4 ms·
Link fraud happens on adtech platforms owned by Google, Microsoft, X, and reddit. They each allow advertisers to spoof links with unverified "vanity URLs", lau
by Sephr 3y ago
Link fraud happens on adtech platforms owned by Google, Microsoft, X, and reddit.
They each allow advertisers to spoof links with unverified "vanity URLs", laundering trust in their systems, while simultaneously deflecting blame onto advertisers when these mechanisms are exploited for fraud.
You can help raise awareness by resharing/rehosting my message on social media and reaching out to your elected government officials. The systemic enablement of link fraud by Big Tech needs to end.
- baxtr 3y agoThanks. It would be great if you could provide some concrete examples. I have read the article but still don’t really understand how this works. Examples help to explain it to other people who need to know.
- TimPC 3y agoBasically any URL shortener would be an example.
- MOARDONGZPLZ 3y agoThis hacker news comment citing a peer reviewed study from the other time this article was posted gives a concrete example of how someone might fraudulently lead someone to a different than expected link: https://t.ly/77r6z https://t.ly/77r6z
- strictnein 3y agoSearch: [retailer] gift card balance Ad shows up: Text: Check Your [Retailer] Gift Card Display URL: https://www.[retailer].com/ Click the ad, get redirected to the malicious site: https://www.[retailer]-gift-card.com/ https://www.[retailer]-gift-card.com/ Ads always have redirection involved, typically through a third party, to track ROI, conversions, etc. How the attackers take advantage of this is their redirection redirects to the real site if it's the Googlebot or from an IP range known to be owned/used by Google (or other filtering based on location, language, etc). If it's not, it redirects to the malicious site. One solution is that the first hop in the chain has to match the domain of the display URL. That at least somewhat shows you can have a redirection that you control on the display domain. Of course, there could be an open redirect on that display domain, but those are becoming increasingly rare. Work for a large retailer and we dealt with this a lot a year or two ago. Built custom monitoring to detect it and we sent gobs of data back to Google showing it happening. Still pops up every once in a while, but they've made some improvements in their detection/prevention.
- Nextgrid 3y ago> One solution is that the first hop in the chain has to match the domain of the display URL Does anyone know why this isn't the default? I can't think of any legitimate reason why a brand wouldn't want to have their true domain displayed? If they want to redirect to a third-party they can implement it on their own website.
- bombcar 3y agoToo many people would complain if they just turned it on, watch the trackers fly by. Since their customers are the people running the trackers and giving them money, they listen to the advertisers and not the cattle who are clicking on ads.
- Nextgrid 3y agoBut you can still have trackers? You can still link to a unique URL on your own domain, and you can still pass query params to your spyware of choice?
- nradov 3y agoLink fraud is a good thing because it undermines the advertising economy. Anything which causes consumers to mistrust and ignore advertising can only be a positive.
- ClumsyPilot 3y agoIf you can’t beat them, join them and insidiously undermine them.
- winternett 3y agoBig Tech doesn't just enable fraud, they collect a lot of profit off of it, and it wouldn't even surprise me if they ran a lot of it. They don't even counter bots and spam posts in many cases any more, they stifle creator post views, they also ran several pphony crypto and NFT marketing campaigns themselves which all bilked millions of people, there is little trust left for these tech companies now, especially the social media companies. They literally run fraud havens.