Banner ads on CNN.com contain keyloggers
twitter.com
twitter.com
Oh and if you want to see what CNN is crapping out without the cruft, lite.cnn.io works well.
Surveillance is helpful information gathering and customer profiling in order to understand customer needs better. This enables us to put more relevant ads in front of your eyes. It also helps us to understand when is most convenient to sneak in the middle of the night and harvest your and your family's vital organs, as permitted by the service agreement you signed.
That listening device is the cost of the plant... don't like it? Then pay to avoid it...
It's that simple, there's no alternative. They have to pay to make that content and send it to you. If it's not advertising that pay for it, that cash won't appear out of thin air. Someone needs to pay for it and if it's not an advertiser that does, it needs to be you.
There's plenty of news agency that offer paid membership without ads, go for them.
There's plenty of people that can't afford to pay or that just doesn't have the means to. I remember the amount of content I was able to learn because advertising was subsidizing it. My parent were sadly against paying on the internet and I'm far from being the only one that learned that way.
That is totally silly - What in the world makes you think I think about the advertisement industry more than the absolute minimum amount possible?
Anyway, the other options are:
- They run their own ad platform - They don't run ads
Just to be clear, I think they are talking about advertisements placed via Google's platform, not ad campaigns by Google.
I think there is only one way to solve this: programmatic ads cannot contain executable code (no access to local storage or network) and ads must come from the same origin as the page they are on. For example, YouTube will host an ad for Subaru on YouTube's servers. The sticking point as people have pointed to me before on HN is fraud. The customer (in this case Subaru) does not trust Google to be honest in counting the number of impressions.
Perhaps what we need is legislation banning this behavior across the board. When no ad vendor is able to allow customers to do what they please on user's web browsers, the customer has no recourse other than to accept that this is not possible. I don't know how such a legislation would work though. Perhaps it needs to be an industry alliance instead of legislation?
Can you cite that as your previous accusation was already proven to be incorrect.
>When one company owns the whole space, finding just one vulnerability is enormously economically attractive.
Google doesn't own the whole space.
It has been changing and improving for years.
Your statement is true for the ad content for sure. (Though sites do take flack for inappropriate ad content, just like print publications have.)
This is irrelevant to the OP’s link, though, since it’s not a keylogger and keyloggers aren’t actually possible.
Ads are subject to the security rules imposed by the browser, and for the most part every abuse that ads have attempted have been shut down. Sometimes not as fast as we’d like, I admit, but for the most part I think the system is working.
Ads can no longer play audio, they can’t see data passing between me and the site they’re embedded into, they can’t abuse popups anymore, etc., etc.. Every time an advertiser comes up with some new annoying way to try and get extra attention, the good folks designing the web and making the browsers patch the hole.
I like that the web standards and browsers, and laws to some extent, are where the responsibility lies, and I wouldn’t want to have individual sites taking responsibility for the security of ads.
As for bemoaning ad blockers, at least keep in mind the ads in ad-supported free content is their revenue stream, and that the majority of ads aren’t malicious. Personally, I’d love to see a better free business model than ad-supported free content. In the mean time, paying directly for ad-free content, and putting up with ads are our main options.
Chrome web inspector kindly gives the "Initiator" for every request. In this case it's cnn-header-second.min.js. Load that, and Chrome again kindly detects minified JS and offers to pretty-print it.
The context here appears to be some kind of ad console tool, added by CNN, not by an ad. The relevant function is at https://pastebin.com/EwgPAM6T
It's a bit obfuscated/minified, and they don't seem to have a non-minified version available, so it's not clear exactly what functionality this is enabling.
Either way, not really a keylogger if it's not capturing all keystrokes and shipping them off somewhere.
The guy who tweeted this jumped to a conclusion, naively shared his discovery, then let it perpetuate leaving numerous victims of an erroneously altered world-view.
To be fair, when they're desperate real world newspapers are like this too.
A flush successful newspaper will make a deal of its editorial independence and insist you write "Advertising Feature" in big letters at the top of your full page ad, use a completely different typeface and give your company's name, but when money is tight the guy selling those adverts is under pressure to compromise. What if it says "Sponsored content" rather than "Advertising Feature"? And rather than big letters at the top, how about small disclosure text at the bottom? The typeface could be a very good clone of your normal editorial typeface, and still count as "different" right? And lets have a byline which says "Our staff", that's vague, and the poor reader might think it means it was written by journalists, but it doesn't strictly _say_ that, it just says "Staff" which could be anybody...
This is how internationally famous British newspapers end up running content literally written in Beijing or Moscow to let everybody know how free and wonderful those countries are, using weasel words like "in co-operation with". And if the _actual_ news is a bit awkward? Well, you wouldn't want that lucrative sponsored content deal to lapse would you? Maybe a brief mention on page 14 is enough, even if those newspapers which still have a backbone ran it on their front page.
What needs to be done is to navigate the site and typing a given char sequence on every page while logging the HTTP traffic, then do a search for that sequence to see if it appears in any request. That's the basic thing you could do to actually verify if there is a keylogger.
Obviously bullshit. That's CNNs CDN, not a "banner ad". This guy did not put in the least bit of effort to verify his claims.
The script is included in https://edition.cnn.com/.a/2.103.4/js/cnn-header-second.min....
Do I need to read a manual for the ad? Also, the ones that actually are dependant on the keyboard will already use Vimium or something else.
They could improve their HTTP header settings a bit. [2]
[1] - https://lite.cnn.io/
[2] - https://securityheaders.com/?q=https%3A%2F%2Fcnn.com%2F&foll...
A keylogger would be possible if there was some kind of zero day exploit, but this isn’t that, it sound like the tweeter didn’t do their due diligence. I’m curious how someone gets as far as looking through the minified JavaScript without knowing the browser doesn’t allow that, obviously(?), otherwise all your passwords and information would have been compromised long ago.
Advertising has ruined every medium it has ever touched. It will ruin the web. It is only a matter of time. It did not destroy ancient network television overnight. It did not destroy cable tv overnight.
The last time I saw cable tv a few years back, it had become so bad that after a long run of ads, they would then put bugs and walk on people right over the content of the show you were watching. Sometimes obscuring important content within that show.
This is why we run ad blockers. Since you won't regulate your industry, we're fixing the problem for you.
Love,
The Rest of the World.
Sincerely,
Concerned users of the Internet.