And they refuse to act on numerous reports of the same issue, over and over, since 10 years... And the Safebrowsing initiative is a joke, since they always say "it is fine".
Badware people are often one step in advance...
And they refuse to act on numerous reports of the same issue, over and over, since 10 years... And the Safebrowsing initiative is a joke, since they always say "it is fine".
Badware people are often one step in advance...
FWIW, they're acting all the time. It's whack-a-mole with the malware providers.
https://old.reddit.com/r/blender/comments/105tht4/be_aware_o...
... but what I suspect happened is they got reports, took a few days to down the ad, the ad goes up under another URL, they get reports, take a few days to down the ad, etc. The malware vendors are tenacious and have a pretty much bottomless well of Turking for CAPTCHAs and backup accounts.
ETA: none of this to imply that Google shouldn't fix the problem or that they don't need to divert more resources to it (if for no other reason than it does actually threaten their bottom line if they can't get on top of it and people conclude it's not worth it to keep recommending Google search to naive users). But the problem's generally harder to fix than most people believe.
That said, it’s pretty common to get a competitor ad above the top search result.
Here's how the vetting you're imagining works:
1. The automated system goes to the advertised site. But Google's IPs are public knowledge, so the site vends a "safe" version to Google's checkers.
2. If Google sends a human being? Same story. That human's coming from a Google IP.
3. Google has a small set of non-Google IPs that they privately use for checking. This process seems to have broken down. My guess is malvertisers have caught wise and have managed to build a good list of those IPs to cloak against Google's back- and side-channel verifies too.
In terms of the actual ad copy: I suspect a lot of that is checked automatically, and the rest is often checked by contractors. So you're trying to solve the "Build an AI to understand when something is confusing" problem. There's probably room for improvement here, but it's not as surprising as I wish it were that stuff slips through the cracks at that layer.
You're telling me that even though attackers of various sophistication are able to get clean, residential IPs all the time for nefarious purposes, Google can't do the same? Come on. It's not that they can't, it's that they don't care.
I see some shady ads right now via adsense on https://getpaint.net
Screenshot: https://imgur.com/a/WRvrddy
Someone will report them, and they will go away, then reappear from a different Adwords account. They don't seem to have a smarter heuristic sort of thing to reject ads that only say, for example "Download Now".
... but if you have any ideas they haven't tried, I suspect they'd love to hear about it in a job interview for any of the openings for ad quality SWE.
The malware continuing to appear isn't sufficient evidence. Malware moves hosts and ad accounts all the time.
ETA: from the article itself, in 2021 Google "Removed over 3.4 billion ads, restricted over 5.7 billion ads and suspended over 5.6 million advertiser accounts." That's a ton of action, but AdWords alone also serves 29 billion ad impressions a day. It doesn't take more than a few bad actors slipping through the cracks to get seen (and at these orders of magnitude, "a few" is still "millions." Completely impractical for human hand-review).
It's clear this will never be prioritized without regulation as scammers money is as good as anyone else's and open source projects cannot afford to sue Google to force action.
I think this really requires governments to step in. I mean one could easily argue that Google is facilitating fraud here, so maybe they should be liable?
Toxic waste doesn't try and hide from the litmus paper or the geiger counter.
There is no reason they have to serve 30 billion impressions a day. If vetting takes that down to 1 billion, that's fine. Lower the volumes (and raise the prices to fund manual vetting) until the problem is resolved.
Toxic waste disposal is a solved problem thanks to (enforced!) regulations that force companies to do so under threat of heavy penalties, not altruism or the fact that the waste doesn't hide from a Geiger counter. We need the same for online advertising.
But even if we accept that there is a downside, it's clearly not enough because this problem keeps happening again and again. Whatever downside there is needs to be increased by a few orders of magnitude for them to take the problem seriously.
There is one thing Google could do that would eliminate the vast majority of this sort of thing. They could require a manual review of all ads and advertisers before putting each ad into the pool. Like traditional media does.
But that doesn't scale, so it's not going to happen. But avoiding something because it doesn't scale is a deliberate choice, and I think it's fair to consider Google to be at fault for allowing this state of affairs to continue as it is.
Or, alternatively, should there be a few tens of thousands of firms allowed to advertise on the Internet and the rest of us can just pound sand?
(... actually, now that I think that "out loud," a distributed trust model would be an interesting idea. Google, instead of vetting ads, could vet trusted ad resellers, and knock entire resellers off the network that failed to do due diligence. The resellers would be responsible for policing their various houses and if you didn't like the terms one provided you could go to another. This is, perhaps, one of those situations where more middlemen would be desirable).
The real issue, IMO, is that Google's business model is just fundamentally bad. But Google is large enough that it doesn't matter. They're like a large industrial polluter poisoning the lands and arguing that there's nothing they can effectively do about it because addressing the problem would be bad for their business.
Firefox advertises at the top of "download browser." Should we cede their ability to be found to whoever Google thinks should be at the top of that organic result? Because by user numbers alone, it probably won't be Firefox!
> because of a (statistically) few bad actors?
It doesn't actually matter how many or few bad actors there are. What matters is how much harm is being done.
I'm not sure what your point is about Firefox, but in general, it doesn't matter if mitigating the harm Google's ad system does adversely affects Firefox or any other advertiser.
I'm not sure what consent means if it doesn't mean "user clicked on a result after asking Google for results." The backstop here is the user doesn't come back because they got screwed by Google, not that some third-party makes that decision for people.
But yes, I suspect if Google can't get on top of this problem they'll lose their leadership position in search.
First, I'm talking about ads, not search results. Although Google conflates the two as much as they can get away with, and people often get confused as to which is which.
I can't imagine how clicking on an ad can be interpreted as consent to being exposed to malware. In order to be considered "consent", the person has to be fully and accurately informed of what they're being asked to consent to.
> The backstop here is the user doesn't come back because they got screwed by Google
I truly wish we lived in a world where that could be expected.
Google dethroned search vendors before them and they aren't bulletproof. If they are, might as well pack up DDG and everything else right now. Shut off the servers and decrease the greenhouse gas emissions, right?
No, I think the backstop here is that DDG has a wonderful opportunity to be the search engine where you don't have to worry about getting vended malware via an ad above the first organic result.
Why shouldn't advertisers have to clear the same hurdle as opening a bank account in most western countries?
All ads on major DSPs already require approval before they can run. Advertiser accounts too, especially at scale. While there are plenty of technical openings for fraud and malware, the vast majority is from known actors that can be resolved through business practices.
A trillion-dollar megacorporation with hundreds of thousands of employees has more than enough resources to handle this. The reason it doesn't is because of the flow of money and incentives across the vast supply chain from advertisers and agencies to vendors and publishers.
But the opposing operators get more and more sophisticated, countermeasures that work to half decade ago get circumvented, and the arms race continues.
Requiring bank-scale KYC on top of that to also work with the advertisers would cut the 4 million advertisers Google currently serves down to a tiny fraction of that (if for no other reason than they don't have infrastructure to background-vet 4 million customers; they don't currently).
Perhaps this is the right approach. It would end the days of being able to set up an advertising account in a few hours. Perhaps that's not needed anymore.
(This would, of course, mean people giving even more PII to Google. However one feels about that).
Yes that's the problem.
> "Requiring bank-scale KYC..."
Nobody said that. The KYC part is an analogy to the financial industry to use procedures to screen out bad actors. But it doesn't need the same requirements.
> " they don't have infrastructure to background-vet 4 million customers"
KYC is not difficult. Again, banks and finance companies which are far smaller than Google do this all the time, for all of their customers and anyone involved in transactions. This is 100s of millions of clients.
> "Perhaps this is the right approach."
This approach is far more nuanced than the binary outcome you're interpreting. There are ad and account approvals already. There are different scales requiring different support and sales already. Having more intensive checks as the spending scales is a very simple and effective strategy that can be applied today.
The company doesn't care about the number of customers, it cares about the revenue against potential risk (just like every other every business), and currently the risk is acceptable for these ads and advertisers to continue.
That ability was never needed and was never a good idea.
By the way, this is already done since Google does check advertiser accounts against various sanctions and watchlists as part of dosing business in every country they operate in.
The point is that it’s not a resource or scale issue (as you keep arguing), but a profit and incentives issue as I said before.
Countermeasures aren't needed if adtech just stopped working with known bad actors and recognizable malpractices.
True, but it looks to me like adtech depends on working with bad actors and mostly ignoring bad practices. It's one of the reasons why I consider the adtech industry itself to be malicious.
But Google had to down on the order of some million accounts in 2021. The crawlers hit rate is probably not enough to keep up with this problem.
Charge Google a fine every time they serve a malicious ad and they will fix it.
Nonetheless, all of my comments are engaging in wishful thinking. Google is a monster and I'm not sure anyone can tame it anytime soon.
But as policy they want to force companies to pay for clicks to their own brands.
Untrue, I can give you quite a few who have been there forever, by private message, if you want.
The longer he keeps them private and confirms they still exist, the more damning the evidence against Google's lies becomes.
This suggests to me that what people are generally seeing is churn, not lack of action (i.e. individual bad actors get taken out but they're up again soon).
There’s malware above things like VLC, Zoom, Firefox, Malwarebytes, Teamviewer, all the time. For the better part of a decade, if not longer.
So it's probably whack-a-mole problems.
In the political dimension, the issue could be addressed by taking advertising away from the people as a service that is generally providable and restricting the right to advertise online to a few elite who have been vetted.
The power of advertising (as in buying influence) should absolutely require vetting and approvals. This is already done today, and comes in many layers as scale and budgets increase. The problem is profits that do not incentivize stopping these ads effectively.
In some way these scores could effect the search result ads that are shown.
Not saying Google necessarily would/should try this but some other smaller ad/search network.
I think it probably would work about the same as Uber/Airbnb, etc. - which is to say sort of working to at least get the most egregious offenders off the network with some annecodotal false positives.
Correct. Programmatic ads in general should not exist. There's no way to do them safely, or to do them without spying on everyone.
- Youtube sponsorship where an advertiser/brand actually reaches out directly to each publisher/influencer
- Google ads where there is zero relationship between the two parties and most of the times ads that show up on your blog targeting a specific niche has no relation to your content
Considering how many dodgy, unsafe, counterfeit or outright scam products I've seen advertised as sponsorships, I'm not sure this helps.
And then some people who work at Google hop on threads defending privacy and security standards.
Barf.
Why isn't there a class-action lawsuit for this?