GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Peter Bhat Harkins (pushcx@ruby.social)'s status on Tuesday, 26-Nov-2024 12:51:43 JST Peter Bhat Harkins Peter Bhat Harkins

    Google has started injecting unlabeled ads into pages that look like an author created them. Can anyone get a reusable example so we can detect the tampering?

    https://support.google.com/websearch/thread/308719098/page-annotation-in-google-app-browser-for-ios?hl=en

    In conversation about 6 months ago from ruby.social permalink

    Attachments


    1. https://cdn.masto.host/rubysocial/media_attachments/files/113/546/954/209/832/546/original/7bc19641b61931d1.png
    • Paul Cantrell and anban repeated this.
    • Embed this notice
      Peter Bhat Harkins (pushcx@ruby.social)'s status on Tuesday, 26-Nov-2024 12:51:42 JST Peter Bhat Harkins Peter Bhat Harkins
      in reply to

      Google claims they are injecting ads live now, so I'd like to quickly turnaround a js snippet that sites can use to detect the tampering.

      I'm strongly reminded of how a motivation for the big lift to HTTPS was slimy ISPs injecting ads into pages.

      In conversation about 6 months ago permalink
    • Embed this notice
      Tim W RESISTS (tim@union.place)'s status on Tuesday, 03-Dec-2024 03:53:05 JST Tim W RESISTS Tim W RESISTS
      in reply to
      • tsk

      @pushcx @tasket can confirm repro, have been seeing it for a few days

      In conversation about 6 months ago permalink
    • Embed this notice
      tsk (tasket@infosec.exchange)'s status on Tuesday, 03-Dec-2024 03:53:07 JST tsk tsk
      in reply to

      @pushcx Also, is the page content being uploaded to Google so they can decide what/where to inject? That is a potential spyware issue.

      In conversation about 6 months ago permalink
    • Embed this notice
      Peter Bhat Harkins (pushcx@ruby.social)'s status on Tuesday, 03-Dec-2024 03:53:07 JST Peter Bhat Harkins Peter Bhat Harkins
      in reply to
      • tsk

      @tasket That's a really good point, thank you. I've added it to the post.

      In conversation about 6 months ago permalink
    • Embed this notice
      Tim W RESISTS (tim@union.place)'s status on Tuesday, 03-Dec-2024 04:15:09 JST Tim W RESISTS Tim W RESISTS
      in reply to
      • tsk

      @pushcx @tasket both on the url you found from the example and all across random sites in the Google Search App over the past few days. Didn't realize what it was until I saw folks posting about it (so I guess it wasn't very effective with me).

      In conversation about 6 months ago permalink
    • Embed this notice
      Peter Bhat Harkins (pushcx@ruby.social)'s status on Tuesday, 03-Dec-2024 04:15:10 JST Peter Bhat Harkins Peter Bhat Harkins
      in reply to
      • Tim W RESISTS
      • tsk

      @tim Thanks for reaching out! On the page from their example? On your own site? On many sites? (Thanks for making this connection @tasket!)

      In conversation about 6 months ago permalink
    • Embed this notice
      Tim W RESISTS (tim@union.place)'s status on Tuesday, 03-Dec-2024 04:31:33 JST Tim W RESISTS Tim W RESISTS
      in reply to
      • tsk

      @pushcx @tasket examples from a random news feed article (suggested by the Google Search App of course). Article link: https://www.power-grid.com/energy-business/under-pressure-from-the-scc-dominion-reveals-the-true-cost-of-data-centers/

      In conversation about 6 months ago permalink

      Attachments


      1. https://media.union.place/media_attachments/files/113/584/875/654/013/998/original/02d2b2f4f1bf681d.jpeg

      2. https://media.union.place/media_attachments/files/113/584/875/724/480/628/original/f6d810fc632d8505.jpeg

      3. https://media.union.place/media_attachments/files/113/584/888/144/210/956/original/56f81a1c7b3d81e2.jpeg
      4. Domain not in remote thumbnail source whitelist: www.power-grid.com
        Under pressure from the SCC, Dominion reveals the true cost of data centers
        from @powergridintl
        A new filing shows electricity demand would be flat without the industry.
    • Embed this notice
      Tim W RESISTS (tim@union.place)'s status on Tuesday, 03-Dec-2024 04:33:42 JST Tim W RESISTS Tim W RESISTS
      in reply to
      • tsk

      @pushcx @tasket obligatory disclosure: I work for Google, I have no special knowledge of this feature (genuinely was confused by seeing it happening until I saw posts here about it!), all posts are my personal opinion.

      My personal opinion: I hate it. This is going to rightfully piss people off and it really isn't that helpful.

      In conversation about 6 months ago permalink
    • Embed this notice
      Tim W RESISTS (tim@union.place)'s status on Tuesday, 03-Dec-2024 04:57:19 JST Tim W RESISTS Tim W RESISTS
      in reply to

      @pushcx if you get the JS it should be easy enough, I can trigger it on that page 😂

      I'd be happy to poke around / help. I'm on a plane and unsure how well the wifi will work then driving home so I'm at least partially out of pocket for a few hours as well but reply and I'll do what I can.

      In conversation about 6 months ago permalink

      Attachments


      1. https://media.union.place/media_attachments/files/113/584/979/638/701/725/original/f41257e39251d2f9.jpeg

      2. https://media.union.place/media_attachments/files/113/584/979/745/866/590/original/7f7d2bc4f4ffe725.jpeg
    • Embed this notice
      Peter Bhat Harkins (pushcx@ruby.social)'s status on Tuesday, 03-Dec-2024 04:57:21 JST Peter Bhat Harkins Peter Bhat Harkins
      in reply to
      • Tim W RESISTS

      @tim I bet it's a slow rollout and you're in the 0.1% (or whatever) it's active for. I'm about to roll into a Twitch stream for Lobsters office hours, but is there a time we could pair on investigating? I'll put a debug script on my blog and you reload to share info. https://push.cx/google-ad-injection has my start at this.

      In conversation about 6 months ago permalink

      Attachments

      1. Domain not in remote thumbnail source whitelist: push.cx
        Google Ad Injection
    • Embed this notice
      Tim W RESISTS (tim@union.place)'s status on Tuesday, 03-Dec-2024 05:00:17 JST Tim W RESISTS Tim W RESISTS
      in reply to

      @pushcx also shows up later for "Google" and "AdWords"

      In conversation about 6 months ago permalink

      Attachments


      1. https://media.union.place/media_attachments/files/113/585/001/942/215/277/original/2154a9d071716fda.jpeg

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.