Live data from Hacker News

Ad Nauseam

hackerfactor.com

41–50 of 59 posts

Re: Ad Nauseam

#41

Stop calling them ad blockers. They block surveillance features that advertisers put in their ads. I do not believe that ads would be blocked by surveillance blockers if they were just ads. Absent the surveillance, how would they recognize them? If ads were identical to the ads in analogue newspapers then surveillance blockers would let them through. When I read an analogue newspaper or magazine nobody is knowing if…

That may be true of the general HN crowd, but I doubt it's true for most people. I block ads because they make the web ugly and slow. It's simply nicer to browse sites without them.

In my case at least, "surveillance" doesn't factor into it. If I were to see ads, I'd actually prefer they be targeted to my interests.

Re: Ad Nauseam

#42
The article misses a major point, ads are a form a surveillance and as such more and more people prefer to block them out of privacy concerns.

Re: Ad Nauseam

#43
post #13

and again Flash is the scapegoat "By converting unsafe flash-based ads to safe HTML5 ads, they lower the risk of infection from a hostile ad." is laughable at best An Ad Network is one of the fastest way to deliver a payload to a lot of users Don't fool yourself, Operating Systems, Browsers and HTML5/JS also have a hell lot of CVE that can be exploited It's funny how a company like Google making Billions from ads, ha…

"and again Flash is the scapegoat" Truth hurts? Adobe Flash and Microsoft Silverlight are common exploit paths because they have new critical exploits every few days. Here's the CVE list for Flash -- notice how many critical exploits there are? It averages to about 1 every 3 days. https://www.cvedetails.com/vulnerability-list/vendor_id-53/p... In contrast, JavaScript itself has been pretty stable for years. I think t…

OK, remember you asked for it

"If you know otherwise, then please cite the specific CVEs. Otherwise, you're just spreading false information"

man, you are so full of it

want proof ? no problemo

1. CVE are organised by vendors and products

HTML and JS does not show as products, only browsers

see http://www.cvedetails.com/top-50-products.php

look #3 Firefox, #4 Chrome, #8 IE

that explains why you will never see a specific HTML and/or JS CVE, that does not mean they don't exists.

Also in term of volume, browsers have more CVE than Flash, it's all here in the numbers: Firefox 1320, Chrome 1216, but no let's ignore them and focus on Flash 713 CVE.

Just that it make your whole argument biased, the part "JavaScript itself has been pretty stable for years" is ridiculous, search for JS blackhole exploit, Rowhammer.js exploit, Heap Overflow exploit in JS, etc. you don't see them in CVE but they are here and exploitable.

It's better to think than JS is secure looking at that http://www.cvedetails.com/vendor/10288/Javascript.html

yeah no exploit in JS, none, we are all safe LOL

this for example http://www.cvedetails.com/cve/CVE-2015-0817/ http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0817 https://www.mozilla.org/en-US/security/advisories/mfsa2015-2...

you don't see it show up under the tag "JavaScript"

2. Number of CVE listed do no equals CVE exploited in the wild

so you say "It averages to about 1 every 3 days", that's completely false

1 vendor patch for a particular product can close numerous CVE at the same time so it's more like "we squashed 50 CVE in 1 day"

look at http://www.cvedetails.com/cve/CVE-2015-8449/

follow up on https://helpx.adobe.com/security/products/flash-player/apsb1...

that's 1 patch, it does not indicate 1 CVE every 3 days, look at the details

"These updates resolve use-after-free vulnerabilities that could lead to code execution (CVE-2015-8050, ..." that's more than 50 CVE of the same type patched and closed at the same time

Also look the "Acknowledgments", numerous security team reported all those CVE for them to be patched, there is no indications they were exploited in the wild.

Saying such things as "oh 30 CVE discovered in 1 month, so that means there were 1 CVE per day" is totally misleading, even more misleading to assume all those CVE were exploited by default (eg. "could lead to").

At best it indicates that they (Adobe and other security team) are more serious about discovering and patching those CVE and so they close more of them more often.

Re: Ad Nauseam

#44
post #23

Earlier quoted context omitted.

Lets look at other media and see if your conclusion is correct. Do TV networks vet, produce and handle the ad-client and ad-publisher relationship, or do they mainly interact through marketing firms? The answer: they work mainly through marketing firms. The TV network is still ultimately responsible for the content they broadcast, as dictated by law. Do newspaper work with individual advertisers, or do they work most…

Are you sure there aren't scams advertised in newspapers and on TV? The main reason you see more scams online though isn't (only) because of inferior vetting. It's mostly because online ads are much cheaper than TV, so the economics work out better for the scammers. Same reason you get more spam in your inbox than your mailbox. (And there are plenty of shady classified ads in newspapers. You probably don't see them b…

In Sweden where i live, a TV station that would repeatably broadcast illegal ads would loose their license. They would not be allowed to use the radio frequencies, and would loose millions from such outcome. When government agency that deal with TV broadcast makes a decision, or the consumer protection agency (a other government branch), they do listen.

Almost a decade ago, ads about subscription services went through a major change. The government dislike how "free" was used in services where all the costs was hidden in the fine print. As such, all ads related to subscriptions was changed so the the total price must be very explicit in the ad. The TV, news papers and street advertisement immediately changed as a result, mostly by stopping having advertisement for such services. They were afterward put back once marketing firms learned how to stay compliant with the decision.

Even further back in history there was a ruling against advertisement that targeted children, where there was one particular channel that went a bit further than everyone else. After the ruling, they stopped.

Now, one could assume that the sword is only dangling above the TV networks and the news papers are running wild with scamming advertisement. Except that I can find rulings (by the consumer protection agency) that target advertisement in print. A ruling in 2003 made a decision against a home catalog, ordering the company to stop printing a style of advertisement (about weight control) or face a fine of $40000 per issue.

Sweden don't have much general classified ads in newspapers, so I guess that might answer why I don't see so many shady versions. Jobs ads are done through the government job agency, and selling things through newspapers tend to be quite expensive so its almost exclusively about cars, boats or houses. Criminals tend to target cheap alternatives so that a failed attempt has less of a sunk cost, which means those who has no vetting process and minimal investment.

Re: Ad Nauseam

#45
post #33

Earlier quoted context omitted.

And then the sites not set up for business reasons end up getting the lion's share of the traffic? Because for however many sites might add a paywall for pay for 'journalism', there's an equal number of sites run by people for fun/a side hobby that are willing to give it out for free. That's always going to significantly limit paywalls online. Too much competition from hobbyists and non profits that see their goal as…

There really isnt any competition from "hobbyists/non-profits". The top publishers on the web all produce a ton of content, none of it can be run without a big business operation which has to earn something, either through advertising or paywalls.

Well, in the gaming scene, most of my news comes from social media sites, fan sites and fan run wikis, which don't tend to be run as businesses.

For example, if I want the latest information about Zelda U, I wouldn't go to IGN or Kotaku or Polygon, but instead to Zelda Informer, Dungeon or Wiki depending on what exactly I was looking for. If it was more general information, then that's what the likes of GoNintendo are for.

Of course, I could always just go to the company instead of a middleman; most of them are moving towards marketing straight to the consumer rather than the press. Given that most of say, IGN's information comes from summarising things like Nintendo Directs and E3 presentations, or from what's trending on Reddit or Twitter or Youtube, it seems more logical to go straight to the source than through the middleman.

Would this work in all fields? No, stuff that's dangerous or complex (like say, reporting on the war in Syria or what not) tends to need more professional organisations. But if you're after information on games, TV shows, movies, music, celebrity gossip or sports, then to some degree you can pretty much entirely replace the professional media with fan sites and blogs.

It's also why paywalls are going to be a problem even in the short term; anything factual you put behind one is going to end up on the fan run sites and aggregators anyway. If a big site puts something interesting up behind their paywall, then it'll be maybe about ten minutes before someone's ripped the whole thing, stuck it on sites like Youtube and its then been posted across the entire blogosphere.

Re: Ad Nauseam

#46
post #29
post #22

Earlier quoted context omitted.

So disable linking. The clickthrough rate on internet ads is execrable. Frequently in the fractions of a percent at best. No other advertising space operates on the assumption that linking represents. Eliminating linking and leaving pure visual ads would be in line with every other form of advertising in existence, and eliminate the "problem" of click fraud, link-bait, and actually fraudulent links. Do we really need…

So you end up with ads that say: copy/paste this URL. What have you solved?

I think realistically, the friction against such a method is strong. People can scarcely be arsed to bother with QR-codes anymore. It could still happen, but this sounds an awful lot like a "perfect is the enemy of the good" sort of argument. Is not some X% of the problem better than the 100% that we have now?

Re: Ad Nauseam

#47

The article misses a major point, ads are a form a surveillance and as such more and more people prefer to block them out of privacy concerns.

Actually, I intentionally left that out. I thought 4000 words was long enough. Surveillance would add in another 4000 words.

Re: Ad Nauseam

#48
post #21

Earlier quoted context omitted.

Yet the news sites demonstrate how utterly clueless they are with the amount they set their online subscriptions to. £1 a day for The Times - very nearly the cost of the actual paper. $1 daily to access Wired. Don't make me laugh. No one consumes all their news from a single source any more. If my usage pattern is anything near representative, 2-5p a day for the Times and .5p a day for Wired, based on how often I vis…

Hmmm, so you now understand advertising is not a evil business really, right? It is effectively a way to price the information, how much should be paid for your view. Note in print days, you still pay your subscription, yet you get shit loads of ads. And you have a variety choices of publishers. So why this is the worst model ever? The article is laughable that it gives no solution, but asks publishers to evolve into…

> Some people are so pissed that publisher got anti ad blocker in place .... if you don't read those shitty articles that much, why are you so pissed in the first place?

I'm not pissed about the anti ad-block. I'm pissed because the sites show up when I'm searching in the first place. I'm pissed because I go to the site thinking I can get the information I was teased with in my search only to find out I've been tricked. I'm forced to do something (unblock the ads), accept some fake implicit agreement (you agree to look at our ads), and be spied on (all the trackers) before I can get to the content I was lead to believe was there.

The fix is to remove all blocked content from the search so we won't even know it exists in the first place. We won't get upset, we won't get blocked, the sites won't get content "stolen" by those who won't view or click the ads to being with. Everybody's happy. Win Win.

Re: Ad Nauseam

#49
post #21

Earlier quoted context omitted.

Yet the news sites demonstrate how utterly clueless they are with the amount they set their online subscriptions to. £1 a day for The Times - very nearly the cost of the actual paper. $1 daily to access Wired. Don't make me laugh. No one consumes all their news from a single source any more. If my usage pattern is anything near representative, 2-5p a day for the Times and .5p a day for Wired, based on how often I vis…

Hmmm, so you now understand advertising is not a evil business really, right? It is effectively a way to price the information, how much should be paid for your view. Note in print days, you still pay your subscription, yet you get shit loads of ads. And you have a variety choices of publishers. So why this is the worst model ever? The article is laughable that it gives no solution, but asks publishers to evolve into…

"Evil" is a ridiculous word to use in the first place; but for what it's worth, in my opinion, a platitude like "[ads are] not perfect, nor evil," glosses over the fact that ads often are vectors for attacks that rely on deception, ignorance, and unwitting surveillance, which definitely has an ugly moral flavor. The business model may not be inherently evil (what is?), but it sure seems to be a convenient technology for deliberate abuse via fraud and malware.

Re: Ad Nauseam

#50
post #21

Earlier quoted context omitted.

Hmmm, so you now understand advertising is not a evil business really, right? It is effectively a way to price the information, how much should be paid for your view. Note in print days, you still pay your subscription, yet you get shit loads of ads. And you have a variety choices of publishers. So why this is the worst model ever? The article is laughable that it gives no solution, but asks publishers to evolve into…

I think anexprogrammer meant that literally: "Charge me 1-2£ per day and give me some choice where the money goes". I have paid for online content, and have considered it often for content creators that I like. You can get movies and music for a low monthly fee, why not articles? Hello business model!?

Pretty much :)

The way we consume media has changed. 20 years ago I'd have a daily newspaper to read on the commute and subscribe to a few magazines - say 5 a month.

In today's terms a spend of perhaps £1.50 a day for media.

Now I'll read 5 articles on the Guardian, 5 on Ars, 1 on Wired, 2 on the register, 1 on the Telegraph, 1 on NYT, another on The Atlantic etc, etc. Tomorrow will be a different selection. If I bought subscriptions as they are typically set online I'd be spending £30 or something a DAY on media. That's ridiculous.

So yes, there needs to be a better micro payments model for media consumption. I'd happily pay. The Google way of doing it is closest thus far, but doesn't give me any control of who gets paid. eg I'm not happy with a percentage of my micro spend going to the clickbaity upworthy article I clicked and bounced straight off.

Post reply on HN