Here's a Google ad impersonating the brew.sh website but linking to a malware site.

Remember, it is always 100% morally and ethically OK to use ad blockers.

@tek it’s so weird that it says Sponsored brew.sh but the link goes to brewe.sh

How does that happen?

@jonathankoren @tek I investigated this for a similar Google ad scam that was imitating Costco to get credit card numbers. When Googlebot fetches the web page, it redirects to brew.sh instead of serving the scam. That seems to give Google just enough confidence to consider brew.sh the "canonical" domain; perhaps because it's the most popular. I dunno about Ads, but Search describes a bit of the process here: https://developers.google.com/search/docs/crawling-indexing/canonicalization
What is URL Canonicalization | Google Search Central  |  Documentation  |  Google for Developers

Learn what canonicalization is, how Google chooses a canonical URL, and whether it matters for your site.

Google for Developers
@twifkak @tek “CLOSED: Works on my machine!”

@twifkak @jonathankoren @tek

Malwarebytes has more info on fake domains showing up in search ads -- in this case it's fake ads for ads.google.com but looks like the same principle (?)

https://www.malwarebytes.com/blog/news/2025/01/the-great-google-ads-heist-criminals-ransack-advertiser-accounts-via-fake-google-ads

The great Google Ads heist: criminals ransack advertiser accounts via fake Google ads

An ongoing malvertising campaign steals Google advertiser accounts via fraudulent ads for Google Ads itself.

Malwarebytes
@twifkak @jonathankoren @tek (and yes, "experienced advertisers" in the USA are more likely to run an ad blocker than average https://www.ghostery.com/blog/privacy-report-advertisers-and-adblockers )
Who’s In the Know: The Privacy Pulse Report | Ghostery

Ghostery research finds that industry insiders are significantly more likely to use adblockers and be more skeptical of their online safety, underscoring concerns about the current severity of user tracking

Ghostery
@tek AdBlockers are a security product
@tek you have to wonder how many google engineers setting up a new laptop have literally used this source for their homebrew.
@tek this is why security folks stroke out when devs yolo it and curl pipe to bash blindly.
@Viss @tek and even if you know the source is reliable you shouldn't do it, save it to a file and run it afterwards, a network hiccup could cause the file to be only partially downloaded and ran anyways

@Viss @tek OK, but it's fun to do that sort of thing in a VM.

That reminds me, I should take QubesOS for another spin on my spare laptop.

Hacker infects 18,000 "script kiddies" with fake malware builder

A threat actor targeted low-skilled hackers, known as "script kiddies," with a fake malware builder that secretly infected them with a backdoor to steal data and take over computers.

BleepingComputer
@Viss @tek Nah, that one apparently gives up when it notices running on a VM.

@tek I remember a while back if you searched Google for F-Droid it did the same thing. A sponsored result led to an unofficial site that was not the actual F-Droid one. Shady AF.

Now I just use my SearxNG instance.

@tek god I just installed brew on a new computer last week. Now I have to double check I was on the right website.

@tek

Ad-blockers are a security best-practice.

Ad-blockers are self-care.

@tek I find it especially fucking insane they allow changing how link is displayed in the ad

Someone will try to search for homebrew
Sees this
But they try to be careful, so they look over the title and look at the link itself
Link is good, so they proceed
And then they won't check the bar above, since they already looked at the link in the search engine so there should be no need
But oops, it's a different FUCKING LINK
@tek just use linux and you wont have to install the package manager.
@tek @auroroboros I use linux and I still have homebrew, though I don't remember the last time I used it
@tek Some ads are malware targeting your computer. ALL ads are malware targeting your brain.
@tek @blogdiva Ad blockers are basically anti virus for the browser that really work, and don’t guzzle up metric shittons of resources.
@schrotthaufen @tek @blogdiva
What is a good ad blocker for Android?
@Darkphoenix @schrotthaufen @tek @blogdiva uBlock Origin. Literally the first thing I do on any device is download Firefox and make it the default browser, then install uBlock Origin.
@mike @Darkphoenix @schrotthaufen @tek my only difference is that i use librewolf, a degoogled and privacy oriented firefox. but yeah, that unblock goes up immediately.
@blogdiva @Darkphoenix @schrotthaufen @tek (Actually I also use LibreWolf; I just didn't want to add that extra layer of complexity to my instructions. I still keep regular Firefox around, as I have to use it for things like Prime Video and Netflix that won't work in a privacy-respecting way.)
@Darkphoenix
Also consider adding the TrackerControl app to your android device https://trackercontrol.org/
@schrotthaufen @tek @blogdiva
TrackerControl for Android

TrackerControl allows you to monitor and control the widespread, ongoing, hidden data collection in mobile apps about user behaviour (tracking).

TrackerControl for Android
@onmywalk @Darkphoenix @schrotthaufen @tek @blogdiva
This one's good. Aside from blocking trackers it also allows users to totally cut off some app's Internet access (if this app didn't try circumventing it specifically), so apps that only connect to the Internet to fetch ads and tracking users can be used without users being tracked or annoyed by ads.
Note that some of the blocking options may result in some app functionality being broken (iirc it once suggested Amazon S3 as a blocking candidate and I'm baffled
​ )
@tek Very similar to how AI Google results are serving up phone numbers to phishers instead of official company contacts.
@tek @ChrisFerguson I haven’t used Google search for so long that I managed to forget about its existence😱
@tek Sometimes, I suspect that `curl | sudo bash` may not be a secure way to install software.

@tek google search is effectively malware now.

I switched to DDG last year and it was better. Switched to Kagi last week and that's been amazing.

@tek

Block Google, get better every day at blocking google. Don't use their software, don't visit their sites.

Don't use Chrome, don't use Chrome named other things.

@tek holy shit I’ve used that website 😅 what should I do?!

@tek

It takes a bit of work, but you can set up the "Search Engine" in your browser (Chrome or Firefox for sure) to:

ttps://www.google.com/search?q=%s&udm=14

This disables AI, *and* ads. It's almost like useful Google again!

@tek been reporting clear scam ads I see every single day on Instagram and they do nothing about it. Finally got reVanced to patch out the ads.

https://fosstodon.org/@wraptile/113707170080345773

When they claim they'll be able to contain AI damage yet can't contain scam ads you could detect in a single line of code 🙄

wraptile (@[email protected])

Attached: 1 image Instagram has been infested with these fake investment ads where: > "celebrity forgot turn off their mic during an interview - it'll shock you what they said" > "Investing into fake investment/crypto website made me millions - it's so easy click here!". I've made an experiment and tried to report all I could find and today I see this on every report 👇 #Meta is one of the leading AI companies and they can't block these extremely rudimentary scam ads? Disgusting incompetence. #instagram

Fosstodon
@tek Who the af clicks on sponsored links? Especially with the title of an developer? 😳