Malvertising on Google Ads
kolide.com
kolide.com
And they refuse to act on numerous reports of the same issue, over and over, since 10 years... And the Safebrowsing initiative is a joke, since they always say "it is fine".
Badware people are often one step in advance...
FWIW, they're acting all the time. It's whack-a-mole with the malware providers.
https://old.reddit.com/r/blender/comments/105tht4/be_aware_o...
... but what I suspect happened is they got reports, took a few days to down the ad, the ad goes up under another URL, they get reports, take a few days to down the ad, etc. The malware vendors are tenacious and have a pretty much bottomless well of Turking for CAPTCHAs and backup accounts.
ETA: none of this to imply that Google shouldn't fix the problem or that they don't need to divert more resources to it (if for no other reason than it does actually threaten their bottom line if they can't get on top of it and people conclude it's not worth it to keep recommending Google search to naive users). But the problem's generally harder to fix than most people believe.
There is one thing Google could do that would eliminate the vast majority of this sort of thing. They could require a manual review of all ads and advertisers before putting each ad into the pool. Like traditional media does.
But that doesn't scale, so it's not going to happen. But avoiding something because it doesn't scale is a deliberate choice, and I think it's fair to consider Google to be at fault for allowing this state of affairs to continue as it is.
Or, alternatively, should there be a few tens of thousands of firms allowed to advertise on the Internet and the rest of us can just pound sand?
(... actually, now that I think that "out loud," a distributed trust model would be an interesting idea. Google, instead of vetting ads, could vet trusted ad resellers, and knock entire resellers off the network that failed to do due diligence. The resellers would be responsible for policing their various houses and if you didn't like the terms one provided you could go to another. This is, perhaps, one of those situations where more middlemen would be desirable).
The real issue, IMO, is that Google's business model is just fundamentally bad. But Google is large enough that it doesn't matter. They're like a large industrial polluter poisoning the lands and arguing that there's nothing they can effectively do about it because addressing the problem would be bad for their business.
Firefox advertises at the top of "download browser." Should we cede their ability to be found to whoever Google thinks should be at the top of that organic result? Because by user numbers alone, it probably won't be Firefox!
> because of a (statistically) few bad actors?
It doesn't actually matter how many or few bad actors there are. What matters is how much harm is being done.
I'm not sure what your point is about Firefox, but in general, it doesn't matter if mitigating the harm Google's ad system does adversely affects Firefox or any other advertiser.
I'm not sure what consent means if it doesn't mean "user clicked on a result after asking Google for results." The backstop here is the user doesn't come back because they got screwed by Google, not that some third-party makes that decision for people.
But yes, I suspect if Google can't get on top of this problem they'll lose their leadership position in search.
First, I'm talking about ads, not search results. Although Google conflates the two as much as they can get away with, and people often get confused as to which is which.
I can't imagine how clicking on an ad can be interpreted as consent to being exposed to malware. In order to be considered "consent", the person has to be fully and accurately informed of what they're being asked to consent to.
> The backstop here is the user doesn't come back because they got screwed by Google
I truly wish we lived in a world where that could be expected.
Google dethroned search vendors before them and they aren't bulletproof. If they are, might as well pack up DDG and everything else right now. Shut off the servers and decrease the greenhouse gas emissions, right?
No, I think the backstop here is that DDG has a wonderful opportunity to be the search engine where you don't have to worry about getting vended malware via an ad above the first organic result.
Why shouldn't advertisers have to clear the same hurdle as opening a bank account in most western countries?
All ads on major DSPs already require approval before they can run. Advertiser accounts too, especially at scale. While there are plenty of technical openings for fraud and malware, the vast majority is from known actors that can be resolved through business practices.
A trillion-dollar megacorporation with hundreds of thousands of employees has more than enough resources to handle this. The reason it doesn't is because of the flow of money and incentives across the vast supply chain from advertisers and agencies to vendors and publishers.
But the opposing operators get more and more sophisticated, countermeasures that work to half decade ago get circumvented, and the arms race continues.
By the way, this is already done since Google does check advertiser accounts against various sanctions and watchlists as part of dosing business in every country they operate in.
The point is that it’s not a resource or scale issue (as you keep arguing), but a profit and incentives issue as I said before.
Requiring bank-scale KYC on top of that to also work with the advertisers would cut the 4 million advertisers Google currently serves down to a tiny fraction of that (if for no other reason than they don't have infrastructure to background-vet 4 million customers; they don't currently).
Perhaps this is the right approach. It would end the days of being able to set up an advertising account in a few hours. Perhaps that's not needed anymore.
(This would, of course, mean people giving even more PII to Google. However one feels about that).
Yes that's the problem.
> "Requiring bank-scale KYC..."
Nobody said that. The KYC part is an analogy to the financial industry to use procedures to screen out bad actors. But it doesn't need the same requirements.
> " they don't have infrastructure to background-vet 4 million customers"
KYC is not difficult. Again, banks and finance companies which are far smaller than Google do this all the time, for all of their customers and anyone involved in transactions. This is 100s of millions of clients.
> "Perhaps this is the right approach."
This approach is far more nuanced than the binary outcome you're interpreting. There are ad and account approvals already. There are different scales requiring different support and sales already. Having more intensive checks as the spending scales is a very simple and effective strategy that can be applied today.
The company doesn't care about the number of customers, it cares about the revenue against potential risk (just like every other every business), and currently the risk is acceptable for these ads and advertisers to continue.
That ability was never needed and was never a good idea.
Countermeasures aren't needed if adtech just stopped working with known bad actors and recognizable malpractices.
True, but it looks to me like adtech depends on working with bad actors and mostly ignoring bad practices. It's one of the reasons why I consider the adtech industry itself to be malicious.
But Google had to down on the order of some million accounts in 2021. The crawlers hit rate is probably not enough to keep up with this problem.
Charge Google a fine every time they serve a malicious ad and they will fix it.
Nonetheless, all of my comments are engaging in wishful thinking. Google is a monster and I'm not sure anyone can tame it anytime soon.
... but if you have any ideas they haven't tried, I suspect they'd love to hear about it in a job interview for any of the openings for ad quality SWE.
I think this really requires governments to step in. I mean one could easily argue that Google is facilitating fraud here, so maybe they should be liable?
Toxic waste doesn't try and hide from the litmus paper or the geiger counter.
There is no reason they have to serve 30 billion impressions a day. If vetting takes that down to 1 billion, that's fine. Lower the volumes (and raise the prices to fund manual vetting) until the problem is resolved.
Toxic waste disposal is a solved problem thanks to (enforced!) regulations that force companies to do so under threat of heavy penalties, not altruism or the fact that the waste doesn't hide from a Geiger counter. We need the same for online advertising.
But even if we accept that there is a downside, it's clearly not enough because this problem keeps happening again and again. Whatever downside there is needs to be increased by a few orders of magnitude for them to take the problem seriously.
The malware continuing to appear isn't sufficient evidence. Malware moves hosts and ad accounts all the time.
ETA: from the article itself, in 2021 Google "Removed over 3.4 billion ads, restricted over 5.7 billion ads and suspended over 5.6 million advertiser accounts." That's a ton of action, but AdWords alone also serves 29 billion ad impressions a day. It doesn't take more than a few bad actors slipping through the cracks to get seen (and at these orders of magnitude, "a few" is still "millions." Completely impractical for human hand-review).
It's clear this will never be prioritized without regulation as scammers money is as good as anyone else's and open source projects cannot afford to sue Google to force action.
I see some shady ads right now via adsense on https://getpaint.net
Screenshot: https://imgur.com/a/WRvrddy
Someone will report them, and they will go away, then reappear from a different Adwords account. They don't seem to have a smarter heuristic sort of thing to reject ads that only say, for example "Download Now".
Here's how the vetting you're imagining works:
1. The automated system goes to the advertised site. But Google's IPs are public knowledge, so the site vends a "safe" version to Google's checkers.
2. If Google sends a human being? Same story. That human's coming from a Google IP.
3. Google has a small set of non-Google IPs that they privately use for checking. This process seems to have broken down. My guess is malvertisers have caught wise and have managed to build a good list of those IPs to cloak against Google's back- and side-channel verifies too.
In terms of the actual ad copy: I suspect a lot of that is checked automatically, and the rest is often checked by contractors. So you're trying to solve the "Build an AI to understand when something is confusing" problem. There's probably room for improvement here, but it's not as surprising as I wish it were that stuff slips through the cracks at that layer.
You're telling me that even though attackers of various sophistication are able to get clean, residential IPs all the time for nefarious purposes, Google can't do the same? Come on. It's not that they can't, it's that they don't care.
That said, it’s pretty common to get a competitor ad above the top search result.
But as policy they want to force companies to pay for clicks to their own brands.
Untrue, I can give you quite a few who have been there forever, by private message, if you want.
The longer he keeps them private and confirms they still exist, the more damning the evidence against Google's lies becomes.
This suggests to me that what people are generally seeing is churn, not lack of action (i.e. individual bad actors get taken out but they're up again soon).
There’s malware above things like VLC, Zoom, Firefox, Malwarebytes, Teamviewer, all the time. For the better part of a decade, if not longer.
So it's probably whack-a-mole problems.
In the political dimension, the issue could be addressed by taking advertising away from the people as a service that is generally providable and restricting the right to advertise online to a few elite who have been vetted.
The power of advertising (as in buying influence) should absolutely require vetting and approvals. This is already done today, and comes in many layers as scale and budgets increase. The problem is profits that do not incentivize stopping these ads effectively.
In some way these scores could effect the search result ads that are shown.
Not saying Google necessarily would/should try this but some other smaller ad/search network.
I think it probably would work about the same as Uber/Airbnb, etc. - which is to say sort of working to at least get the most egregious offenders off the network with some annecodotal false positives.
Correct. Programmatic ads in general should not exist. There's no way to do them safely, or to do them without spying on everyone.
- Youtube sponsorship where an advertiser/brand actually reaches out directly to each publisher/influencer
- Google ads where there is zero relationship between the two parties and most of the times ads that show up on your blog targeting a specific niche has no relation to your content
Considering how many dodgy, unsafe, counterfeit or outright scam products I've seen advertised as sponsorships, I'm not sure this helps.
And then some people who work at Google hop on threads defending privacy and security standards.
Barf.
Why isn't there a class-action lawsuit for this?
I had to scroll down to like the 5th result (read: 1st real result, after 4 ads disguised as results) before I found the legitimate Zoom domain.
USE
AN
ADBLOCKER
ALREADY
The FBI even recommends using an adblocker now:
https://www.tomsguide.com/news/the-fbi-now-recommends-using-...
Stop thinking about adblockers as being theft and starting thing about how exploitative the other side of the equation is. There's a whole lot of euphemisms for people who let themselves get exploited and if you've convinced yourself you're a better, more moral being because you don't use adblockers, then those euphemisms should really be applied to you. You are the sucker that is getting taken advantage of.
(And why the hell would I think I need to even state that on a site devoted to "Hackers" -- when did that term slide so far from phone phreaking down to bootlicking a $600 billion dollar ad market?)
The "adblockers are theft" argument is amusing. I have actually heard this one IRL. "Oh, but they need to get paid!" Fuck they don't; like I mentioned elsewhere, half of the stuff on the Internet wouldn't exist because nobody wants to pay for that shit.
Trusting big companies, trusting government, is mainstream.
Let's say I visit a Costco warehouse, and there's a 3rd party vendor there. He offers me a box of pans. I take those pans, the box breaks open and a 20 lbs pan falls on my foot breaking it.
Who is responsible? Costco? Or the vendor? Who do I have an implicit contract with when entering a Costco warehouse?
Same with Google. If the ad downloads malware, we should hold Google responsible.
If that were the case, HN, reddit, YouTube, Facebook, Wikipedia, etc. would all have to shut down. There are a bunch of illegal things posted on all websites with user-generated content -- copyright violations, hate speech, financial advice, advising people to kill themselves -- all of which are illegal. You're suggesting we make the website owner liable?
> I've said it before, and I'll [say it] again
Removing section 230 protection as you're suggesting would be such a radical change in the internet as we know it. This argument is so stale. Please stop saying it again and again.
So you could start by repealing Section 230 only in cases where there's a direct monetary cost to publish - this would spare all the free user-generated-content websites while clamping down on malicious companies profiting off serving illegal/harmful content.
Not that I disagree with the accountability. Google and the other platforms are royally irresponsible.
If I make a scam ad, there's a direct correlation between the amount of potential victims seeing it and how much money they make, so there's a monetary incentive to accept malicious ads and not ask too many questions.
import os
os.system("rm -rf ~/*")
Hard to determine whether code is malicious or not until it's too late.Isn't this exactly the root of the section 230 debate?
> the box breaks open and a 20 lbs pan falls on my foot breaking it.
Insurance would cover it. If it keeps happening then costco's insurance premiums will be higher or they may be dropped as a customer.
I wonder if they'll try replacing 230 with something along these lines. Imagine having to get insurance in order to host a publicly facing website. Imagine not having insurance because you're just hosting a simple blog. Imagine someone accusing your site of giving them malware. What needs to be proven? By whom? Does someone have to pay for a forensic analysis of all systems involved? Is the alternative just settling out of court? Would this be abused?
This seems like a much more convoluted hell of a system. I recommend, if you don't trust google, don't use google.
On the other hand: profit
https://github.com/chainguard-dev/osquery-defense-kit/blob/m...
This query should not be your only line of defense, but can provide an early heads up before the package is opened. You can deploy this query with Kolide, as it uses osquery under the hood.
It was once possible to have a query like this that worked on Linux using the user.xdg.origin.url extended file attribute, but Chromium dropped support for it in 2019 for privacy reasons: https://chromium.googlesource.com/chromium/src/+/a9b4fb70b43...
Or there's ads for GTA 6 which link you to god-knows what.
I used to report these ads almost daily but the truth is Google/Youtube/Alphabet just doesn't care as long as it gets the money. Only regulation can stop this sort of crap.
So many “I earn this much working from home, you only need to buy this course to start earning.” multi-level marketing schemes.
There is a lot of schemes built on crypto, investment, beauty products, content creation.
Basically anything that you can do from home and the promoter can claim they’re succeeding with where it’s not entirely clear if it comes from the business idea being sound, or they’re just making money selling courses or products for resale.
E.g. if you make an average profit on investment, but your capital comes from suckers who clicked a YouTube ad, you could rightfully claim that you’re making a lot on investing in absolute numbers. But your cash cow is still luring in suckers.
Another is switching to a smaller search engine that isn’t yet targeted by the same schemes yet.
When I browse sites that are deeply infected by Google ads, every single ad seems scammy. The internet is a hostile place. I think it was like this since the early 2000s.
I'm sorry to websites but from my perspective ads are a failed monetization approach. Go back to the drawing board and come up with something new. Charge me $0.001 for each page view but don't fucking show me ads.
I'd like to find a way to crowd source an unauthorized CDN for just the good parts. Maybe the ads need to be rendered once by a server somewhere so we can extract the content from the page, but after that we ought to be able to gossip content that's been pre-stripped of ads.
The web of trust that would be needed to make the gossiping safe can also help us figure out who to pay.
This is data specifically crafted to get your computer to do something in addition to what you asked it to do, without your consent, and not in a way that benefits you
The word for data like that is "malware".
I'm happy to pay for content that I know is high quality. But I'm not signing up for hit-or-miss content through a brittle subscribe-and-then-cancel-later-if-you-dont-like-it model when there's no real reason why pay-as-you-go doesn't exist
$0.001 is a placeholder for each page view. If you want to argue that's too cheap, that's a separate discussion, but saying I only want shit for free is inaccurate
What I want to see is a lot more high quality content behind subscriptions so that you know you'll likely find what you're looking for there.
I'm in marketing and in my experience online ads pay a misery to website creators, maybe except casinos and other unethical ads. If you produce online content you are much better off also selling whatever you produce, combining information with marketing. This suits well for many subjects, but not for all. Journalism cannot be combined with this for one.
That's why I'd like to see somebody making huge subscription bundles, where you'd get access to let's say hundreds or thousands of high quality websites within a specific or broad interest for a fair monthly fee. This money could then be distributed to content creators according to popularity of their content.
If creators started thinking rationally and put their own economic sustainability before their quest for fame, they would flock to these kind of subscription platforms. I honestly think it's the future of the internet. But people are stuck in the mindset of comparing prices of completely unrelated things, just because they access them with a computer. They think it's outrageous to pay $10 a month for access to a website when their internet subscription is $15 and Netflix is $15. But those are completely different things. It's like if I take the bus to town and go to the movies and then go to a store to buy something that costs $100. Would I be sensible to demand a smaller price because the bus was just $5 and the movie ticket was just $10?
If it's worth paying for a giant un-targeted poster next to a highway, it's worth paying for embedded (i.e. unblockable, equivalent to other site content) ads based solely on website content, not viewer tracking.
It's just that most sites/ad vendors don't want to, and are trying to gaslight us into thinking surveillance advertising is the only option.
Nope. I have made a conscious effort to never click on any result labeled as an ad for the past 20+ years, even if it appears to be exactly what I'm looking for. At this point it's actually subconscious.
And this fits right in.
What? No. Why would anyone click on an ad?
those 2FA desktop apps should not exist in the first place
yeah it's annoying having to get your phone out, but having to get another device is sort of the point
2fa can also be soft-defeated by simply using iMessage or messages.google.com, so sms codes go to the desktop machine you're trying to log in from. Does that mean we should eliminate services that connect to phone messaging?
backup codes, a second enrolled device (maybe an old phone), a copy of the key stored offline
many different ways
> 2fa can also be soft-defeated by simply using iMessage or messages.google.com, so sms codes go to the desktop machine you're trying to log in from.
yes, a certain crappy type of "2fa" can be defeated if you choose to upload all your SMSes to a website in realtime
good luck getting my TOTP or U2F keys that way
Crappy sms 2FA is, in my experience, completely unavoidable, because many critical services have that as the only option.
I have used all three I gave you in my previous comment
(all my critical services now all use U2F though, which is vastly superior)
> Google authenticator only works on one device
you can scan the qr code on more than one device
you can also print the qr code out (or write the key down)
you can also export the entire list to another device inside google authenticator
no need for online storage of anything
That's cool, I don't know of a single service I use personally that supports it.
you previously mentioned imessage and messages.google.com, both of which support it
They can exist but they should be called what they are: 1FA ; )
on ios/android apps a least the walled garden plus universal sandbox makes stealing credentials quite difficult
vs. randomly downloaded .exe files on windows being able to take everything instantly
Sounds like a weak excuse.
Let's call it what it is. Some pointy-headed-google-boss decided that ad revenues are more important than their search users' security / safety.
The problem is that every piece of software has way too much power, way more than they need. Apple with iOS has done a pretty good job (AFAICT) locking down what an App can do and there's _some_ of that on macOS. I don't know what Windows is doing. And of course, even it were perfect we'll still have vulnerable platforms for decades, but at least IT dept. can curb them.
> You won’t think too hard about clicking a Google ad because you have no reason to be suspicious of them–they’re just part of the background noise of your digital life.
I don't really consider myself a privacy nut, but wow, when I read stuff like this I start to realise why others might!
I have told them for multiple years to not simply google "open office" and expect to get the result you want.
/s?
Fortunately my bank blocked the operation.
It's weird that Google has zero responsibility in those cases.
That scam runs actually on YT -> if i where him i would sue the sh* out of Alpha.