Fraudulent Advertising on Facebook
medium.com
medium.com
1) the scammers came.
2) governments started holding Google accountable for running ads for online gambling and prescription medication. Google (and Microsoft and Yahoo) had to pay large fines for running ads for products and companies that governments saw as illegal.
As the years passed, Google has become ever more restrictive in what ads it will run. To the point where trigger-happy Google Adwords staff whose job is to approved ads reject many ads that are actually fine.
I think Facebook will go down the same path.
My main product is software used by poker players to track and analyse their winnings and losses. I haven't been able to advertise on Google for years, because the ad reviewers see the word 'poker' and demand proof that I am certified to running a gambling company in the locales I'm advertising in. I've given up trying to argue my case to Google that just because my product has the word 'poker' in the title doesn't mean I'm running a casino!
Facebook, however, still approves my adverts within a few hours. I'm expecting this to stop as Facebook tightens up after a few large government fines.
I think Facebook is able to let more questionable stuff run in part because the micro-targeting makes it easy to disperse bad stuff to narrowly targeted audiences. On Google, investigators could search well known pharmaceutical terms and it was plain as day the advertisers were breaking US law. It is kind of like putting crack for sale in your storefront window verse in the back behind a maze of doors.
From what I have heard first hand, Facebook's platform was much more difficult initially and now is more lax. This could be in part the sheer scale of their ad network and the difficulty in policing it, or everyone figured out which loopholes Facebook couldn't plug without screwing up their quarterly numbers.
An ads platform launched in 2007. The current one is very much an entirely new platform.
I was able to discover an oddity in the approval process, that created an arbitrage opportunity for me that was quite lucrative in the online dating space.
This was very nice since I had just finished college in 2008 and the global economy and job market stood in ruins all around me, and I really, really didn't want to get a 9-5 job.
My efforts were very tame (and within Facebook guidelines) compared to what other affiliates engaged in. At one end were cloaking scripts based on geolocation. Facebook ad reviewers were sent to one landing page, and visitors to another shadier and more profitable one.
But even more egregious, an affiliate acquaintance I met once bribed a Facebook employee, who set his account to autoapprove any ad he wanted. He used this to advertise Google Is Hiring: Work from Home credit card rebill offers. He told me he made $80,000 in the four days it took Facebook to discover it.
It was a cat and mouse game between Facebook and the affiliates in those days. This was after a short period where Facebook itself allowed these credit card rebills to be advertised on the site.
Affiliate marketing was a nice cash infusion for me at the time, but I am glad to have walked away from what is really the bottom of the barrel in the internet marketing world.
This does seem like they're trading long-term trust for short-term profits - users will click on fewer and fewer sponsored posts as the number of deceitful posts like this increase.
Bait and switch scams have existed since the dawn of time.
Often marketing platforms (like Hubspot or whatever) lets you create multiple landing pages which might all be on a subdomain(s) to rather than handing full control of the root domain to the platform. In these cases, you wouldn't want pages.ctvnews.com to appear as the display domain.
Also not to mention the myriad of services and ways that act as a middleman for the click, in the same way that the link display on Twitter appears as ctvnews.com but it's actually a t.co link
Marketers can buy domains if they won't want to display a sub domain, and Facebook can check the final destination landing page. I mean, they already do! Every time you make a new ad they scrape the final destination for meta tags and content.
I'm saying they should have to suck it up and buy the domain they want to display.
It looks like Facebook host a lot of ads themselves, so I guess that advertisers use URL shorteners as a way to verify click throughs from Facebook.
For unsophisticated advertisers (i.e. with no referrer log analysis) I guess it's pretty easy and effective.
In that case most advertisers are unsophisticated. Even the biggest ad-networks/retargeting/tracking solutions all depend on redirect via their servers to their end customer.
I am constantly disappointed with the technical knowledge and understanding display by our advertising partners. A large number of them have almost zero understand of how the internet work. Of cause part of the problem is that as a developer you're inclined to point out that something won't work because it won't work 100% of the time. That a useless answer for the advertising department and you end up with duct taped solution that works well enough, but of cause create their own set of problems.
I secretly suspect they -at least- know, but prefer to sweep these issue under the rug and that's why they prefer to involve as little technical people as possible. And that's why I don't work in this industry anymore and I won't come back to it until they've all burnt to the ground.
The fix is super simple: Their tracking pixel receive our order number, all they need to do is accept that it's unique and just tracking the first occurrence. Part of their problem is of cause that they switch to a new platform and didn't migrate any data.
Because many of the amount are so small, they just accept a ton of errors and as you say: "sweep these issues under the rug" because it's just a few cents so who cares. But it adds up.
Advertisers and the networks that serve them will never be on the consumer's side. If a consumer wanted to do what an advertiser wanted, the advertiser would be out of work. It's all subversion.
This is a danger, but in an optimal system, one that doesn't come into play. Advertisers pay for eyeballs, eyeballs are there because they haven't been driven away from the product by ads that ruin the experience.
I've see frequently (and have documented) numerous cases of ads implying that a famous person has died (e.g. Sly Stallone, The Rock, Lamar Odom, Colin Kaepernick), luring clicks for details.
But what really disgusts me is the "Suggested Post" mechanism. In the past week alone, I've had "Suggested Posts" from people selling obviously counterfeit merchandise and sites that claim to be the "Official NHL/NBA/MLB Store", when they are not. And these include plain text that should be simple to parse and check, if they cared. (A more complicated strategy to catch is when the bogus claims are only in text within the ad image, like the oft-posted phony Ray-Ban Official Site.)
And Facebook (and especially the ad network who made the ad) makes money for every sucker served.
- I'm not sure how his ads break the ToS, but something like what this article describes might be part of it.
- Put some non violating ad on for approval, then change it.
- He changes the destination based on whether the viewer is coming from FB's network.
- Use a prepaid card with phony details to pay for the ad.
- Says he is one of FB's largest customers. Readily admits to being a bit shady with his ads, doesn't seem to bother him.
I have no idea whether things have changed much in the past couple of years wrt to how the system works.
Content marketing like this blurs out what is someone's genuine opinion and what is advertisement.
I do not like it. Where I live, in Norway one has to clearly mark content marketing as advertisement or risk some steep fines.
If they just said that and put the ad target to their domain I wouldn't have minded.
One could argue that it's a huge piece to get a one-liner across, but I feel that's true about a lot of news stories, so base rate fallacy applies.
2) Install uBlock Origin on your browser.
3) Install Privacy Badger* on your browser.
* I used to use just uBlock origin, but things work so much better with privacy badger. There must be some kind of code to indicate "yeah, yeah, you're tracking me so well" because I don't get nearly as many broken sites. Third party comments don't work (like disqus), but HN is about the only place comments add value.
Fraud, malware, deceit unwanted intrusions are reasons to block all advertising. Facebook or otherwise, they are becoming the norm. We see this over and over again. It is past time to take a stand.
On a related note. Does anyone know whether or not there are advertising groups that provide single line, vetted ads (single line could be small non-intrusive ads) to be embedded into a site rather than injected from an ad network? There has to be SOME good actor providing single line unobtrusive ads like the old google ads.
But this seems to be the norm. Google displays highly misleading ads, especially on mobile. I see fake virus scans, "fix battery issues" and other junk. Google's main search ads had malware downloads, even for popular things like Skype. (And Chrome?)
Microsoft's store had many misleading apps, including fake Netflix apps. It took several interactions between MS and Netflix to get that sorted, and MS still ran fake apps (paid!) for popular software and movies. MS wouldn't even deal with ISVs that complained. Hell, the Windows Store even carried a fake version of Windows at one point! They didn't (don't) verify any details, such as publisher name. For a while, typing "Facebook" into the Start Menu brought up a fake FB app. This should put W10's invasiveness into new light: MS is not competent when it comes to this kind of stuff.
I do wonder how much money this stuff brings in. Is it a significant percent of business for these companies? It can't just be simple incompetence -- in MS's case, they sometimes paid for the junk apps.
I'm still sort of surprised that this junk can make enough money for people to advertise it though. Guess even 20 years after the net started getting popular, there's still enough unsavvy people to scam.
Same shit as forcing upgrades with dark patterns and silently changing things so Windows 10 can be a success on powerpoint slides.
From a legal perspective, I wonder if the legitimate sites can sue Facebook over that, or if there's a case for class action on behalf of users.
In any case, I don't buy any arguments that claim this is intentional to help actual advertisers or an oversight. From a security standpoint this is a spoofing tool and without any kind of validation or verification it should be clear what this tool is being used for. Facebook's in the business of collecting and analyzing data, and I'm sure they know very well that it's being misused.
if (display_domain == landing_page_domain) { approve_ad = true; }else{ approve_ad = false; }
is, for one thing, not robust against cloaking (if malicious advertisers see the request coming from a Facebook IP, they might actually redirect to the displayed domain).
Of course, it'd probably turn into an arms race as malicious advertisers try to profile FB's bot behavior and properly redirect it.
That is to say, I agree with you, the problem is non-trivial.
It's not rocket surgery.
That opens you up to a URL which redirects you somewhere trustworthy when you check it but redirects later ad-clickers somewhere shady when they check it; mitigating that is harder but approachable.
The problem with checking them is that if you make the check look just like a normal click-through, the advertiser gets billed for a click by their ad broker.
Facebook needs to ensure that their setup works in a way that the rest of the business expects. What Facebook seems to lack is the resources and dedication of Google to find the fraudulent ads.
But of course they won't do that.
Also, for example, if they claim to be CNN, it should go to a relevant page, not just cnn.com
Or the ads simply did not generate a positive ROI. I have read that Facebook advertising (especially for US traffic) is very expensive and tends to not convert well. I often see people run Facebook ads for non-scammy purposes (for example three months ago James Altucher ran Facebook ads for his books, and those ads are gone) and then pull them down , presumably because the conversion is crud. No one ever pulls a successful advertising campaign because they 'made enough money'.
Their ad approval process is random. I've had ad's that were not approved, resubmit for "automatic" approval. (Keep trying till it passes into the sample group of Auto-Approve, it's an older account?)
All that said... I know Facebook was under pressure after their IPO to get revenue coming. They've figured out now how to monetize their traffic base and marketers are flocking to their platform. I expect that over time you're going to see slow tightening of their policies, especially as marketers learn to exploit it. It's still impossible to get someone on the phone from Facebook if you have a problem and though you can generate very low cost CPA actions from facebook, it's dangerous to bet big on them right now as this article points out, change is going to have to come.
So I am pretty confident that they don't allow this stuff on purpose just for profits. I can believe they are slowly walking up the learning curve of how they can be defrauded, and it is slow. You have to train a lot of people. But it gets better. Now if I were in a leadership position in Facebook's advertising group this would be on my list of top priorities to get done.
http://chunk.io/f/d1c9168e2f0c41edb8ea4bf3d29ddadc.png
scroll to the right and you get this:
http://chunk.io/f/f6020ad14aa84a6c9a3415291cfbb920.png
Yes, someone's being charged for an ad where even if I scroll I can only see a few pixels on the left. If I make the window a bit narrower I don't see it at all, but it's presumably still an "impression".
When I advertise on Facebook, they charge me per click, not per impression. I assume this poorly displayed ad also is charged per click.
Feel the burn Facebook.
Perhaps we can also do an education campaign so that people don't think buying dick pills from scrambled domain names is a good idea. A Youtube video ad starring Ron Jeremy with the motto "Size Doesn't Matter".
Facebook ad's can have different display-URLs and target-URLs, even the domain can be different, e.g. ad shows cnn.com but leads to myshadysite.com
+ some subtle promotion for Hunchly (full-text search for your browser history)
The age of debating whether ads are acceptable or not is long passed; ads are not acceptable because they are malware. Period. We should be teaching people how to avoid malware and that means avoiding all ads. How can we expect FB to fix this problem when they are causing the problem and they are profiting from it? On the other hand, putting ad blocking technology into the next Firefox would not only fix a huge chunk of the problem, but also send a clear message from a huge fraction of web users that malware is not acceptable in any form, including in ad form. I can't think of a better solution.
i know a number of people that play in the space spending 6 figures a month doing this... they wouldnt be hard to catch, if you tried, but why would facebook want to get rid of that revenue until absolutely forced to? and imagine, i only know a handful of them.
[1] https://www.youtube.com/watch?v=oVfHeWTKjag