Live data from Hacker News

Hackers Make $5M a Day by Faking 300M Video Views

forbes.com

131–136 of 136 posts

Re: Hackers Make $5M a Day by Faking 300M Video Views

#131
post #50

Earlier quoted context omitted.

> It was discovered years ago And yet they're still active with the same tech stack.

They only have to do the very minimum to recover from detection. The incentive is for them to keep the largest possible bag of tricks ready to deploy every time they get a dip in revenue due to fraud detection to milk the fraud. Besides, most of the countermeasure takes the form of javascript to be executed by the client, since the fraudsters control the client, they can alter the operating environment of the fraud d…

I don't think that's quite right.

When three-letter television companies will buy an audience extender from one of these shady guys rather than tell the advertiser that they don't have as much traffic as they projected, you don't really even need to worry about detection.

There exist passive techniques powerful enough to really map these kinds of actors out thoroughly, however the industry has been reticent to stop it because everyone from Viacom to Google has facilitated ad fraud, and there's this fear that stopping things too abruptly will cause advertisers to lose faith in this (still nascent) $60 billion dollar industry (US numbers).

Re: Hackers Make $5M a Day by Faking 300M Video Views

#132
post #66

Earlier quoted context omitted.

At this point, advertisers just assume some level of fraud is part of the deal with any platform. As long as you're hitting your target ROI than advertising on still makes sense.

The world can be divided up into two types of advertising. DR (Direct Response) or Branding/Awareness. The goal of DR is drive an immediate action, for ex. a purchase or news letter signup. Branding/Awareness is more about keeping the brand/product top of mind for the eventual time when the purchasing is actually done. Usually small and mid-sized advertisers focus on DR. That's why you see a lot of re-targeting type…

The frusturating thing about this is how obvious it should be that the publisher account getting paid for the impression is _not_ the premium publisher that it said it was. If your account with, say, AppNexus is registered to "Mikhail Gorsky's Ad Fraud Ring" and it's registering video plays on espn.com/video at a $30 CPM, there are some very very basic heuristics that AppNexus could run to determine there is something off about this arrangement.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#133
post #66

Earlier quoted context omitted.

At this point, advertisers just assume some level of fraud is part of the deal with any platform. As long as you're hitting your target ROI than advertising on still makes sense.

The world can be divided up into two types of advertising. DR (Direct Response) or Branding/Awareness. The goal of DR is drive an immediate action, for ex. a purchase or news letter signup. Branding/Awareness is more about keeping the brand/product top of mind for the eventual time when the purchasing is actually done. Usually small and mid-sized advertisers focus on DR. That's why you see a lot of re-targeting type…

> younger audiences (40 and under)

Thank you.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#134

Earlier quoted context omitted.

It isn't just in theory but also in practice do ads connect people with products. Actual transactions are happening from real people clicking ads and companies are realizing real returns on marketing dollars spent. "Getting rid of most online ads" doesn't remove a business' need to connect with consumers in the most effective, lowest cost way possible. It also doesn't change a news agency's need to get paid for the c…

What actual purpose do ads fulfill? Do they help you in making any decision in what to buy? No, they just mislead you, because you don't end up buying the best product, but the one that spent the most marketing dollars, meaning the product where the price is inflated the most (as, ifthey didn't pay for marketing, you could have gotten it cheaper). Instead, you should make your decisions on what to buy based on indepe…

Here's a quick definition of the actual purpose of advertising: https://www.entrepreneur.com/encyclopedia/advertising

Based on the way you describe business and what you think is objectively the best way to purchase products, my hunch is that you have little experience working in a company or making products you need to sell to others.

I mean this in a most genuine way: if you have any aspiration of managing a company or even building your own, it will greatly help you to learn more about why marketing and advertising are important to business. You simply won't succeed without them.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#135
post #66

Earlier quoted context omitted.

The world can be divided up into two types of advertising. DR (Direct Response) or Branding/Awareness. The goal of DR is drive an immediate action, for ex. a purchase or news letter signup. Branding/Awareness is more about keeping the brand/product top of mind for the eventual time when the purchasing is actually done. Usually small and mid-sized advertisers focus on DR. That's why you see a lot of re-targeting type…

The frusturating thing about this is how obvious it should be that the publisher account getting paid for the impression is _not_ the premium publisher that it said it was. If your account with, say, AppNexus is registered to "Mikhail Gorsky's Ad Fraud Ring" and it's registering video plays on espn.com/video at a $30 CPM, there are some very very basic heuristics that AppNexus could run to determine there is somethin…

That's my personal position.

The vendors that are letting the supply in (SSPs and exchanges) should do more to verify the supply. This could verifying their supply id with provided domain (would get rid of a lot of crappy arbitrage). Additional verification on new suppliers who are generating more traffic. And longer net payment terms for new suppliers to allow for clawing some of it back.

The problem is that many vendors are unwilling to do that. In many cases because they still make money on fraudulent traffic / arbitrage that goes through their platform. Or because they tend to be more accepting of bad data, because adtech is so duct tapped together. People setup their tags/campaigns incorrectly, adservers re-wrap urls, other incorrect rewrapping (fraud/viewablity/attribution), bad javascript, bad publisher sites and hostile browser environments. So they default to be more accepting to not lose on that revenue.

Re: Hackers Make $5M a Day by Faking 300M Video Views

#136

I'm not involved in ad tech, but am curious - isn't the easy solution for the advertiser to only show ads on sites that they pre-approve?

They do whitelist. MethBot was faking URLs though so it's hard for platforms to detect that in milliseconds. This goes to the IP level at this point with that list posted online. Our company is already getting asked to provide full reports by IP address to see how far this goes.

isn't the whitelist bound to the user? i mean if i register account as a publisher on some ad exchange, i should be asked for domains where i will be showing my ads. in that case i can not simply report that my username is generating traffic from cnn.com f.e. as this domain is not associated with my account. or this is not how it works?
Post reply on HN