This is your brain on fraud apologetics
In 1998, two Stanford students published a paper in Computer Networks entitled āThe Anatomy of a Large-Scale Hypertextual Web Search Engine,ā in which they wrote, āAdvertising funded search engines will be inherently biased towards the advertisers and away from the needs of consumers.ā
https://research.google/pubs/pub334/
If youād like an essay-formatted version of this post to read or share, hereās a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
https://pluralistic.net/2023/02/24/passive-income/#swiss-cheese-security
The co-authors were Lawrence Page and Sergey Brin, and the ālarge-scale hypertextual web search-engineā they were describing was their new project, which they called āGoogle.ā They were 100% correctāāāprescient, even!
On Wednesday night, a friend came over to watch some TV with us. We ordered out. We got scammed. We searched for a great local Thai place we like called Kiin and clicked a sponsored link for a Wix site called āKiinthaila.com.ā We should have clicked the third link down (kiinthaiburbank.com).
We got scammed. The Wix site was a lookalike for Kiin Thai, which marked up their prices by 15% and relayed the order to our local, mom-and-pop, one-branch restaurant. The restaurant knew it, tooāāāthey called us and told us they were canceling the order, and said we could still come get our food, but weād have to call Amex to reverse the charge.
As it turned out, the scammers double-billed us for our order. I called Amex, who advised us to call back in a couple days when the charge posted to cancel itāāāin other words, they were treating it as a regular customer dispute, and not a systemic, widespread fraud (thereās no way this scammer is just doing this for one restaurant).
In the grand scheme of things, this is a minor hassle, but boy, itās haunting to watch the quarter-century old prophecy of Brin and Page coming true. Search Google for carpenters, plumbers, gas-stations, locksmiths, concert tickets, entry visas, jobs at the US Post Office or (not making this up) tech support for Google products, and the top result will be a paid ad for a scam. Sometimes itās several of the top ads.
This kind of āintermediationā business is actually revered in business-schools. As Douglas Rushkoff has written, the modern business wisdom reveres āgoing metaāāāānot doing anything useful, but rather, creating a chokepoint between people who do useful things and people who want to pay for those things, and squatting there, collecting rent:
https://rushkoff.medium.com/going-meta-d42c6a09225e
Itās the ultimate passive income/rise and grind side-hustle: It wouldnāt surprise me in the least to discover a whole festering nest of creeps on Tiktok talking about how they pay Mechanical Turks to produce these lookalike sites at scale.
This mindset is so pervasive that people running companies with billions in revenue and massive hoards of venture capital run exactly the same scam. During lockdown, companies like Doordash, Grubhub and Uber Eats stood up predatory lookalike websites for local restaurants, without their consent, and played monster-in-the-middle, tricking diners into ordering through them:
https://pluralistic.net/2020/09/19/we-are-beautiful/#man-in-the-middle
These delivery app companies were playing a classic enshittification game: first they directed surpluses to customers to lock them in (heavily discounting food), then they directed surplus to restaurants (preferential search results, free delivery, low commissions)āāāthen, having locked in both consumers and producers, they harvested the surplus for themselves.
Today, delivery apps charge massive premiums to both eaters and restaurants, load up every order with junk fees, and clone the most successful restaurants out of ghost kitchensāāāshipping containers in parking lots crammed with low-waged workers cranking out orders for 15 different fake āvirtual restaurantsā:
https://pluralistic.net/2020/12/01/autophagic-buckeyes/#subsidized-autophagia
Delivery apps speedran the enshittification cycle, but Google took a slower path to get there. The company has locked in billions of users (e.g. by paying billions to be the default search on Safari and Firefox and using legal bullying to block third party Android device-makers from pre-installing browsers other than Chrome). For years, itās been leveraging our lock-in to prey on small businesses, getting them to set up Google Business Profiles.
These profiles are supposed to help Google distinguish between real sellers and scammers. But Kiin Thai has a Google Business Profile, and searching for ākiin thai burbankā brings up a āKnowledge Panelā with the correct website addressāāāon a page that is headed with a link to a scam website for the same business. Google, in other words, has everything it needs to flag lookalike sites and confirm them with their registered owners. It would cost Google money to do thisāāāengineer-time to build and maintain the system, content moderator time to manually check flagged listings, and lost ad-revenue from scammersāāābut letting the scams flourish makes Google money, at the expense of Google users and Google business customers.
Now, Google has an answer for this: they tell merchants who are being impersonated by ad-buying scammers that all they need to do is outbid them for the top ad-spot. This is a common approachāāāAmazon has a $31b/year āad businessā thatās mostly its own platform sellers bidding against each other to show you fake results for your query. The first five screens of Amazon search results are 50% ads:
https://pluralistic.net/2022/11/28/enshittification/#relentless-payola
This is āgoing meta,ā so naturally, Meta is doing it too: Facebook and Instagram have announced a $12/month āverificationā badge that will let you report impersonation and tweak the algorithm to make it more likely that the posts you make are shown to the people who explicitly asked to see them:
https://www.vox.com/recode/2023/2/21/23609375/meta-verified-twitter-blue-checkmark-badge-instagram-facebook
The corollary of this, of course, is that if you donāt pay, they wonāt police your impersonators, and they wonāt show your posts to the people who asked to see them. This is pure enshittificationāāāthe surplus from users and business customers is harvested for the benefit of the platform owners:
https://pluralistic.net/2023/01/21/potemkin-ai/#hey-guys
The idea that merchants should master the platforms as a means of keeping us safe from their impersonators is a hollow joke. For one thing, the rules change all the time, as the platforms endlessly twiddle the knobs that determine what gets shown to whom:
https://doctorow.medium.com/twiddler-1b5c9690cce6
And they refuse to tell anyone what the rules are, because if they told you what the rules were, youād be able to bypass them. Content moderation is the only infosec domain where āsecurity through obscurityā doesnāt get laughed out of the room:
https://doctorow.medium.com/como-is-infosec-307f87004563
Worse: the one thing the platforms do hunt down and exterminate with extreme prejudice is anything that users or business-customers use to twiddle backāāāadd-ons and plugins and jailbreaks that override their poor choices with better ones:
https://www.theverge.com/2022/9/29/23378541/the-og-app-instagram-clone-pulled-from-app-store
As I was submitting complaints about the fake Kiin scam-site (and Amexās handling of my fraud call) to the FTC, the California Attorney General, the Consumer Finance Protection Bureau and Wix, I wrote a little Twitter thread about what a gross scam this is:
https://twitter.com/doctorow/status/1628948906657878016
The thread got more than two million reads and got picked up by Hacker News and other sites. While most of the responses evinced solidarity and frustration and recounted similar incidents in other domains, a significant plurality of the replies were scam apologeticsāāāmessages from people who wanted to explain why this wasnāt a problem after all.
The most common of these was victim-blaming: āyou should have used an adblockerā or ānever click the sponsored link.ā Of course, I do use an ad-blockerāāābut this order was placed with a mobile browser, after an absentminded query into the Google search-box permanently placed on the home screen, which opens results in Chrome (where I donāt have an ad-blocker, so I can see material behind an ad-blocker-blocker), not Firefox (which does have an ad-blocker).
Now, I also have a PiHole on my home LAN, which blocks most ads even in a default browserāāābut earlier this day, Iād been on a public wifi network that was erroneously blocking a website (the always excellent superpunch.net) so Iād turned my wifi off, which meant the connection came over my phoneās 5G connection, bypassing the PiHole:
https://pluralistic.net/2022/04/28/shut-yer-pi-hole/
āDonāt click a sponsored linkāāāāwell, the irony here is that if you habitually use a browser with an ad-blocker, and you backstop it with a PiHole, you never see sponsored links, so itās easy to miss the tiny āSponsoredā notification beside the search result. That goes double if youāre relaxing with a dinner guest on the sofa and ordering dinner while chatting.
Thereās a name for this kind of security failure: the Swiss Cheese Model. We all have multiple defenses (in my case: foreknowledge of Googleās ad-scam problem, an ad-blocker in my browser, LAN-wide ad sinkholing). We also have multiple vulnerabilities (in my case: forgetting I was on 5G, being distracted by conversation, using a mobile device with a permanent insecure search bar on the homescreen, and being so accustomed to ad-blocked results that I got out of the habit of checking whether a result was an ad).
If you think you arenāt vulnerable to scams, youāre wrongāāāand your confidence in your invulnerability actually increases your risk. This isnāt the first time Iāve been scammed, and it wonāt be the lastāāāand every time, itās been a Swiss Cheese failure, where all the holes in all my defenses lined up for a brief instant and left me vulnerable:
https://locusmag.com/2010/05/cory-doctorow-persistence-pays-parasites/
Other apologetics: ājust call the restaurant rather than using its website.ā Look, I know the people who say this donāt think I have a time-machine I can use to travel back to the 1980s and retrieve a Yellow Pages, but itās hard not to snark at them, just the same. Scammers donāt just set up fake websites for your local businessesāāāthey staff them with fake call-centers, too. The same search that takes you to a fake website will also take you to a fake phone number.
Finally, thereās āWhat do you expect Google to do? They canāt possibly detect this kind of scam.ā But they can. Indeed, they are better situated to discover these scams than anyone else, because they have their business profiles, with verified contact information for the merchants being impersonated. When they get an ad that seems to be for the same business but to a different website, they could interrupt the ad process to confirm it with their verified contact info.
Instead, they choose to avoid the expense, and pocket the ad revenue. If a company promises to āto organize the worldās information and make it universally accessible and useful,ā I think we have the right to demand these kinds of basic countermeasures:
https://www.google.com/search/howsearchworks/our-approach/
The same goes for Amex: when a merchant is scamming customers, they shouldnāt treat complaints as āchargebacksāāāāthey should treat them as reports of a crime in progress. Amex has the birdās eye view of their transaction flow and when a customer reports a scam, they can backtrack it to see if the same scammer is doing this with other merchantsāāābut the credit card companies make money by not chasing down fraud:
https://www.buzzfeednews.com/article/rosalindadams/mastercard-visa-fraud
Wix also has platform-scale analytics that they could use to detect and interdict this kind of fraudāāāwhen a scammer creates a hundred lookalike websites for restaurants and uses Wixās merchant services to process payments for them, that could trigger human reviewāāābut it didnāt.
Where do all of these apologetics come from? Why are people so eager to leap to the defense of scammers and their adtech and fintech enablers? Why is there such an impulse to victim-blame?
I think itās fear: in their hearts, peopleāāāespecially techiesāāāknow that they, too, are vulnerable to these ripoffs, but they donāt want to admit it. They want to convince themselves that the person who got scammed made an easily avoidable mistake, and that they themselves will never make a similar mistake.
This is doubly true for readerships on tech-heavy forums like Twitter or (especially) Hacker News. These readers know just how many vulnerabilities there areāāāhow many holes are in their Swiss cheeseāāāand they are also overexposed to rise-and-grind/passive income rhetoric.
This produces a powerful cognitive dissonance: āIf all the āentrepreneursā I worship are just laying traps for the unwary, and if I am sometimes unwary, then Iām cheering on the authors of my future enduring misery.ā The only way to resolve this dissonanceāāāshort of re-evaluating your view of platform capitalism or questioning your own immunity to scamsāāāis to blame the victim.
The median Hacker News reader has to somehow resolve the tension between ājust install an adblockerā and āChromeās extension sandbox is a dumpster fire and itās basically impossible to know whether any add-on you install can steal every keystroke and all your other dataā:
https://mattfrisbie.substack.com/p/spy-chrome-extension
In my Twitter thread, I called this āthe worst of all possible timelines.ā Everything we do is mediated by gigantic, surveillant monopolists that spy on us comprehensively from asshole to appetiteāāābut none of them, not a 20th century payment giant nor a 21st century search giantāāācan bestir itself to use that data to keep us safe from scams.
Next Thu (Mar 2) I'll be in Brussels for Antitrust, Regulation and the Political Economy, along with a who's-who of European and US trustbusters. It's livestreamed, and both in-person and virtual attendance are free:
https://www.brusselsconference.com/registration
On Fri (Mar 3), I'll be in Graz for the Elevate Festival:
https://elevate.at/diskurs/programm/event/e23doctorow/
[Image ID: A modified version of Hieronymus Bosch's painting 'The Conjurer,' which depicts a scam artist playing a shell-game for a group of gawking rubes. The image has been modified so that the scam artist's table has a Google logo and the pea he is triumphantly holding aloft bears the 'Sponsored' wordmark that appears alongside Google search results.]














