Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Pretty sure it'll be because of the semi-shady ad networks that service torrent sites and various other filehosts. The networks themselves aren't shady, per se, but they don't have the resources of Google to adequately police all of the ads that run through their networks. As a result, they end up serving malicious ads that link to dodgy installers or even straight up 0-day browser exploits.


Google ads themselves serve plenty of dodgey ads, go search "$popular_software download" for instance.


Absolutely, but those ads aren't usually pointing at outright malicious software, just shitty adware like download accelerators or whatever. Google's algorithms and manual approval processes have been pretty good at filtering out anything explicitly malicious, at least in my experience.


Even malware makes it into adsense , and if i remember correctly it took a few hours after reporting the ad for it to be removed. It's been a while since i ve had these reports though.


Could you give a real example for $popular_software which is showing a dodgey ad?


Searching for firefox on Google always returned a paid ad for a download of Firefox with 10 separate bundleware offers included.


They recently changed the rules for download sites doing that - https://news.ycombinator.com/item?id=9502026


I don't think that sort of ad is permitted anymore.

Here's what I see when I do that search: http://i.imgur.com/505yzNW.png


Google Search recently put a lot of time into this area and as of a few months ago, you should rarely see these malicious ads and results.


then why block/replace the top-level page instead of the embedded content like an adblocker would?


Because a site that is willing to host these kinds of ads may use more than one ad service, and Google may not have detected all the bad ad services.

The fault here lies squarely with the websites. They choose to work with scum. Let them fix the mess instead of blaming Google.


> and Google may not have detected all the bad ad services.

You're basically arguing that false positives in an external content blocking service is better than false negatives.

I strongly disagree with that kind of notion. It reeks of nannying.


I think it's more of a game-theoretic "principal-agent-problem avoiding" solution. If system X.Y.Z is having a problem, the way to allow the most degrees of freedom in the way it gets fixed (and therefore, usually, the way to get it fixed most efficiently) is to put pressure on component X. X will put pressure on X.Y, who will in turn put pressure on X.Y.Z. But if the system can also be fixed by, say, getting X to find a new X.Y, that's good too!

An example of this: auto insurance. When you get in an accident and want money, you don't sue the other guy; you sue your own insurance company, who sues the other guy's insurance company, who in turn sues them. If, somewhere during that propagation, an alternative is found (e.g. the two insurance companies agree that it was a no-fault collision under arbitration and settle for some amount), then you end up achieving the same effect while putting less stress on the system as a whole.


>The fault here lies squarely with the websites. They choose to work with scum.

It isn't much of a choice, since they're not allowed to use AdSense or any of the other major ad networks.


I have a browser. I tell the browser to go to a site. The browser refuses to go to the site. This is clearly an issue with the browser.


The interstitial for blocked content is implemented on a per-page level. You can test this yourself by creating a test page with an iframe to http://ianfette.org.

Suppose that Chrome just tried to replace the malicious embedded content. What happens when that embedded content is styled with CSS properties to make it hidden from the user?


They could overlay the message or have an information bar or whatever. UI design is not an argument against more measured blocking.

I don't see a technical necessity to block a whole top-level page when the security model of a browser consists of many different origins.


Erring on the side of caution.

If a page has included known exploits, it might also include unknown exploits.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: