Why is Stack Overflow trying to start audio?
meta.stackoverflow.com
meta.stackoverflow.com
- Nick Craver, Architecture Lead at Stack Overflow
It's ridiculous. It's a text-based ad. At worst, it's a clickable image. At what point did it become okay in your minds to let advertisers run arbitrary code?
I've left ads turned on specifically on StackOverflow because 1) I want to support StackOverflow, and 2) I trust them not to run malicious ads.
I don't even care that they're running ads network-wide. But if they're going to be running these kinds of ads anywhere on the site, they're going right on the ad block list along with everyone else.
Imagine a TV ad that tries to make your phone call a 1-900 number so they can rip you off, and the station says they don’t know where it came from but they’re trying real hard to put a stop to it. And somehow watching the ads themselves before broadcasting them never crosses their mind.
No single publisher today really has the power to change much, no matter how big they are. The issue likes with adtech (like Google) and advertisers.
Unfortunately running javascript means these ads can do anything at any time and change into malware. Other than adding some technical guardrails, the best practice would be to ban bad actors (of which many are known and usually the same shady people) but many large adtech companies look the other way because it makes money and they have no consequences.
Malware and adfraud is primarily a business problem, not a technical one.
It's not that simple. There are many layers in the supply chain that currently requires JS. Publishers can't disable the JS and they can't demand JS-free creatives either.
You’re saying that doing this would drastically decrease ad revenue. Which is what I’m saying too: it’s about money, not necessity.
Would a site like SO be unable to survive without ads that run arbitrary JS? I don’t know. Even if the answer is that they must do this to survive, it’s still insane that content companies let randos inject arbitrary code into their pages. If this is so entrenched in the industry that there’s no way around it, that just means the industry is insane.
Simple doesn't mean it's easy or realistic. Yes, adtech has major problems but they're being slowly worked on and won't change overnight. This applies to any other industry where you think can just walk in and solve everything if everyone just did X. Reality doesn't work that way.
Of course reality doesn’t work that way. Ad companies aren’t going to change, because they like money and don’t give a shit about users.
We’re stuck in a local minimum. It’s insane. It could be easily fixed if everyone just stopped doing the insane things. And they won’t stop.
And yes, I'm enjoying my 90's internet and enable JS when it is needed (rarely) for specific domains.
* adverts are vetted by a human
* adverts are not allowed to inject JavaScript.
There have been a few interesting blog posts from businesses outside of the adult entertainment industry where they discuss just how work is involved in getting an advert approved on adult sites.
It’s a sad state of affairs when an adblocker is less required on porn sites than it is on Stack Overflow.
Adult ads are definitely not better and are served by even looser networks that allow anything. That industry has pioneered things like popunders, clickjacking, and monetizing every possible action on a window while serving as the primary vector for malware and browser bitcoin mining. I'm not sure what blog posts you've read but the only strict standards they would have is on getting paid.
What you’re effectively doing is looking at Source Forge and then arguing that Github, Gitlab and Bitbucket are all probably just as bad.
* remove the ability for 3rd parties to abuse their automatic powers (ie disable their ability to inject JavaScript)
* or have a human manually vet every creative
The problem here is you neither want to control their access nor take responsibility for monitoring their access. So the blame equally lies with yourselves for not managing an easily exploitable vector of attack.
If this were any other system, eg VPN, security professionals would tear you a new asshole and point out just how irresponsible your lack of management is.
You’re only excuse here is greed and frankly I’m disgusted.
I'm not sure who you think I am or why you're accusing me but none of this is down to a single person.
In any other context we would call this a security vulnerability. I think that label also applies here.
[0]: https://www.reddit.com/r/privacy/comments/bpr6xs/if_you_choo...
But that's assuming it doesn't try to connect elsewhere if it detects it doesn't have internet.
Imagine having to take countermeasures like this to prevent things you've purchased from spying on you!
Could we require advertisers to sign their ad code to have a trail of where it came from, prevent tampering, and make it easier to pull the plug on bad actors?
The people bearing the costs of the internet ad economy aren’t the people in any position to do anything about it. So there’s very little pressure to fix anything.
Maybe if the US government started threatening to enact something like GDPR unless the a democratic industry gets its shit together.
By serving this ad with JavaScript not vetted to StackOverflow's presumed standard, StackOverflow has violated that trust. Thus the onus is on them, not the user, to remove the offending ad or risk damaging their brand.
Honestly, what you said is like saying "why would you ever not keep a hand on your wallet" after someone got pickpocketed in a nice restaurant. Reasonable people have reasonable expectations of safety in certain places which they trust to provide it for them. No-one should go around being constantly paranoid of pickpockets everywhere, no more than anyone on the web should be constantly paranoid of malicious JavaScript even on sites with established records of safety.
I agree that StackOverflow is at fault here, but enabling JS is not a binary choice — "allow all JS on this site" vs "block all JS on this site" are not your only options.
Tools like uMatrix allow me to control JS coming from different domains on different domains independently. For example, on SO I have enabled JS from Stack Exchange and related domains, but not from Google or other snoopers.
https://feature-policy-demos.appspot.com/
https://developers.google.com/web/updates/2018/06/feature-po...
You also need to somehow <iframe> the ad content (and serve it from somewhere else with the feature policy header set/attribute on the iframe set) or else sacrifice use of these features on your own site.
The solution is to make the ads inert. They do not need to run code.
> To the people confused why ads need to run their own Javascript (even ones that are just static images): The short answer is that Ad Networks do not and cannot trust website operators. They need to run their own JavaScript served from their own servers in order to verify that a real user saw the ad and for how long, and they can't trust the website operator to tell them. And these pieces of JavaScript tend to be more invasive and privacy-destroying than the website's JS because they care, far more than the actual website does, that the "user" is not a bank of iphones in a sweatshop in China.
[1]: https://meta.stackoverflow.com/questions/386487/why-is-stack...
"The ad is attempting to use the Audio API as one of literally hundreds of pieces of data it is collecting about your browser in an attempt to "fingerprint" it... Your browser may be blocking this particular API, but it's not blocking most of the data."
Seems like killing the audio is the metaphorical putting a finger in the dyke of serving arbitrary JavaScript to your users.
Are you really aware of the issue? The issue people have here is not the fact that the ad is trying to access the audio api per se but that it is trying to fingerprint the users.
People looking at the source code, like what happened here.
Imagine if all the ads in the print edition were spying on and tracking your every move.
Re-selling digital personas as commodities must be far more lucrative.
Is that the evil twin?
Their other income is from job ads, and I guess the value is that they have lots of data points about their logged in users (with scores high enough to imply they've interacted with the site a fair bit), in the form of what is posted, worth more than the aggregated list of websites that a user sees (as reported by ads).
I'd love to know more about this, as I have very little understanding of the economics of serving targeted ads. How much can they be making from ads?
Perhaps you should stop doing that.
If you're serious about this, I've built tools for the publisher side for stopping exactly this.
My email address is in my profile.
It's hard to read the obfuscated code and be sure what's being done with the browser environment information. This script seems to generate some hash and put in some global variables, presumably for some other script to consume. I don't know whether such scripts send it to a server, compare it locally to a previously-known value, or ignore it.
Google has is currently as far away from their previous world famous "don't be evil" corporate culture.
Other examples are AMP where Google wants to make it harder to de-individualise URL's. This is being driven to an extend where Chrome on Android makes it harder to edit the URL.
Or games like Egress or PokemonGo, which in my opinion helps Google constantly update their WiFi SSIDs-To-GPS-location database.This database is rhen furthermore being used to track users location through a little permission called "WiFi Control", which also can not be found in the regular App Permissions settings entry.
To me WiFi-Control sound nothing like location tracking. But I have to admit, I am not a native speaker. Therefore I might be misunderstanding something.
This library is very popular.
https://github.com/Valve/fingerprintjs2/blob/master/fingerpr...
This is not just ads, but about fingerprinting and tracking users somehow or the other by third parties. It's plain evil, and not a decent thing to continue foisting on your unsuspecting users after you've known it. Tell management to take an ethical stance and preserve the reputation of SO.
The only time they'd do that is if the marketing team decided that the value-add from taking ads off cancelled out the profit loss from taking the ads off.
Maybe he (or someone else in the team) has already given this as a temporary solution but it's been rejected. Since we don't know what's going on in the background, this suggestion being put on a public forum is still worthwhile. It could also help external parties (like HN readers) add more pressure in not letting this kind of surveillance continue just because the company doesn't want to stop making money while they're working on a solution or waiting for Google (or someone else) to help.
Every minute they delay cutting this off puts thousands of people in a position of vulnerability.
- Stack Overflow makes a blog post about not using dynamic ads.
- Dynamic ads found on Stack Overflow, with aggressive fingerprinting.
- Architecture Lead doesn't know how this happened and is getting serious.
I have so many questions. I hope this gets a post-mortem.
How We Make Money at Stack Overflow: 2019 Edition: Taking money from Microsoft and Google fingerprinting our users 100+ ways
source: https://stackoverflow.blog/2016/11/15/how-we-make-money-at-s...
1. Text based ads only (no third party js)
2. HTML based ads but no js (run it through DOMPurify https://github.com/cure53/DOMPurify)
3. Look for a js sandbox -- this _will_ break arbitrary js, will not be supported in all browsers, and will require dev work on your side:
* Google Caja https://github.com/google/caja
* MentalJS https://github.com/hackvertor/MentalJS
other options are available as well, in varying levels of maturity and support.I think using a sandbox iframe is not going to be able to defeat browser fingerprinting, because the sandbox control options are not rich enough. You would need to block all JS.
Or use iframe.sandbox, which was designed for it. https://www.w3schools.com/tags/att_iframe_sandbox.asp
1. scrollbars and positioning can cause problems with iframes that an inline div doesn't have, especially if there are multiple small iframes on the page.
2. As soon as you allow script in the sandbox iframe, then you are susceptible to these types of fingerprinting attacks. The fact that you have origin isolation doesn't really block what the ad was doing. This is because iframe sandbox was never designed to block fingerprinting attacks, it was design to create a separate origin that gave the dev broad control over features like 'allow js' 'allow access to origin', etc.
I'm not quite sure what you mean here, but I'm curious. Have any examples?
But at the same time, you want to see all the content in the iframe. If you knew ahead of time exactly the layout of the text in the iframe you could do this, but it's harder when you have dynamically generated content inserted into the iframe, and now add to that wanting the page to be on different devices with different viewports, resolutions, users resizing the page, users increasing or decreasing text sizes for accessibility or changing default fonts.
And if you don't control the content, some of it may contain fixed size elements or absolute positioning inside the frame.
It's a really difficult problem that we were struggling with before ultimately giving up on trying to use iframes for this purpose. And when you make a mistake you either get ugly scrollbars in your iframe or part of your content is cut off when the user resizes the page.
That's why I think the idea of running each site in a container is so effective.
And while we're at it the container should just spit out random shit like different resolution, audio api, user agent, once in a while (unless the user turns it off) to thwart such attempts.
Unfortunately when the creator and maintener of 67% of all browsers is an ad company who is exploiting this in the firsr place, then there is no chance that this could happen
Wouldn't that break the legitimate feature-detection uses for these APIs? Asking the user to identify and whitelist each call is impractical, especially since the fail-case in this scenario would be subtle (you'd still see the page but it might randomly be in the wrong mode, or images might be scaled incorrectly, etc). At that point you might as well just turn Javascript off.
My guess is the difference between "regular CSS that adapts to screen size" and "responsive CSS" is that the former only has a single set of rules while the latter has different CSS rules that get enabled/disabled based on screen size.
Conditional rules -> different content gets loaded -> server gets notified of what rules are enabled -> fingerprinting
Things went downhill once we started writing HTML which required knowing screen size ;-<
That way, the page displays correctly for you, but the server has no idea your actual fingerprint.
There's some trickiness to get this to work right; the collection of fake fingerprints would have to have a certain amount of persistence, because if it was regenerated every pageload, the server could probably tell that only one fingerprint kept showing up repeatedly. Maybe each fake fingerprint should have a completely realistic-seeming browsing session, happening in parallel with your real one, with half the collection continuing on browsing even after you're done? Except wait, ads could just separately target every fingerprint, and it doesn't matter if 99% of them are fake as long as its accuracy for your real one is still good. To defeat that you need the randomized activity using your real fingerprint.
The ideal would be if this was done through a proxy server, which would then know every fingerprint ever sent to a website. It could then provide you with a random collection of past fingerprints that have actually visited the same website, so every visitor gets a collection of fingerprints randomly drawn from the same "bag", rendering visitors indistinguishable.
It’s not harmful, as long as you’re not one of the people who gets tricked. But it does indicate that they want to do you harm, and try to. That they failed doesn’t make it all better.
Considering the alternatives, that sounds really appealing for me. I'd also buy it for my less tech-literate parents.
Also, ISP-level adblock will lead to tons of support requests, esp. when news websites start blocking that ISP and tell customers to call the ISP's support to "fix" the internet.
Besides disabling JavaScript you can put hosts file blocklists.
Simple corporation block list (e.g. Facebook, Google) https://github.com/jmdugan/blocklists/tree/master/corporatio...
"Someone Who Cares" list http://someonewhocares.org/hosts/
Ultimate Hosts Blacklist: 1 million blocked domains (once in a while you might need to unblock something) and also a bonus known hacking IP blocklist. https://github.com/mitchellkrogza/Ultimate.Hosts.Blacklist
Anything involving javascript will do shenanigans for various reasons. Fingerprinting via any means possible is industry standard ad-network behavior at this point. No one in the industry could imagine doing any less - it's impractical, it's absurd. But targeting! But fraud! But the only fix is to just give it all up, go back to how it was done in the 90s.
that sure would keep me up at night.
obviously, i know google does more, but it seems like a large chunk of their revenue must be dependent on shady technical tricks like these working.
https://blog.mozilla.org/futurereleases/2019/04/09/protectio...
[1]: https://github.com/gautamkrishnar/nothing-private/blob/maste...
[1] https://en.m.wikipedia.org/wiki/Usage_share_of_web_browsers#...
Other options would be that if you are a content distribution company, e.g. youtube, google, facebook, twitter, instagram, etc. then you cannot have any control of the client side applications that consume the content. Trustbusting would come into play here.
Or legal obligations to follow a user's desire not to be tracked with real criminal fines and jail time applied to executives, managers, and developers who failed to follow the law.
It's easier to just use Firefox with uBlock Origin, Cookie AutoDelete, etc etc.
If you want to buy advertising online you're probably gonna end up dealing with them either directly or indirectly.
Audio feature detection isn't even a novel techique.
I've seen trackers look at download stream patterns to detect whether or not BBR congestion control is used, I have seen mouse latency based on the difference between mouse ups and downs in double clocks and I have seen speed-of-interaction checks in mouse movements.
Just checking for the constructor of something an ad might legitimately use (like audio) is relatively benign to be honest and it is naive to expect ads to not do this and it is why I use an ad blocker even on sites without annoying ads
See also the recent decision to allow animated banner ads on various Stack Exchange network sites.
The fact that even people of a big site like stack overflow don’t know where it comes from instantly, is only further proof that using an adblocker is a resonable decision.
Maybe it is naive, but all ads should be in my eyes is a picture and something that counts the page views. And when you are a site that has ads as it’s main income you should have at minimum one employee who knows and tests each ad before it gets accepted and put onto your server.
Only then your customers will trust the ads you use and only then any reasonable person can even consider deactivating the adblocker for your site.
I am pretty sure somebody explored this idea before me, why doesn’t it work?
It would be interesting to see where we are in ten years.
Savvy users will continue to block on machines that aren’t walled gardens and through pi-hole style blocking.
I think the cat and mouse aspect will be completely overshadowed by tech giants continually neutering their users ability to block ads.
Safari on iOS allows for content blocking, and Firefox for Android allows users to install extensions.
And, I was referring to the future and trends rather than the current situation. System wide ad blocking used to be possible on iOS without jailbreaking, now it’s not.
I expect in time google will go similar and change android APIs, or play store rules, to do similar.
It also works inside apps adopting Safari View Controller.
At the very least, though, eventually advertising agencies will hopefully figure out that this sort of tracking is pointless; "newspaper-style" ads are more likely to actually engage with the people encountering those ads (since said ads would be selected based on the page content rather than the person reading that content). This is how DuckDuckGo's ads work; the sponsored results are selected entirely by the actual search query. If content-driven ads (plus affiliate links, but I somehow doubt that's enough of DDG's traffic to be a deciding factor here) is enough to pay for enough computational power (and the development team to run it) to serve up 30+ million queries a day, then there's no reason it can't be enough for any other site.
Security-wise, I think the best we can hope for is more and more OS-like sandboxing and isolation, capability-based security, and other defense-in-depth measures.
Privacy-wise, for defeating tracking and the like, ideally I'd hope for technical countermeasures to win the battle, but if we do end up having rely on legal measures, they have my full support, GDPR and CCPA included.
(Random idea for a technical countermeasure against fingerprinting: have you heard of those projects trying to defeat behavioral tracking where, whenever you visit a page, it simultaneously opens a bunch of other random pages in the background, hidden from you, and simulates activity on them, the idea being that Facebook has no idea what actual websites you like to visit because it's lost in the noise? What if instead, whenever you visit a page, your browser or a plugin or a proxy or whatever opened the same page simultaneously in a bunch of hidden background windows, with a random configuration of audio enabled/disabled, user agent, screen resolution etc fingerprinted characteristics?)
Indeed it is. It is not, however, dependent on running arbitrary Turing-complete code in my browser automatically and without my permission. Write-once-run-anywhere is perfectly possible and feasible under the traditional "download and install this program and run it" model.
I'm optimistic about WebAssembly (on that note) because of its usefulness beyond the browser; like I described in a different comment, it's only a matter of time before we start seeing GUI-enabled WASM runtimes that allow WASM-modules-as-programs to work as desktop or mobile apps indistinguishable from their native (or kinda-native, in the case of Android) counterparts.
You can't build apps without turing complete code. We would be back to downloading and executing applications/programs.
Sure you can. None of these things should require me to run your arbitrary Turing-complete code in my browser:
* Reading an article
* Writing an article
* Shopping online
* Searching for things online
* Reading social media posts/comments
* Submitting social media posts/comments
* Browsing a code repo
* Submitting issues / PRs / etc. to a code repo
* Reading documentation
That (non-exhaustive) category accounts for a solid 80% of everything I do online (and the other 20% are things which I'd rather be doing through native apps). All of these things should be possible (and indeed are possible) entirely with HTML (and optionally CSS) + a server somewhere handling the backend logic. If they're not, then your "app" is over-engineered, or it is indeed better off as something I explicitly download and install, which brings me to...
> We would be back to downloading and executing applications/programs.
Good. That's the direction the mobile world has already been going for a decade now. Native apps actually integrate with the platform. Web pages don't (or at least don't do so well). At least in that situation I'm explicitly "downloading and executing those applications/programs" by my own choice.
We even have things like WebAssembly now, with experiments and effort toward making it usable as a general-purpose compilation target/runtime outside a web browser. No reason why it'd take more than a decade for someone to figure out how to wire a WebAssembly module into some sort of Qt-based (or whatever) runtime + UI and get the best of both worlds.
I genuinely don't understand this argument at all -- either you understand something about native platforms that I don't, or you're working under the assumption that all of your native apps:
a) aren't already vacuuming your data at the same rate as web apps.
b) wouldn't get considerably worse if they replaced the web ecosystem.
On the first point, native sandboxing is almost universally terrible. There's some promising stuff happening (notably with MacOS and with Flatpak/Wayland) but it's all just playing catch-up to where the web was years ago.
Pick just about any company that maintains both a website and a native version of the same app -- almost universally, the web version is safer to use. Nobody should be installing Facebook, Twitter, or Reddit on their phone. In fact, I would say the single best piece of advice I can give to anyone to improve their privacy/security on their phone is to stop installing things.
On the desktop, the situation is better, mainly because the desktop is very slowly turning into a niche platform and the web is a much more attractive place to put skuzzy, privacy-violating software. But this is a bit like the old argument that MacOS was more secure than Windows because no one was targeting Mac with viruses at the time. Get rid of the web and all of those skuzzy developers you hate aren't going to go away, they're just going to start making native apps. Where, again, the current sandboxing for most users and OSes is completely inadequate.
If your security model on the desktop is, "I'll only run code I trust", you can already do that on the web today. You can already turn off Javascript. And if you don't feel like the modern web-app ecosystem accommodates that decision, then what makes you think a theoretical, purely native world would accommodate you running a small, tight system that only includes code you trust? I can run a beautiful, tight Linux system because I don't have to install much software on it.
The unfortunate, horrible problem, is that running code we don't trust is gonna be necessary, no matter what world we move to. Sandboxing and permission systems are something we are going to have to figure out. Web or not, there is never going to be a world where you'll be able to trust all of the code you run on your computer. And currently, despite the many problems that browsers have, they're still still the best consumer-accessible solution for sandboxing code.
Of course integration and app performance suffers on the web. But frankly, neither of those are more important than sandboxing.
And in the proposed 10 years being discussed here, there's no reason to believe locally-installed applications won't have exceeded browser sandboxing capabilities, let alone caught up.
Meanwhile, the web sandbox is actively deteriorating specifically because frontend developers want to do the things locally-installed applications can do.
> Nobody should be installing Facebook, Twitter, or Reddit on their phone.
Not at the current state of native app deployment, no, but that's improving rapidly and substantially, especially in the mobile space. Also: the vast majority of users are doing that anyway, so it's worth investing the time and energy into being able to sandbox apps without needing an entire HTML + CSS + JS engine/stack to do it (and indeed, both Google and Apple have made significant strides on that front in the last 10 years, though there's certainly still room for improvement).
> The unfortunate, horrible problem, is that running code we don't trust is gonna be necessary, no matter what world we move to.
Yes, but at least with a locally-installed app, I'm explicitly opting into that app existing and running on my device. This on its own will at least somewhat cut down on the amount of untrustworthy code running on my system.
Yes, I can do the same thing for a website's JS code (and indeed do so), but it's asinine that I need Javascript enabled to read a blog post or post to social media or do the myriad number of other things that are theoretically and practically possible with server-side processing exclusively.
> Of course integration and app performance suffers on the web. But frankly, neither of those are more important than sandboxing.
No, but sandboxing - again - is a problem that can (and almost certainly will) be solved within the next decade, at which point integration and performance benefits will make local app installation even more attractive than it already is.
What? Sure there is!
1. The reason to believe native apps' sandboxing won't exceed the browser is that any sandboxing that works on native apps would also work on the browser app itself.
2. There's also 2 reasons to believe native apps' sandboxing may always be inferior to the browser:
(a) The Web has wider reach, and people are already more confident/careless visiting strange websites than downloading and running strange apps, so exploits targeting the Web are more valuable and therefore more resources are spent battle-testing it.
(b) Native apps currently have deeper access to the device which makes it easier for them to do bad things, and (similar to reason 1) will never have less access to the device than the browser app which is also an app.
(I'm aware there's arguably a slight exception here about Mobile Safari and W^X, but I don't think that disproves the overarching reasoning.)
> almost universally, the web version is safer to use. Nobody should be installing Facebook, Twitter, or Reddit on their phone.
Not only is this true, this would be even more true without JavaScript—if those sites were still usable, which they definitely could be, they just choose not to be. (Well, maybe except Facebook Live, but that could be an optional standalone app.)
> you can already do that on the web today. You can already turn off Javascript.
Of course, this isn't really true, precisely because so many websites that could function fine without JS (including things like news sites that should just be static content!) instead choose not to.
Which of course is the real problem with yellowapple's idea. Lots of services cripple their mobile website and push you to install their app instead; if we removed JS from the Web, everyone who could would just start doing the same on desktop too, right? Upstarts trying to maximize growth probably will work great on the Web, but as they get more established they'll start pushing people more and more towards their native apps, and existing established players will do that from Day 1 (of the new, JS-less world), including everyone mentioned so far—Facebook, Twitter, Reddit, GitHub, major news sites, because people will deal with the one-time friction of installing the app in order to access the network or content.
In fact, I almost spat out my Coca Cola, I was so surprised that you would think that.
On the other hand I think that it is the one that blends the best and can even have some value. For example I can imagine that people enjoy a car heist movie more if actual cars that exist are being used as opposed to some made up stuff.
In France there are laws against "accidental" advertising so in news and TV almost any brand will be taped over or blurred. It is actually way more jarring and ugly than just leaving it as it is. It is especially funny when you have the logo of national rail company, which is basically a gradient, blurred.
[0] https://arxiv.org/abs/1412.1897 [1] https://arxiv.org/abs/1710.08864
Personal opinion: Laws are needed to make what advertisers are doing illegal. Advertisers are spying on people to the extent where if the government did it they'd need a warrant.
But when ads block content; include flashing animations, audio, and video; and take up more layout space on a site than the actual content; then people have had enough.
Meaning, if advertisers hadn’t built more and more intrusive ads and had stuck with static ads that don’t severely harm the UX, then I doubt most users would bother with ad blockers.
The advertiser arms race has resulted in a classic tragedy of the commons. That's my diagnosis of the problem. Traditionally regulation is needed to fix that. Exactly what that entails is beyond me.
I think most can agree here this level of spying on users is bad. Its sorta like child labor but a lot less obviously bad, in that it is obviously bad, nobody likes it, but there's enough taking advantage of it not being illegal, so its just socially tolerated thing. But once made illegal it will be looked back on like "how the hell did we think that was okay? how the hell did we willingly let it occur?"
- Chrome is the fast one.
- IE is the one that have to use for some government/old websites.
- Ad Blockers are for safety (akin to anti-virus).
This was from a group that didn’t even know how to install Chrome on the new computers they got this year.
Group knowledge on this topic is largely going to be driven by what they’ve heard in the news or perpetuated by their social circles. And scary things will stick for long after they stop being true.
Unfortunately the water hole has been poisoned, so now I have to block it all.
There is some discussion of the technical cat-and-mouse game he has to play as advertisers try to make their content avoid detection and blend in with the regular programming. In this version of the future, the ad blockers eventually win and network television is destroyed. (The book also features networked computers and email ("telefax"), but the concept of ads appearing on them was still too futuristic for 1985.)
https://books.google.com/books?id=Q6o51-W_z8MC&lpg=PP1&dq=go...
Adnix and Preachnix were the essence of capitalist entrepreneurship, he argued repeatedly. The point of capitalism was supposed to be providing people with alternatives.
"Well, the _absense_ of advertising is an alternative, I told them. There are huge advertising budgets only when there's no difference between the products. If the products really were different, people would buy the one that's better. Advertising teaches people not to trust their judgment. Advertising teaching people to be stupid. A strong country needs smart people. So Adnix is patriotic. The manufacturers can use some of their advertising budgets to improve their products. The consumer will benefit. Magazines and newspapers and direct mail business will boom, and that'll ease the pain in the ad agencies. I don't see what the problem is."
Adnix, much more than the innumerable libel suits against the original commercial networks, led directly to their demise. For a while there was a small army of unemployed advertising executives...
It's clearly always possible to detect whether an ad was seen. Often, the content owners do not bother putting such measures in place, but the advertisers definitely do. (It's even easier from their perspective to check if the ad has been served or not, as many ad blockers prevent the ad from even downloading by sending all requests to that domain into a black hole and so the ad is never even requested from the server.)
I agree that the lobbyists will win. I wish we had politicians with some moral character though.
I love utopian visions of the future.
Kind of like how https://old.reddit.com/r/gaming/ is just a sequence of ads being flawlessly delivered to an ad-averse demographic that eats the ads up.
They've already won.
This issue is cross domain tracking like we see with ad network that profile you over many different sites.
There is no reason these ads should be anything other than a linked image.
e.g. Browsing to an arstechnica.com article, with speakers on but nothing else playing.
Ad URL: https://static.adsafeprotected.com/sca.17.4.95.js
JS Domain: adsafeprotected.com
Domain Owner: Integral Ad Science, Inc[0]
Google's recent stance on the matter of fingerprinting[2]:
>Chrome also announced that it will more aggressively restrict fingerprinting across the web. When a user opts out of third-party tracking, that choice is not an invitation for companies to work around this preference using methods like fingerprinting, which is an opaque tracking technique. Google doesn’t use fingerprinting for ads personalization because it doesn't allow reasonable user control and transparency. Nor do we let others bring fingerprinting data into our advertising products.
The important part being: _Nor do we let others bring fingerprinting data into our advertising products._
The same company advertises their fingerprinting capabilities:
>Browser and Device Analysis: We analyze the technological fingerprints of browsers and devices in order to uncover bots fraudulently posing as human users. We can validate what type of mobile or desktop device a browser is running on, providing additional context with which to identify fraud.
And it is this fingerprinting that gets them selected as a Google Brand Safety and Viewability Preferred Measurement Partner[1]
>New York, NY – Integral Ad Science (IAS) has been selected as a preferred partner in Google’s Measurement Program for both brand safety and viewability. Partners were selected after meeting rigorous standards for accuracy and using reliable methodologies to measure KPIs that matter for marketers. The program is designed to make it easier for advertisers to source trusted, third-party measurement providers.
The gist of it being that Google has heavy cognitive dissonance, with their advertising wing rewarding partners that fingerprint users (against their own policies), and the Chrome team barely managing to introduce some anti-fingerprint measures, which are clearly not enough.
[0]: https://integralads.com/capabilities/ad-fraud/
[1]: https://integralads.com/news/google-selects-ias-brand-safety...
[2]: https://blog.google/products/ads/transparency-choice-and-con...
Perhaps, but I think some of that behavior only appears dissonant. Like the NSA, Google often uses carefully constructed language that is designed to sound like a statement about a topic of concern without saying anything actually useful. For example:
> Google doesn’t use fingerprinting for ads personalization
The only reason to add "...for ads personalization" is if they are using fingerprinting for for other purposes. This could include other ad-related purposes like attribution.
Google claims about not using specific data for a specific purpose are probsabl7 true. They simply fingerprint (and probably correlate) everything else.
If you don’t use an ad blocker you should consider your computer compromised.
Honestly, how are still allowed to execute javascript at all?! I get it if the ad-manager still executed javascript, but how is it okay to let random 3rd parties run js on your website?
This would get rid of the greasy ads, and Google could focus on making tools that allow site owners to filter by "features used in ad", and ad developers could actually return to delivering ads, rather than collecting fingerprints?
They already invented that: https://github.com/google/caja
"Caja uses an object-capability security model to allow for a wide range of flexible security policies, so that your website can effectively control what embedded third party code can do with user data."
If so, what kind of rates can I get?
Eh, that's like 10x average CPM nowadays. And advertisers usually are paying per click, not impression.
1) Measured by analyzing the traffic I got from Google Ads 2) That's what I get from Google ads as a publisher, but you used to get a lot more in the epoch, like $5-10 CPM
This practice could stop tomorrow if the best and brightest of us decided so.
I'm not so sure that education would help either, it's my impression that ethics is just individually set. Of the people that understand Kant's categorical imperative, some will act accordingly and others will ignore their knowledge because doing so gets them more money.
integralads is guilty of developing and selling this technology. Microsoft is guilty of buying it and using it Google is guilty of serving it. And why not also StackOverflow is guilty of offering that space to advertisers without enough vetoing of their ads.
After reading about integralads I'm not even sure if the purpose is to fingerprint, it seems to be more targeted towards detecting fraud, which does not require fingerprinting necessarily.
My point is that it's not as easy as pointing to one company and blaming them. This is a problem that concerns anyone on the Ad space.
Kind of makes sense why companies like Google and Facebook have invested so much in creating open-source front-end frameworks. The ROI is probably phenomenal.
I get that stackoverflow isn't an SPA, it just made me think of this point.
Side-note: you can block JS on stackoverflow and still view answers. That works for 98% of my usecase for the site.
... Then I move on. Those dorky little crapware widgets are basically never worth looking at in any case, and I do take that sort of strategic tooling decision as a signal that I probably don't want to accept the 'bargain' being offered.
[1]: https://meta.stackexchange.com/questions/329763/were-testing...
It's not ironic at all if you think about it a bit.
>>annoyingly aggressive,
Volunteer labor from nerds who expect you to match their idea of perfection
>> ad moderation is annoyingly permissive
Done by employees so it costs SO money.
https://meta.stackexchange.com/questions/329763/were-testing...
which is being prominently announced in a yellow "featured on Meta" box you can read:
"If you see any ads that are inappropriate or have any questions about this experiment, please let me know by starting a new question and tagging it with advertising"
and
"If you wish to report an advertisement, please take a screenshot of the ad and paste the URL (if possible) along with the site where you saw it to a comment or answer. I'll report it to the ads team and we can track it down to investigate."
Screenshots? Start a new question with a tag? Track it down? Shouldn't you cut to the chase and have a "report this ad" button built-in so you can immediately be alerted to malware/abusive/inappropriate ads? Perhaps it's not moderators who have the power here. As a non-moderator/employee I couldn't care less what you call the people who do it; it seems entirely inadequate. Run the ads now and if enough people complain or it gets embarrassing - like google and/or microsoft spying on users - then publish a theatrical apology. No, that doesn't work for me.
No, my ad-blocker is never coming off.
The most likely use-case here is ad fraud detection anyway.
I'm not so sure. There's a lot of market value in knowing that User 2341423 went to Site A, then Site B, then bought this item, etc.
We need a real alternative - without stupid ads and master-slave karma-based community relations.
They can track me through websites and I don't want that. Already using ublock origin.
I don't have enough info to quantify the amount of data blocked though.
I have a tweet in my timeline which illustrate this: https://twitter.com/gorhill/status/934474012377444352
How does uBlock calculate the "blocked since install" percentage?
This encapsulates the entire problem with the current state of digital advertising in 1 simple sentence.
Sure, SO is easier than parsing a forum thread, but the actual value that I care about is the answers provided for free by their users. I could easily return to 90's era usenet, it wasn't as convenient but it worked. What I couldn't deal with is a lack of a platform where people ask technical questions & get answers, I remember being on dial-up and reading paper manuals that were out-of-date/incomplete. But SO isn't irreplaceable, and I am oftentimes frustrated with finding questions closed for incorrect reasons, normally my answer is buried 2 links deep in SO because my DDG search (and Google too) takes me to an improperly closed question where the 'previously addressed' question is adjacent to my query.
StackOverflow does not provide an irreplaceable service; like github they do some nice things but there isn't any reason they must be the dominant platform. And the real value is in the answers, which SO gets for free.
I'm sure you could return to the old internet, but many billions of other internet users enjoy the content they consume for free. Use your adblocker and stick with paywall/subscription sites because we're unlikely to ever go back to a pre-commercial internet.
As far as a non-commercial internet goes... well, we can always hope. We just have to wrangle the means of content production and control (heh, heh, see what I did there?). The resources are there to do that and have a free (both as in beer and in freedom) and high-quality internet, what we are missing is... attention of the masses, the most expensive thing.
Yes, most people would not be "fine" if they lost their googles and youtubes and stack overflows. But then in a few weeks or maaaybe months they'd get over it, because none of these "free" services are in any way essential. Paid alternatives will pop up where needed.
And paid alternatives have been tried for decades (ExpertsExchange if you want a specific example here). It's not a revolutionary idea, it just doesn't work for most content.
How large reputable sites trust third party ad servers is a mystery to me.
Besides, native ads that could be served from StackOverFlows own servers would be harder to block.
Then there's layers of targeting, accountability, measurement, and insurance that gets requested and bought from anti-fraud, brand-safety and verification vendors. That's likely where this fingerprinting came script came from.
Going to individual agencies with your own different supply path is not going to get any attention and nobody is going to change the way they buy millions in advertising just for you. No single publisher has that much power these days, not even Stackoverflow.
Advertising at big companies is the only space left for traditional sales teams and it's all outsourced to agencies. Adtech vendors and publishers sell to these agencies, not the client (and if they do, its just redirected) but there aren't any long-term deals because everything is constantly shifting. Agencies have lots of teams, they win and lose accounts, work on multiple campaign initiatives and strategies with constantly changing budgets and requirements, and use dozens of vendors to create and execute campaigns.
This is the opposite of a traditional SaaS contract sold for a term directly to the people that will be using it. There's also a steady trend towards all inventory being traded programmatically which will eliminate most of the sales negotiations. Unique inventory and formats can still stand out but they also cost more in effort and money so there's less overall demand. It's very hard to scale custom sales like that, especially if one of your requirements is to avoid all the javascript verification, brand-safety and measurement.
Most media sales these days is more about biz dev to get the pipes connected to exchanges and represent your inventory in the best way possible while letting the market work.
There are private marketplaces and other deals you can work out with agencies but this is usually for inventory against existing campaign RFPs, and comes with all of the typical creative requirements. They're not going to run an entirely custom campaign under your own terms and restrictions, not at any sustainable scale.
There are private marketplaces and "automated guaranteed" deals to isolate their inventory in its representation and pricing from the rest of the market but the actual campaigns they get exposure to, and the creatives delivered, aren't special to them.
https://www.stackoverflowbusiness.com/advertising
They do sell job postings and have sponsored tags so it's not all network ad revenue, but that's a minority of the income. Since they released their Q/A SaaS product now, maybe they’ll shift to selling that as the primary revenue stream.
Is SO smaller business? Possible... just surprised.
He also sells three ad spots on his mostly weekly podcast for $6000 each. He’s a one man business grossing over 1 million a year without a sales team.
It doesn't just scale up linearly and getting to $10M is magnitudes more work, especially if they're going to place their own requirements on campaigns and creatives. Even buzzfeed went back to programmatic ads with layoffs because their custom articles didn't sustain the business.
1) He has a sales person that sells ads on his podcast: http://neat.fm
2) Extrapolating from published rates is not very reliable. Nobody except John Gruber and his accountant knows how many sponsors really pay the sticker price.
In my mind major respected operation like SO should have an easier job. I interpreted OP to imply "nobody is big enough to run bespoke ads".
I guess I don't have metrics for it and my impression that's clearly a more reliable investment of one's advertising dollars is a mistaken one :-/
I suspect there's a demand problem: while a bigger site might be better at gaining the attention of those buying non-network ads, there may not be a sufficient volume that is even considering buying ads in that market to support a larger site, and changing that takes either more or bigger sites than even SO.
Does it? If native ads were blocked less, couldn't these units reach more eyes than RTB trash?
Liquidity becomes an issue, which is why Reddit is a good example. They also use adzerk and built their own custom self-serve ad network but they make very little money compared to similar traffic using standard programmatic demand.
Companies basically have to advertise, and they'll buy time with whatever outlet serves the eyes they want to reach. Ford Motors isn't gonna let MyPillow.com take over ESPN.com on Super Bowl day just because they don't like the advertising provider, method, or architecture.
It's very hard to scale and again there are networks and agencies that aggregate channels for most campaigns and buyers. Anyway, Stackoverflow isn't producing their own content and the pricing mechanics of Youtube/video advertising is very different than display ads so this isn't really comparable.
At that point I'd expect sites like Stack Overflow to point out that they have a specific of way of running their sites as well - and that shouldn't include having ads execute arbitary javascript.
While those requirements would certainly exclude a significant number of ad agencies, I can't imagine that there aren't enough advertisers left that would happily play by Stack Overflow's rules to reach a rather large and specific target audience with (likely) disposable income.
I appreciate you trying to fight the argument that's being made, and you have a background for a valid opinion people are dismissing.
That being said, I'm on the buying end and work a lot of different channels, and would argue that there are definitely direct buy models that SO could utilise.
Lots of smaller sites have started offering direct buy inventory in larger quantities recently, and pretty much every media package I've bought this year has had some internally served display with it. I'd expect this to work its way upwards, and would fully expect something self serve to come soon for internal buys.
Also, SO seems prime for a self-serve product akin to AdWords, Reddit, or even Facebook. We already buy on those channels (even though through an agency, the agency is just buying self-serve on their end - and they put their insurance, tracking and ASBOF & TI on the cost).
That's be a really cool project actually, self-serve ad platform for a forum/knowledge base.
I covered it in other comments but yes, SO could start their own self-serve ads like Reddit (since they both use adzerk). The problem with that ends up being lower quality ads and the inevitable support costs, and the fact that they don't have unique formats other than banners. Reddit, Quora, Pinterest, and others have custom formats but it's definitely something they can pursue.
Separately, in your opinion, what sort of stack should a publisher consider if they want to be privacy-friendly? Obviously if certain values are left out of the bid request, fill RPMs will suffer, but that may be acceptable for some publishers as the cost of striking a better balance between privacy and ad revenue.
I realize there's a lot to unpack, but feel free to get technical with me, I'm on both the buy and sell side.
If you have that volume, then the first step is to create private marketplace deals (with deal ids) and negotiate with all the big agencies and trading desks. It's mostly about getting the right intros and meetings but is good outcomes for both sides and is easy to maintain.
Privacy-friendly is a whole different game though and the industry is not ready. Everyone is still focused on cookies even though we're rapidly getting to 50% of impressions not having them at all (or having no persistent ones). One option is running your own adserver (several that you can buy on the market) to control the endpoints (reduce adblocking and cookie loss) but that doesn't really affect the bid requests and creatives as you say. It's really just fixing the final layer and it's also a lot of work for most pub dev teams. Hard for anyone but big sites that can dedicate enough resources to a self-serve system and back it up with a sales team.
The long-term solution is working with and upgrading RTB to handle privacy compliance. This is a new project that my team has started called Privolta [1] which is a privacy-first ad server and SSP that removes all PII and identifying marks in a bid request while still allowing buyers to maintain frequency caps and aggregated targeting. The biggest challenges are in working with DSPs to clear a supply path and also monitoring and modifying creatives safely so no tracking data is collected while the ad is rendered. Happy to discuss more if you're interested, let me know.
Yep, direct buy with the site, I'm in a niche with a lot of sector specific media - some mix it with other inventory (so I guess serving it as bespoke through a standard DSP), and some only have direct bought. We also buy a lot through standard platforms too for reach and retargeting, but I've noted a marked increase in the last year-18months of sites offering it directly (often at competitive rates).
> Also it seems like you're in the UK, is that right? Aren't the privacy laws having a major effect on the programmatic market there?
Not massively to be fair, the market has just consolidated a bit more - so large scale buys are going more and more through Google (as the industry trusts them to either know their stuff or pay the fines if they get caught). Perhaps the rise of sites offering it is as a result, thinking they can offer a more privacy conscious option, but my assumption is that they're just trying to offer a more niche offering with closer alignment between content and ads (and trying to slowly push CPMs up - which is somewhat fair, my CTRs are higher on direct bought vs prospecting ads).
> SO could start their own self-serve ads
I think that's why other commenters have been getting agro, the fact is they could do it, and they have some very useful 1st party data to make it quite a compelling offering, but they're relying on all our old tools. I'd like to see them get the revenue in and then build it out.
Techies expect the world to bend over backwards because they make money. A decent chunk of that is basically funded by ads.
That being said, techies—unlike admen—are still builders and the people who build the shit will always ultimately have the clout. It’s just a question of using the clout effectively.
I don’t just mean Silicon Valley/West Coast.
The big gap is in licensure and education. You can get a high paying job in tech starting with a GED if you play your cards right. That is because demand is so high, and the field has zero professional standards (in the sense of an actual profession with an actual organizing body, like nursing or medicine or engineering, etc.). The latter part is important. There may be lots of demand for nursing, etc., but real professional organizations do not lower their standards in order to accommodate demand.
Two things will happen this century. First, there will be many, many more people who know how to build basic systems (Web applications, etc.). Second, people will have a much better understanding of the risks involved in software development, which are now still mostly abstract to the public (but this is already changing). Once those risks become apparent, there will be an attendant demand for actual professionalization (standards bodies, licenses, codes of ethics, etc.). There will be greater regulation and classification of software development as a profession (i.e., you might not need a license for some kinds of work, but for other kinds, you will have strict licensing). This will drive up the compensation of (credentialed) developers to the level of doctors and engineers, but will also create many more barriers to entry in the process.
I'm curious what you think the world wide demographics of SO are.
If we're adults, lets also acknowledge that this relationship between me and SO is not really symmetrical and that forcing me as a user to accept privacy invading ads has a hint of blackmail in it. This is not about supporting the site's content. If they would introduce a paid service that lets me have the exact same site, but without ads, I would sign up in a second. Hell, my employer would likely want to foot the bill, so they wouldn't even have to be modest with their pricing.
Why is this not an option, I ask you. Why keep sites like this insisting on their surveillance model?
> and appreciate that they are actually trying to solve this issue.
It's very hard not to be cynical about this. They care about their image. I'm not convinced that they care about my feelings. They is absolutely no evidence for that.
And then do that and then suddenly users think it's not worth the money for reason X and they tank. It has happened many times before and few companies can pull that off when their products were established as free.
Any ad that fingerprints and tracks users is not "passive".
And they certainly do contribute a massive amount of value to our community -- and as far as I can tell, they've always tried their very best to be good folks.
I'm not going to tell you how to think, but they have built up a lot of trust and goodwill in my book over the past decade.
I believe them when they say they'll work hard to do the right thing.
I've been playing around with ideas about more ethical analytics and advertising, and I think they're pretty easily built platforms. But the question is are they marketable? Would GloboCorp and MarketingCo give up the ability to track consumers so closely in favor of a more ethical approach, or has it been too valuable for them to give up?
I run NoScript with all JS blocked by default and only whitelist the domains I want. On most sites you can get by with no JS or just scripts from the same domain whitelisted. Maybe a CDN from time to time
Mind you that I am only running NoScript and not a "real" adblocker. Show me ads in a static image and I'm fine with that. Selfhost the ads on your own domain and you are also going to get whitelisted.
I mainly do it for cases like this where Stackoverflow has enabled an ad network that is pushing code to all of their users that is doing some weird things (like querying/opening audio devices) and stackoverflow is not even aware that it is doing that. What if it was a cryptominer?
Well, this is easy to exploit. Use an URL under my domain and proxy to the ad server. JavaScript is a problem. Simple as that.
I'm not fully up to date with how these things are usually set up - is there anything in the web security model that prevents "ads" from exfiltrating arbitrary information from any page that they're on? Could an ad read my keystrokes, or scrape private messages?
Doesn't stop them fingerprinting the browser though
I know Mozilla made an anti-fingerprinting announcement recently but IIRC all it does is check scripts against a blacklist: https://blog.mozilla.org/futurereleases/2019/04/09/protectio...