Ad network uses advanced malware technique to conceal CPU-draining mining ads
arstechnica.com
arstechnica.com
1. Ad networks / exchanges allow (don't catch) these ads
2. Publishers don't do enough to stop them
3. Browsers allow it to happen
I'm still blocking ads and javascript everywhere I browse. If the ad networks are the ones distributing this malware, they're either complicit or negligent. Either way, the source of the malware from my perspective as a user is still "ads".
Advertisers and publishers should pressure ad networks and browsers to do a better job fighting fraud though.
I don't have time to be submitting complaints to faceless Internet corporations. I just want to use the web without being bothered.
You've got 3 or 4 different parties involved in the current ad system: The content publisher who host the ads, the ad network, the advertisers, and, possibly, the company the advertiser hires to write the ad. And it's not like old school print ads where the content publisher gets to look over a proof before everything gets sent out. Several of these parties either don't or can't really understand how the ads really work and what the final product is going to be like.
In this kind of situation, whose responsibility is it to maintain integrity and keep the bad actors out? I'm not sure that it's anybody's. _Maybe_ it's the ad network's, but, realistically, they're sitting on top of an immensely complex system that is going to be very hard to police properly, so they won't spend the money on it unless they're forced to.
I suspect that the only way to force them to do it is to have a court find that an ad network hosting a malignant ad is either tortious, or makes them an accessory to a crime.
Publishers bear liability for serving up malware to their readers; ad networks for serving up malware to the publishers. We're just waiting for an enterprising lawyer/litigation financier to put the pieces together.
Actually … hang it, just thinking about where the threshold is has taken up too much of my time. I will just block all ads.
I also agree that browsers could and should do more to stop unnecessary scripts. At some point, a blacklist will not be enough (I think we're here already) and a whitelist will be the only viable approach going forward. The question is, how to curate a whitelist for the majority of users? Also, why Firefox and other open source browsers don't include things like ad blocking and script blocking by default.
I don't think white/blacklists are the best solution, though they do work most of the time right now - I'd rather see a flag that publishers can enable to browsers that lets them use more resources. IF your site is a web-app, allow it to use a lot of resources. If its a blog / non-intensive site, simply don't let it use a lot of resources or just ask the user if they want to use more resources.
I don't know if sites would self identify or if a browser could just analyze them on the fly, but this approach seems to make sense. (A little rocky at the start, but it would scale effectively).
Publishers pushing miners themselves is super interesting, but definitely not fraud like in this article.
I was insinuating that there is a financial interest by the publisher to "make more on ads" that is abetted by injecting bitcoin mining into the ads they serve up. Doing this in the ads gives them a great 'out' when they are discovered "oh its bad actors in the ad network, what can we do?"
The Salon article is a demonstration that publishers do in fact consider this as an alternative. I doubt Salon was the only one and I doubt that all publishers would be so ethical as to "ask first" given their behavior in the adblocking war.
2. Publishers tolerate this and use such ad networks.
3. Browsers do what they're supposed to do, execute the code delivered by the publisher's site and the resources it references.
The only thing browsers could do is show a warning that "www.publisher.example.com is using large amounts of CPU resources" to discourage web sites from being shitty, but ultimately, it's the responsibility of the publisher to make sure his site doesn't serve malware.
Keep in mind that next time, it could be a 0day exploiting your browser instead of a miner.
At least nobody will be able to give the old "Oh, but advertising is necessary for Capitalism" excuse. This is way over the line. Down with the corporate capitalist "internet" of ads!
Use Firefox. Use uBlock. Use NoScript. Use Privacy Badger.
and just to make it all-the-more simpler for some folks, a few links:
Firefox: https://www.mozilla.org/en-US/firefox/new/
uBlock: https://github.com/gorhill/uBlock#installation
NoScript: https://noscript.net/
Privacy Badger: https://www.eff.org/privacybadger
This is such a well defined concept that I'm having trouble believing that even a troll would advocate a "The Advertisers doesn't mean anything" viewpoint. I might as well claim that there's no ad blocker either.
Now if they started serving the JS from random domains and URLs that would mean trouble because you couldn't just use the URL-based filter approach most adblockers use. I'm surprised this doesn't appear to be more common. If it gains steam we might have to use a whitelist approach for trusted 3rd party javascript sources. Not necessarily a bad thing IMO, although that might stifle innovation a bit on the web.
you don't even need random domains. random urls from the same domain would work fine.
What stops someone from blocking the domain? I think a combination of random domain + url would make it rather hard to detect these things.
Moreover, the Firefox/webext version allows you to remove specific inline script tags before the document is parsed by the browser.[1]
uMatrix can selectively block web workers, which are typically used by coin miners.[2] I have long been thinking of bringing that ability to uBO, but I want to do it right UI-wise.
* * *
[0] https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
[1] https://github.com/gorhill/uBlock/wiki/Static-filter-syntax#...
Maybe we should get rid of web workers at browser level until we figure out this mess. Web workers are seldom used and could be enabled manually per site.
Whom by?
They just need to hide coinhive from the ad platform, which is what they use the random domain for. When the ad platform fetches the ad code from the domain to inspect it, the random domain serves harmless code. When the user fetches the ad code, they get the miner.
The solution is for ad platforms to disallow external resources and custom JavaScript, and for publishers to be held responsible when their sites serve malware (whether directly or because they used an ad platform that sold the space to another ad platform that sold the space to another ad platform that sold the space to a bad guy who was able to serve a custom script because each of the platforms along the chain let everyone include arbitrary scripts).
Consider the whole web hostile. Browse with uBlock Origin and JS off. Enable JS for trusted domains only. Give up, blacklist, and go elsewhere if whack-a-mole enabling needs too many unknown random domains enabled just to read that article.
[0] https://chrome.google.com/webstore/detail/scriptsafe/oiigbmn...
Also has a "don't filter on this domain" switch for things like bank sites and other fragile ops.
It also allows blocking webworkers which mining sites tend to rely on.
It's not that nobody's interested - people I know are interested in finding out how my browser is able to display pages so much faster than theirs, and how my computer remains responsive even when I have a bazillion tabs open. But effectively using NoScript inevitably requires having at least enough technical knowledge to understand how JavaScript works and predict which blocked components are causing the bit of the page that you actually want to fail to load.
It's almost like there needs to be a NoScript-like plugin that crowdsources a whitelist of domains (or, maybe better yet, specific scripts) so that non-technical users can have access to the knowledge of people who have the ability to figure this mess out. But, of course, you'd need to figure out a crowdsourcing method that's resistant to attack, because the ad networks and other malicious players would immediately be paying the click farmers to vote their scripts into the whitelist.
I don't think trying to convey what ad or script blocking choices they should be making really works with non-tech folks any more. To be fair it was always a bit of a stretch...
That has been the model since the beginning. The problem is that web developers and browser developers have a greater interest in doing their thing than in protecting end users. Thus the introduction of cookies, javascript, iframes, etc. It's been a continuous curve of increased scope inside tbe browser. Now we have web assembly, workers, websockets, local storage, etc. and no good way for the end user to actually observe any of this shit. Browser developers are reinventing the operating system, but poorly.
That browsers don't implement any effective autoplay control still is idiotic (but then, the solution is simple: deactivate all codecs, and use youtube-dl for a better and ad-free user experience anyway).
Perhaps it would be a good idea to similarly visualize tabs with high CPU/GPU consumption?
A browser does most (if not all) of what an OS does, so it shouldn’t be surprising if a task manager (which shows CPU usage) is also useful for browsers.
I'm not an expert in any of this. I'm not even remotely sure what I'm proposing is possible or would be effective. I just want to start a conversation because I know what I don't want and throwing ideas out into the wild is better than staying quiet. I know I have no interest in giving up any privacy for a potential few seconds saved on load time for a site I'm not sure I even want to visit in the first place. Load times should be the burden of the site owner. Ideally that would be optimized by serving only what is absolutely necessary to get me to the thing I wanted to see. Not that plus the 10 other things you and/or third-parties decided they deserve to serve and hope my machine has pro-actively pre-fetched so I don't perceive the shit-show going on behind the scenes. Given all the details of how this stuff works, I don't think most users would volunteer for it either.
Video, particularly HD video, absolutely requires ads or subscriptions. Social networks could probably be built atop WebRTC and run in a federated way, more like IRC... but image or video sharing would start to demand significant resources.
The downside of losing ad-supported media will be ad-sponsored media paying to write the content itself.
I'm extremely skeptical. It's not at all hard to think of a lot of different ways that would be enormously convenient and highly transparent to users to have direct pay options. I think they haven't been tried because of the standard technology issues: we're in a local minima and there is enormous inertia with what "everyone uses" already. But that's not at all the same thing as being in an absolute minima, where any change would necessarily be less efficient. Quite the contrary, in tracking flow of money and resources advertising looks to have quite a few unnecessary inefficiencies between user goals and publisher goals. That being the case I see no reason to believe inherently that something better could not be developed if there was sufficient motivation, and an existential threat would certainly be that.
Without government backing, the system you envisage would ironically be prohibited by antitrust laws. It would be a rather clear example of price-fixing and collusion by competitors. Maybe there's some way to do this through peer pressure or incentives, but I think we've seen that approach fail so often that it's hard to see what could be done differently short of a hardline approach that would trigger regulatory scrutiny.
Maybe the alternative is: if you don't want to charge for the content you produce or give it for free don't bother producing it. There are huge chances your content is just shit anyway.
Many people I know (myself included) pay for articles they read on the sources they choose.
It's the websites that copy the articles, mix the words a bit and republish that get into trouble and in my experience have the most problems with ad blockers. I don't think that's a bad thing.
Like others said here, if nobody wants to pay for your articles you either publish them for free or do something else with your life.
The other form of dumping comes from tech companies operating in the red but surviving on investment dollars. Frankly, this is a result of growing wealth and income inequality that leaves investors with few avenues for growth outside of ad-funded moonshots as consumers aren't able to drive growth like they used to due to flat income.
[1] https://en.m.wikipedia.org/wiki/Dumping_(pricing_policy)
Edit: Imagine a world where the average consumer makes $10k more per year, then turns around and spends some of that on online services. You now have a situation where the interests of the user and web service provider are aligned. The user is now the customer, not the product.
Sorry but your website's business model is an infinitely lower priority than me needing to re-image my Windows install yet again because one of your fellow companies is asleep at the wheel regarding security.
[0]: https://github.com/gorhill/uBlock/wiki/Blocking-mode:-hard-m...
I've been patient for months but it still isn't fixed, thus I'm trying to shed my dependence of it if uBO can offer me the same thing on its own.
I usually unblock the embedded domain, manually allow frames, then force-reload the page, but it usually seems to work.
Looks like I finally need to get around to researching the options for this.
I'll have to stick with the more naive DNS blacklist based blocking for network wide protection though, as I don't want to tell others to use something more aggressive then have to support "this site doesn't work!" requests.
[adnauseum]: https://adnauseam.io/
Previous discussion: https://news.ycombinator.com/item?id=10611594 https://news.ycombinator.com/item?id=13222733
Which is arguably the correct one to take these days.
I basically have. DDG + Fastmail + Firefox. Google is not some magic technology elf that makes the web work. And frankly, their products aren't THAT good. Search has been declining in usefulness for years, YouTube is a hot mess that's in the process of demonetizing all the niche content.
Plain text or image ads are fine. They can track passively without JS. The problem is that they're using JS to do all kinds of shady stuff.
But JS can do much more shady things than tracking people.
No, I think that this case demonstrates that it's JavaScript which is the ultimate problem: cryptomining is a code-execution problem (although there is a network-access component to it, since the mining code needs to get block information & submit block results somehow).
I like to imagine that in a few decades we'll wonder how we ever thought it was a good idea to grant frictionless full-execute privileges to all the code everywhere, but honestly I'm far too pessimistic to believe that we'll ever wake up.
Personally, my JS has been disabled since Meltdown/Spectre. There are sites that don't work and some of the big ones that I have more trust in I'll whitelist. But for the most part it stays off.
https://github.com/gorhill/uBlock/wiki/Blocking-mode:-medium...
Also, it not just random domain names. It is random registrant data. It is short lived domain names. It is obfuscated NS infrastructure.
Checking your CPU usage via `top` is a relatively "power-user" esque function so your experience is unlikely to be reflective of the general population.
For example, newly registered domain names tend to get a small added spam score when used in emails. Spammers could wait a month but that gives registrars time to detect the fraudulent registrant data and revoke the name before it can be used.
Spam filters has many years to adapt and develop. The arms race for browser security is just in the beginning. I expect to see score based systems becoming popular, just like it did with spam filters.
> This page is consuming a lot of resources, do you want to keep executing JavaScript on this page?
> Stop / Allow only this time / Allow always
On the other hand if you set it too high then those websites will aim for that limit to maximize profit without triggering the warning. You'll still waste a ton of resources and you've only mitigated the issue somewhat.
I'm not saying it's impossible, just that "just add a dialog when CPU usage is high" might be a bit naive. There's a subtle balance to these things.
I'm not going to file patent for this, thanks in the code will be enough. Enjoy :)
As an alternative, you could do a survey at install time - check if a battery is present, get power profiles, run your benchmark js stuff, check CPU, RAM, disk type (HDD/SSD) - then download profiles for that/those configuration(s). Then put a 'sensitivity' slider in the advanced options to allow power users to tweak/turn off the limit.
No need to send me code. Cash will do fine.
They allow it because the point of scripts is to consume some level of CPU resources, and setting an arbitrary limit on how much is too much is bound to cause a bad user experience when e.g. rendering large visualizations or playing a fast-paced game.
Of course, they could start asking for permission before letting a site use more than X CPU, or before letting the site execute JavaScript at all, but most people don't want additional popups like that.
Someone said that Firefox warns you when a site uses a lot of CPU but I couldn't trigger that warning (maybe I didn't run it long enough or the feature is in a newer version).
Are any of the legit ad networks doing anything to combat the problems in the article?
As long as there are bad actors, the good ones will get caught up in the net and must own the major share of combating the problem that affects their core business.
[0]: http://blokada.org/
Only if the "obvious reason" you meant there is "Google abusing its Android monopoly power".
I wish the EU would include that part into its anti-trust investigation against Google, too. It should be illegal for Google to ban ad-blockers on its store, for the same reason multiple courts in Europe have found that ad-blockers are legal: the user should have the power to block ads if he or she wants it.
This is especially true in this case, because Google can't even use the "security" argument as it did in the early days of ad-blocker banning. This app is functionally the same as a regular VPN, so unless it's saying that all VPNs are a security risk and it wants to ban all of them, then Google has no technical justification for banning VPN-like ad-blockers.
As as side note, why doesn't Blockada use HTTPS? My trust in that app dropped in half for this reason alone, when it's so easy and free to enable HTTPS these days.
On the subject of banning apps: my complete lack of empathy for less technically capable users is probably showing right now, but as long as I'm able to sideload apps onto my phone running AOSP, I'm good with whatever.
BTW was there any discussion on how Google could be split? Android doesn't bring enough money to develop it, it would make sense to just drop it. Manufacturers would need to maintain their own OSes, that might be interesting.
Firefox on Android supports uBlock Origin very well. It's awesome.
This is getting out of hand.
I'm considering changing my local DNS to NXDOMAIN the whole TLD if it's this messy.
With the right PoW algorithm and the hardware access to optimize it, it really seems like an excellent economic model, specifically if you must opt-in in exchange for seeing no ads.
Today we deal with advertisements that destroy the user experience and have a very real cost to the user in having to navigate through intrusive ads. Which also, by the way, often cause the same over-revving and slow downs as mining do.
In response, ad blockers rewrite or block a site’s code to eliminate the ads, consuming the content but starving the site from its only revenue stream. Not theft, perhaps not even morally wrong, but certainly to the detriment of the site owner.
Microtransactions or subscription-based content pools with view-based payouts have been proposed for years and have had some traction but certainly aren’t widespread.
If you could opt-in to mine on behalf of the sites you visit in a way that respected your real-time compute resources, in exchange for a completely ad-free experience, would you do it?
It seems like mining for someone is the ultimate micro transaction. There is no overhead and no fees and you can mine for a portion of time equal to tiny fractions of a cent of value. In fact, mining for enough cycles to produce even a penny of value would be a fairly substantial amount of computation.
The crucial question is the effeciency of the process. There are no transactions fees whatsoever to mine for someone else, the bandwidth is minuscule, the code is fairly tight. But the one thing that makes it inefficient is if you’re consuming more compute than necessary to most optimally perform the PoW. In other words, if your hashrate per CPU-second is sub-optimal because the sandbox doesn’t allow an efficient PoW implementation, or because the algorithm can be run orders of magnitude more efficiently on specialized hardware, that in itself is a form of transaction fee.
If we can get a PoW algorithm which runs near-optimally on general purpose computers on a blockchain that isn’t dominated by botnets, then the economics should work out that you are paying whoever you mine for approximately the cost of the electricity required to perform the mining, effectively leading to a way to make free micropayments.
Those on cheap or slow hardware might be limited to older or less valuable content.
Now that is a dystopia I don't think anyone would like to see.
The premise is that opt-in mining can be used as an efficient micropayment. Any new technology can be used toward dystopian ends, or not, so it’s not a reflection at all on the merit of the idea.
That is to say, your machine is constantly mining 24 hours / day at an extremely preemptable low-priority on behalf of the various sites you visited that day.
Definitely it can’t work that you’re only mining on behalf of the site while you’re actively looking at it, because when you’re sitting in front of your device is precisely when you don't want to be mining!
As far as how much advertising value does the average internet user provide in a day? Facebooks ARPU is about $25 in the US. And apparently Facebook users spend an average of 50 minutes per day on Facebook. So that’s 8.2 cents per hour, so we’re within an order of magnitude!
Because of the race to the bottom incentives for publishers, we will see both intrusive, secret crypto-mining AND advertisements, not either-or.