Hacker News new | ask | show | jobs
by nyanpasu64 980 days ago
For one thing, Google search ads should not show users a domain different from the domain Google redirects directly to. If a website wants to track clicks, the URL they ask Google to send users to should not live on a different domain than the domain the user sees before clicking. Anything else invites impersonation like this, and makes Google complicit in undetectable phishing.

See previously, gilimp and https://fxtwitter.com/ericlaw/status/1712531148356661494.