Live data from Hacker News

Ad Nauseam

hackerfactor.com

11–20 of 59 posts

Re: Ad Nauseam

#11
post #5

"I think that we need to hold the web sites accountable for the content that they display. If browsers get infected by ads at Forbes or people buy knock-off watches from ads at Yahoo, then we need people to sue Forbes and Yahoo. Remember: these web sites authorized the placement of the ad on their web page." So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to scree…

> So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to screen every ad before it is shown when using an ad network.

Or you could have ad networks that only circulate carefully vetted/curated ads.

Imagine if you had an ad network that was picky and only allowed ads that were clever/interesting, short, not annoying, and didn't lead to malicious/fake products!

Re: Ad Nauseam

#12
post #5

"I think that we need to hold the web sites accountable for the content that they display. If browsers get infected by ads at Forbes or people buy knock-off watches from ads at Yahoo, then we need people to sue Forbes and Yahoo. Remember: these web sites authorized the placement of the ad on their web page." So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to scree…

> So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to screen every ad before it is shown when using an ad network. Or you could have ad networks that only circulate carefully vetted/curated ads. Imagine if you had an ad network that was picky and only allowed ads that were clever/interesting, short, not annoying, and didn't lead to malicious/fake products!

Most of the good ad networks today (like Adsense) try very hard to do this already. The problem is that it's not easy. For instance, how do you stop a malicious advertiser from creating a legitimate looking ad that points to a legitimate looking page, then redirecting it to a different page after the ad is vetted? What if it only redirects for certain IP address ranges? And that's just one example of a technique a malicious advertiser could use. None of the top tier networks want malicious ads on their platforms. The problem is that it's difficult to remove them.

Also, even if you could catch everything with manual human vetting of every ad, it would be cost-prohibitive. (Either you would have to pay less to publishers, or charge more to advertisers. The latter would likely be a non-starter, because it is already difficult for most small advertisers to run positive ROI campaigns. The former would put further pressure on publishers, making them even less likely to accept the risk of these proposed lawsuits.)

I would love to see online advertising improved, and I think there are certainly possible ways to go about it. I'm just trying to illustrate that it's not as easy as, "don't let people publish or distribute bad ads."

To borrow the analogy from the article, we couldn't stop spam by going after the email providers for allowing it through.

Re: Ad Nauseam

#13
and again Flash is the scapegoat

"By converting unsafe flash-based ads to safe HTML5 ads, they lower the risk of infection from a hostile ad." is laughable at best

An Ad Network is one of the fastest way to deliver a payload to a lot of users

Don't fool yourself, Operating Systems, Browsers and HTML5/JS also have a hell lot of CVE that can be exploited

It's funny how a company like Google making Billions from ads, having ton of smart engineers, have never figured out during the last decade how to "scan ads for malware".

It's not like anyone can upload an ad to those big network, or that they don't QA the ads before delivering them ...

Imagine this unlikely scenario: malware delivered by HTML5/JS

I guess we'll all have to run for the hills if that happen

Re: Ad Nauseam

#14
post #5

"I think that we need to hold the web sites accountable for the content that they display. If browsers get infected by ads at Forbes or people buy knock-off watches from ads at Yahoo, then we need people to sue Forbes and Yahoo. Remember: these web sites authorized the placement of the ad on their web page." So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to scree…

> So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to screen every ad before it is shown when using an ad network. Or you could have ad networks that only circulate carefully vetted/curated ads. Imagine if you had an ad network that was picky and only allowed ads that were clever/interesting, short, not annoying, and didn't lead to malicious/fake products!

"Or you could have ad networks that only circulate carefully vetted/curated ads."

No, you make it simpler than that

you simply forbid ads to be interactive or to contain any code

eg. you do only static ads like text, image, video

no code, no way to hide nasty stuff

Re: Ad Nauseam

#15
post #13

and again Flash is the scapegoat "By converting unsafe flash-based ads to safe HTML5 ads, they lower the risk of infection from a hostile ad." is laughable at best An Ad Network is one of the fastest way to deliver a payload to a lot of users Don't fool yourself, Operating Systems, Browsers and HTML5/JS also have a hell lot of CVE that can be exploited It's funny how a company like Google making Billions from ads, ha…

"and again Flash is the scapegoat"

Truth hurts? Adobe Flash and Microsoft Silverlight are common exploit paths because they have new critical exploits every few days. Here's the CVE list for Flash -- notice how many critical exploits there are? It averages to about 1 every 3 days. https://www.cvedetails.com/vulnerability-list/vendor_id-53/p...

In contrast, JavaScript itself has been pretty stable for years. I think the last vulnerability related to JavaScript ES5 impacted old Firefox browsers. http://www.cvedetails.com/cve/CVE-2015-4516/ https://www.cvedetails.com/vulnerability-list/vendor_id-452/... (Two JavaScript exploits for Firefox in 2015, both low risk.)

And HTML5? Extremely stable. There may be specific plugins or specific browsers that are vulnerable, but the underlying HTML5 specifications are very safe and have been safe for years. https://www.cvedetails.com/google-search-results.php?q=html5...

If you know otherwise, then please cite the specific CVEs. Otherwise, you're just spreading false information. You wrote, "Browsers and HTML5/JS also have a hell lot of CVE that can be exploited". I say: Prove it. Cite your sources.

Edit: Adding links to Firefox exploit CVEs.

Re: Ad Nauseam

#16
Or a third way, everybody hides content behind paywall, hail the new web 3.0. Maybe not a bad thing, subscription could bring the old qualified journalism back the in the print era.

If you don't think anti ad blocker is a problem, where is this article coming from? Hmmm, afraid that more websites would follow the trend so less content to read? The attitude that this is only websites and advertisers' problem is not as constructive as the author might presume.

Re: Ad Nauseam

#17
post #14

Earlier quoted context omitted.

> So effectively what you're saying is that we should eliminate ad networks. There is no reasonable way to screen every ad before it is shown when using an ad network. Or you could have ad networks that only circulate carefully vetted/curated ads. Imagine if you had an ad network that was picky and only allowed ads that were clever/interesting, short, not annoying, and didn't lead to malicious/fake products!

"Or you could have ad networks that only circulate carefully vetted/curated ads." No, you make it simpler than that you simply forbid ads to be interactive or to contain any code eg. you do only static ads like text, image, video no code, no way to hide nasty stuff

Your proposed approach will stop direct risks to browsers, but does nothing for ads that link to web pages that are hostile. E.g., you click on an ad because you are interested in the product and get directed to a phishing site or a site offering counterfeit goods or a site that has malware and infects your browser.

It's not just the graphic used by the ad, it's also the ad's destination.

Re: Ad Nauseam

#18
post #3

"But keep in mind: not everyone is Google, not ever web site has a huge amount of traffic. With online ads, payment is usually tied to the click-through rate (CTR). The CTR is typically around 1% (actual percentage varies by web site). So if 100 people visit your web page, then 1 person will probably click on the ad, generating a fraction of a cent. If each click pays $0.001, then you need 1000 clicks to earn $1. And…

>> "The CTR is typically around 1%"

That's pretty optimistic, on some ad networks representative CTR's are lower by an order of magnitude or two.

Re: Ad Nauseam

#19
post #16

Or a third way, everybody hides content behind paywall, hail the new web 3.0. Maybe not a bad thing, subscription could bring the old qualified journalism back the in the print era. If you don't think anti ad blocker is a problem, where is this article coming from? Hmmm, afraid that more websites would follow the trend so less content to read? The attitude that this is only websites and advertisers' problem is not as…

Yet the news sites demonstrate how utterly clueless they are with the amount they set their online subscriptions to.

£1 a day for The Times - very nearly the cost of the actual paper. $1 daily to access Wired. Don't make me laugh. No one consumes all their news from a single source any more.

If my usage pattern is anything near representative, 2-5p a day for the Times and .5p a day for Wired, based on how often I visit equivalent sites and how many stories I read whilst there.

Seems like unless it's something very specialised (medical journal or similar), or the FT charging as though it was our sole news source just demonstrates how out of touch they are.

Sure, charge me £1-£2 a day for consumption, but that would have to be spread across 50-100 sites daily, some of which I've visited just once in the last year, for one article. AND, if I am going to be willing to be micro-charged I want a way to NOT pay a specific site (perhaps I visited and the content was poor). Make that happen I'll subscribe today.

Ask me for £1 for your shitty site daily and you'll wait forever, but good luck with your greed - that's what caused the adpocalypse in the first place.

Re: Ad Nauseam

#20
Stop calling them ad blockers. They block surveillance features that advertisers put in their ads. I do not believe that ads would be blocked by surveillance blockers if they were just ads. Absent the surveillance, how would they recognize them? If ads were identical to the ads in analogue newspapers then surveillance blockers would let them through. When I read an analogue newspaper or magazine nobody is knowing if I read the ads or not. They only know whether they get results from advertising in that outlet. And they know that by tracking. They could run ads that don't spy on people. I always use surveillance blockers. I never shut them down for anybody. It is especially offensive when sites that are hardcopy outfits which have gone digital to keep up with the times complain about surveillance blockers. They certainly know how to run ads that are just ads. There is no technical difference between the ads and the rest of the page. The layout is the thing. They have experience with this and professional advertising people know about tracking results.
Post reply on HN