Live data from Hacker News

Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

techcrunch.com

111–120 of 156 posts

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#111
These guys are pretty annoying. And it ads an "untrusted" advertising stream to the page, a channel which has been the source of malware infections in the past.

I'm really curious how this all turns out. I can't imagine the deteriorating system lasting another 5 or 10 years. So what happens after? Clearly advertising has _some_ value, I loved BYTE magazine as much for the ads as I did for the articles, and there are under served retailers (a lot of Business to Business stuff) as the trade magazines take hits. So how do people discover this stuff? How do they find those opportunities when Internet ads are dead?

Or do we get to a more reasonable advertising load? Something without flash/js jiggling around and trying to get your cursor. How will sites let users know they don't allow "invasive" ads? How will users respond? For me at least I think it is the difference between Web 2 and Web 3.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#112
> Google and the Berkeley researchers found that ad injectors are now available on all major platforms and browsers.

Bull. iOS is a HUGE chunk of web browsing and its immune from this stuff unless you jailbreak or are conned into installing a root cert and VPN.

You can't just download an app from the store or visit a site and find it installed like you can on a desktop.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#113

Earlier quoted context omitted.

Am I the only one who thinks this reality sucks? Everything locked down, no way to tweak or repurpose any of your software. I know, there are bad actors out there, etc. but shouldn't there be a limit for destroying utility of things in the name of security?

Why would proper sand boxing limit tweaking or repurposing of software? (I must admit I'm not sure exactly what you mean by that). It just limits apps interactions with each other and the OS environment.

You answered your own question:

> It just limits apps interactions with each other and the OS environment.

That makes a whole slew of modifications and tricks harder and/or impossible without having access to the sourcecode of the software, which is (on windows at least) not rare at all.

Any kind of interaction not explicitly allowed is then forbidden and the sandboxing will be a lot harder to overcome than two apps on the same machine talking to each other using a third.

Maybe some kind of unified app-to-app messaging protocol can take care of this, similar to how linux systems uses 'dbus' and the likes.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#114

Earlier quoted context omitted.

Fortunately they have 'watsi' too. Downvoters are invited to explain what's wrong with this comment, I see installmonetizer as one of the low points in the history of YC and watsi as the high point, possibly the high point in VC investing in the last decade or more.

Spending your weekends volunteering at a soup kitchen doesn't give you the right to throw litter onto the highway. Just because YC has watsi doesn't mean they shouldn't have to explain why they're affiliated with InstallMonetizer, and justify their decision.

I agree with that in principle, but: YC invests in companies at an absolutely enormous rate, they have relatively few 'rotten apples' when you take into account that they encourage companies to pivot post investment and that they couldn't change what a company actually does even if they wanted to (they own a very small minority of the stock after all).

If I were in YC/PGs shoes I would have dropped installmonetizer the second I found out what they did but then again, I don't run the most successful start-up accelerator on the planet for a good reason.

In fact, I wouldn't have invested in them in the first place. But on the whole if you select for hackers driven to make money at any cost you can expect to get a rotten apple every now and then.

Whether or not YC should have dropped installmonetizer once it became clear what they were up to (if that wasn't clear from the application alone) is something everybody has to decide for themselves, for me it is clear that they should have.

Also, to their credit I haven't seen them invest in anything as shady as installmonetizer after that point so maybe some lessons were learned.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#115

I googled for "Open Office download" on a family's computer and went with the first download -- download.com or cnet, I think. It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site. It was scary, being a technical professional,…

I never download from 3rd party sites like cnet. Just take the extra few seconds to identify the official site and go there.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#116
post #85
post #2

You can't trust anybody except for open source repositories. The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware. There are whole companies dedicated to this concept of piggy-backing junk.

>You can't trust anybody except for open source repositories. That is patently false. Established profitable companies in a market with multiple competitors usually do not fuck with their customers, if they charge up-front for their product/service. On the other hand, companies that give away stuff for "free" have to find unique ways to pay the bills (be it hosting fees, or hardware costs, or developer time, etc). In…

> Established profitable companies in a market with multiple competitors usually do not fuck with their customers, if they charge up-front for their product/service.

Lenovo (and lots of other hardware manufacturers) are proof positive that this is absolutely not the case. There isn't a windows machine bought over the years by my extended family that did not have a whole pile of junk on it right from day one including ad injectors such as described in the article.

Whether or not open source is 'viable' for large numbers of users is no longer a question that needs settling. For bandwidth we have torrents if need be.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#117

I googled for "Open Office download" on a family's computer and went with the first download -- download.com or cnet, I think. It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site. It was scary, being a technical professional,…

This is fundamentally Microsoft's fault. The shareware culture of Windows is insanely insecure these days. Any sane operating system should have a packet manager, with all the software you could want included, and nothing you don't.

Yeah it's Microsoft's fault for allowing third-party applications be be installed on their OS. You'd never see OSX or Linux letting people install software without going through a walled garden.

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#118

These guys are pretty annoying. And it ads an "untrusted" advertising stream to the page, a channel which has been the source of malware infections in the past. I'm really curious how this all turns out. I can't imagine the deteriorating system lasting another 5 or 10 years. So what happens after? Clearly advertising has _some_ value, I loved BYTE magazine as much for the ads as I did for the articles, and there are…

How did you discover websites before advertising took over the web?

I don't remember having any trouble discovering new stuff, rather the opposite, word of mouth and following links gave an endless stream of new and interesting stuff.

This site alone generates more info in that bracket than I can keep up with (even though I really try to).

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#119
post #79

I googled for "Open Office download" on a family's computer and went with the first download -- download.com or cnet, I think. It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site. It was scary, being a technical professional,…

A nice benefit of using DuckDuckGo is the distinctive way it flags an official site.

[deleted]

Re: Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed

#120

Earlier quoted context omitted.

Why would proper sand boxing limit tweaking or repurposing of software? (I must admit I'm not sure exactly what you mean by that). It just limits apps interactions with each other and the OS environment.

You answered your own question: > It just limits apps interactions with each other and the OS environment. That makes a whole slew of modifications and tricks harder and/or impossible without having access to the sourcecode of the software, which is (on windows at least) not rare at all. Any kind of interaction not explicitly allowed is then forbidden and the sandboxing will be a lot harder to overcome than two apps…

Exactly this. I still remember the times when if I needed to change something in an application, I could just write to its process memory directly. Those were fun times...

What I want is to retain the ability to repurpose the software on my terms. To move data in and out of the software whether software's authors like it or not. It's becoming harder each day, as more and more tools move to the cloud and turn into apps. I'm happy we still have userscripts in the browser but how long will it take before they get banned too?

This problem has many names. "War on General-Purpose Computation" is one of them, but I suppose the "professionalization of programming" is another. How long will it take before you'll need an engineering license to be allowed to use a compiler, or work with a Turing-complete language?

Post reply on HN