HNHacker News
TopNewBestAskShowJobs

j027

29 karma · joined January 28, 2026

submissionscomments
j027··on Why is Google still serving dodgy ads?
Another major issue is google safe browsing whitelists many of these subdomains that the attackers like to host their scam pages on.

As a result, even though "Enhanced" safe browsing can use Gemini Nano to do client side detection of scams and then flag it in google safe browsing for everyone, the entire domain and all subdomains are whitelisted, so that detection never seems to actually fire. https://blog.google/security/using-ai-to-stop-tech-support-s...

I'm not sure which domains this applies to, but it seems to apply to most of the domains that these scammers actually like to use.

j027··on Why is Google still serving dodgy ads?
Wow I am surprised to see this.

I created a tool that automatically follows ads to try to find scams.

But that was usually reserved to typosquat domain ads or ads on porn websites. I didn't know scammers used normal page ads too.

I know tech support scams used to use google search ads, but I don't think they do that as much anymore, so maybe they have moved onto things like adsense.

These scammers usually do IP address checks to check for residential IP before showing the scam, and some also do some basic fingerprinting checks, so that is how they get past detection. That said, it shouldn't be too difficult for google to do some better checks if they actually cared.

j027··on Residential Proxies Are a National Security Threat
I don’t understand this being a “national security” threat.

Besides, mobile proxies exist which work differently. All you need is a mobile data plan that you run a proxy server on. It allows for easy IP rotation and since it’s a pool shared with other customers you cannot easily block it. This is because of things like CGNAT.

IP rotation is easy because reconnecting to the network gives you a new IP address.

Static residential proxies also are a thing, even if they are less effective sometimes.

j027··on An update on residential proxies and the scraper situation
Depending on the IP reputation as well as the kind of IP address you have, this can happen.

Google also prefers if you have a Google account logged in.

j027··on Anthropic says Alibaba illicitly extracted Claude AI model capabilities
Phone verification services exist to give you a real number for the purpose of passing this kind of verification.

They even have APIs for these services. They make money since they can use the same number to verify different things.

j027··on Exit IP VPN servers mitigation rollout
This sounds like some LLM to me
j027··on Google broke reCAPTCHA for de-googled Android users
To add onto this, cloudflare switched away from recaptcha a while ago. https://blog.cloudflare.com/moving-from-recaptcha-to-hcaptch...

I think they now use their own Cloudflare turnstile if I remember correctly, but back then they switched to hcaptcha.

j027··on Google broke reCAPTCHA for de-googled Android users
You can still use the audio captcha, but I’m not sure how long that’ll be around.
j027··on Canvas is down as ShinyHunters threatens to leak schools’ data
Canvas seems like it’s not that great. But if you then use Blackboard Ultra it makes canvas look amazing.
j027··on Hunting AitM Phishing Infrastructure Using Certificate Transparency
OP here. My university was targeted by a recent phishing attack, and these are my findings. I hope this helps others, but this was my first experience with an Adversary in the Middle (AitM) attack.