Live data from Hacker News

How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

buzzfeednews.com

11–20 of 108 posts

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#12
post #7
post #3

I seems to me that - besides the specific fraud scheme in the article - there is something else to be worried about. From the article: >The revelation of this scheme shows just how deeply fraud is embedded in the digital advertising ecosystem, the vast sums being stolen from brands, and the overall failure of the industry to stop it. And, more relevant: >Pixalate’s latest analysis of in-app fraud found that 23% of al…

"Impressions" is a rather meaningless metric. If A$ = B impressions = C clicks = D sales then the amount of fraud is irrelevant it's just a question of A$ = D sales from the advertisers perspective.

Every single brand still cares about impressions at some level, even if everyone knows they're broken. C-level likes to see that spend was $100k, we had 12.5MM imps, and drove $600k in revenue.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#13
post #3

I seems to me that - besides the specific fraud scheme in the article - there is something else to be worried about. From the article: >The revelation of this scheme shows just how deeply fraud is embedded in the digital advertising ecosystem, the vast sums being stolen from brands, and the overall failure of the industry to stop it. And, more relevant: >Pixalate’s latest analysis of in-app fraud found that 23% of al…

> they perfectly know that more than 1/5 of their ads expense is having "null" results but overall they are ok to spend the 100% price for less than 80% "real" impressions Don't ad companies charge fees as a function of spend? The chumps in this chain are (a) shareholders and (b) the managers hiring the agencies. (Counterfactual: if this spend is that useless, it should be possible to start a competitor that focuses…

> Counterfactual: if this spend is that useless, it should be possible to start a competitor that focuses on high-ROI advertising.

Exactly! And that's where online ads, user tracking, online-to-offline came in. The whole reason why it gained so much traction in the past 20 years is that it began to offer better tracking and results than other forms of advertising.

If Google (or Facebook, or anyone else) stands still and lets fraudsters abuse their ad networks, the return on their ads will drop, opening space for their competitors.

So controlling ad-serving quality is a competitive advantage.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#15
post #2

> This means a significant portion of the millions of Android phone owners who downloaded these apps were secretly tracked as they scrolled and clicked inside the application. By copying actual user behavior in the apps, the fraudsters were able to generate fake traffic that bypassed major fraud detection systems. So the fraudsters essentially did what Google is best at -- tracking and making 'use' of the information…

[deleted]

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#16
post #3

I seems to me that - besides the specific fraud scheme in the article - there is something else to be worried about. From the article: >The revelation of this scheme shows just how deeply fraud is embedded in the digital advertising ecosystem, the vast sums being stolen from brands, and the overall failure of the industry to stop it. And, more relevant: >Pixalate’s latest analysis of in-app fraud found that 23% of al…

It’s defintiely 2. But ads are priced on value to the advertiser. If someone reduced fraud to 0% they would just charge 20% more, and that money goes from fraudsters to advertisers, not more ads. This exists already, networks that filter out fraud better can charge higher rates.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#17

I'm always curious how exactly the fraud detection happens. Is Pixalate doing network analysis? App Analysis? Could I do the same thing myself with wireshark on my home network?

Basically all "spyware" traffic is encrypted, you can however see which IP's users of your network connects to (and some meta-data such as domain name, protocol and hand-shakes) using for example Wireshark or tcpdump. My guess is that the fraud is detected by monitoring the traffic on the ad server, see that a "impression" is registered from their test phone's IP, and by looking at the phone they affirm that no ad was displayed.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#18
post #3

I seems to me that - besides the specific fraud scheme in the article - there is something else to be worried about. From the article: >The revelation of this scheme shows just how deeply fraud is embedded in the digital advertising ecosystem, the vast sums being stolen from brands, and the overall failure of the industry to stop it. And, more relevant: >Pixalate’s latest analysis of in-app fraud found that 23% of al…

Publishers already stuff as many ads in the space they have as viewers will tolerate, so it's unlikely that a reduction in fraud will result in consumers seeing more ads. If anything they'll see fewer ads, since the existing ad space will become more valuable. The fact that ad space is primarily sold in the form of real-time auctions, and advertisers can track end-to-end results online (e.g. "we generated $10 in new sales per 1000 impressions last month") ensures that the price goes down when there's more fraud and up when there's less. Undetected impression fraud leads to publishers earning less for their legitimate impressions, not advertisers paying a premium.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#19
I have mixed feelings about the ad market. Automated ads is a very nice business model, compared to trying to get users to pay for your content. Running ads basically automates your whole sales organization, you do not even need a sales organization. On the other hand, I forget what's the term in game theory, but it's a lose-lose game, where the one with the most ads wins, not necessary the one with the best product. - Forcing competitors to also spend money on ads. And because it's fully automated - it's easy money for bad actors.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#20
post #17

I'm always curious how exactly the fraud detection happens. Is Pixalate doing network analysis? App Analysis? Could I do the same thing myself with wireshark on my home network?

Basically all "spyware" traffic is encrypted, you can however see which IP's users of your network connects to (and some meta-data such as domain name, protocol and hand-shakes) using for example Wireshark or tcpdump. My guess is that the fraud is detected by monitoring the traffic on the ad server, see that a "impression" is registered from their test phone's IP, and by looking at the phone they affirm that no ad wa…

It is functionally trivial to rotate IPs from the "test phones". There are shady brokers who will sell you Residential IP-based proxy servers (hacked home machines which will proxy your calls and make them appear to come from homes all around the world).
Post reply on HN