Google Ad Disguising Itself as www.gimp.org
old.reddit.com
old.reddit.com
Google misrepresented the ad as the product of the Gimp project, and were paid as a result. They usually use an "obeying the law would not scale" type argument in court, but that would clearly be bullshit in this case. They have a business relationship with the ad buyer, and should have verified their affiliation with gimp.org. Also, a simple string match on the URL would expose the attempted fraud on Google's end.
I'm not sure how to check if Gimp is a registered trademark in the US. This page kind of implies it might be (or that the author of the page does not understand trademarks):
I don't know why, but that sentence terrifies me. It's like the silicon valley version of a dystopia.
Shouldn’t the right course be to change the law before taking such actions?
"The laws are impossible to follow at scale. How do we fix that."
Or as a thinktank feeds it to a speechwriter to a politician: "Our antiquated laws have failed to keep up with the speed of technological development, and are now becoming an active handicap on progress. We need a set of laws that are as forward-thinking as our best selves hope to be, and a set of legislators that are responsive to the energy and creativity of the young while respecting the intelligence and hard-earned wisdom of the old."
A corporation like Google does it and the court agrees. Corporations are not people in the worst way possible.
because it is true.
We have seen the same pattern in copyright infringement handling, spam or fake news control, user support...
This is something that ideally the government (its consumer protection branches like the FTC) should be policing proactively, filing suits preemptively against systems that are trivially exploitable.
It's particularly problematic when a business is providing a platform for other entities to post a message. We don't hold the post office liable for transferring copyrighted/trademarked content, do we?
Now I take a rather dim view of the dmca. But the general concept is to move enforcement of the law out of the normal slow bureaucratic channels. Now enforcement is handled directly by the injured party. Much more efficient.
If you immediately see how ripe for abuse this system is. congratulations. you are now more far sighted than the originators of this system.
Now to it's credit, the dmca limits the enforcement(I think, I have never read the law) to a formalized version of "if you stop doing it we won't press charges" however this is still widely abused.
I’d love to see them trying that one out in an EU courtroom
I feel like your general argument is proving too much: Google clearly indicated this is an Ad, and you couldn’t reasonably hold Google or any other publisher of ads responsible for every claim made in every ad. However, I agree that the domain part is troubling, and even seems like a potentially misleading representation by Google — I’m surprised you’re able to set this arbitrarily. However, as discussed in a thread below, maybe you can’t and this is exploiting an open redirect in gimp.org? I think some details would be needed before you can jump to assigning blame so quickly.
Why not?
They might work for BigCo, but rather than have the ad point to bigco.com/product they instead have the ad point to tinyurl/bitly so they can track how many people click the ad and repoint it to another URL easily.
There is a whole industry of these redirection services that gather stats, direct users different directions based on mobile/desktop or country. It isn't rare to bounce a user via a whole chain of them.
To support all those users, ad networks have to allow the apparent URL and actual link target to differ.
the g, i, m, or p are replaced with characters from a different character set. Looks right, but the domain is registered with a different character.
Example: * gіmp.com is fake. * gimp.com is real.
They look the same, don't they? But if you click on the fake gіmp.com, your browser will take you to the domain xn--gmp-jhd.com as it is using the і from the Cyrillic character set.
[1] https://old.reddit.com/r/GIMP/comments/ygbr4o/dangerous_goog...(Mostly I mention this because someone else might be thinking at as well.)
It's disgusting that a competitor can buy an ad for your brand on Google, Apple, etc. and place their result before yours. This is especially harmful for new, up-and-coming companies.
I've had competitors buy ads in our name before. It's a shameful tactic.
It's beyond unfair when these monopoly-like ad companies spent hundreds of billions to co-opt the web and personal mobile computing and shackle us to this fate. It's the nightmare Microsoft and AOL once envisioned, yet now it's actually come to pass.
We already pay for domains and trademarks. We shouldn't have to keep paying protection money to defend ourselves when we're already having to jump through the platforms' obtuse rules and pay their outrageous taxes.
Trademarks should be sacred, and no company should be able to profit off of yours.
How can anyone argue against blocking ads when this argument is used literally in court as explanation for why they are unable to police the ads they're putting on their own platform?
Then don't scale...
The issue here seems to be that the Gimp team does not have a registered trademark for "Gimp" (at least not in the U.S). This can be verified at the USPTO website [2].
(Here's a few random recent examples: https://redd.it/xxkx5s https://redd.it/vvrxko https://redd.it/xwkky8 https://redd.it/vuqu1r)
Ad networks and content providers get up in arms over widespread ad blocking but then allow stuff like this through.
It is basically a condom for the Internet. It makes maintenance for family computers much easier.
/s
I was using the Internet Junkbuster (and later: Privoxy) in the mid-90s, many years before that. https://web.archive.org/web/19961222061917/http://www.junkbu...
Of course, back then you could just disable javascript in your web browser to protect yourself from malicious sites and annyances, and practically all sites would work perfectly fine.
Google's other big line of business is shaking down businesses for cash by selling the top result for someone's own brand name unless they're paid for protection.
I want real opinions written by real people with no conflict of interest. People who are't getting paid by the corporation.
But the incentives for advertising remain the same, so another similar competitor with similar evilness would emerge to replace them.
I don’t believe the problem is “Google is evil”.
I think the problem is that the incentives create evil, and there is little effective effort (that I have seen) to fix Google’s incentives through legislation or other means.
I worry that many other major companies we interact with are heading down the same path.
TVs are one canary warning us.
Another example: Apple seems to be getting keener on advertising revenue, and I’m not sure that opposing incentives (within Apple or by their customers) are strong enough to overcome the financial temptation. That temptation leads to eventual sin (to use a religious metaphor!) Apple already commits egregious harm through many kinds of “free” apps.
If you think I'm trolling, report me. If dang tells me to stop, I will respect his decision. Don't accuse me of "baiting" otherwise. This isn't 4chan.
That's maybe 10% of what advertising does. Everyone on the planet is well aware that Coke is a carbonated beverage.
Advertising is pretty gross.
And maybe that wasn't always the case, and maybe it's also using advertising in place of another word, but that's where it's ended up in my understanding of the world.
It's become lifestyle sales, of you buy this, you'll be this. They use that technique just about everywhere now. Used to be just cars and fashion. Like someone else said, emotional manipulation, narcissistic [my add].
Most people don't think with logic, but with emotions, so they're easy targets. Which makes me sad, because frankly no one deserves to get scammed and lied to.
I'm the type of person to appreciate direct and frank discussion. Many don't like this, especially people having power ambitions.
And yet it tries do "educate" the public about why they should buy whatever product or service they're offering. Lies and half-truths are common.
In these screenshots you have to pay good attention to see the top result is an ad.
To keep their conversion numbers up they had to constantly reduce the difference between the ads and everything else. The fact that they can do this and we are so used to it that we don't first identify that as the culprit is quite interesting.
I have ran a few Google ads in the recent years and the people who come through them, some of them, clearly have no idea that they have clicked on an ad. This might be good for business but I think it does more harm overall.
But it's often no longer possible. The actual search reasult you want is the ad and the link is no longer duplicated in the organic search results.
So you have to click the ad.
Disclosure: I work at Google but not on Search.
The ad's ID is DChcSEwiPvfuL-YX7AhVmkmYCHUXQC1wYABAAGgJzbQ (displayed when reporting it), the display URL is https://www.gimp.org/ and the final location after clicking the ad is https[:]//gilimp[.]org/ (with no intermediate redirects via gimp.org).
Update: The DNS records for gilimp.org have been deleted. Archived snapshot: https://web.archive.org/web/20221029152445/https://gilimp.or....
-------------
Original comment:
The Reddit user says the ad's display URL was different from landing page URL. If that's the case it is particularly concerning. I believe Google Ads only allows the advertiser to set the path component of the display URL, and takes the domain from the landing page (real) URL; so it's unclear how the mismatch could happen.
Maybe the Reddit user took the screenshot on a separate occasion from when they clicked the malicious link, and the ad changed in that time (currently I can see an ad for GIMP, and it links to the official domain, and the linked Twitter thread linked by @pmoriarty says the attacker is actively changing things). The only other explanation I can think of is that the official GIMP website has an open redirect vulnerability.
edit: nevermind. I was being saved by ublock origin. Searching with it disabled shows the malicious ad.
The scam ad says "gimp.org" but if you follow it, the landing page is hosted at gimp.monster. It's a clone of the proper gimp.org with a the download instead pointing to who-knows-what .exe on Dropbox.
WHOIS gimp.monster has WHOIS-guard, but the Icelandic "privacy" address turns up a bunch of Reddit links about scam sites. Namecheap is the common thread, but that's hardly a lead.
I've seen both Amazon and Best Buy URLs on scam ads.
URLs are sacred. Please don't fuck with them. Please.
That was never the intent of hiding the path, it was and is to help users identify what a site’s domain actually is. To distinguish malicious sites with recognizable domain-like strings in/overlapping their paths as well as malicious sites with recognizable domains as subdomains. It’s not a panacea, but it’s effective. Chrome (and IIRC Firefox) also experimented with similar approaches before ultimately splitting the difference with higher contrast text for the domain.
Linux mint, for example, the attacker updated the checksums for the ISOs on the page when it was compromised https://www.infoworld.com/article/3036178/lesson-from-linux-...
I don't really have a solid solution to this, besides searching the checksum on google to see if it's listed anywhere else as a soft 3rd party check
Surprisingly, I think no attacker has ever forged a OpenPGP signature in a real-world security incident, likely because there's a lack of overlap between crypto nerds and crackers.
Though, public keys do not change often and leave somewhat of an "audit trail". I usually search the key fingerprint on the web to see if it has been mentioned elsewhere as a quick check. Some projects store signing keys in an official upstream git repository. It's somewhat of a higher guarantee, but one can still creates a false upstream page for phishing... But I guess it's too much of an effort so nobody has tried to do this, yet.
Thankfully, for distro users, it's only something for packagers to worry about, end users always receive verified packaged via the distro package manager.
I suspect in the real world almost nobody validates PGP keys of software downloads manually. They might do it automatically (for example via a Linux package manager), which a fake key wouldn't fool. Thus, faking the key isn't necessary because 99% of users that could be fooled won't bother checking.
A perhaps less appreciated advantage is that in practice the identities are stored offline with each entity that will be verifying the signatures. So an attacker has to justify the use of the new identity to what would normally be a large number of entities. That might explain why that sort of attack is so rare.
A hash method would quickly run out of disk space before it could be used to verify every single file. Hence hashed b-tree for xfs (or is it jfs? I forget), and stuff like that.
A verify once used many times method is more efficient on a large scale.
I'm no maths expert, heck i don't even know calculus.
DANE may be of interest here as well:
https://www.infoblox.com/dns-security-resource-center/dns-se...
In particular, it's crazy that I can't just stick a public key for my email address in the DNS record for my domain, and have email auto E2E encrypt to it.
(No, that wouldn't scale for gmail, but they could do a two level thing, where the gmail key signs the public key for each mailbox -- assuming people bothered to set up their own keys, or that gmail just silently opted them in to server side encryption.)
But it's trivial for responsible members of an organization to set-up a continuous, automated verification of the checksums listed on a web page. It wouldn't be practical to do that with the ISOs, directly.
Of course if the organization is lazy or incompetent, and chooses not to do so, then they have only themselves to blame. But if you fail to compare your downloaded files to the listed checksums, that's all on you.
My solution to this when designing Homebrew’s binary packages was to store the checksums for the binaries in Git but the binaries themselves elsewhere (inspired by Homebrew already storing source checksums in Git).
On Homebrew, therefore, you’d have to compromise both the binaries and the Git repository.
These are both nowadays on GitHub but the binaries in GitHub Packages are addressed by their checksum and the Git repository has a good audit log.
[1] - https://addons.mozilla.org/en-US/firefox/addon/ublock-origin...
The way they say it really comes off like a protection racket. "Nice number one spot for searches for your brand name you have there, would be a shame if anything were to happen to it."
They make people feel better about it by giving a steep discount over normal ads, but that doesn't make it less of a racket.
Like, if you search for "Nike" and Nike hasn't bought the branded ad space, you might get an ad for Adidas as the top result, with Nike's homepage the fourth item in the list.
The term for this is "racketeering."
However, I have reported dozens of phishing sites for the company I worked for. The phisher would simply buy ads for $BRANDNAME and create a convincingly similar site and phish users. I would report the website to "safebrowsing" and report the ad. Typically it would take 1 to 3 days for the website and/or ad to be removed, which would give them enough time to do countless damage. Then they would simply register a new domain, and repeat.
At some point the only thing you can do is outbid phishing sites for your own brandname?!
It's a shame google can not self-regulate such evil behavior, but it's clear that it should be illegal for google to allow people to buy ads on brandname searches.
I mean, if nothing else, how do they not share the liability for damages done by the spyware they're literally promoting? For the businesses squatting on the names of more notable ones? AdWords goes too far.
What's happening is Google would rather accept the cash up front and keep it if and when someone reports an ad. No forethought is given to people tricked by this.
† Obvious exception for unicode squatters but even they should be filtered out entirely automatically. Invisible or misleading characters in your domain should be automatically blocked.
> dig +short gimp.monster
194.110.203.75
> whois 194.110.203.75
...
role: IT Resheniya LLC
nic-hdl: ITR30-RIPE
address: ul. Novoselov, d. 8A, of. 692
address: 193079 Saint Petersburg
address: Russia
abuse-mailbox: abuse@rentaserv.su
...Would love to poke it for research.
Edit: Here be dragons. Found a source: https://old.reddit.com/r/GIMP/comments/ygbr4o/dangerous_goog...
https://www.virustotal.com/gui/file/acea176b67cb7c77dfd0780f...
Of course whoever went to the trouble to create the scam sites and ads probably also did modify the executables in some malicious way.
The site looks legit
You think "gilimp.org" is legit website for gimp??
Google also allows many deceptive AdSense ads, I constantly have to block ads that run on my website that are nothing but a big "Download Now" button which lead to some malware.
I've been using Bing for a year now. Not perfect, but 1) never seen something like this on it and 2) if Google feels less like an invincible monopolist, perhaps they'll have some incentive to provide an acceptable service.
I can't believe that Google allows this but tracking is clearly more important to them than user security.
*Yeah, I know, I kind of answered my own question. So I guess it's rhetorical, and less shocking in retrospect.
Maybe dang could even make it an automatic redirect?
Old school ads only threatened to stink up the room with the scratch and sniffs....
Filing a lawsuit is not something within reach of most smaller projects.
Or at least validate ownership of the target domain.
This is amazingly frustrating because I've wasted weeks of my life trying to deal with how google usually makes this impossible.
I can't say enough nice things about gl.inet deviced and switched to a cellular model when ad-blocking on a 4G ipad was too much trouble.
I orginally setup a Spitz gl-x750v2 and removed the ec25-af lte and put it in an external enclosure and move it between better spec'd gl.inet routers to run adguard home.
"Halt" is a good browser on IOS to block all YT ads, but a portable router workes well with a dedicated sim or tethering a phone.
Ads are soooooo 1980's TV :p
Oh great, they'll get their account closed and need to make another one to continue scamming people.
How about Google fixes this by displaying the URL that the ad actually goes to?
Of course they don't want to do this because the URL with all of the tracking parameters looks ugly and it would hurt conversion rates. $$$ > user safety.
The proper response is of course to ignore their excuses and block all advertising unconditionally.
I expected Google Search ads to be above this. But in retrospect I shouldn't be surprised that ads would lie to you.
It's really important to report thibgs lime this to the developers and owners of the software.
I've reported dozens, yet they never finish coming at me.
this is a good example of how chicken shit design leads to security vulnerabilities. google probably lets the user post one link and make it lead somewhere else when you click it, as a "UX" feature. in reality it makes phishing much easier. this could have been avoided by not being a chicken shit and making links behave as one would expect, at the cost of 1% of use cases no longer working. the whole idea of treating URLs as a UX object is a misconception anyway, URLs should be opaque bit strings.
You would think keeping a curated list of well-known software projects (and others) would be low-hanging fruit. Instead, it is apparently better to throw money into complicated systems... that can't even catch the most basic form of linkjacking.
> this is a good example of how chicken shit design leads to security vulnerabilities. google probably lets the user post one link and make it lead somewhere else when you click it, as a "UX" feature.
I have always found a bit of subtle arrogance in this kind of thought process. It's like they've never bothered learning the basic functions of the web and how it is meant to work and think they know better than the original creators.
This. Gmail freely warps the email standards when they feel like it. If AMP is a "standard" (I haven't checked) it's a standard that only Goo uses.
solution is to install adblock on every device
Put on your thinking caps and play the game. What else could be going on here?