Just Convincing Enough: Why Thin Sites Still Beat the Real Thing & Trust is the World's Rarest Commodity
A ROM site outranking a genuine game preservation project. A job board that exists purely to harvest your inbox. A returns process built to be unusable. Three different problems with exactly the same mechanism underneath.
I went looking for a way to play Pepsiman — the PS1 cult classic that's just been rebuilt to run natively in a browser, no emulator needed. Top result: not the recompilation project itself, a ROM site. File listing, some scraped release info, ads everywhere, dressed up just enough to look like a games database. It's not the first time I've noticed one of these outranking something genuinely useful — it's just the one that made me stop and actually think about why.
Same week, different flavour of the same thing. I signed up to a couple of job sites looking for roles. What I got back wasn't jobs — it was a steady drip of noise. Listings that don't match anything I searched for, emails I never asked for, the inbox equivalent of a filing cabinet someone's tipped out onto the floor. Different problem, same trick: assemble just enough content to look like the real thing, and let the traffic — or the email address — do the actual work. Turns out it's not just a personal annoyance either — Texas Attorney General Ken Paxton has just opened a formal investigation into LinkedIn over exactly this, examining whether the platform profited from ghost job listings while selling Premium subscriptions to people who assumed the postings were genuine. Independent estimates cited in that investigation put ghost jobs at 20–33% of listings on the platform. Same mechanism, just with a state attorney general's name attached to it now.
A third version of the same trick, closer to home: an online retailer that looks entirely legitimate at checkout — real product photos, a proper-looking site, a customer service team that replies promptly and politely. The trouble only surfaces once you actually need to return something. First it's a request for photos before anything can be discussed. Then a discount code to spend with them again, in place of a refund. Then, if you push past that, a return address on the other side of the world that costs more to ship to than the item's worth. Every step looks reasonable in isolation. Stacked together, it's a returns process built to be technically compliant and practically unusable — the retail equivalent of a website that ranks but doesn't actually answer the query.
It's Not New. It's Just Faster.
The Cluetrain Manifesto called this decades ago: hyperlinks subvert hierarchy. It's one of the internet's oldest observations, and it's basically an early warning about what happens once link-based ranking becomes possible — the moment a link count doubles as a proxy for authority, someone works out how to fake the count. That's what powered the churn-and-burn era of SEO — buy links cheap, rank fast, extract whatever value you can, abandon the domain before anyone notices, spin up the next one. It's an old trick dressed in new clothes every few years.
Domain authority (trust signals now, or is it convergence vector optimisation this quarter?) still counts for a lot in how things rank today. What's changed isn't the mechanism, it's the manufacturing speed. Content that used to take a small team to fake convincingly — enough surrounding text, enough structure, enough "looks like a real site" — can now be generated in bulk. That's not AI inventing the scam. It's AI industrialising one that's been running for twenty years.
There's a simpler version of this contradiction sitting in plain sight: agencies that openly sell link building as a service, no euphemism, no hiding it. If a link is supposed to work as an organic vote of confidence, an agency selling them at scale should be an obvious red flag, and it should be trivially trackable if Google could be bothered to follow the footprint. A conversation with someone in the industry a few weeks back made the point plainly: forums like Reddit and MoneySavingExpert still pulse in the rankings off the back of exactly this kind of link equity. Links clearly still work. What's changed is the shelf life and the scale — techniques that used to take real effort to pull off, hidden text, cloaked backdoors, the lot, still work today, they're just cheaper and faster to deploy at volume now that AI's doing the heavy lifting. That's not a fringe problem. It's a massive, ongoing one, hiding in plain sight of an industry that still sells it openly.
Worth a nod here to Aaron Wall's SEO Book on exactly this subject. The site itself hasn't been kept secure in years — no padlock, straight http — but the content holds up better than most things published this week. Google's own Matt Cutts spent a fair chunk of his career trying to stamp out precisely what that post describes. The fact the argument is still this relevant, running on an unsecured domain nobody's bothered to update, is its own small joke about what actually matters versus what gets flagged.
Cut it, shut it
The honest answer to "how do you deal with it" is the same one you'd get from anyone who's ever dealt with chop shops: you shut one down, another opens under a different name a week later. It's a whack-a-mole enforcement problem, not a one-time fix, because the incentive underneath it never actually goes away. Reactive measures buy time. They don't solve the structural reason these sites exist in the first place.
The businesses stuck in the middle
Here's the part that actually matters if you're not just an annoyed jobseeker or someone hunting for a niche PS1 port. Somewhere out there is a genuinely good trade business, or a locksmith who does honest, careful work, watching a thin site outrank them and having absolutely no idea why. From the outside it looks arbitrary — better product, better service, better site, so why aren't they top? The uncomfortable answer is that sometimes a junk site wins, temporarily, not despite being thin but because gaming the system is faster than being good at it.
There's no quick fix for that. There's only ever a quick burn for the site currently beating them — most operations like this have a shelf life, Google eventually catches up, the domain gets binned and a new one spins up somewhere else. Cold comfort if you're the one losing traffic this quarter. Which is exactly the point: the answer was never "wait it out." It's building something that doesn't depend on gaming a system that keeps shifting under everyone's feet.
My dad used to say something that's stuck with me longer than most SEO advice has: don't worry about what they're doing, focus on what you are. It sounds too simple for a problem this structural, but it's not actually bad strategy — you can't out-game a churn-and-burn operation on its own terms, and trying to usually means becoming a worse version of yourself in the process. The businesses that still stand once a scraper site's burned out and gone are the ones that spent that time being genuinely good instead of chasing it.
There's a version of this that just sounds like moaning otherwise: it's not fair, they're cheating, why should good work lose out to a shortcut. All true, and also beside the point, because these operations come and go by design — chasing the fairness argument just keeps your attention pointed at someone else's business instead of your own. What's actually worth focusing on is building around your own values, and if quality and longevity are among them, that shows up in unglamorous places first: site architecture that makes sense to a person browsing it and to whatever's crawling behind them, copy written to actually sell the thing rather than just rank for it. Call it a two-pronged approach — selling to the humans who'll buy and to the machines that decide who gets seen. Some rules bend. Some get broken outright. Some shortcuts genuinely aren't worth the effort of avoiding. But the fundamental discipline, the one that holds up regardless of what a scraper site or a churn-and-burn agency happens to be doing this month, is looking hard at your own business and not spending energy on someone else's.
The Apple Has Gone But There's Always the Core
Which raises an uncomfortable question underneath all of this: if trust is genuinely the thing search engines, banks and buyers are all trying to measure, how do you actually mine it, quantify it and, inevitably, sell it back to someone as a shortcut? That's the real business model sitting under most of what's described above. Trust isn't cheap to build the honest way — reviews take time, a returns process earns its reputation slowly, backlinks accrue because people genuinely wanted to reference you. But once you can roughly measure what "trustworthy" looks like from the outside — a review count, a returns policy that reads correctly, a customer service team that replies fast and politely — you can manufacture the appearance of it far faster than the substance.
Take the returns example from earlier, expanded a little. The first crack showed up before returns even came into it. An order confirmation arrived, then the site's own order tracker couldn't find the order when the number was put in — nothing, no record, as if it hadn't happened. Around the same time, the emails started: a reminder to finish checking out, then 5% off if you complete it now, then 10% off on top of that, all addressed to an order that had already been paid for. A reply pointing out the item had already been bought got a polite acknowledgement and nothing more. On its own, that's a basket/cart bug — annoying, forgivable, the kind of thing any ecommerce platform can throw up after a bad update.
Curiosity took it further. A bit of digging turned up a duplicate domain — the same storefront running under two different endings, with different products indexed on each, a pattern that shows up when a business is testing which version survives. Digging past that, into Companies House, showed the person behind the registration wasn't new to this: a trail of short-lived companies, same address, one dissolving close to when the next incorporated. Not a first business. Almost certainly not a last one either.
None of that individually proves anything — bugs happen, companies restructure, domains get consolidated for entirely boring reasons. But stacked together with the returns process described earlier — request photos, offer a discount code, offer a partial refund, hand over an unreachable address only as a last resort — it stops looking like a series of unrelated coincidences and starts looking like a pattern that's been run before, on a different name, and will very likely run again on the next one.
Which is the point of the title. Whatever brand sits on the storefront, whatever "apple" is currently being sold, is disposable. The domain, the branding, the name on the invoice — all of it can be exposed, abandoned and replaced within weeks. What survives, and gets reused again under a new skin, is the core: the process itself. The script for delaying, the tiered retention offers, the address that's technically valid but practically unreachable. That's the part worth watching for, because it's the part that doesn't change even when everything visible around it does.
The tell, if you want one
You can usually spot a thin site just by looking properly rather than glancing. Ask what it's actually about, not what it's ranking for. A real site has a point of view and depth in places you wouldn't expect. A thin one has ads in the places depth should be, and content that reads like it was assembled to satisfy a checklist rather than answer a question. Backlinks in isolation, domain age in isolation, even freshness in isolation — all of it's gameable on its own. What's harder to fake is the whole picture together, which is exactly where any serious evaluation — human or AI — needs to be heading: not scoring signals one at a time, but reading a page the way a sceptical person actually would, all at once.
That's the sites that survive whatever comes next. Not the ones built to pass a scoring system. The ones built to actually be good.
More on the Pepsiman project this piece opens with — the actual recompilation, not the scraper site pretending to be it — over on PC Play.
If you're wondering whether your own site, or a supplier's, looks a lot better than it behaves, the contact form is here. And if invisible failure interests you more than manufactured trust, the summer party covers the other half of the same problem.
