Again, I'd like your List of Malware-Free Sites, so I dont get anymore malware.
When every site gets their ads served from the same central location and that location is compromised, everyone is at risk unless they have strict anti-ad rules implemented.
Its as simple as if you don't like games/songs/media with DRM, buy the non-DRM ones and reward the authors.
If you are truly principled then you would avoid going to websites that have those ads and only go to websites whose revenue model is aligned with your interests.
You're still not really completely protecting yourself. So it seems to me like you're hedging your bets by assuming that primarily websites which have ads are a liability, but websites with no ads, but with equal opportunity for exploiting vulnerabilities are not.
Not only that but the ad networks also get all your details which makes Internet advertising quite unlike other advertising.
If the ad networks have no "ethics" I see no reason to feel an ethical obligation back. Sucks for content providers, yeah, but if they have to die to get rid of the sketchy ad networks so be it.
I'd be willing to whitelist ad networks which were sandboxed and could only show me straight up images proxied through the first party site. Anything more than that and I'll show some control of my own hardware and block it. Ultimately, it's my hardware, if it does anything I don't like, I have a right to fix it.
If a large enough segment of the population uses an ad-blocker it signals a clear and direct message to site-owners and ad network's wallets that you won't put up with ads and that they won't make money from you until they come up with a different business model. What could be better? It's way more effective than just leaving, emailing the webmaster, or writing an angry blog post.
I long for the day when I don't need an incredibly aggressive content filter on the web for it to be usable, safe, and private.
They're going to take the 'easier' route of trying to keep bypassing the blockers than changing the entire revenue model. That's why supporting websites which are founded on a non-advertising revenue model is crucial.
>It's way more effective than just leaving, emailing the webmaster, or writing an angry blog post.
What argument do you present for this?
If you're concerned with what's possible then any website that has JS is a potential vector for malware. Then you can just disable JS and browse the web that way. But wait, websites can also attack you with HTML browser bugs with malformed HTML, or PNG or JPG renderer bugs with malformed images, etc etc. At some point, you're going to have to be practical and compromise or something. My point is if you want to be principled, then reward websites with no ads by visiting them and don't reward websites who have ads.