Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

For take 3 consider explaining exactly what the issue is that you are upset about. This appears to be just a few generic definitions of what URL shorteners are and some links to a Twitter thread of random articles about URL spoofing.

Do you not like typo domains? Ads? URL shorteners? What do you want "Big Tech" to solve for you?

For what its worth at least some of your examples have simpler explanations like a user being confused that a website can both be the first search result and a sponsored link at the same time.



This isn't about URL shorteners at all. The issue is a particular “feature” of major ad platforms: in your ad, you can show a link on a domain that you don't own.

Let's say I've built a version of Firefox that sends your cookies back to me, and now I want to distribute it. I can set up a phishing page, then buy an ad on Google that shows https://www.mozilla.org/firefox/ instead of my URL.

This has already happened with GIMP [1], and I suppose many other opensource / freeware apps, too. This is just one example of an attack this “feature” makes possible.

[1]: https://www.bleepingcomputer.com/news/security/google-ad-for...


Thanks for stating it clearly. I read the article quite long way and didn't get it.


Agree, the original article could benefit from a concrete "explain like I'm five" example.


While advertizers are abusing some mechanism, isn't the underlying issue that browsers allow that to happen?

When following a link that did claim to go somwhere, but then does not, add a warning page?

Then feed those cases to some cetral database to blame the worst offenders for bad publicity.

Getting the big ad networks to behave won't solve the problem only reduce it. Only local mechanisms can avoid it.


Here we are not talking about a « real hyperlink ». Ads are just showing the vanity URL, very much like they could show some text or image. Browser cannot protect users if they click on something that resembles a link without being one.


I would suggest putting a sentence like “google ads can show a trustworthy/trademarked url (such as YouTube.com) but if the user clicks, the link actually goes to evilscam.com” in the first paragraph. I didn’t understand that this might be what the article is about until clicking through to the examples and still felt uncertain about it until reading the comments here.

The language about how the tech companies are complicit, have a negative effect on society etc is dramatic. I think more focus on the mechanics of the fraud and how it works and less ideology would make the piece more credible. If the article makes it very clear how companies are screwing up, the reader will make those judgments on their own.


> but if the user clicks, the link actually goes to evilscam.com

Often it's more like youtue.com, something the user is unlikely to notice as a slight deviation from the expected URL


Yeah they made the classic mistake of writing an article using the kind of manipulative rhetoric that typically works on 100 IQ people, and then sharing it with Hacker News.


The first example provided explains the situation exactly - a link that google shows as going to gimp.org in fact takes the user to scam.com (or whatever). Is the "manipulative rhetoric" you're referring to an expectation that a reader actually read the article?


Are you referring to one of the many twitter links? I didn’t see that in the article itself.


When you search for an app, google will happily allow attackers to buy that result and direct mislabeled links to the attackers' site. A former ceo got his laptop owned that way trying to install Adobe Acrobat because he unfortunately trusted google and thought the first result for a search for Adobe Acrobat would be legit. I was quite annoyed about having to clean up his laptop but you have to be relatively sophisticated not to get taken in.

This continues to be a problem; from the article, see eg this ad for Bitwarden:

https://x.com/KarlEmilNikka/status/1792554054893072672

Google allows the attacker to target navigational queries (in this case, bitwarden) and display "www.bitwarden.com" as the link text on a link that does not actually go to www.bitwarden.com .

The root cause is Google are parasites that (1) monetize navigation / install queries; and (2) force you to buy ads on your own company's name [1]. This opens the gate to attacks like the above, which they also don't effectively police.

[1] https://nymag.com/intelligencer/2019/03/why-businesses-have-...


> you have to be relatively sophisticated not to get taken in

More than that, you have to be ever vigilant, which is not a resonable expectation for anyone. It only takes one lapse at the wrong moment.


Should searching for "legit software" and clicking on the first result which displays www.legitsoftware.com in it in fact take you to legitsoftware.com? You'd think so except Google likes money.


Not the OP but I think Google search has started losing its organic nature in the sense that the top results are slowly and steadily consolidating into a handful of social network domains (other big techs mostly).

A related point is also that the web itself is losing its diversity. Whatever happened to the small dude's wordpress blog, why are they no longer turning up in the search results as much as reddit, quora, etc? What happened to the IRC, news letters, bulletin boards and forums (phpBB), etc? No doubt some of these sites are also thriving on the backend somewhere but Google's step-motherly treatment towards them in the results is surely hurting the web's diversity.


I think the sheer volume of "recent" content happens on those platforms absolutely dwarfs anything that anyone creates on their own time and private platform. For every 1 person writing their thoughts or findings on a blog, you have maybe 10 Thousand people making low-effort FB, Reddit, Instagram, TikTok postings. These people might as well be low-IQ "bots" and the platforms love them because they drive engagement, eyeballs, clickbait, rage and controversy.

We will never get that Web back. That innocence, naivety, hope and shared and private space is long lost.


Try search.marginalia.nu (free) or kagi.com (paid).

Both prove that it is very much possible to come up with better rankings than Google do.

Googles problem very much seems to be that quote by Upton Sinclair that “It is difficult to get a man to understand something, when his salary depends on his not understanding it.”

search.marginalia.nu and kagi.com have nothing to gain by sending people to websites that result in ad impressions for Google so for them it is a whole lot easier to rank fairly.

Also without this incentive it turns out that the feature everyone asked Google for - personalized blocklists - wasn't as impossible as googlers have told us over the years.


I didn't know about Marginalia, thanks!

I've been trying out https://www.mojeek.com/ recently. I mostly like it, but haven't made it my primary habit to use it first before duckduckgo.

I'm avoiding kagi for various reasons.


https://wiby.me/ is also a good search engine for (re-)discovering the alternate (or rather original) web.


> why are they no longer turning up in the search results as much as reddit, quora, etc?

Because they might contain "fake news" and are thus too problematic to show to you. And of course, they don't make any profit for Google since those kinds of sites are largely ad-free.

The sites are of course still out there, Google et al. just don't want to show them to you.


The key issue brought up in my article is that ad networks are choosing to allow advertisers to defraud the public.

These ad networks are playing the victim by tying their hands behind their back and refusing to do anything about the issue that they created. They all support link spoofing while simultaneously declaring policies that they don't effectively enforce.

As a result, I believe that these advertisers are effectively complicit with the fraudsters that "abuse" them.


You are correct and they absolutely are complicit. They have a fool-proof solution they refuse to implement: remove the feature until they can solve the problem another way.

The fact they don’t is clear evidence they prioritize their own profits over the harm they directly cause. A fact that should surprise no one.


This is why ad blockers are absolutely essential, and any browser vendor that says otherwise should be avoided at all costs.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: