r000t,
@r000t@fosstodon.org avatar

The Associated Press just served me an ad for fake anti-virus. The entire page was taken over, and forwarded to the malicious site, within seconds of opening the news article, every time.

An ad blocker isn't just something to hide some annoying eyesores, it's a vital layer of security.

If you have friends or family who might fall for fake AV or "windows technical the department" scams, they need an ad blocker. No site they visit can be considered "safe" unless it simply doesn't have ads.

video/mp4

kkarhan,
@kkarhan@mstdn.social avatar

@r000t +9001%

Otherwise the only valid option is to become a and forcibly.migrate them to @ubuntu / LTS and never gibe them privilegues and instead forcibly update their shit per SystemD service.

mikeloukides,
@mikeloukides@hachyderm.io avatar

@r000t Absolutely. I've gotten malware-infested ads from sites as legit as the BBC. Whenever I get a "please turn off your adblocker" message, I'm "you don't publish anything I need badly enough to risk my computing infrastructure."

ToddLa,

@r000t the problem is not ads, a site can easily run well curated first-party ads, with no tracking bs. But the problem is they give control of placing ads to bottom feeder “ad-networks” that race to bottom

HugeGameArtGD,
@HugeGameArtGD@mastodon.gamedev.place avatar

@r000t Maybe try a proxy like https://www.removepaywall.com/

kkarhan,
@kkarhan@mstdn.social avatar

@HugeGameArtGD @r000t also https://12ft.io works well, and OFC forcing a metric ton of blocklists as well...

MOULE,

@r000t It's funny how the fake malware scanning page calls some of the malware "Win32" even though it's served on an Android device :MOULE_Ha:

kkarhan,
@kkarhan@mstdn.social avatar

@MOULE @r000t you'd be surprised how lottle care and how persistently they'll forego all warnings and security settings...

https://mstdn.social/@kkarhan/111439207999697827

seth,

@r000t I cannot browse the internet without uMatrix and uBlock Origin; that is to say, it would be literally unusable without them.

kkarhan,
@kkarhan@mstdn.social avatar
mspsadmin,
@mspsadmin@msps.io avatar

@r000t I've encountered that ad as well a week ago (usually integrated app browsers) Crazy they haven't fixed it.

Of course I have clients still clicking the first Amazon link they get when searching Amazon on Google and they end up at a MS Support Scam site. If Google still can't prevent malicious ads 🤷‍♂️

Ad blockers definitely are a solid security layer.

kkarhan,
@kkarhan@mstdn.social avatar

@mspsadmin @r000t They are way more effective and useful than the entire & industry that is 3rd party on ...

https://mstdn.social/@kkarhan/111439207999697827

mspsadmin,
@mspsadmin@msps.io avatar

@kkarhan @r000t Yeah - Clients always look at me funny when I explain McAfee Security Scanner spreads more than an actual virus.

r000t,
@r000t@fosstodon.org avatar

On a related note, based on the last few times I've been hit with an ad like that, I've been eventually forwarded to a real McAfee checkout page, product already in cart, ready to give them money.

I see two possibilities here:

  1. Malware site detects a platform that the scammer's not prepared to remote into
  2. McAfee has some sort of referral/affiliate program, which makes them complicit in malicious scareware takeover ads.
briankrebs,

@r000t McAfee and Norton both have affiliate programs and you are almost certainly correct in that this is affiliate abuse. This has been going on for years, and usually it starts with someone accepting notifications on a dodgy or hacked site, and the next thing they know they're getting "notifications" on the desktop that look like they came from the OS, saying it's time to install/update/etc Norton/McAfee.

briankrebs,

@r000t I wrote about this in 2020, and when I asked NortonLifeLock they blamed affiliates. https://krebsonsecurity.com/2020/11/be-very-sparing-in-allowing-site-notifications/

sharkmime,

@briankrebs @r000t So why doesn't their checkout page indicate that you are going through an affiliate, with a "report affiliate fraud" button? Not that the answer isn't obvious.

kkarhan,
@kkarhan@mstdn.social avatar
tasket, (edited )

@briankrebs @r000t As a longtime user of Qubes OS, the idea that UI environments would keep removing more and more visual context in order to make content presentation more sleek just baffles me. If you remove too much context (such as displaying mouseover URLs in the browser canvas instead outside it, near the window frame, or removing actual window frames or dividers between app controls and content) then users lose critical information about what is/isn't a system function, app function, or remote content.

And then the same orgs that trade proper context for sleekness then go on to bemoan how users keep falling for attacks and scams. And then they pelt us with "security advice" and rules that are 80% garbage.

AlesandroOrtiz,

@briankrebs @r000t I've seen an uptick from likely same actor in the past 2 weeks. Have seen redirects from Wired, Gizmodo, eonline, and many other major news sites. Same URL pattern which indicates likely same actor.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • modclub
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • cubers
  • GTA5RPClips
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • tacticalgear
  • ethstaker
  • kavyap
  • Durango
  • anitta
  • everett
  • Leos
  • provamag3
  • mdbf
  • ngwrru68w68
  • cisconetworking
  • tester
  • osvaldo12
  • megavids
  • khanakhh
  • normalnudes
  • JUstTest
  • lostlight
  • All magazines