.
I think I managed to connect to ftp://ftp.opera.com and install Opera.
Update: looks like it still works today. Anyone looking for a 2004 BeOS version?
1. Bing allowing malicious ads
2. Edge not marking malicious sites
Problem #1 has nothing to do with Edge (other than Edge using Bing by default) and I’m sure Google may let malicious ads through from time to time.
But problem #2 is entirely Edge.
> The malicious URL that Bing is happy to promote can’t fool Google or Firefox. When I simply type the above URL into my Firefox browser I’m faced with a bold red page declaring “Deceptive Site Ahead” completely with details and an option to go back.
The recommendation to stop using Edge to download Chrome is indeed wrong though.
I know it's a tired point, but it nevertheless amuses me that someone would search for BattleNet. The name is literally the domain name: battle.net.
That's not a great solution, since many people are barely aware what at url is, but I think it should still be one that you and I (as people who are) use.
Similarly the article is fixed by guessing that google chrome is probably at chrome.google.com (also chrome.com), firefox is probably at firefox.com, cnn is probably at cnn.com, gmail is probably at mail.google.com, gmail.google.com, or gmail.com (actually all 3), hacker news is probably at hackernews.com (oops), etc.
Which also risks ending up on the wrong site (e.g. Steam is not at Steam.com). I'd trust Google to know the correct URL more than my guess.
Basically I'm trading Google/Bing and ads known to be malicious, for ICANN/registrars, self interested companies, and a reasonably functional "legal" system. Edit: And less tracking, and faster access to websites.
.com is pronounced 网 wǎng, "net", which doesn't leave much conceptual space for other TLDs.
Guessing domain names is even worse than Googling.
Microsoft went apeshit and called all their products .NET in the early 2000s. The branding was all over the place so I could see how calling your product *net might get you installs by association.
The industry never matured (to handle spam, malicious content or fraud) thanks to the Duopoly of Fb and Google, and even the biggest players are not immune to these issues as the onus is on the user to not to click on ads that offer to upgrade browsers, or any system software through ads.
It is the same systems that served malicious election results, the same systems that contributed to the echo chambers that impacted recent elections.
Create a "safe" ad network that is not a vector for drive-by downloads or privacy violations, and go after publishers that are being hurt by ad blockers or experiencing reputation damage from security breaches.
Bing can easily fix this domain spoofing vulnerability. I've reported this vulnerability to MSRC previously but received no response.
This is also why open redirects can be so dangerous. Even if this domain spoofing vulnerability is fixed on Bing's end attackers can abuse open redirects to achieve the same result.
I wonder what makes them think this is acceptable.
If Bing is returning malicious search results, that's a reason to stop using the search engine, _not the whole OS_. The October update fiasco is a reason to stop using Windows. These are separate issues in separate projects made by separate teams, happening at separate times.
The implication is that everything MSoft touches is insecure or otherwise out to get me is weakly supported. It may or may not be true, but a quick toss in of one data point about how Windows is bad and oh by the way Ubuntu is better isn't convincing.
Here's a screenshot of the same exploit on Google: https://plus.google.com/u/0/115181074626403443464/posts/fSPm... (The included hijack was blocked as a malicious site on Edge, but wasn't on Chrome.)
Ads should always be forced to display in the URL text the actual URL the ad directs the browser to. Maybe as a side bonus, less tracking URLs will get used to keep it looking cleaner.
It might be labour intensive to have human eyes on every ad that is sold when you're at Google, or even Bing, scale. But it seems a little bit too hands-off, and irresponsible, to take money without vetting the input and then letting every scammer get into that very "blessed" and visible top spot of a search page.
If you want something done right, do it yourself. You can't expect scammers to not to be scamming.
Your recommended children’s videos are actually disturbing parodies? Easily solved with human curation. Some Alex Jones story makes its way into your news aggregator? Having people check the story would fix this. Scammy or malware-ridden ads on your site? See above.
Obviously this isn’t practical for everything, but tech companies take it way beyond what’s necessary, then act like the problems are impossible to avoid.
It is near impossible for Bing to manually review every advert so perhaps it would be beneficial for search engines to provide a way for users to report rouge promoted links, similar to how YouTube allows you to report its sidebar ads.
Why? Are there hundreds of ad campaigns being created per second?
If you paid a person or a team of people to remove adverts promoting fake websites, the person reviewing the advert would have to understand the product being sold, the company selling the product and the companies real website. For Chrome this may be easy, but for more obscure projects such as a cryptocurrency wallet or email client it'd be hard for a person to distinguish between real and fake continually over the course of an 8 hour work day.
People who are searching for a product already understand that context and so will be able to make a less erroneous judgement on whether a promoted link is real or fake.
That calculus applies to just about everything.
They very specifically do not make it clear, they (and I mean all of them) intend to make sponsored results look as identical as possible to organic results to improve the likelihood that you'll click them. They only have subtle markings showing that they're ads because if they didn't, such an abuse of trust would be ruinous to any search engine.
What's even worse here is that in the linked video, the Bing ad shows the domain as `google.com`, which is something you expect to be accurately represented in any listing, organic or paid. That's the sort of thing that should be ruinous to Bing.
There's a reason for this - ad tracking for conversion, performance or even to make sure the advertising network is honest. The ad tracking domain is not always the same as destination domain.
AFAIK, this problem seems easily solved.
All Ms has to do is flag ads whose displayed URL do not match the final URL for manual review. Or simply ban it.
Still, fraudsters have ways of changing the landing page to something different. In this case someone seems to have successfully convinced bing that the landing page domain is google.com -- it's unlikely that it's "easily solved". Or that the next one will be easily solved.
The ad did match the final URL, it just selectively redirected to the legitimate or malicious page based on user agent. See https://twitter.com/sephr/status/1055751684146655232?s=19
I don't agree with this. Reviewing ads should be a straight forward process, much more so than reviewing an app submission. Plus, obvious issues can easily be automated, reducing the load of manual reviews.
You're absolutely right - it would be beneficial for them to dump their responsibility on the end users.
But, still, Microsoft's browsers still aren't good. In my workplace (where we do some complex cross-browser work) they're an enormous nuisance to development and QA. I wish Edge were far better than IE, but they're both quirky. Firefox and Google Chrome ordinarily work predictably. Safari has a few quirks, Edge is really quirky, and IE is a narrow gauge steam train, all different.
Why doesn't Redmond stop throwing good money after bad and just license Firefox? Are they stuck in the sunk-cost fallacy?
also, we don't run some random PowerShell script written by god-knows-who on your machine. All installs are driven by pure data, so the only thing you need to trust is the appget client itself.
e.g. https://github.com/appget/appget.packages/blob/master/manife...
However, I think it's more of a branding thing. Microsoft wants a complete experience when you install their OS, and they want something that will keep users on that platform. If they build IE, they can control the platforms it runs, which means users will feel uncomfortable on anything else.
So it's frustrating to see Bing hurt their reputation with something as stupid as this. If Microsoft want more people to switch, they've got to be at 100% in all areas, they can't afford to let Bing Ads ruin the whole service.
Malware like this targets the lowest hanging fruit I guess.
If you get ads for a malicious version of a browser on a new PC, why isn't it possible to get ads for a malicious version of an ad blocker?
There's no end to this rabbit hole unless you can acquire the software without the use of a search engine, or the search engine cleans up its act.
Linux got it right with the built-in package repositories. Unfortunately Windows and Mac have never really adopted the super-easy "apt install this" style.
2. You install "this" with your package manager
3. Even if the "this" installed wasn't the "this" you read about in your browser, it still came from your package manager repos, which you could consider safe, and you'll be able to uninstall it cleanly.
Then I look at the Windows Store and weep.
I will admit that Chrome/Chromium is one of the few things you can't easily get from the repos, on Ubuntu at least.
The security of the package repository system falls down when people add apt signing keys that are untrusted/unverified, which is what happens when you add a ppa in Ubuntu.
We're sort of in a loop here -- how can I know what is the official Chromium website?
Yeah, unfortunately that's what verifying the legitimacy of the chromium-team Ubuntu ppa requires...
Anyway, there are two quick ways I found:
* Go to chrome://settings/help and see the link to Chromium.org (but obviously this doesn't work if you don't have Chrome already)
* At the bottom of google.com/chrome there is a link to Chromium.org
Googling debian google chrome results in instructions for getting chrome on debian.
I have 3 different distros installed on 3 different computers. Chrome is listed on all app searches.
Yes. I know. I'm not picking on debian specifically here, fedora's dnf doesn't help you install chrome either.
My point is rather the following: The GP asserts that the way to find (and subsequently install) software is "apt search `software`" and that way breaks down on exactly the piece of software that the article is about. You have to google instructions and then install either the .deb or add googles repo. And that's where the attacker could just as well insert an ad pointing you to a malicious repo. Just as the attacker currently points people to a malicious download. So the GPs solution isn't a solution at all. Not to this problem.
Unfortunately Google Chrome is a bad example here as it's not available in most repos (since it's closed source).
That’s a bold statement to make, especially since a single piece of malicious software is sufficient. And yes, I want chrome. I need chrome. I need to test stuff on chrome.
Chromium is available in the repos.
I have my doubts that any Linux distribution is capable of auditing every line of every package they distribute, so I think the relative lack of malware on Linux (and possibly MacOS as well) may not actually be caused the specific method of distribution.
I don't agree. If you search for "chrome" or "firefox", you will get a page full of spammy apps that are anything but what you searched for.
Linux distributions probably don't audit every single line of code in the packages, however this is code written by trusted developers that is mandated to be open source and distributed through official channels.
Getting malware into the package repositories would be very difficult, but it seems that getting a fake Google ad on Bing is very easy, so in my opinion the distribution method makes a big difference.
You know how Google & Firefox could easily help fix this? List their browsers in the Mac and Windows Store.
The interface for this is "start nice gui front end, type firefox into search bar, select firefox package, click install"
It's tricky to get win32 apps in general into it, too.
For general win32 apps I do think the situation has improved since I last looked.
You depend on your distro mantainers to package what you need to install. If it isn't packaged, best case scenario is you get a tarball, which is already too hard for 99% of computer users. Snaps and Flatpaks are still too unpolished.
Getting all your user applications (DAW, IDE, etc) from your OS developer (instead of getting it from the application developer) is also against the sentiment of freedom that so many Linux users preach.
There are many alternative repositories for essentially all distorts today; snaps and flatpaks are indeed not yet polished enough, but they are much better and easier for 99% of users than tarballs, so calling tarballs a “best case scenario” is, in my opinion, wrong.
You were complaining tarballs are the “best case” and are not good enough because they’re too hard for regular users.
PPA is as easy as windows downloads; it updates the same way as the main system unlike windows; and it always go through ununtu’s Servers which makes it somewhat more monitorable. But that’s a new discussion.
But package managers can also have lookalike names. Npm and pip has had a few famous misspelled common packages that contained malware instead. Those are more open than apt or the big app stores but even on Google play you will find tons of lookalikes.
This whole incident just shows you should never just search for anything by name and pick the first good looking result. You really have to verify the source regardless of which search engine you are using. What I very much dislike is companies who refer to their own app in the app store only by name and then you when you search you get 10 results which all look equally shady. And because they outsourced the app development the publisher doesn't even match. Place a god damn link or show the unique package name on your websitr instead.
take a look at https://appget.net if you use windows.
I frequently come across malware hosted on onedrive and I've stopped bothering to try to report it, its still there months later and I've never received a response from Microsoft.
It avoids using malicious options accidentally and it also means I don't need to go through each installer. Plus I can just send the file to friends and family when they get a new comp.
edit: just wondering why people disagree with this idea?
It was signed, but most users won't catch that it's signed by the wrong party.
In fact, when I tried to look for a specific class of malicious ads (looking for "mapquest") recently, DuckDuckGo was even as bad as Google, it was Bing who gave the least malicious results. But obviously they've failed here.
Automated advertising platforms have been overrun by malware and no automated solutions are going to fix it.
I think that the sponsorship model many YouTubers use these days works really well, because there isn't any code involved that I have to run.
Now I'm sure you can dig up some vulnerabilities, and a select few of them may even had (remote) exploits. But I've never run into any problems, and I'm not especially careful, have been around the seedy underbelly of the web, and don't run any anti-virus. Just not clicking on any .exe that suddenly downloads seems to be enough. Being on MacOS rather than Windows may also help, although as far as I can tell, security on Windows today is also far far better than it was a decade or so ago.
Considering all that, I can't shake the suspicion that people complaining about JS vulnerabilities to defend their use of ad blockers are just searching for justification.
People are cheap and don’t want to pay for content, it’s as simple as that.
The number of horrendous tracking/ads/spam domains you'll see rushing by is unbelievable.
Also consider that most browser vulnerabilities -- not "JS vulnerabilities" -- are virtually impossible to exploit without JS.
Malicious ads pretending to be MapQuest remain alive and well. After pausing my Pi-hole, I can confirm that it refuses to actually provide directions when asked, and promptly tries to add an extension to my web browser.
Part of the problem with ad platforms like these (including Bing's), is even if you report one and take it down, it's trivial for the same people to stand up the same website on a different cloud server with a slightly different domain name and do it again.
Notes:
- My sole extension not made by Mozilla itself is the EFF's Privacy Badger. I also use Firefox Multi-Account Containers and the Facebook Container, both first party.
- Do recall that advertisers can target users by a variety of variables (browser, location, etc.), your ad experience does not reflect everyone else's ad experience.
Software should be distributed via apps stores. Preferably vetted lists as opposed to free for alls you can post malware to for $25.
Linux has been doing this correctly for a long time. Any time you guys at Microsoft want to rip this off properly would be absolutely fantastic.
Unless it's an IDN homograph attack?