TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Google Ads: An effective phishing delivery mechanism for over a decade

5 点作者 cloudyporpoise将近 2 年前

2 条评论

scrum-treats将近 2 年前
Oh, Google knows. They don&#x27;t seem to care. At all.<p>I can share some of what Google told me:<p>- Have you read our privacy and security resources?<p>- Have you updated your password?<p>- If you think that a crime has been committed, contact your local law enforcement.<p>- Please use Google Help Centers if you need help with a Google product.<p>So, you know, I took their advice. I contacted federal agencies and cybersecurity investigators. I detailed the vulnerabilities, and how each vulnerability is being exploited in multiple ways. Why? Over 2 billion people are impacted by Google&#x27;s negligence on this. Because Google Search is the default for iPhone Safari browser, the blast radius is even greater. So, Google is poisoning Google and Apple (and every other service that uses Google Search).<p>It&#x27;s Google&#x27;s arrogance about their own negligence that was most shocking to me. I just didn&#x27;t expect it. I sincerely believed Google maintained a baseline that was above this mark. Joke&#x27;s on me.<p>It&#x27;d be great if Google employees were required to take their own cybersecurity training on Coursera. Additionally, if Google could update their unit testing and integration testing regiments to include testing for these vulnerabilities (to ensure they are not reintroducing them), across services such as Search and Ads and JS and Tagger, that&#x27;d be... expected from a top corporation such as Google.<p>Additionally, if any Google employees can offer more meaningful guidance on how to report ongoing security vulnerabilities beyond the fluff I&#x27;ve been given please do share. I&#x27;m happy to file a formal report.
novoshield将近 2 年前
they DO, actually - compared to others (meta, for eg). they have bounty hunter rewards, all kinds of new developments. at least you can actually GET to a human response of some sort. but yes - when the &quot;system&quot; favours monopols, dont expect too much battling over your patronage