Leading 'anti adblock' provider gets hacked- pushed malware to end users
blog.pagefair.com
blog.pagefair.com
Noscript would have protected you though, which has a pretty large install base.
This is an example of them failing to live up to their role in the their preferred moral order (i.e. "you don't have to block our ads out of safety concerns because we'll safeguard them for you").
That's why nobody ever argued that running antivirus is morally wrong.
Normal ads are malware for the brain. It's just that this type of malware is legal and considered by many to be a respectable occupation.
e.g. http://arstechnica.co.uk/information-technology/2015/05/sour...
This is more like Banquo's ghost: Something they hoped everyone would forget which comes back to haunt them.
Out, out, damned spots indeed.
Site owners: Market your ads directly or through smaller exchanges, and host them yourself. This is the only viable long-term option.
Disabling javascript does not protect you against a sufficiently malicious enterprise - and I'd label both the three-letter-agencies and the ex-Soviet mafiya as such. Both have been proven to use such tactics.
Then convert it to png yourself.
You can't prevent exploits from all angles, but you can prevent exploits from some angles.
This is nice because it makes me want to make good decisions for the user experience (no multi-page image galleries) which I believe will help attract the types of visitors my advertisers want to interact with.
Selling your own ads takes work for sure, and a different type of work. Instead of technical know how, you need to put in time and energy selling ads and not just sit around waiting for sales to come to you.
You also obviously get to keep 100% of the money from the sale which is nice.
You may be able to link up to a big player, but hosting things yourself will require quite a bit of overhead and they pay off may not be worth it, unless you're getting substantial volume (or appealing to a very targeted audience)
btw, traditional display ad CTR is rubbish from an advertisers perspective and we all want to go all in on programmatic + retargeting.
Not if the big ad companies (google's adsense) create a plugin or program that serves the ads up locally instead of making obvious 3rd party calls to their own networks. I suspect they're working on such a plugin as we speak.
I think google's looking to do what's best for their bottom line. If it becomes more profitable, or even much more profitable to decentralize in that way, they will do it without hesitation.
Perhaps they're looking for a way to decentralize their ads, yet still retain the data & meta-data. Basically, have their cake and eat it too.
And they were able to convince website owners to grant them access to visitor's connection in order to prevent people from blocking ads? And they were also able to convince them to pay money for this service?
Since it seems to play an ad after every song (?!) this basically prevents ublock users from using the free version of rdio.
whereas the song content is served from a different host entirely (m.cdn2.rd.io). Presumably this is just because the ads are served from an external ad network, not rdio itself.
You can see the ad request failing in Chrome dev tools, and the console tab shows "net::ERR_BLOCKED_BY_CLIENT".
I just refresh, and it usually works.
I'm not willing to disable Ghostery and uBlock, though; 12 things blocked by Ghostery and 31 by uBlock - I don't need any of it, Hulu, thanks.
* Pay for content. * Still have to watch commercials. * Have data about my usage sold to highest bidder. * Video client that is not as good as putlocker (or whatever the cool kids are using these days)
it is owned by nbc, disney and fox. they still don't get that you can sell content, sell ads, or sell nothing. Very little overlap.
But they can, and do. We pay for our Hulu subscription, and so do literally millions of others.
They are toeing a very fine line, however - too many ads, and I'll ditch them and either use Netflix (which doesn't have the most recent TV shows), or pirate things.
It's also pretty interesting that they're offering a new, more expensive, ad-free service. I wonder how long that one will stay ad-free.
I imagine it tries to play an ad if it hasn't successfully played one in a certain time period. Since you're blocking them, that's between every song. If you weren't blocking them, it would probably be less often.
[1] largest in the western world
It would have been nice that the article spelled out the exact hostname from that CDN, to find out whether it is blocked by default by blockers.
I've seen integrity validation schemes work well for small enum lists but we'd have to know what the data set size is and the expected rate of change. This of course all before properly adding an SLA to their content providers.
Certainly interesting but I think it may not be the easiest or best way to tackle this problem. I'd love to hypothesize about it if you want to suggest some workflows.
If you want to use Subresource Integrity to prevent this kind of a problem, you need to first devise a mechanism to communicate the correct expected hash from the 3rd party site to their 1st party customers in a trusted manner. This is non-trivial. It adds a lot of friction to Pagefair's software development and deployment processes (think about how you would implement A/B testing, for example). It's also not a guarantee - if your servers can be hacked, it's possible your "trusted hash communication mechanism" would be as well, unless you follow stringent security protocols (human confirmation for signing, offline keys, etc.) which would add even more friction.
Of course, you would need cooperation and involvement from your first-party customers for SRI to be effective in the first place, and I don't know how many of them would be thrilled to have to devote engineering resources to fixing potential security problems caused by their partners... sounds like a good reason to consider switching to a competitor.