Live data from Hacker News

How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

buzzfeednews.com

101–108 of 108 posts

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#101

Earlier quoted context omitted.

If you're removing 700,000 apps a year from your store for violating your own policies, it's fair to say your system is not only not perfect, it's horribly broken.

Completely disagree. Could also mean they're doing a great job finding problematic apps.

Another way to look at it is their submission process fails to catch problematic apps. Making it necessary to pull them from the store after they have been published.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#102
post #65
post #49

Earlier quoted context omitted.

Can you point me towards credible work determining ROI for online advertisement? Whats the current state of the art? edit: I should rephrase, this sounds hostile. I know there is wide work in influencing people to buy stuff when influenced in person. The interpersonal dynamics are widely studied. I also know, that chumming content and goating works to gather more views, but that can only be turned into a ROI by peopl…

Shall I point you towards some keywords: ghost ads, conversion lift, brand lift studies. But what does it have to do with the ad fraud?

I dont think its surprising, that people are involved in scams when it comes to advertisement.

We know possible targets try to scam the system, this article shows so. We know, that certain parts of advertisements are trying to sell stuff to people they dont need. As naive as it sounds, most advertisement isnt there to inform us of stuff we dont know of and would want to buy if we knew. And if you pay people to make other people act against their own interests, it is not unreasonable, that they would do the same to the people hiring them. And not just the same, but alot more. I think its only reasonable to assume, that professional scammers would not just try to scam the people, they are payed to scam, but also the people who pay them in the first place, who offer a much larger payout.

Why wouldnt advertising agencies not put alot more effort in convincing potential customers of their own, that they need their advertisement, then trying to influence the potential customers of their customers on the abstract level of brand awareness.

If brand awareness is not a matter of ROI but bullshit and just a matter of triggering interpersonal marketing mechanisms. "Your competition is spending this amount on" brand awareness and all the other true and tested mechanisms. Marketing your advertisement services to companies for brand awareness sounds like just another sales gig. And one where the methods are true and tested. Be it selling used cars or selling you your appearal as your image or selling the concept of creating a brand throguh digital ads.

Lobbying works for a reason in politics. My question was, if there is a reason to not assume the same for online banner marketing for brand awareness.

Thank you for your keywords, i will look them up.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#103
post #75

Earlier quoted context omitted.

And without doing experimental setup (RCTs), how do you know you are not just paying for organic conversions? I had this presentation a few months ago: https://www.slideshare.net/mobile/gregak/if-youre-not-measur... I would be interested to know what you think.

Very interesting presentation. The question your research is attempting to answer is certainly a valid one for major sites, where people might be on the site anyway without having clicked on a given ad. In my specific case, most of the sites/offers we market through Facebook ads wouldn't have attracted many organic visitors, let alone conversions, on their own, so it's not a question I need to answer. These sites rel…

If close to 0 of your traffic is organic, then you don’t have to care too much about the whole correlation vs. causality problem, yes.

What you describe is certainly interesting. I guess you are building a graph of unique IDs, with each shared URL containing the ID of the parent as a query param or something like that?

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#104
post #98

Earlier quoted context omitted.

Assuming we erect such a system, what's my incentive to not use an ad blocker anyway? I don't want to see ten ads a day, I want to see zero.

Advertisers would pay me to watch the add in its entirety. Consider an example: timeshare sellers actually pay people to listen to their pitches.

Timeshare sellers are an excellent example, as they're typically scummy, underhanded, and will try to back out on their already dodgy payment if you don't take the bait.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#105

Earlier quoted context omitted.

If you're removing 700,000 apps a year from your store for violating your own policies, it's fair to say your system is not only not perfect, it's horribly broken.

Completely disagree. Could also mean they're doing a great job finding problematic apps.

They have "only" 2.6 million apps (as of March 2018):

https://www.statista.com/statistics/266210/number-of-availab...

37% fraud-rules breaking rate is pathetic. Maybe they should spend time vetting these things before allowing malware-infested spyware out into the "ecosystem."

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#106
post #103

Earlier quoted context omitted.

Very interesting presentation. The question your research is attempting to answer is certainly a valid one for major sites, where people might be on the site anyway without having clicked on a given ad. In my specific case, most of the sites/offers we market through Facebook ads wouldn't have attracted many organic visitors, let alone conversions, on their own, so it's not a question I need to answer. These sites rel…

If close to 0 of your traffic is organic, then you don’t have to care too much about the whole correlation vs. causality problem, yes. What you describe is certainly interesting. I guess you are building a graph of unique IDs, with each shared URL containing the ID of the parent as a query param or something like that?

Something like that, yes. When you visit any URL on the site, we use javascript to rewrite the URL in the location bar with a shortened, unique, trackable URL. So we know both what URL you came in through, and the new URL that we then assigned to you. With this we can track every click all the way back up through the tree to the initial click, even if you just copy/paste the URL or hit the button on your phone to text the page to a given contact. Where possible, we also track any link preview engines that visit the URL, so we can usually tell not just that you shared, but how you shared (skype, telegram, iMessage, gmail, facebook, twitter, etc.).

I initially wrote this system so that I could retarget through Facebook ads people that had previously shared viral news articles, but now we have found great applications for it in ecommerce and lead gen as well.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#107
post #103

Earlier quoted context omitted.

If close to 0 of your traffic is organic, then you don’t have to care too much about the whole correlation vs. causality problem, yes. What you describe is certainly interesting. I guess you are building a graph of unique IDs, with each shared URL containing the ID of the parent as a query param or something like that?

Something like that, yes. When you visit any URL on the site, we use javascript to rewrite the URL in the location bar with a shortened, unique, trackable URL. So we know both what URL you came in through, and the new URL that we then assigned to you. With this we can track every click all the way back up through the tree to the initial click, even if you just copy/paste the URL or hit the button on your phone to tex…

You wouldn’t know who shared until someone doesn’t actually visit the shared link, right? Unless I’m misunderstanding something. Also I don’t see how you would build a custom audience on FB for the people who shared, e.g. by copy-pasting the URL from the location bar. I see how you would do it on some javascript event (e.g. page load, click on share button, etc.), but that’s not the same.

Re: How a Massive Ad Fraud Scheme Exploited Android Phones to Steal Millions

#108
post #107

Earlier quoted context omitted.

Something like that, yes. When you visit any URL on the site, we use javascript to rewrite the URL in the location bar with a shortened, unique, trackable URL. So we know both what URL you came in through, and the new URL that we then assigned to you. With this we can track every click all the way back up through the tree to the initial click, even if you just copy/paste the URL or hit the button on your phone to tex…

You wouldn’t know who shared until someone doesn’t actually visit the shared link, right? Unless I’m misunderstanding something. Also I don’t see how you would build a custom audience on FB for the people who shared , e.g. by copy-pasting the URL from the location bar. I see how you would do it on some javascript event (e.g. page load, click on share button, etc.), but that’s not the same.

Correct, we don't know who shared until someone visits the link. But, we can build a custom audience after the fact because the Facebook retargeting pixel lets you pass an arbitrary ID of your choosing with each pixel load (the variable name is "extern_id" [1]). So when a click comes in on a given URL that we know had to have been shared, we know what extern_id we gave to Facebook for the original user that shared the link on the pixel fire back when they first visited the site. We can then build a custom audience using a list of those extern_id's for only people that have shared, after the fact.

https://developers.facebook.com/docs/marketing-api/audiences... - see "External Identifiers"

Post reply on HN