Live data from Hacker News

Google AdWords Exploit Seen in the Wild

wp.josh.com

161–163 of 163 posts

Re: Google AdWords Exploit Seen in the Wild

#161

Earlier quoted context omitted.

This might come as a surprise to you, but every company doesn't have infinite developer time to reinvent things which already exist.

Then they should be held accountable for their choice not to vet ads they send to their users. If this was enforced legally, a bunch of companies would suddenly be able to invest the "infinite time" required to register a damn click.

That's obviously not the hard part.

Re: Google AdWords Exploit Seen in the Wild

#162

Earlier quoted context omitted.

I guarantee you that I can craft URLs users will click even if the whole URL is exposed. This "solution" makes developers feel better but provides essentially zero additional security.

Can you give an example? And will it never help? I think it’s silly to argue against this. It’s like saying “computer security is hard so why bother at all.” It’s a continued arms race, where you continue to make things harder and harder. This strategy is working the rate at which people are hacked on platforms like iOS is a fraction of what it used to be like for general computing. There will always be security hole…

Never is a silly standard to measure against.

I'm clearly not saying don't do it at all, I'm saying that this approach won't succeed at anything other than making developers feel like they're Doing Something™. Actual spam filtering and 2fa are examples of real security, showing users the URL is an example of security theater.

The corollary is the nonsensical "security is hard so let's force non-technical users to do it".

Re: Google AdWords Exploit Seen in the Wild

#163

Earlier quoted context omitted.

Then they should be held accountable for their choice not to vet ads they send to their users. If this was enforced legally, a bunch of companies would suddenly be able to invest the "infinite time" required to register a damn click.

That's obviously not the hard part.

"The hard part" can still be outsourced to a third party without resorting to redirection chains, either by sending the click information to them on the server-side or by sending it client side using a script.

Either way, "the hard part" is generally undesirable to users because it compromises their privacy in order to manipulate them.

Post reply on HN