TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google will warn users when sites contain social engineering ads

151 pointsby PirateDaveabout 9 years ago

23 comments

tyingqabout 9 years ago
From the article: &quot;Others pretend to be “Download” or “Play” buttons, as if clicking them would provide access to the video content or stream the user had wanted. &quot;<p>These are actively being served through Google Adsense, right now.<p>Here&#x27;s a few example, live sites, where I see &quot;Download&quot; buttons in an ad, in a context that would be confusing.<p><a href="http:&#x2F;&#x2F;www.getpaint.net&#x2F;index.html" rel="nofollow">http:&#x2F;&#x2F;www.getpaint.net&#x2F;index.html</a><p><a href="http:&#x2F;&#x2F;downloads.tomsguide.com&#x2F;PaintNET,0301-4883.html" rel="nofollow">http:&#x2F;&#x2F;downloads.tomsguide.com&#x2F;PaintNET,0301-4883.html</a><p><a href="http:&#x2F;&#x2F;filehippo.com&#x2F;download_paint.net&#x2F;" rel="nofollow">http:&#x2F;&#x2F;filehippo.com&#x2F;download_paint.net&#x2F;</a>
评论 #11482521 未加载
评论 #11482819 未加载
评论 #11482377 未加载
评论 #11484688 未加载
评论 #11483125 未加载
评论 #11482350 未加载
FilterSweepabout 9 years ago
From Wikipedia[0]:<p>&gt; <i>Social engineering, in the context of information security, refers to psychological manipulation of people into performing actions or divulging confidential information. A type of confidence trick for the purpose of information gathering, fraud, or system access, it differs from a traditional &quot;con&quot; in that it is often one of many steps in a more complex fraud scheme.</i><p>Honest question: When you take a look at the &quot;manipulation of people into divulging confidential information&quot; part, wouldn&#x27;t this, by definition, incriminate the vast majority of the modern (&quot;Internet 2.0&quot;) web, WRT unremovable-cookies, tracking, &quot;analytics&quot;, and so forth?<p>I fully admit there is a difference between downloading a random AdobeFlashPlayerUpdate.exe or MacKeeperApp.dmg from a malicious site and having all your personal data and information about you sent off to a 3rd party company......but where do we(or Google, here) draw the line?<p>Just last week, Facebook started gleaning contacts from my phone and injecting them into the &quot;People you may know&quot; page - these were people I did NOT want on my Facebook - ranging from business contacts to tinder matches. I knew this was (sadly) standard behavior for users of the Facebook App, or users of &quot;Facebook for Mobile&quot;, but I have never given my phone number to facebook, not once, and I only access it via a mobile browser.<p>Is it social engineering to see my recent searches in the Amazon app on mobile reposted on Facebook on my desktop Web browser?<p>[0]: <a href="https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Social_engineering_(security)" rel="nofollow">https:&#x2F;&#x2F;en.wikipedia.org&#x2F;wiki&#x2F;Social_engineering_(security)</a>
评论 #11481447 未加载
bradorabout 9 years ago
It&#x27;s worth remembering that this is the pain point Adsense and Adwords originally solved for by only allowing a title, 2 lines of text, and a URL. And they did it so well they disrupted&#x2F;killed a mutli-billion dollar industry of online flash ads practically overnight.<p>And then they become that problem by taking on flash ads a few years ago.
评论 #11486292 未加载
评论 #11484597 未加载
6stringmercabout 9 years ago
What about on their own sites? Like YouTube?<p>Yesterday I just saw a banner ad on a YouTube music video - from Google AdWords - that was alerting me I may need some &quot;Drivers&quot; for my machine and I should get them from some suspicious company called TechSoft or RealSoft or something like that. It was the &quot;dying car alarm drops a sick beat&quot; extended remix if that&#x27;s of any interest.<p>I did take a screenshot but don&#x27;t have it handy right now.
评论 #11482135 未加载
putasideabout 9 years ago
The only time I have been bothered with these kind of ads, is when DoubleClick serves me those on my Android.<p>DoubleClick certainly is not the worst offender of this, but they are the biggest player. Is Google going to block&#x2F;penalize the sites of their own customers? That would feel weird. Is Google going to block&#x2F;penalize the sites of their competitors? That would also feel weird.
评论 #11481349 未加载
评论 #11481755 未加载
评论 #11483389 未加载
josephjrobisonabout 9 years ago
And Google&#x27;s own Adwords ads looking more an more like organic search results and pushing the organic results further down the page isn&#x27;t social engineering at all, right?
评论 #11481193 未加载
michael_habout 9 years ago
Why stop there? When a site contains the offending ads, push them down to page four of the results. The ads will disappear in a matter of days.
评论 #11485243 未加载
评论 #11482610 未加载
评论 #11482343 未加载
ilyanepabout 9 years ago
Can&#x27;t wait until Google has to block websites using AdSense because they themselves served such an ad through a reseller.<p>...or until they don&#x27;t and have an Anti-Trust suit on their hands.
elcapitanabout 9 years ago
I didn&#x27;t even know that there are ads that <i>don&#x27;t</i> involve social engineering.
ikeboyabout 9 years ago
&gt;[Update: Google published this news today on its corporate blog, but this was previously announced earlier this year. We’ve asked Google to clarify why it was republished, if that was in error, or if it represents any changes since the first announcement.]<p>This was previously discussed at <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=11032270" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=11032270</a>.
评论 #11482201 未加载
diegorbaqueroabout 9 years ago
I&#x27;m not saying an ad-blocker IS the solution, but it works on blocking not only ads but making websites faster and safer.
评论 #11482631 未加载
blaze33about 9 years ago
Well I block ads on my desktop so I&#x27;m not really seeing fake &quot;download&quot; buttons that often. On the other end what really bothers me on mobile (using the latest chrome) is ads automatically redirecting me to another site, happens quite regularly when I browse Google news. I don&#x27;t really know if those ads use an exploit of some sort or if they consider I&#x27;ve clicked the ad when I only tried scrolling the page with my finger but that should clearly be checked. And it happens on well known newspapers websites, not that I was browsing some obscure shady part of the web...
spriggan3about 9 years ago
Will they do that on their own sites too ? like youtube or blogger ? because yes, I got plenty of &quot;Your computer is infected by a virus, Please call Microsoft hotline&quot; popups from those.
评论 #11482530 未加载
cha5mabout 9 years ago
What hypocrites <a href="http:&#x2F;&#x2F;imgur.com&#x2F;3Emyw5y" rel="nofollow">http:&#x2F;&#x2F;imgur.com&#x2F;3Emyw5y</a>
MichaelGGabout 9 years ago
That&#x27;s rich, coming from them. When I used mobile apps with ads, the majority seemed to be fake &quot;update battery driver&quot;&#x2F;&quot;uninstall virus&quot; type nonsense. In flashing red and yellow.
fireworks10about 9 years ago
I see this warning in effect on <a href="http:&#x2F;&#x2F;kat.cr" rel="nofollow">http:&#x2F;&#x2F;kat.cr</a> in Chrome:<p><pre><code> Deceptive site ahead Attackers on kat.cr may trick you into doing something dangerous like installing software or revealing your personal information (for example, passwords, phone numbers, or credit cards).</code></pre>
JamilDabout 9 years ago
Since sites like this are so ubiquitous, I wonder if users will see warnings like this so often that they&#x27;ll start to ignore them and just click &quot;proceed&quot; without thinking.<p>It&#x27;s definitely a step forward in the right direction, provided Google Adsense, well, adheres to their own company&#x27;s guidelines…
dfar1about 9 years ago
This is a good start to solve an old problem. However they need to start filtering out their own ads. I don&#x27;t know which is easier, catch them before it goes live, or after, but either way... that&#x27;s something in the right direction.
chinathrowabout 9 years ago
Why warn? Why not simply drop&#x2F;block them and notify the ad network&#x2F;ad buyer?
评论 #11482641 未加载
jevinskieabout 9 years ago
Hmm... I just saw this mess on Youtube today. An &quot;Ads by Google&quot; ad for some malware.<p><a href="http:&#x2F;&#x2F;i.imgur.com&#x2F;vQkjZWU.jpg" rel="nofollow">http:&#x2F;&#x2F;i.imgur.com&#x2F;vQkjZWU.jpg</a>
Strilancabout 9 years ago
They count fake download buttons as social engineering. Excellent.
评论 #11481937 未加载
gueloabout 9 years ago
I&#x27;d rather my adblocker deal with these instead of my browser.
nxzeroabout 9 years ago
Most people don&#x27;t realize that Google&#x27;s &quot;Safe Browser&quot; sends via Chrome &amp; Firefox the URL of ever single URL you visit to Google; as far as I&#x27;m able to tell.
评论 #11482013 未加载