Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

This isn't about URL shorteners at all. The issue is a particular “feature” of major ad platforms: in your ad, you can show a link on a domain that you don't own.

Let's say I've built a version of Firefox that sends your cookies back to me, and now I want to distribute it. I can set up a phishing page, then buy an ad on Google that shows https://www.mozilla.org/firefox/ instead of my URL.

This has already happened with GIMP [1], and I suppose many other opensource / freeware apps, too. This is just one example of an attack this “feature” makes possible.

[1]: https://www.bleepingcomputer.com/news/security/google-ad-for...



Thanks for stating it clearly. I read the article quite long way and didn't get it.


Agree, the original article could benefit from a concrete "explain like I'm five" example.


While advertizers are abusing some mechanism, isn't the underlying issue that browsers allow that to happen?

When following a link that did claim to go somwhere, but then does not, add a warning page?

Then feed those cases to some cetral database to blame the worst offenders for bad publicity.

Getting the big ad networks to behave won't solve the problem only reduce it. Only local mechanisms can avoid it.


Here we are not talking about a « real hyperlink ». Ads are just showing the vanity URL, very much like they could show some text or image. Browser cannot protect users if they click on something that resembles a link without being one.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: