Live data from Hacker News

“We're considering banning domains that require users to disable ad blockers”

reddit.com

191–200 of 259 posts

Re: “We're considering banning domains that require users to disable ad blockers”

#191

Earlier quoted context omitted.

The problem is incorporating third party content that is neither screened nor sanitized. The proportion doesn't matter as much as the fact that there is nothing stopping attacks. They only get cleaned up afterwards. You don't expose your users to attack without warning. I think very few websites allow one person to embed arbitrary scripts that will be shown to another person.

The problem is incorporating third party content that is neither screened nor sanitized. It is impossible to screen or sanitize third party content if the third party is hosting it and the user loads it when your page refers to it. The third party can change that content at any time, without your knowledge or consent. This is how almost all ad networks work. It is also how almost all CDNs, web font services, image ho…

Why are you conflating individually-trusted CDNs with the servers of some random guy? And allowing only images, like most embeds do, is a form of sanitation.

I'll repeat myself. "I think very few websites allow one person to embed arbitrary scripts that will be shown to another person." This is not happening as a result of you using an image host. No scripts are involved there. This is not happening as a result of the site using a CDN. No user triggered that load of jQuery.

It's fine to load jQuery from a specific server that you trust. It's also fine to load ads from the ad network's server, as long as they are policing uploads properly. The problem is they usually don't.

Re: “We're considering banning domains that require users to disable ad blockers”

#192

Earlier quoted context omitted.

"In any case since the sites are still able to use curated self hosted ads (ie not JavaScript redirects to externally hosted providers) they are able to sell static ad space to make money even with adblockers enabled." Ad blockers don't just block external ads, they use CSS rules to block internal ads as well. So the only way to avoid ad blockers is to make advertisement completely indistinguishable from content. Ima…

In what ways do ad blockers block internally served ads? I'm perfectly happy with static ads served from the same site as the content. If seems adblockers should have an option to block only the "bad" ads, I.e anything referencing one of a list of known ad nets.

Go to the reddit homepage. Look at the very top link (that's highlighed with an outline). That's an ad, but it's hosted by reddit and contains no scripts or iframes, in fact doesn't even contain offsite images. Its div has the CSS class promotedlink. If you look in the default list used by Adblock Plus https://easylist-downloads.adblockplus.org/easylist.txt you will see that it blocks this because it contains the line

    reddit.com##.promotedlink
But Adblock Plus actually contains a second list of "Non-intrusive advertising" that actually allows ads on reddit. Many people are very angry about this list because many companies pay to get their ads put on it and allowed.

Re: “We're considering banning domains that require users to disable ad blockers”

#193

Have media companies ever considered something like the cable TV model? I'm thinking something like ten different sites form a network, and readers pay once (on a subscription basis) for access to the whole network instead of paying each site separately. I definitely am not interested in subscribing separately to (e.g.) Wired, the NY Times, the Economist, WSJ, the New Yorker, etc. But I think I'd be totally down for…

There's Google Contributor which you can pay monthly to see no or reduced ads on many sites that use Google ads.

https://www.google.com/contributor/welcome/

Re: “We're considering banning domains that require users to disable ad blockers”

#194

Earlier quoted context omitted.

You don't get a free pass on ethics just because ethics are inconvenient for your business model. I think calling this an ethical issue is quite a stretch. In many cases, we're talking about visitors who are not only enjoying the content from someone else's site completely for free, but also employing tools that actively modify the intended presentation of that content to the detriment of the host site's operators. A…

> already generously offering their content for free If they're attempting to make money from ads, they're not offering it for free.

If a visitor is using an ad blocker, they're getting it for free anyway. As an ethical principle, I don't think you can have it both ways. Either the site operator is commercial, in which case ad blockers are unethical because the visitor is depriving them of revenue, or visitors are free to browse the content without obligation including blocking any parts they don't want to see, in which case why does the site operator owe them anything?

In any case, even in a commercial transaction, there is an element of reasonableness to what is expected. If I buy a $50,000 car and it breaks down on the second day of having it, that's obviously well below a reasonable standard. If I buy a $10 toaster and it breaks after a couple of years because the crumb tray didn't quite fit? Maybe that's more reasonable. If I buy a $10 toaster and it catches fire and burns my house down after a couple of years because of a design flaw that the manufacturer knew about but didn't fix? Again, not so reasonable.

In this case, we have a content provider who is making at best a tiny amount of ad revenue from a visitor, yet some people here seem to think there is an ethical obligation on that content provider to provide a literally impossible standard of monitoring of the behaviour of the ad networks anyway. As I've mentioned elsewhere, even the argument that they just shouldn't use an ad network in the first place doesn't really work, because logically you'd also have to apply the same ethics and accept responsibility in the same way for any other third party content, such as scripts hosted on CDNs. By the time you've finished knocking out any sort of third party hosting just in case a rare instance of malicious content slipped through the net, the web would be a much worse place.

Re: “We're considering banning domains that require users to disable ad blockers”

#195

Earlier quoted context omitted.

The problem is incorporating third party content that is neither screened nor sanitized. It is impossible to screen or sanitize third party content if the third party is hosting it and the user loads it when your page refers to it. The third party can change that content at any time, without your knowledge or consent. This is how almost all ad networks work. It is also how almost all CDNs, web font services, image ho…

Why are you conflating individually-trusted CDNs with the servers of some random guy? And allowing only images, like most embeds do, is a form of sanitation. I'll repeat myself. "I think very few websites allow one person to embed arbitrary scripts that will be shown to another person." This is not happening as a result of you using an image host. No scripts are involved there. This is not happening as a result of th…

It's fine to load jQuery from a specific server that you trust. It's also fine to load ads from the ad network's server, as long as they are policing uploads properly. The problem is they usually don't.

You keep saying they usually don't, but billions of harmless ads are served every day while only a tiny fraction of the served ads are malicious. I just don't see how it's reasonable to assume depending on a third party ad network for content is fundamentally risky yet depending on some other third party service is not. CDNs and other hosting services get hacked and serve malicious content sometimes too, but that is also very rare and also usually gets fixed very quickly if it does happen.

Re: “We're considering banning domains that require users to disable ad blockers”

#196
post #169

Earlier quoted context omitted.

They're not great. About 40% of the recommendations are things I'd never watch, 40% are things I've already watched. YT has trouble figuring me out because I watch a lot of gamers that also appeal to a younger audience (eg Yogscast). I get recommended a lot of terrible stuff targeted at that audience that I have no interest in (eg PewDiePie and Markiplier). I have no idea why they recommend stuff I've already watched…

I too can not figure out why YT wants me to watch things again. Or also common, the last 10 seconds of a video is just links to the user's other videos, so I move on. Then YT wants me to "finish watching" it. No, I don't want to finish watching the last 5 seconds of an outro.

My own daughter uses YT almost exclusively as a music jukebox so sure, here comes that Taylor Swift song again, why not.

IF YT even understands that different populations use their system in completely different manner, then perhaps they've miscategorized you.

Something interesting to think about is we may be raising a population who see personalized suggestions as mere spam, if it suggests it you should ignore it because its always wrong. A poisoning of the well. In that way the whole concept of personalized advertisement might disappear.

Re: “We're considering banning domains that require users to disable ad blockers”

#197
post #44
post #17

Earlier quoted context omitted.

No-one has a responsibility to keep Wired or Forbes in business. Either they'll figure out a business model that works, or they won't; either way it's not the redditors' problem.

Obviously redditors like their articles, so they will have a problem too. I don't think this is black-and-white "ads are bad/readers are good" issue.

"Obviously redditors like their articles"

Do they? Isn't being coated in ads a normal condition of clickbait? Is clickbait high quality content?

Re: “We're considering banning domains that require users to disable ad blockers”

#198
post #192

Earlier quoted context omitted.

In what ways do ad blockers block internally served ads? I'm perfectly happy with static ads served from the same site as the content. If seems adblockers should have an option to block only the "bad" ads, I.e anything referencing one of a list of known ad nets.

Go to the reddit homepage. Look at the very top link (that's highlighed with an outline). That's an ad, but it's hosted by reddit and contains no scripts or iframes, in fact doesn't even contain offsite images. Its div has the CSS class promotedlink. If you look in the default list used by Adblock Plus https://easylist-downloads.adblockplus.org/easylist.txt you will see that it blocks this because it contains the lin…

Using an adblocker that takes money to whitelist seems like a bad idea.

In any case: I'll make sure that my ad blocker allows non intrusive ads. That said, "non intrusive" must not be deceptive either. It should be clear that it is an advert.

Re: “We're considering banning domains that require users to disable ad blockers”

#199

Earlier quoted context omitted.

In this case, high-profit ads include dynamic content (JavaScript or Flash). Safe (but boring) ads would simply be an image or text link with no tracking capabilities that doesn't use CSS hacks to interrupt your page reading. It just sits up there saying, "If you want it, check this out."

Javascript and Flash ads are the more immediately dangerous ads, but you can still distribute malware over image and text links. You just move from exploiting browser vulnerabilities to exploiting user trust, like all of the imitation VLC download pages that have popped up over the years. We'd be better off with only static image/text ads, yes, but malware distribution by means of poorly vetted advertising wouldn't t…

Yes, and they'd be burning image library 0days in the process. Security would improve overall.

Re: “We're considering banning domains that require users to disable ad blockers”

#200

Earlier quoted context omitted.

In this case, high-profit ads include dynamic content (JavaScript or Flash). Safe (but boring) ads would simply be an image or text link with no tracking capabilities that doesn't use CSS hacks to interrupt your page reading. It just sits up there saying, "If you want it, check this out."

Tracking still happens with "safe" ads. Generally "image pixels" as they call em are actually server side scripts that then pretend to be an image that way they can still track the users IP and what they were doing at that point in time.

That data is already sent to the server. This doesn't give the server control over the user's hardware.
Post reply on HN