Google Targets Fake "Download" and "Play" Buttons (torrentfreak.com) 117
AmiMoJo writes: Google says it will go to war against the fake 'download' and 'play' buttons that attempt to deceive users on file-sharing and other popular sites. According to a new announcement from the company titled 'No More Deceptive Download Buttons', Google says it will expand its eight-year-old Safe Browsing initiative to target some of the problems highlighted above. 'You may have encountered social engineering in a deceptive download button, or an image ad that falsely claims your system is out of date. Today, we're expanding Safe Browsing protection to protect you from such deceptive embedded content, like social engineering ads,' the company says.
Good (Score:2)
Some sites get ridiculous with that.
Re:Good (Score:5, Insightful)
SOME!?
More like nearly ALL!
I've seen download sites for FOSS software have a lot of this crap. It gets confusing for me as an IT professional sometimes to figure out the legit download links, I can't imagine how normal computer users manage to navigate the hazardous waters long enough to actually get a legit non virus laden download. Then you have even legit downloads from massive companies filled with toolbars (like adobe reader and flash).
Like shark infested water. Hopefully this move will do some good
Re: (Score:3)
IMGBurn. Not FOSS, but freeware. There's even ads on their site with the IMGBurn icon and a download button but they are for PC Mechanic.
Re: (Score:2)
I still use it myself, but I'm done recommending it to anyone. There's no alternative I like and it's relatively full-featured.
Re: (Score:2)
True. The only safe ways of installing it are:
-Portable install
-Ninite
-Disable internet access / set dummy proxy during install. It will skip past all the "offers" tabs.
Re: (Score:2)
Try installing it through Ninite. It's a fresh computer set up person's dream. Check the software you want, download the installer, and BOOM all installed, no crapware, no having to click "I accept" repeatedly.
Brilliant little tool.
Re: (Score:2)
It would sure beat the zillion declines/skips/noIdontwantyourfuckingcrapware buttons I clicked. And they get so fucking deceptive that it's sometimes difficult to tell which button opts out rather than really says Hahahagotyafucker!
On the other hand, I make plenty of weed money off my friends who always use Express Install (Recommended)!
So the evil twin inside me tells me not to recommend it to my friends....and I think the good guy is passed out...what
Re: Good (Score:1)
Sourceforge user?
Download Now (Score:4, Insightful)
|\
|--\
|----\ Click to start
|----/ DOWNLOAD
|--/
|/
Re: (Score:3)
Your link is broken.
Re: (Score:3)
Re: (Score:3)
To be aware of what the average user sees?
Re: (Score:3)
Adblockers don't stop this rubbish. yet
Re: (Score:1)
Sometimes they do. I recall reading people complain about the large misleading DOWNLOAD buttons on SourceForge, and I was left wondering what the hell they were talking about. Turns out Adblock had a default filter to eliminate those things.
Re:Good (Score:5, Interesting)
I agree. There are tons of fake download links on otherwise reputable sites, there are gray area sites like TPB where you have to be careful what you click, and there are tons of fake download sites where none of the links are legitimate at all. Try Googling for "[random device] driver" and you get many dozens of bullshit SEO'd sites where all the links point to some EXE full of who-knows-what. I hope they're going to combat all three categories.
As an aside, I wonder if SourceForge will get penalized...
Re:Good (Score:4, Informative)
SourceForge will likely be fixed, there was another Slashdot story on this.
Re: (Score:2)
Now I wonder whether Sourceforge's new or previous owners were aware of this before the official announcement.
Re: (Score:2)
Re: (Score:2)
Hence, "before the official announcement". It wouldn't surprise me if Dice had heard of this policy weeks ago, perhaps as a friendly warning, and decided to sell before they got hammered.
Re: (Score:2)
Re: (Score:3)
That's surprising. I just went there as a test with a browser that had no adblocker or script blocking installed, and sure enough, the site popped open a page telling me some critical software was out of date, trying to trick me into upgrading.
Honestly, I think Google's a little scared by the advent of adblockers, which also tend to both implicitly and explictly double as malware blockers. I see this as a move by them to make web browsing safer without having to resort to installing ad blockers. They can
Re: (Score:1)
Not just sites
+------+
| Play |
+------+
I heard it happens in the comments of sites, too!
+----------+
| Download |
+----------+
How many years for google to notice scammers? (Score:3)
New subject question about how long, the answer is "The google don't care, just like the honey badger." Or you could reword it in terms of the google's new motto: "All your attention are belong to us."
However, the post by OverlordQ that I'm responding to said:
Some sites get ridiculous with that.
No, it is NOT the websites or even the app, though there are things an app developer can do that can make it easier or harder for scammers to use that sort of misleading ad. The REAL problem is that the google don't care about scams or the victims ther
Re: (Score:3)
How would this work? (Score:2)
I get it if those ads are part of Google's network, but they rarely are. How would Google target them (in Chrome or whatever) when they're basically just images, unless they do some kind of image parsing for literally every image that loads, in which case, bye CPU cycles.
Re-purpose (Score:5, Funny)
How would Google target them
You know that 20% of free project time Google employees get? Yeah, now it's looking for download button images.
It's not even like they lose anything as they only tell the Google workers that were surfing porn anyway to save off URL's as they browse.
Re: (Score:2)
Re: (Score:2)
Did you miss the memo? Google Owns the Internet. They can do anything.
Re: (Score:2)
They may add an ad-blocker to Chrome ... to block and ad that is not coming from Google.
Re: (Score:2)
... Ghostery. Solves the same problem, but in Chrome. And I like Chrome more than I do Firefox.
Re:How would this work? (Score:4, Informative)
When you visit a web site flagged by Safe Browsing (in Chrome), there's a full screen warning before allowing you to go to the site. They could probably replace the ad image with a similar warning that you have to click through in order to load the ad.
But it looks like they're just flagging the whole page (see the article linked in the headline - hey, whipslash [slashdot.org], we don't want this), letting the site owner take the damage to their reputation for allowing the ads.
Re:How would this work? (Score:4, Informative)
As well they should. Any site owner that tolerates these deceptive tactics, which are generally also mal-ware vectors, deserves to have their reputations shredded.
Re:How would this work? (Score:4, Interesting)
All you have to do is sign up for Google Adsense to end up on Google's blacklist. That's going to backfire real quick. They still have fake download buttons on Adsense [ycombinator.com].
Re: (Score:2)
Re: (Score:3)
it seriously wouldn't be hard to correlate images that have been flagged as saying download in them with redirection scripts and or links that don't originate from the server hosting the website.
Oh great. For the next 3 years, every reCAPTCHA response will be "Download"
Re: (Score:2)
P.S. It would honestly be a welcome change compared to house number photos from street view.
Re: (Score:2)
I always try to answer the house number photos incorrectly if possible. For example if it's a 6, but could pass for an 8, I'll answer 8.
I assume their algorithm shows the same image to a number of people and take the consensus.
Re: How would this work? (Score:2)
It does work by consensus, but if consensus is already reached, you might fail the CAPTCHA.
Re: (Score:1)
Force sites to do it themselves (Score:4, Interesting)
Sites want to get indexed by google. If a site hosts ads that have bullshit Deceptive practices google can downrank them. Google doesn't have to be 100% effective. Even a crude system for spotting these is going to turn up hits if a site isn't blocking these kinds of adertisers. And so on. If a site doesn't do it's own ads but instead hosts ads from and advertising aggregator and they do this bullshit then the site will drop them to stay in google's good graces.
And so all google has to do is scan adds that show up in content providers and then punish them. so it's top down.
They can also try to go bottoms up, and seek out companies that do these kinds of ads but that's going to be impossible to block unless they are actually hosting the page. However that's not completely nuts. companies like Opera and Amazon who offer compression and caching of web pages in their browsers do have the capacity to edit the webpage to remove content from ad agencies they deem to be scum.
Does google do that for android mobile? (I have no idea). But apple is talking about ad blocking. And thrid parties like ad block plus have the capability to erase ads from nasty advertisers.
Once these technologies start denting revenue and page views those ads will dry up by themselves.
Analyze the image once, block it 10 million times (Score:4, Interesting)
That same green "play button" image is displayed millions of times per day, linking to the same URL. They only need to check it once to discover that it's bogus. Then Chrome can block it for all Chrome users who see that image linked to that URL.
That does involve communicating something about the block list between Chrome and Google's blacklist server. Hopefully they get that part right. The right way will probably involve communicating a strong hash of the two URLs rather than the URLs themselves.
Re: How would this work? (Score:2)
Re: How would this work? (Score:1)
Seeing as though Google already has filters to match up similar images, and plays with facial recognition etc, a few buttons shouldn't be that hard.
Sure, the scummers can obfuscate their buttons, but the whole point is to make them look convincing enough like a legit download button that people mistakenly click it so there's only so much variation they can do.
Re: (Score:3)
Right next to the title https://torrentfreak.com/googl... [torrentfreak.com]
Hopefully they will go back to putting links in the summary shortly.
Re: (Score:2)
Submitter here. It used to be that if you put the link in the link box on the submission page the editors would insert it into the summary for you. Sometimes I'm too busy/lazy to do it, and what are editors for?
Maybe the new people didn't realise, but it's better to put the link in the summary. Please edit it in next time.
Re: (Score:2)
Actually they started this a couple months before it changed hands.
Still yet they should always put a link somewhere in the summary.
Re: (Score:2)
Re: (Score:1)
They fixed it. I think that's a good sign.
Re: (Score:2)
Re: (Score:2)
yeah the mobile version is pretty much worthless.
Re: (Score:1)
It doesn't catch near the amount of crap it should. I can see this project will be just as worthless.
If you prevent 5% of fraud, it's not worthless, it's just not as good as it could be.
Imagine your attitude were what everyone had used toward spam filtering fifteen years ago. We wouldn't have good spam filtering until some kid without the preconception that it was impossible sat down and hacked it out.
A question (Score:1)
Why does everything need a specific .exe installer? Couldn't they devise some kind of standard mechanism? Or at least, why don't they provide a linux version of the .exe?
Re:A question (Score:5, Funny)
You're right. We need cross-platform compatibility for malware. Who's with me?
Re:A question (Score:4, Interesting)
Microsoft could have worked on an alternative executable format that is safe and sandboxed
You mean MSI / Windows Installer Service? That's about as good as you can hope for, but it does nothing for a user who is convinced they are downloading a program - and digital signatures aren't even shown to the user to match against the name of the software being installed. It only shows if there's not one or it's invalid.
If the user thinks they're going to install software, they're going to give it admin permission to install necessary registry and file permissions. How do you sandbox that away without blocking a legitimate installer?
Re: (Score:2)
An office suite often needs to associate file extensions. Lots of apps use shared libraries, which only needs to exist once on a system (VB6 runtime, .NET, etc). Non-registry settings files shouldn't be in program folders (so that they can be discovered for backup and/or separated from executable files - user files should not be under the Program Files folder).
Sandboxing a Photo manager app to only its own directory means you couldn't even use the default Photos folder to manage a photo library. Reading
Re: (Score:2)
Yep. It's been long overdue too. And they've been able to solve it for mobile phones and touchpads, where you are giving permission in advance. With Windows 10 moving towards one codebase for mobile and PC it should become easier to roll out.
Verifying redirect addresses. (Score:3)
Mind your own business (Score:1)
Google should probably start warning about their search engine, which presents search result hyperlinks, that by default point to a Google webserver, that redirects you to the target.
Re: (Score:2)
I've noticed that. It doesn't do it all the time but when it does it's a serious PITA.
Re: (Score:1)
There are a variety of GreaseMonkey scripts to take care of that. You'll want one to disable Google's redirection.
Download.com (Score:5, Informative)
They can start with Cnet's Download.com, nothing but ad banners with identical looking green "download" buttons.
Re: (Score:3)
Cnet's Download.com didn't start off that way. "Back in the day" it could be a great "go-to" for software downloads. But they have or are cutting their own throats, it's hard to imagine anyone downloading anything from these clowns today. Let alone actually read any of the "articles" they publish, I mean seriously, who reads that shit?
Re: (Score:2)
I stupidly kept using their site for years after they started doing that. I didn't really quit using it until they started posting "Visit Site" buttons instead of download links. I can't unwaste my time after doing a quick search only to be redirected to a slower download method. And the whole point of visiting download.com was to avoid the hassles of the original site.
Re: (Score:3, Informative)
A while back, it was an excellent source for software... the closest thing Windows ever got to a repository. However when they started bundling foistware [1] with other people's downloads, they changed to yet another site that is not worth visiting.
[1]: Software that adds browser add-ons and toolbars, then adds a loopback VPN and a trusted root CA into Firefox's keystore is not exactly trustworthy.
Re: (Score:2)
" the closest thing Windows ever got to a repository"
Except how you can't trust a site that requires an installer app. The most trusted rep for windows used to be http://www.tucows.com/download... [tucows.com]
Re: (Score:2)
And the damned proprietary executable they require you to download and install, just to then download the program or file you actually want.
I don't go to download.com, a pox on them and all their houses.
Hopefully that include fake FBI warnings (Score:2)
Re: (Score:3)
Such as the ones at the beginning of DVD/Blurays?
Re: (Score:2)
Microsoft Windows strikes again .. (Score:1)
can they expand this to GWX malware? (Score:2)
"You have attempted to use Google on a known spyware system. Your machine will now reboot."
put it into ad services, too.
thanks.
Re: (Score:3)
Microsoft already reboots my computer enough without my permission. I don't want Google doing it too.
Classic google (Score:2)
Nope (Score:2)
Re:Nope (Score:5, Interesting)
Re: (Score:1)
But they're not blocking those advertisers from their advertising network; they blocking it from the browser end. Yes, that means Chrome can block a web site for not manually filtering ads being provided by Google.
Excellent. (Score:2)
They need to concentrate on (Score:2)
blocking the fake "submitted by timothy" links on Slashdot
Oh wait...there'd just be a blank page left. NM.
Re: (Score:2)
Actually since I started complaining about it today http://it.slashdot.org/comment... [slashdot.org] There has been two posts by Yaelk.
Still it would be a very short page.
Oh They Noticed? (Score:2)
Google needs to look at itself!! (Score:4, Interesting)
Guess who is my ad provider? Google AdSense.
Google, heal thyself.
Re: (Score:2)
It's a bottomless pit. I've personally banned hundreds of advertisers with crap "download" banner ads - I suspect they're automatically created AdWords accounts, or some variant of dirt cheap labour.
I want the ad revenue, but not at the expense of my visitors getting mislead - that's bad for the sales side of my website.
Come to think of it, it's been about a month since I did a purge in my AdSense account... I'd probably be shocked and appalled at the new batch of crap ads...
OCR that shit (Score:1)
This would solve problems of white-on-white text, text in images, pages diffe
this is priceless.. (Score:1)
half the fucking internet delisted from google.... because THEIR OWN FUCKING ADS are a primary source of this fake download bullshit... not only on sites using their ad networks, but also GOOGLES OWN RESULT PAGES have ads with misleading bogus malware infested download pages.
google... clean up your own fucking house before you try to clean up the rest of the internet.
Re: this is priceless.. (Score:1)
It doesn't matter the page, it's the Ad Network that needs cleaning
But Google sends me false warnings themselves. (Score:2)
Every time I try to use YouTube or Google Drive through the latest and greatest Pale Moon, I am greeted with a page (or a ribbon in the case of Drive) telling me my browser is no longer supported and that I need to use the latest version. Umm, this is the latest version. When I choose to go through anyhow, everything works just fine.
They could afford to start a bit closer to home.
Too bad it's probably browser-only (Score:2)
Can they get Microsoft to stop trying to trick me into downloading Windows 10?
So far, I've run the programs to strip those notifications and updates from my system, but Microsoft keeps getting trickier.
Hope they also include... (Score:1)