Live data from Hacker News

How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

buzzfeednews.com

51–60 of 108 posts

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#51
post #7

Earlier quoted context omitted.

"Impressions" is a rather meaningless metric. If A$ = B impressions = C clicks = D sales then the amount of fraud is irrelevant it's just a question of A$ = D sales from the advertisers perspective.

Depends. Are the ads direct or banding? Coke ads to have you buy offline for example, the sales are not so easily tracked.

Coke still "just" cares about sales, they simply can't directly measure it as well and thus use impressions as a proxy for sales. It’s clicks they don’t nessisarily care about.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#52
post #21

As someone who works monitoring ad network traffic at a large ad-tech company (not FAANG, but just below), let me just say: everyone does fraud . Some don't need as much of it (e.g., Google), but quite literally saying "there's fraud in my online traffic" is like saying "there's tomato sauce in my spaghetti". It's quite literally such a normal thing that I've become immune to even getting roused by it (and remember,…

Beyond this, ad spend ASSUMES some level of fraud. It's baked into your ROI numbers, at least for performance advertising. Probably the main people getting stiffed are the publishers who are offering real traffic, and getting a smaller share of dollars relative to the incremental value they deliver.

> Probably the main people getting stiffed are the publishers who are offering real traffic

Unless you're a large premium publisher like say a NYT, a Techcrunch, or even a Forbes, more of your traffic probably wont be real, and you have little to no control over that. The online ad/traffic buying game is so mind-blowingly convoluted, you can be a small publisher (foo.com), having your site spammed, and what little revenue you've made via your supply completely wiped out (i.e., clawed back by your upstream partner - even large publishers don't operate by themselves), and your reputation takes a hit.

The main people getting stiffed are the web users, and the advertisers. But it doesn't seem like either of them care enough about it to do something that can have a lasting effect

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#53
post #25
post #11

Google's blog about it: https://security.googleblog.com/2018/10/google-tackles-new-a...

a security blog you can only read after enabling javascript for a dozen domains. Nice one google.

Adding ?m=1 to Blogger blogs usually works. https://security.googleblog.com/2018/10/google-tackles-new-a...

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#55
So, to summarise online advertising:

1. It has been a vector for viruses / malware / cryptocoin mining

2. It tracks users activities on the internet without their knowledge to form a picture of their 'online personality'

3. It can invade a users privacy by keeping records of personal and / or intimate details of their online activities

4. It often uses more bandwidth than the content of the site it's on

5. auto-play videos

6. unexpected audio

7. As per rayvy's comment "everyone does fraud"

As the Joker said "this town needs an enema".

Given that "all the smartest people in the world work for advertising" it's a remarkable collective of all kinds of failure. And yet it continues to make a shit-ton of money because it's pretty much the only game in town.

What's the alternative? Word-of-mouth? That requires a product that's good and useful both now and into the future; not a fad. The growth-rate can also be glacial for a long initial phase, which needs commitment and passion from it's developers and management over the long term.

I can't see any revolution on the horizon though. It's going to take an impossibly sized critical mass of society to protest, and given the number of people still on Facebook... 'Brands' aren't going to stop advertising for fear of competitors getting more eyeballs.

I'm going to start an advertising company called Raypenpillidge Sleepwell.

Footnote: Point #3 is separate to point #2 because tracking and privacy invasion should be considered separately - tracking could be done more openly with user consent which would mean the level of privacy invasion could be chosen by the user.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#56
I’m kind of amazed how much money can be tied up in things that are not well understood by the vast majority of people who fund those things.

Ad networks. Various products from financial institutions. Cryptocurrencies. Heck, even app stores (as a developer, if your app was sold to somebody and Apple/Google’s system was simply broken and somehow they made their cut but you didn’t, how would you even know?).

At a certain point, it sure seems that people rely on popularity as proof of proper functionality (i.e. “lots of people seem to use this just fine” = “nothing can go wrong”). In reality, we should be expecting a lot more: asking harder questions, demanding more proof of activities, expecting extremely reliable support, etc. And frankly, a lot of these things should have open-source implementations to make it even easier to ensure that they work the way they claim to.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#58
post #49

Earlier quoted context omitted.

Beyond this, ad spend ASSUMES some level of fraud. It's baked into your ROI numbers, at least for performance advertising. Probably the main people getting stiffed are the publishers who are offering real traffic, and getting a smaller share of dollars relative to the incremental value they deliver.

Can you point me towards credible work determining ROI for online advertisement? Whats the current state of the art? edit: I should rephrase, this sounds hostile. I know there is wide work in influencing people to buy stuff when influenced in person. The interpersonal dynamics are widely studied. I also know, that chumming content and goating works to gather more views, but that can only be turned into a ROI by peopl…

Also interested. I suspect the lack of noise is a result of lack of impressive results.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#59

Earlier quoted context omitted.

When it comes to email spam or fake email accounts, Google not only allows it, they enable it. One scammer can setup thousands of gmail accounts and google doesn't blink an eye. Gmail also allows "scammer+1@gmail.com" and "scammer+2@gmail" to be the same account. I've reported obvious gmail abuse to Google through their channels, but nothing. Same scammer keeps coming back with new email accounts.

>Gmail also allows "scammer+1@gmail.com" and "scammer+2@gmail" to be the same account. This is a well-documented feature that has many legitimate uses. If you're trying to stop fraud, clip any gmail addresses after the +. For example, I believe Facebook does this.

I do clip it. I have to do many other things too (spending time and money) to counteract scammers usage of google's services. Given google's ability to track people, they'd could do more against fraud, instead of letting scammers use their services freely (hence my comment of them enabling scammers).

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#60
post #26

Didn't this type of fraud require massive domain expertise?

1. record all network interaction going out of your MRAID adapter, from your few, actual users. 2. replace timestamp and userIDs fields on the network requests you will replay with Math.random() 3. Profit! Seems pretty simple and banal to me.

> userIDs fields on the network requests you will replay with Math.random()

Isn't this _why_ you'd need domain expertise? Random User IDs would be detectable - a French user suddenly clicking on English ads and following East Coast time would be a red flag.

Post reply on HN