Live data from Hacker News

An iframe from googlesyndication.com tries to access the camera and microphone

techsparx.com

271–280 of 280 posts

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#271

I think this sounds more like some sort of fingerprinting attempt. It good to see that random access to these kind of resources fails due to new(er) browser controls. However, this does not mean that the fingerprinting actually failed. There is probably some way to determine if the request was denied automatically by the browser or manually by the user (e.g., time to get "response"), which is definitely something whi…

Very likelx true. I am more and more of the opinion that more users should attempt click fraud. I know that advertising does pay for infrastructure, but most advertisers are just interested in their competition not being able to do more.

But since there is absolutely no consideration for privacy from corporations like Google or Facebook, I don't see the need to support their perverse business model.

If enough users participated in such schemes, maybe these privacy invasions would stop.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#272
post #252

Earlier quoted context omitted.

Fingerprinting with any accuracy is hard. As a legitimate use case, I had a corporate client who wanted their management software only accessible to sub-management employees from certain on-site locations. And they wanted this without sending those employees through a VPN or having a static IP for each location. So what I allowed them to do was to let a manager clear a given device's browser fingerprint (e.g. on the…

But isn’t this exactly what client-side certificates are invented for?

Yeah. Maybe out of paranoia, there was concern that a rogue employee could snatch a client side key and reestablish a session from outside. The fingerprinting was aimed at making any attempt at that easily identifiable.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#273

Earlier quoted context omitted.

> Since ads can run arbitrary JS it's hard to enforce policy programmatically. It's not that hard, at least not at my end. I just don't run ads. Why on earth does goo think that running arbitrary JS on their visitors' computers is OK? I mean, I know this is the policy, and I assume the policy of other ad networks is at least as "liberal". So I'm sorry, chaps, but no ads run on this screen. I wonder if this is a race…

>Advertising to poor people has traditionally been a pretty bad pitch Is that true? It seems like poor people spend, in aggregate, more than rich people and they tend to buy the cheaper, more mass-produced stuff. The grocery business alone must be build on the commerce of poor people, right?

> The grocery business alone must be build on the commerce of poor people, right?

How often do you see grocers advertising own-brand baked beans? If you see baked beans advertised at all, they're drawing attention to the fact that their Heinz beans are 1p cheaper than $COMPETITOR's Heinz beans.

I'm not convinced that advertisers spend much money on pitching to poor people. Most of the ad pitches that I see are for high-end products like cars, holidays, and household appliances. There's not much point in advertising to people whose weekly budget doesn't stretch to luxuries. They will buy only what they need; they don't have choices.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#274

Earlier quoted context omitted.

But the context/question is whether or not the adverts are different, not whether the search results are different.

As a counter point, google used to (still does?) recruit based off of your search history. the famous “now you’re speaking our language” popups

https://news.ycombinator.com/item?id=17289580

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#275
post #14

Is this just click bait? I don't know the intricacies of Google's ad serving, but is this not just someone (e.g., an ads customer) slipping a request for camera and mic access into an ad script? But the title seems to suggest Google is doing something malicious here.

Well, it's HN. HN has become a FUD machine.

"When disagreeing, please reply to the argument instead of calling names. 'That is idiotic; 1 + 1 is 2, not 3' can be shortened to '1 + 1 is 2, not 3."

"Please don't sneer, including at the rest of the community."

https://news.ycombinator.com/newsguidelines.html

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#276
post #132

Earlier quoted context omitted.

> Letting ads run arbitrary JS is the policy, right? I mean, anything on the Web can run arbitrary JS. The entire point is that it's a sandbox environment where arbitrary JS can't do any harm (excluding cases where vulnerabilities are found). If you're not comfortable with arbitrary JS running on your computer, you'd have to either (a) not use the Web, (b) disable JavaScript, or (c) only visit sites which you have ve…

> (a) not use the Web, (b) disable JavaScript, or (c) only visit sites which you have vetted and deem to be trustworthy. > I don't know what else you could really expect of them. Your option C is basically how it must work, and mostly does. To be safe online we go to sites we trust. When Google delivers malicious JS through ads, the site operator probably doesn't know Google has harmed the user on their behalf, so th…

> To be safe online we go to sites we trust.

I'm fairly confident in saying that nobody, but nobody, only goes to sites they trust. Come on. You're on HN: do you mean to tell me that you never click to open a link from a post unless you've pre-vetted the website and know it to be trustworthy? That's simply not a practicable model.

And every site pulls in JavaScript which, to you, is arbitrary. You don't know that they won't add a new third-party script, and you don't know that any given third-party script won't change. You don't know that transitively for the scripts loaded by the scripts. Etc etc etc. Nobody can practise the approach you are setting out here, not both diligently and honestly.

Your complaint here is just about how the internet works. It's absurd to expect Google to vet the JavaScript that all of its users host, as much as it's absurd to expect Squarespace or Weebly or even AWS or Cloudflare to do the same. The model of the internet does not and cannot rely on any and all JavaScript being vetted for 'malice' by a trusted party before being loaded. It relies on the JavaScript runtime being a safely isolated sandbox where malice or the lack thereof doesn't matter either way.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#277

Earlier quoted context omitted.

>Advertising to poor people has traditionally been a pretty bad pitch Is that true? It seems like poor people spend, in aggregate, more than rich people and they tend to buy the cheaper, more mass-produced stuff. The grocery business alone must be build on the commerce of poor people, right?

> The grocery business alone must be build on the commerce of poor people, right? How often do you see grocers advertising own-brand baked beans? If you see baked beans advertised at all, they're drawing attention to the fact that their Heinz beans are 1p cheaper than $COMPETITOR's Heinz beans. I'm not convinced that advertisers spend much money on pitching to poor people. Most of the ad pitches that I see are for hi…

If placement is considered a kind of advertising spend (and I think it is) then impulse buys are going to be an ad spend in general. Gambling, porn, junk food, that kind of thing.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#278
post #268

Earlier quoted context omitted.

Doesn't seem like a great example since the image itself is perfectly safe. The exploit still needs JavaScript to extract and execute the payload embedded in the image, and then relied on Flash to install malware. Without JavaScript it's just an image like any other. The NSO group iMessage exploit is a more interesting example, essentially turning a poorly bounded JBIG2 decompressor into a virtual machine.

haha, if a country wants to spend a 9 figure sum or someone comes back in time from the future to hack me, I'll be happy to consider myself pwned It's a huge bummer that I HAVE TO block all ads as a security measure, though, and that people accept "Download advertisement.exe and run it in a half-assed sandbox or you're stealing that clickbait article" as the way things should be

> if a country wants to spend a 9 figure sum

After the initial investment in developing the exploit and before the vulnerability was patched, there would have been a near zero cost to hack any one user in particular.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#279
post #276

Earlier quoted context omitted.

> (a) not use the Web, (b) disable JavaScript, or (c) only visit sites which you have vetted and deem to be trustworthy. > I don't know what else you could really expect of them. Your option C is basically how it must work, and mostly does. To be safe online we go to sites we trust. When Google delivers malicious JS through ads, the site operator probably doesn't know Google has harmed the user on their behalf, so th…

> To be safe online we go to sites we trust. I'm fairly confident in saying that nobody, but nobody, only goes to sites they trust. Come on. You're on HN: do you mean to tell me that you never click to open a link from a post unless you've pre-vetted the website and know it to be trustworthy? That's simply not a practicable model. And every site pulls in JavaScript which, to you, is arbitrary. You don't know that the…

I didn't say people always have a good reason for trusting the sites they go to. I trust that HN links are safe because I think that someone would make a stink, at least, if there were malware on a page linked here. It's not perfect but it is how things work. A nasty part of contemporary business and business in general is: as long as trust isn't visibly betrayed, people go on trusting. That doesn't excuse any of the actors who benefit from the ignorance.

Re: An iframe from googlesyndication.com tries to access the camera and microphone

#280

Earlier quoted context omitted.

Then i just get put on another list :)

You get put on a different list each time. :)

Or you get put on the same list again. And again. And again. The list of users that have only visited once and never came back (because when you came back you were sometime else).
Post reply on HN