15 ms·
Big Tech's role in enabling link fraud
- Sephr 3y agoLink fraud happens on adtech platforms owned by Google, Microsoft, X, and reddit. They each allow advertisers to spoof links with unverified "vanity URLs", laundering trust in their systems, while simultaneously deflecting blame onto advertisers when these mechanisms are exploited for fraud. You can help raise awareness by resharing/rehosting my message on social media and reaching out to your elected government officials. The systemic enablement of link fraud by Big Tech needs to end.
- baxtr 3y agoThanks. It would be great if you could provide some concrete examples. I have read the article but still don’t really understand how this works. Examples help to explain it to other people who need to know.
- TimPC 3y agoBasically any URL shortener would be an example.
- MOARDONGZPLZ 3y agoThis hacker news comment citing a peer reviewed study from the other time this article was posted gives a concrete example of how someone might fraudulently lead someone to a different than expected link: https://t.ly/77r6z https://t.ly/77r6z
- strictnein 3y agoSearch: [retailer] gift card balance Ad shows up: Text: Check Your [Retailer] Gift Card Display URL: https://www.[retailer].com/ Click the ad, get redirected to the malicious site: https://www.[retailer]-gift-card.com/ https://www.[retailer]-gift-card.com/ Ads always have redirection involved, typically through a third party, to track ROI, conversions, etc. How the attackers take advantage of this is their redirection redirects to the real site if it's the Googlebot or from an IP range known to be owned/used by Google (or other filtering based on location, language, etc). If it's not, it redirects to the malicious site. One solution is that the first hop in the chain has to match the domain of the display URL. That at least somewhat shows you can have a redirection that you control on the display domain. Of course, there could be an open redirect on that display domain, but those are becoming increasingly rare. Work for a large retailer and we dealt with this a lot a year or two ago. Built custom monitoring to detect it and we sent gobs of data back to Google showing it happening. Still pops up every once in a while, but they've made some improvements in their detection/prevention.
- Nextgrid 3y ago> One solution is that the first hop in the chain has to match the domain of the display URL Does anyone know why this isn't the default? I can't think of any legitimate reason why a brand wouldn't want to have their true domain displayed? If they want to redirect to a third-party they can implement it on their own website.
- bombcar 3y agoToo many people would complain if they just turned it on, watch the trackers fly by. Since their customers are the people running the trackers and giving them money, they listen to the advertisers and not the cattle who are clicking on ads.
- Nextgrid 3y agoBut you can still have trackers? You can still link to a unique URL on your own domain, and you can still pass query params to your spyware of choice?
- nradov 3y agoLink fraud is a good thing because it undermines the advertising economy. Anything which causes consumers to mistrust and ignore advertising can only be a positive.
- ClumsyPilot 3y agoIf you can’t beat them, join them and insidiously undermine them.
- winternett 3y agoBig Tech doesn't just enable fraud, they collect a lot of profit off of it, and it wouldn't even surprise me if they ran a lot of it. They don't even counter bots and spam posts in many cases any more, they stifle creator post views, they also ran several pphony crypto and NFT marketing campaigns themselves which all bilked millions of people, there is little trust left for these tech companies now, especially the social media companies. They literally run fraud havens.
- deleted 3y ago[deleted]
- dimask 3y agoMoreover, such links can be used to evade email filters that companies usually employ [1]. Combined with the habit of these corporate email services to obfuscate links "for safety", it can make it much easier to get tricked into being phished. [1] https://www.bleepingcomputer.com/news/security/linkedin-smart-links-abused-in-evasive-email-phishing-attacks/ https://www.bleepingcomputer.com/news/security/linkedin-smar...
- charcircuit 3y ago>Google's policy is that both display and landing page URLs should be within the same website. This means that the display URL in your ad needs to match the domain that visitors land on when they click on your ad. https://support.google.com/google-ads/answer/6246601?hl=en https://support.google.com/google-ads/answer/6246601?hl=en The author paints the picture that bad actors can just use any URL when that does not seem to be the case.
- strictnein 3y agoSee my comment here on how they get around that: edit: https://news.ycombinator.com/item?id=39006581 https://news.ycombinator.com/item?id=39006581
- sokoloff 3y agoYou meant to link to: https://news.ycombinator.com/item?id=39006581 https://news.ycombinator.com/item?id=39006581
- strictnein 3y agoOops. Yep, thanks!
- Sephr 3y ago> This means that the display URL in your ad needs to match the domain that visitors land on when they click on your ad. This policy is fundamentally impossible to enforce without domain ownership verification. 'It is against our policy' isn't exactly a good excuse when said policy isn't technically enforceable. Google practices sampled URL resolution (which is insufficient as explained in my blog post) and does not currently require domain ownership verification for the use of vanity URLs.
- andersa 3y agoI don't get it. Solving this is trivial. Simply display the url that the ad links to. Why the hell is it configurable?
- godelski 3y agoIt amazes how many blatantly fraudulent spam twitter accounts there are, with links not even masked behind url shorteners. Every single day I get these accounts liking random comments of mine and these are so bad they can be caught by naive bayes filtering. Here's some examples[0] that all have a ".click" domain and their bios are very clearly spammy. But I think my favorite is that I have messages that Twitter classified as spam, and that I have reported these profiles, but months later they still exist. Profiles that are even clones![1] What's even more funny is that when I originally got the message from this person twitter would suggest similar profiles and I could see 30 others with the exact same profile picture, all created in the same month, all without any activity, and all with the same pattern of name + random number string. I agree with the article's point, but I just want to point out here that there's even a far lower bar that these platforms are failing to achieve. If I'm reporting 5 people a week and those profiles still exist months later, clearly the platform is doing something wrong. [0] https://twitter.com/Eleanor1541800 https://twitter.com/Eleanor1541800, https://twitter.com/Eva626692385410 https://twitter.com/Eva626692385410, https://twitter.com/Serenity1260229 https://twitter.com/Serenity1260229 [1] https://twitter.com/ReneeYoung71651 https://twitter.com/ReneeYoung71651, https://twitter.com/Jessica77414656 https://twitter.com/Jessica77414656, https://twitter.com/Jessica43172228 https://twitter.com/Jessica43172228
- padolsey 3y agoYep I've encountered so so many of these too. It's amazing how obvious they are even to the most primitive filter, so I'm just at a complete loss as to why X/Twitter is so disincentivized to fix it ... especially given Elon's spiel about removing bots from the platform.
- godelski 3y agoYeah I've never had much faith in Elon. Always seems to care more about what is said than what is done. I'm just surprised people still believe him considering he's promised so much and delivered so little. I mean not that he hasn't done stuff, but he promises far more. But I guess he's the richest man alive and I'm not, so what do I know.
- 3y ago
- 6510 3y agoOne terrible version here in NL were free to call phone numbers starting with 0800 usually followed by 4 digits. Google allowed to spoof those and point them at 1 euro per minute phone numbers. They just redirected to the free number. Lots of people I know got weird phone bills for numbers they've never seen before. For some of these, during rush hour, 20-30 min waiting time is normal. A 2022 law now forbids people with paid numbers to redirect to 0800 free to call numbers. I'm really curious how much money this google scam made. If I know 5 people who spend 20-40 euro on it there must be many thousands of victims. The ads spoofed things like the tax office. First thing in the morning that number alone gets thousands of calls. One just types "tax office phone" (in dutch) in the search box and the ad says 0800-0543 You click on it and get the tax office. You might have to wait a bit because they are very patient and try to answer all your questions to the best of their ability, put you on hold to ask around etc Some people must repeatedly call the number for more than a hour in the same month. They wont notice anything until the bill comes in.
- 1vuio0pswjnm7 3y ago"I anticipate that the US federal government may start requiring adblockers on all federal employee devices at some point in the future."
- nyanpasu64 3y agoWas the previous submission at https://news.ycombinator.com/item?id=38916266 https://news.ycombinator.com/item?id=38916266 a draft for this article? That article has formatting errors (Helvetica text) and is not in the site's article index.
- deleted 3y ago[deleted]
- Sephr 3y agoYes. My original draft addressed too many issues at once and didn't receive enough engagement on HN. I re-drafted it to be easier to understand the key points. The improved accessibility seems to have helped. Also, thank you for noting the formatting error in my previous article. I just fixed it.
- cstrat 3y agoTwitter enables this through not checking the account in a URL... a simple fix would be to actually respect the Twitter URL components, if the account doesnt match the linked tweet, don't redirect... Right now you can spoof (just as far as the URL displayed in an anchor tag) the account to be whatever you like: Example: https://twitter.com/elonmusk/status/1745190441539293271 https://twitter.com/elonmusk/status/1745190441539293271 This will redirect you to the following, but as content within a tweet, it will look like a legit post from Elon. Crypto-scams are using this in every single post. https://twitter.com/ElonMuskAOC/status/1745190441539293271 https://twitter.com/ElonMuskAOC/status/1745190441539293271
- est 3y agoFraud is one thing, but be warned, any anti-fraud measurements can be also used for speech censorship.
- palmfacehn 3y agoI dislike spam as much as the next person, but the article makes some serious leaps. Demanding that the governments regulate hyperlinks while decrying "regulatory capture" feels like a non-sequitur. Moreover, it isn't immediately clear how vanity URLs or redirects are part of regulatory capture. However, it is easy to see how inviting regulation of hyperlinks could lead to regulatory capture.
- Sephr 3y agoI'm demanding that existing laws be enforced. Adtech has created a system that systemically enables normal fraud in the context of links. This is not a unique concept, nor does not require any new regulations or laws to address. Big Tech is deflecting blame by pretending that these problems (that they also made) cannot be solved. Government agencies believe these claims, which results in situations like the FBI asking you to install an adblocker.