Major sites including New York Times and BBC hit by 'ransomware' malvertising
theguardian.com
theguardian.com
Despite all of the talk about "blocking the ad blockers", I've yet to receive a phone call from anyone saying this or another web site didn't work, "Can you fix it?" I'm guessing their usage is limited enough that they don't encounter it (my dad does visit Forbes, but I haven't heard complaints).
There's no way I'd surf the internet these days without ad blocking enabled and I rarely white-list sites out of concern for my data. It's becoming as important as personal firewalls / antivirus once were.
[1] There was a brief period during the time that they received the malware that MSN had been hit by malvertizing and they had that as their homepage, but it could have come from elsewhere. The bottom line was that there were no sites in the riskier categories that were in their browsing history and my parent's proficiency does not include a good understanding of "incognito browsing".
A while back I had a few sites warn me about ad-block, but I haven't seen it in a while.
Unfortunately, LastPass started acting up in FireFox a few weeks ago and I decided to give in to Chrome, again, so I've happily returned to uBO.
I go back and forth on which to install for people that routinely come to me for help (I'm a developer, not a helpdesk, dammit!). I'm not sure if it's still the case, but months ago I actually did receive a call from my father when he attempted to install an open-source PDF creation tool that he uses at work on his home PC. It was hosted by SourceForge which uBlock had large swaths of in its blacklist. The installer did contain a bull$#*+ toolbar (several, actually), but he's familiar with avoiding crapware directly placed within installers (and to avoid "Express Installations").
Doesn't mean it's not happening. Maybe people assume the specific page is just broken.
I'll get a phone call every time when a piece of crapware causes videos to play on Google's normally spartan search page, or ransomware is asking for "... something called a 'Bitcoin'? I don't remember installing a 'Bitcoin'."
They don't bother calling when one of the thirty places they get news from stops working.
Sometimes I think we ought to have civil liability for software security. A few lawsuits would shut stuff like PageFair down.
It baffles me that that isn't already boilerplate in advertising contracts. Sites whine about having their revenue impacted by ad blockers, but they make no effort to ensure the security of their users. Why is nobody ever held accountable for these sorts of breaches? Shifting risk to your customer is a horrible idea - nobody would buy a new car without a warranty, so why on earth are we expected to play Russian roulette with our bank accounts, personal data, and often our employer's assets?
I guess the market will teach them sooner or later, but I really do not understand why the current state of ads is so widely accepted by the people who are trying to sell them.
The profit motive is the ultimate incentive. If it takes too much time, reduces revenue by too much, or increases expenses, the ad publishers and networks will find ways to mitigate those issues.
If there aren't waves of lawsuits from users who received malware from ads, there is no direct cost. If vetting ads before they are hosted costs money or reduces the bids for those ad placements, networks are incentivized against doing so.
In my experience, most ad networks have blacklists for bad actors but no vetting and thus no whitelists. Blacklisting means there necessarily will be end-users that get infected and only a percentage of them will know it, a percentage of those will know where it came from, a percentage of them will report it, and only a percentage of those reports will culminate in advertiser blacklists.
It's a numbers game and currently the expenses from lawsuits (the only perceived expense for publishers+networks) is much less than the revenue lost + expenses from pre-vetting all ads before they are used.
It would be interesting to see what happened to their numbers. I imagine they alienated a lot of users by doing that and had to stop.
At my company we have an initiative to roll an ad-blocker out to about 2,500 desktops just to prevent the clean-up costs and improve user experience while using our own white lists. Given our industry, we just can't risk it even with threat management firewalls, OpenDNS Umbrella, and some well-engineered multi-layer security going on.
The disappointing thing for me is that I appreciate well-placed and curated ads. I white list some sites to support them, etc.
It's the websites the remind me of the sort of silliness in the movie Idiocracy [1] are impossible to use, not to mention trust with your computer.
[1] https://filmdump.files.wordpress.com/2013/06/idiocracy-1.jpe...
Just go to www.bbc.com and look at what domains your ad-blocker denies: edigitalsurvey.com, chartbeat.com, googletagservices.com, scorecardresearch.com, effectivemeasure.net, iperceptions.com, krxd.net, optimizely.com... now imagine if your printed newspaper shot at you a GPS receiver with a mic, a cam, etc. Surely it wouldn't be morally wrong to duck and avoid that bug?
Thanks for the kind words too, I've really tried to make the site a place that I would personally like to browse and am glad to hear other people feel the advertising is nicely done.
I'll add to the praise for your site. Your ads remind me somewhat of those from The Deck [1], although yours are nicer because they're 1st-party. Are you able to share any info. about the model? Do advertisers pay per click or per impression? If the latter, how do you prove your traffic figures to them, or have you built up a suitable level of trust?
As far as the model is concerned, a lot of the industry is familiar with magazine advertising so I just go with a monthly rate to keep things simple. There is trust involved, though most run a trial before committing to anything longer-term so they are able to see if the level of generated activity meets their expectations.
It is much easier to do this kind of advertising because the content itself is so narrow that the readership ends up being narrow, whereas a general site like BBC or CNN you end up having a wide audience and then end up needing tracking tools to help narrow the audience into smaller groups.
Obviously it wouldn't work 100% of the time, but it might yield interesting results.
I can use it with uBlock Origin and the 3rd-party filter "Anti-Adblock Killer | Reek" turned on.
a) I like to limit the number of random extension I install on my browser.
b) The fact that Forbes turned on an adblock-blocker shows me that they are seeing a significant revenue hit on account of adblocking, which will force them to do paywalled content sooner or later. I don't value Forbes content that much (in fact, it's often click-baity), so I'd like to wean myself off it sooner rather than later.
Has anyone proposed getting sites that serve e.g. ransomware to pay the ransoms for everyone affected? That seems entirely reasonable.
*Or insert your own offensive ad concept here.
[1] With the obvious caveat that a website can't reliably determine that.
It doesn't seem surprising that BBCW use an external advertising network: it would be a pretty huge investment to operate their own advertising markets throughout the world ... and surely if they did, they'd then on-sell those services!
Seems that the notable part of this attack is that several high-profile websites were affected, so BBC (and NYT, and AOL, etc) suffered some damage to their brand, so they'll have to work on that. The article notes that "malware was delivered through multiple ad networks", which speaks to failures by those service providers. Reckon there will be some very heated conversations and perhaps fee renegotiations with the networks happening over the next few weeks ;-)
It is becoming clearer and clearer to me that this is one of possibly two options left for businesses wishing to make money online via advertising. Self-hosted adverts are probably the best way to regain trust and circumvent ad-blockers. A quality, trustworthy third-party network is the only other possible option I can imagine, but that seems far less viable.
I'm sure that most networks start off with such lofty ideals, maybe they even believe them ... :-o
EDIT: To expand a little on the previous thought: you were shocked that the BBC website was serving up dodgy ads, presuming maybe that they'd have their own curated advertising portfolio. Closest comparison I can think of is perhaps the Economist website, also London-based, and no small prestige branding that they make sure to protect by only showing ads for Lexuses and Rolices (Rolexen?). The major differences of course are that Economist is somewhat more up-market, and the ads are seen locally in the UK.
I can't readily find any figures on how much cash BBCW makes off website ads, but I'd have to assume that it's burger money -- a few quid here and there for negligible effort, and after all who cares if the brand is tarnished abroad?! If on the other hand BBCW went into the ad curation business, and even if it happened to be profitable, there's every chance that voters or MPs would get stroppy about it, and BBC gets a hard time going into the next licence fee negotiations. Ultimately, BBC's brand outside the UK isn't something that the UK public necessarily worries about.
http://www.bbc.co.uk/bbc.com/faq/
> You will have noticed that the BBC website features a limited amount of advertising when viewed from outside the UK.
There's a bunch of people outside the UK who use BBC content and who want a way to pay the BBC. It's a shame the BBC uses ads (which are pretty horrible) rather than working out a better payment (or even micro payment) system. The BBC said this in 2014:
> Can I pay a subscription to view the site without ads?
> We're unable to provide a subscription service at the moment but will be able to do so in the future. As soon as the service is ready we'll communicate it to all our international users.
This is the largest reason I install adblockers on my own laptop and phone as well as everyone in my family. I allow zero exceptions for ads. I'm willing to pay for content via other means (for example google contributor), but attack surface is simply too large.
One of the things I've long known as a programmer for the web is that when you let a third party put content on your web site, you don't have control over what they do.
Whether it's a person entering content and you fail to sanitize it, or pulling in ads from an external network, the end result is that you get something like this eventually.
I don't have a solution, really, because nobody wants to pay for content, so sites have to use ad networks. But I'm surprised this hasn't happened much sooner.
- an adblocker
- javascript disabled
- addins disabled (click to play)
Except when some idiot thought that he needed to create a complex SPA to render a blog article. But is the opinion of such an idiot really worth reading?
I have it enabled and use uBlock, and I've never had an issue with this sort of garbage getting on my machine.
There is zero reason to require javascript to display a few paragraphs of text. You might enhance it with javascript but that wouldn't be a problem when viewed without. The blogs designed by an idiot I am referring to are blogs that will display a white page with javascript disabled.
uBlock Origin's advanced mode supports this: https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
I use browsers at Uni without it and get the full experience of autoloading video, flashing ads etc. and think "how do people live with this crap"
> The load time goes from 1.48s, to >45s
Maybe we have reached the point where browsers should implement the top 10-20 effects in standard ways (that of course the user can choose to override). That would make it feasible for many web sites to avoid JavaScript entirely and still produce the effects they want, and let us move away from this “execute arbitrary remote code by default” aspect of web pages.
Most of the JS that we do on websites those days is really helpful for the end user and are the result of the recommendation of UX specialists. (form management, navigational help, async loading of content, preloading content, front-end browser geolocalisation, better responsive for mobile, etc.)
Instead, I'm using Policeman ( https://addons.mozilla.org/en-US/firefox/addon/policeman/; similar to uMatrix https://github.com/gorhill/uMatrix/releases, but the first is easier to use for me ) which blocks 3rd party anything by default.
If they serve their own JS from their own servers, let it be. Others (Facebook connect, GAnalytics an Twitter seems to be _everywhere_): walk away.
This obviously renders most of the sites to bare HTML due to the excessive and unneeded use of CDNs, and is a massive pain to use for the first weeks, but after a while the whitelist gets you to a friendly web level.
uBlock also runs in the background, just in case things leak through, or I quickly want to check something and I need to turn Policeman off.
While not necessarily related to privacy, I've found sites where blocking self-served JS creates a better browsing experience because it gets rid of annoying effects and things like scrolljacking.