Big Tech's role in enabling link fraud
eligrey.com
eligrey.com
But I think my favorite is that I have messages that Twitter classified as spam, and that I have reported these profiles, but months later they still exist. Profiles that are even clones![1] What's even more funny is that when I originally got the message from this person twitter would suggest similar profiles and I could see 30 others with the exact same profile picture, all created in the same month, all without any activity, and all with the same pattern of name + random number string.
I agree with the article's point, but I just want to point out here that there's even a far lower bar that these platforms are failing to achieve. If I'm reporting 5 people a week and those profiles still exist months later, clearly the platform is doing something wrong.
[0] https://twitter.com/Eleanor1541800, https://twitter.com/Eva626692385410, https://twitter.com/Serenity1260229
[1] https://twitter.com/ReneeYoung71651, https://twitter.com/Jessica77414656, https://twitter.com/Jessica43172228
Wonder why HN doesn't have the same spam problem? Because Dang actually cares about the site's content quality and not about quarterly user growth :)
It all stems from the "free speech" unwillingness to ban accounts, and gutting the account-banning teams. As well as the very real problem that some of the big grifters that he loves on the platform also love their inflated follower counts.
Ofcourse no actual real life user wants to inundated with spam, scams and advertising.
I think he believed it would be an easy project and a funny meme to own it, and it will soon be repossessed by Morgan Stanley.
They each allow advertisers to spoof links with unverified "vanity URLs", laundering trust in their systems, while simultaneously deflecting blame onto advertisers when these mechanisms are exploited for fraud.
You can help raise awareness by resharing/rehosting my message on social media and reaching out to your elected government officials. The systemic enablement of link fraud by Big Tech needs to end.
Examples help to explain it to other people who need to know.
Ad shows up:
Text: Check Your [Retailer] Gift Card
Display URL: https://www.[retailer].com/
Click the ad, get redirected to the malicious site: https://www.[retailer]-gift-card.com/Ads always have redirection involved, typically through a third party, to track ROI, conversions, etc. How the attackers take advantage of this is their redirection redirects to the real site if it's the Googlebot or from an IP range known to be owned/used by Google (or other filtering based on location, language, etc). If it's not, it redirects to the malicious site.
One solution is that the first hop in the chain has to match the domain of the display URL. That at least somewhat shows you can have a redirection that you control on the display domain. Of course, there could be an open redirect on that display domain, but those are becoming increasingly rare.
Work for a large retailer and we dealt with this a lot a year or two ago. Built custom monitoring to detect it and we sent gobs of data back to Google showing it happening. Still pops up every once in a while, but they've made some improvements in their detection/prevention.
I can't find a single sponsored result on Google for your search query.
Checking Jimmy John's, Subway, and Whole Foods, they are all seemingly targeted by shady non-official gift card checkers, which for all I know harvest gift cards. But none of these are sponsored, and only Whole Foods' target from Buyatab was a first result.
So I am still confused about a concrete, real example. Like I understand it exists, but maybe someone should share a real example.
I tried:
target gift card balance
chilis gift card balance
kohls gift card balance
sephora gift card balance
… in each case, the first result was to the actual retailer. (I clicked it, just to be sure; in each case, I went to what appeared to be [retailer].com, and the legitimate site of the owner of that brand.) In each case, the result was an organic (i.e., non-ad) result; there were no ads on these queries. (I do not have an adblocker that would block these, but regardless, I went into private mode anyways, which is configured to disable uBlock.)My post was more to illustrate an example of how this had been done in the past and briefly explain the tactics of how the threat actors were able to do it.
To be fair, there are other companies that are not helping this problem. This is the legit official website for a MasterCard giftcard[0]. Seriously!?! Why is there a whole new fucking domain? Mastercard.com redirects to mastercard.us. That's weird enough but you're telling me we can't have mastercard.{com,us}/giftcard or giftcard.mastercard.{com,us}?
The reason I bring this up is because legitimate companies are teaching users bad behavior and it makes it difficult for them to develop good bullshit/spam detection. Let's even check these two websites and their whois: [1] [2]. What here tells me which one is legit? You might go check the cert and find "This website does not supply ownership information." in the blurb but unless you look at the actual cert it says the organization. So even legit companies are not making it easy to identify them. Or you might even get antagonistic behavior like target does[3], which will redirect you to a login page. Yes... a login page for a gift card... what a fucking joke. They act like they want their customers to get hacked.
I'm not saying Google and the social media companies are not responsible (they definitely have some) but just saying that the legitimate companies create an environment that makes it easy for spammers and scammers to deceive people. Normal people are not going to have the means to actually verify the validity of a website and legitimate websites aren't even making attempts to make this easy, arguably they are just creating more noise.
[0] https://www.mastercardgiftcard.com/
[1] https://www.walmart.com/account/giftcards/balance -- https://www.whois.com/whois/walmart.com
[2] https://www.walmartgift.com/wmgift -- https://www.whois.com/whois/walmartgift.com
Does anyone know why this isn't the default? I can't think of any legitimate reason why a brand wouldn't want to have their true domain displayed?
If they want to redirect to a third-party they can implement it on their own website.
But some people use services like ClickCease which helps mitigate click fraud (e.g. if your competitor clicks your ad over and over, ClickCease and similar services can automatically exclude their IP so they can’t click your ads.. or at least that’s the pitch)
Some of these services work by being the first hop in the redirect chain.
I was under the impression that Google whitelists services allowed to be used for redirects.
Since their customers are the people running the trackers and giving them money, they listen to the advertisers and not the cattle who are clicking on ads.
I think many people think that advertising is "Kohl's goes to Google and buys an ad" - it's much more often Kohls hires an agency that hires an agency that manages a independent company that fills out the actual ads, and they all want to track their piece of the pie.
In your scenario, the attacker is creating ads pretending to be the [retailer]?
A 2022 law now forbids people with paid numbers to redirect to 0800 free to call numbers.
I'm really curious how much money this google scam made. If I know 5 people who spend 20-40 euro on it there must be many thousands of victims.
The ads spoofed things like the tax office. First thing in the morning that number alone gets thousands of calls. One just types "tax office phone" (in dutch) in the search box and the ad says 0800-0543 You click on it and get the tax office. You might have to wait a bit because they are very patient and try to answer all your questions to the best of their ability, put you on hold to ask around etc Some people must repeatedly call the number for more than a hour in the same month. They wont notice anything until the bill comes in.
Right now you can spoof (just as far as the URL displayed in an anchor tag) the account to be whatever you like:
Example:
https://twitter.com/elonmusk/status/1745190441539293271
This will redirect you to the following, but as content within a tweet, it will look like a legit post from Elon. Crypto-scams are using this in every single post.
https://support.google.com/google-ads/answer/6246601?hl=en
The author paints the picture that bad actors can just use any URL when that does not seem to be the case.
This policy is fundamentally impossible to enforce without domain ownership verification. 'It is against our policy' isn't exactly a good excuse when said policy isn't technically enforceable.
Google practices sampled URL resolution (which is insufficient as explained in my blog post) and does not currently require domain ownership verification for the use of vanity URLs.
These platforms operate more like oligarch crime lords than friends of society. There's no "free market" solution to fleecing the public, it's lucrative and all the players participate in it.
Actual free market is a myth.
[1] https://www.bleepingcomputer.com/news/security/linkedin-smar...
Big Tech is deflecting blame by pretending that these problems (that they also made) cannot be solved. Government agencies believe these claims, which results in situations like the FBI asking you to install an adblocker.
Also, thank you for noting the formatting error in my previous article. I just fixed it.