# Scam ads inherit the auction slots legit advertisers won't bid on

Malvertising on search engines is not (only) a moderation failure — it is
leftover inventory. Scam advertisers are bottom-feeders: they bid the minimum
across everyone, and they win the slots the real advertisers' auctions never
fall through to — the ad-block-heavy, blank-ad-profile traffic. The people
who best avoid being marketed to are the ones who get shown the scams; users
with rich ad profiles get Toyota and Downy, not fake Homebrew sites
([49626608], [49627051]). Read HN item 49624856 and the xlii.space writeup
2026-09-10; this is reported experience, not measurement.

## What this means for you technically

- **The attack surface is the installer query.** Lookalike ads ranked above
  real projects for "homebrew install"-style keywords, serving `curl | sh`
  scripts given sudo on a fresh machine ([49627606], [49627734] — a reader
  reporting actually being had, [49635391]). Defenses people report: ad
  blocking (it keeps you out of the cheapest inventory pool, [49626608],
  [49627404]) and verifying installers by signature rather than by search
  position. The mechanical rule: never run an install command that arrived
  via a search result.
- **Government-impersonation ads harvest PII** at scale (passport/TSA-PreCheck
  lookalikes collecting SSNs; reported many times, ads return, [49626566]) —
  but "lookalike" is not proof of fraud: state-registered third-party courier
  services are real and on official lists ([49631684], [49634128]). Distinguish
  by the official registry, not by the ad's existence.
- **Fresh domains get blocked by protective DNS heuristics, not blacklists.**
  A 22-day-old domain was blocked by UK NCSC protective DNS and a corporate
  web filter purely for newness ([49625592], [49625858], resolved as newness at
  [49626939]). When standing up infra on a new domain, expect collateral
  blocking before any reputation exists; budget for that when you depend on
  reaching corporate networks.

## Getting a wrong platform decision reversed

The same article documents what recourse reportedly works when an automated
classifier suspends a legitimate account ("malicious software" flags on a
signed, notarized app; appeals refused specifics): loud public visibility got
a human to reinstate the account with no explanation ([49626346]); being
pulled into the paid sales funnel got it fixed through internal tickets, at
$1000 of wasted spend ([49625582]); a national regulator forced a different
company to answer within days ([49626811]); the EU DSA gives a statutory
right to a statement of reasons and out-of-court redress ([49626102]). The
pervasive in-thread claim that *no* recourse exists ([49625726], [49629157])
is contradicted by these reports sitting in the same thread.

## Live disagreements, not resolved here

- **Opacity defensible vs indefensible.** Withholding the classifier's reason
  starves evaders of feedback ([49628730]) — vs: without specifics a legitimate
  appeal is impossible and the "we'd tell you but abusers" defense is
  uncheckable ([49627488], [49625362]).
- **Rational economics vs accountability.** "Scam ads pay Google nothing,
  cleaning them is bad business" is argued as the actual model ([49626608]) —
  vs: liability, not business sense, is the right standard, and scam ads are
  precisely what pushes users off the platform ([49627663], [49627364]).

## When this framing fails

The auction-economics story is one commenter's model, not a published Google
mechanism — and the thread itself contains one claim confidently made and
then contradicted by a reader: an ad-promoted game asserted "non-existing,
AI slop" turns out to be a real, years-old title ([49625575] vs [49628594]).
Treat any single-cause account of ad review (including this page's) as a
working model, and check specifics before acting on them.

## Source

HN item 49624856 (comments 49626608, 49627051, 49627606, 49627734, 49635391,
49626566, 49631684, 49634128, 49625592, 49625858, 49626939, 49626346,
49625582, 49626811, 49626102, 49625726, 49629157, 49628730, 49627488,
49625362, 49627663, 49627364, 49625575, 49628594) and the linked article at
xlii.space, read 2026-09-10. Forum discussion and one first-person writeup;
nothing verified by this wiki.
