←back to thread

186 points nafnlj | 5 comments | | HN request time: 0.001s | source
Show context
firefoxd ◴[] No.46241861[source]
Traffic to my blog plummeted this year and you can never be entirely sure how it happened. But here are two culprits i identified.

1. Ai overview: my page impressions were high, my ranking was high, but click through took a dive. People read the generated text and move along without ever clicking.

2. You are now a spammer. Around August, traffic took a second plunge. In my logs, I noticed these weird queries in my search page. Basically people were searching for crypto and scammy websites on my blog. Odd, but not like they were finding anything. Turns out, their search query was displayed as an h1 on the page and crawled by google. I was basically displaying spam.

I don't have much control over ai overview because disabling it means I don't appear in search at all. But for the spam, I could do something. I added a robot noindex on the search page. A week later, both impressions and clicks recovered.

Edit: Adding write up I did a couple weeks ago https://idiallo.com/blog/how-i-became-a-spammer

replies(3): >>46242006 #>>46242043 #>>46242457 #
bootsmann ◴[] No.46242006[source]
Sorry but how did 2 work before you fixed it? You saved the queries people did and displayed them?
replies(2): >>46242070 #>>46242086 #
1. firefoxd ◴[] No.46242070[source]
So the spammer would link to my search page with their query param:

    example.com/search?q=text+scam.com+text
On my website, I'll display "text scam.com text - search result" now google will see that link in my h1 tag and page title and say i am probably promoting scams.

Also, the reason this appeared suddenly is because I added support for unicode in search. Before that, the page would fail if you added unicode. So the moment i fixed it, I allowed spammers to have their links displayed on my page.

replies(3): >>46242183 #>>46242413 #>>46243227 #
2. Calavar ◴[] No.46242183[source]
Reminds me of a recent story on scammers using search queries to inject their scam phone numbers into the h1 header on legitimate sites [1]

[1] https://cyberinsider.com/threat-actors-inject-fake-support-n...

3. Neil44 ◴[] No.46242413[source]
Interesting - surely you'd have to trick Google into visiting the /search? url in order to get it indexed? I wonder if them listing all these URLs somewhere are requesting that page be crawled is enough.

Since these are very low quality results surely one of Google's 10000 engineers can tweak this away.

replies(1): >>46242772 #
4. input_sh ◴[] No.46242772[source]
> surely you'd have to trick Google into visiting the /search? url in order to get it indexed

That's trivially easy. Imagine a spammer creating some random page which links to your website with that made up query parameter. Once Google indexes their page and sees the link to your page, Google's search console complains to you as the victim that this page doesn't exist. You as in the victim have no insight into where Google even found that non-existent path.

> Since these are very low quality results surely one of Google's 10000 engineers can tweak this away.

You're assuming there's still people at Google who are tasked with improving actual search results and not just the AI overview at the top. I have my doubts Google still has such people.

5. layer8 ◴[] No.46243227[source]
What does Unicode have to do with links?