Live data from Hacker News

An ad plugin was stealing revenue for a year and I didn't even notice

kvirkvelia.com

161–170 of 195 posts

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#161

Earlier quoted context omitted.

The article seems to be down for me. But I’ve gathered it was spelled out in the license? They even returned money? Removing a person’s revenue stream because someone wrote a blog post is by default, an overreaction. If they’re going to change it all anyway, why rush it?

> But I’ve gathered it was spelled out in the license? Just curious, is this your attitude towards other things as well? There used to be a very popular ebay scam, which had people sell large screen TVs and video game systems for very cheap. At the bottom of the auction description, in fine print, the auction also clearly stated that you were bidding/buying only a photo of the product, not the actual product. In othe…

LOL. That’s pretty funny, actually. Is it a scam when toys say batteries not included in small print too? IDK, maybe it’s my outlook on making sure I’m getting what I’m buying (or what I’m not getting as the case may be)! I don’t see anything shady here, but I couldn’t access the article earlier. I’ll try again here in a bit!

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#162
post #151

Earlier quoted context omitted.

You don’t read the contract, you pay the price. People just arbitrarily pulling in code from random people on the internet and expecting everything to be fine is hilarious. Your project, due the due diligence. To answer the hypothetical, the author is still at fault even if was malware.

> To answer the hypothetical, the author is still at fault even if was malware. Wow, that's as explicit victim blaming as you can get.

Dismissing something as "victim blaming" is the best way to say "I am not mature enough to accept that I have responsibilities, and I will play the role of a victim for as long as I can stay unaccountable for my actions".

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#163
post #151

Earlier quoted context omitted.

You don’t read the contract, you pay the price. People just arbitrarily pulling in code from random people on the internet and expecting everything to be fine is hilarious. Your project, due the due diligence. To answer the hypothetical, the author is still at fault even if was malware.

> To answer the hypothetical, the author is still at fault even if was malware. Wow, that's as explicit victim blaming as you can get.

Victim blaming? OP is bragging about his revenue in the very same blog post! He used open-source code without taking the time to understand what the code did and somehow we're victim blaming?

> THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.

That's the license OP agreed to when he used the code.

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#164

Earlier quoted context omitted.

> But I’ve gathered it was spelled out in the license? A 2% cut was spelled out in the license. A 30% cut was not, but the plugin author silently upped it to that over vague assertions of abuse of the plugin. > "After check, we find your app in the black list, and a random higher rate will be applied. Usually when a guy is using a fake license key, or send unusual attacking request..."

Further in that same paragraph, the plug-in author goes on to say that they removed the guy’s app from said blacklist and even upgraded him to a fully paid license for free. And on top of all that he even gave dude back $4000 bucks! I really don’t see either party as underhanded here, maybe lazy in respect to both communicating and with paying attention, but I can’t see either as being shady. It’s just a series of hu…

I'm left wondering how many other sites are quietly getting 30% of their revenue siphoned off due to a similar "malfunction", and how much of the easy refund process is to avoid a public fuss that'd reveal that fact.

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#165

The responses here to this story defending the plugin author are appalling. They all seem to boil down to "you didn't read the fine print or the source code, so whatever the plugin does is defensible". What if instead of taking a percentage of the ad revenue, the plugin siphoned credentials or ran malware as a revenue generator, or did whatever else? And what if it openly explained in the fine print that it would be…

> What if... They plugin siphoned credentials or ran malware (etc.)

If you hypothesize that the software did something illegal, I hypothesize that nobody would defend it.

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#166

Earlier quoted context omitted.

> To answer the hypothetical, the author is still at fault even if was malware. Wow, that's as explicit victim blaming as you can get.

Dismissing something as "victim blaming" is the best way to say "I am not mature enough to accept that I have responsibilities, and I will play the role of a victim for as long as I can stay unaccountable for my actions".

I asked this question in another comment, but same thing: Just curious, is this your attitude towards other things as well? There used to be a very popular ebay scam, which had people sell large screen TVs and video game systems for very cheap. At the bottom of the auction description, in fine print, the auction also clearly stated that you were bidding/buying only a photo of the product, not the actual product. In other words, it was "spelled out", so no one was getting scammed according to your perspective here, right? It was on the fault of the buyers for not reading the license/auction description?

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#167
post #163

Earlier quoted context omitted.

> To answer the hypothetical, the author is still at fault even if was malware. Wow, that's as explicit victim blaming as you can get.

Victim blaming? OP is bragging about his revenue in the very same blog post! He used open-source code without taking the time to understand what the code did and somehow we're victim blaming? > THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AU…

I really wonder if you have the same approach to all other situations with fine print, not just software contracts? Ebay scams, usury lending agreements, everything?

If on line 37, page 409, of a car rental agreement that you sign, it states that if you are an hour late in returning your vehicle, the car rental company will take your firstborn, and you sign this agreement, then it's on you, right?

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#168
post #101

Earlier quoted context omitted.

There is a huge divide between "oh hey you didn't read the license and missed the fact that this OS addon takes 2%" and "the license said 2%, but it's actually 30%, oops my friend!"

I see zero difference. There is an explicit mention that bad things will happen if you subvert the license system. A license is $20, OP is just too lazy to read the terms of code he blindly incorporates. Op called 2% stealing, 30% is for basically triggering the anti cheat. OP should have paid paid the license and read the rules.

The author didn't at first didn't even notice the addon was taking a cut, let alone attempted to "cheat" it. That is clearly the author's "oops", but what are you getting on about "cheating?"

In the license, it clearly state that is perfectly acceptable to use the addon unlicensed, and if you go above a certain monetization level, it will take a cut. The explicitly calls out the cut as 2%. Except the license was a lie, it is not 2%, it's 30%. That is theft.

If the addon took 2%, as the license explicitly states, it would have been completely legal. It was not 2% and it is theft.

Is it really a good model for funding Open Source software to bake in clearly illegal landmines that steal from anybody using said OSS? If so, that feels way more like malware than OSS.

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#169

Earlier quoted context omitted.

The article seems to be down for me. But I’ve gathered it was spelled out in the license? They even returned money? Removing a person’s revenue stream because someone wrote a blog post is by default, an overreaction. If they’re going to change it all anyway, why rush it?

> But I’ve gathered it was spelled out in the license? Just curious, is this your attitude towards other things as well? There used to be a very popular ebay scam, which had people sell large screen TVs and video game systems for very cheap. At the bottom of the auction description, in fine print, the auction also clearly stated that you were bidding/buying only a photo of the product, not the actual product. In othe…

[deleted]

Re: An ad plugin was stealing revenue for a year and I didn't even notice

#170

Alternate sort of off topic take: if you have a service that is valuable, charge people money for it instead of depending on ad revenue. I try my best to stay away from ad supported business models, if there is an app in the App Store for instance that has an in app purchase to turn off ads, I have no problem paying for it if it something I’m going to use.

Piracy is a thing and in poorer countries people don't give a sh*t that they're suffocating you, so I'd rather support the ad industry than get suffocated by the people who is supposed to support me in the first place.
Post reply on HN