TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Google serving sponsored link to Homebrew site clone with malware

53 pointsby carlos-menezes4 months ago

7 comments

__jonas4 months ago
How is it possible that in this screenshot, the URL shown on the sponsored result &#x2F; ad is &quot;<a href="https:&#x2F;&#x2F;www.brew.sh" rel="nofollow">https:&#x2F;&#x2F;www.brew.sh</a>&quot;?<p>Can a Google search ad display a different value there than the actual origin of the page?
评论 #42768936 未加载
评论 #42768901 未加载
评论 #42768919 未加载
bcye4 months ago
I don&#x27;t get what non-malicious reason there would be for not automatically verifying domain ownership of display urls as an advertising network. The advertiser is highly likely to already have a Search Console account in which they&#x27;d have had to verify it, and URL verification is easily done by all kinds of systems via meta tags, CNAME or TXT entries, etc. Why not for ads?
评论 #42769036 未加载
eipi10_hn4 months ago
Every time there&#x27;s this kind of news, there&#x27;s always other comments with similar news: <a href="https:&#x2F;&#x2F;x.com&#x2F;alexrozanski&#x2F;status&#x2F;1881043544204599330" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;alexrozanski&#x2F;status&#x2F;1881043544204599330</a> (or <a href="https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Bitwarden&#x2F;comments&#x2F;1cwc0r9&#x2F;caution_a_sponsored_google_head_result_for&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.reddit.com&#x2F;r&#x2F;Bitwarden&#x2F;comments&#x2F;1cwc0r9&#x2F;caution_...</a>)<p>And then some people here attacked content blocker users with:<p>&gt; Why would I, as a developer whose income stream is based on advertising, intentionally cater to users who are costing me money?<p>&gt; you&#x27;re destroying the open web<p>If even the FBI calls out your industry[1], sorry, your AdTech industry, your source of income is beyond broken now.<p>[1]: <a href="https:&#x2F;&#x2F;www.ic3.gov&#x2F;PSA&#x2F;2022&#x2F;PSA221221" rel="nofollow">https:&#x2F;&#x2F;www.ic3.gov&#x2F;PSA&#x2F;2022&#x2F;PSA221221</a>
sevenseacat4 months ago
Ugh, I&#x27;ve seen this before with Todoist. I got as far as downloading the app package before realizing it was spelt incorrectly, and so was the domain. (Though the domain was correct in the ad, and the ad was identical to the actual search result below it.)<p>It has to be deliberate by Google at this point.
drtgh4 months ago
SEO is also damaging the search engines, and IMHO should be considered as a viral activity.<p>It is not uncommon to find a legitimate software site on the second page of a search, while all the hits on the first page are crap, often with malware added.
评论 #42768696 未加载
arcfour4 months ago
That has to be the most suspicious possible alternative they could have chosen to &quot;blindly pipe curl into bash,&quot; which most developers would probably run without a second thought.
beginning_end4 months ago
Any advice on what to do if you might be a victim to this?
评论 #42767699 未加载
评论 #42778380 未加载
评论 #42767547 未加载