Can ads on a page read my password?
security.stackexchange.com
security.stackexchange.com
IMO (and this is really deep into opinion) this has slowly been contributing to the lack of attention spans and un-inquisitive response most people have when things on facebook just straight out tell lies. Web-advertising has such a feeble value for the cost it's exacting.
DemDex "captures behavioral data on behalf of Websites and advertisers and stores it in a 'behavioral data bank.'"
uMatrix blocks it for me, but this shit could harvest banking credentials??
It's not that it happens or could happen, the problem is that when credentials are leaked the user gets all the blame: "not our fault, you probably had a virus on your device", and most users will believe it.
The only unclear thing is the distinction between processor, manager and collection of data. That's because it's narrow in scope.
1) it will not happen, not even Cambridge Analytica did and Facebook plans for more "privacy" took the media, Facebook did nothing or too little and now people think they are safer
2) People will not help making digital security and privacy any better, I can't explain why, but it must come from trully ethical developers
Privacy must be set by default. Ad tech co. have an conflict of interest in this privacy matter and can't lead the way. Developers from ad tech will always truly believe they are doing what's better for users but they just can't for many reasons.
Privacy by default is not a dream, it is not utopia, but it requires another business model. Ads will simple not allow privacy.
My opinion anyway
The biggest majority of Web users do not even realize how this stuff works. I asked one no technical friend what he thought about Google business model, the answer surprised me: they positioned themselves as intermediary on the Web so that most traffic goes through them so that they could serve ads. That's probably not completely incorrect but what regular paps and moms don't know is that web site creators themselves agreed to this deal with the devil and their soul is now completely gone. When no-one, not even the most valuable or knowledgeable customers complain about the gazillions of tracking scripts on the page, there's no way this could get better. For regular people "Privacy" means a few setting that you could change on some conglomerate web site until they rebuild/reset the page so that you'll have to do this all over again.
Far from it:
From https://revenuesandprofits.com/how-google-makes-money/ :
>68.3% of the total, from the advertising over the Google websites
>21.2% of the total, from advertising over the Google Network Member’ websites
I couldn't find a more up-to-date source, but judging from these numbers website creators are responsible for only around a fifth of google's revenue.
Once upon a time it was a similar question if you wanted to run a hobbyist website, you needed a dedicated box somewhere or maybe to fork out 15/mo for some space on a shared host.
Now-a-days that MUD could easily run on the smallest cloud instance you could find with one less server even for a total of 10/mo - if you want to run a blog and tell the world about your intense interest in widget manufacturing there are cheap ways to host it - if the content is standard enough you might even be able to cut down the price to 10-20/yr.
It used to be that if you were so passionate about a topic you thought there needed to be a website about it then... you'd start it and host it yourself, it'd be an incidental cost that you'd just eat - then the mentality shifted to the assumption that your hosting of this thing should be profitable to you - you should get paid for maintaining such a site!
That's the real problem, people expect other people to pay for shit that nobody would pay for - since no one steps up to the "so reasonable" 10/mo subscription then ads are injected to make up for the "loss". If your site isn't valuable enough to get subscribers that doesn't mean it shouldn't exist, it just means that you should put up a donation page and treat any money you get out as an unbelievably strong endorsement of your decision to fund the existence of your little corner of the internet.
We break stories on corruption, injustice, and all kinds of other content. I think that running ads allowing us to do that would constitute as a benefit.
It's not a criticism of you if you can't do that. It's where we need to be. Nobody opted in for all this surveillance. And there does also seem to be a lot of fraud in online advertising. Get everyone's phones and home routers running something like pi-hole and the whole advertising lanscape would change for the better. Google would hate it, sure, but so what? You might find your ads are more valuable too because seeing an ad in a genuine news source as context has more influence on a potential purchaser than seeing the exact same ad on john-does-racist-blog. Even if they are the exact same 2 eyeballs seeing both copies of the same ad.
Ads, sure. We're all basically fine with ads per se. Just not the current advertising arrangements involving reaming us with surveillance and all the other nasties as well. Didn't agree to it, don't want it, will block it and will prosletyse ad blocking.
It's high time to accept responsibility for content you're serving! (As it is, high profile sites often deny any liability for 99% of the traffic they are brokering. The ad-and-tracking inflation of recent years is just insane.)
Speak for yourself. I'm pretty allergic to ads - stopped watching tv, reading newspapers etc. a decade ago. No way I accept ads on the web just because they are in more traditional formats.
But ads on webpages - they're resource sucking privacy invading unvetted proprietary software. If your business requires you run those then you're getting blocked on every device I come into contact with forever.
I promise to stop punching you in the face if you pay me is not something I think is all that great to be honest. And then I'd have to trust them. But yeah, Ars Technica is not what it used to be since being bought by Conde Nast, right?
If the entry to a club was "either be punched in the face, or pay", I bet the majority of patrons would simply pay or go elsewhere. But on the internet, 99% of people either get punched or refuse both options and enter anyway.
The analogy breaks down.
You aren't given the option, you wrote the option that websites and their 3rd party providers have to punch you without your knowledge. Stop reading Ars. Does that help you now you wrote that option? Maybe it does.
Better is to exercise your option to disrupt evil with uMatrix, pi-hole etc. Prosletyse it. The less money there is in the evil, the less it happens. How we defeated popups, for example.
How many people do videos for purposes other than monetization?
Years ago I am sure that some people just wanted to share stuff with the world and get some feedback from like minded individuals.
I’ve paid for news before and they still bloat their pages with ads to track me. It’s not a matter of people not wanting to pay. Customers are willing to pay for X and Y if and when it nets them a positive gain in their experience with a product. The problem is more about how these corporations are constantly making our experiences worse while also still tracking our every click.
The problem is that publishers apparently(!) cannot properly distinguish between ad-driven revenue streams and good/loyal-customer revenue streams. (I don't know why this is even an issue, but here we are.)
Do NOT serve ads to your loyal revenue stream. Even if you can't make ends meet, do NOT do it. That will piss them off to no end, and they're your most loyal readers; they'll leave and never come back.
Think about it from the advertisers’ perspective:
You have a user base with a bunch of people. The ones that paid you to remove ads are, at least on average, wealthier than those that don’t. They certainly have disposable income.
In other words, the people that paid for a subscription are exactly the fraction of the audience the advertiser is paying for access to!
Of course, this argument falls apart for per-user targeted ads when ad blockers are prevalent. However, it makes perfect sense for display ads that are targeted based on content, or audience demographics, such as traditional mass media: tv, radio and newspapers.
In fact, the logic seems to extend to any website that is trying to charge an above-bottom-feeder premium for ad real estate.
I used to be editor-in-chief of my college newspaper. Most of our print ad revenue didn't actually come from direct sales. It came from national agencies that gave us insertion orders. I don't think we could have had a print edition based on our in-house ad sales.
Now imagine this problem for all kinds of other niche websites that can't afford to have their own ad sales teams... Suddenly it becomes clear why outsourcing ads generates a lot of value for cheapskate media consumers and for cash-strapped media organizations.
Fortunately this is no longer possible because of HTTPS, but I was able to convince some big sites to switch to HTTPS because of it.
If you look at the second answer (https://security.stackexchange.com/a/214877/12942) it looks like the GA code Goodreads is using specifically will use http:// instead of https:// if the current page is http-only. So that this would still work. There isn't a good reason to get third-party resources via http if https is available, even on non-https pages.
I spent years browsing the web before there were any advertisements at all. There is no need for this garbage despite how many Stanford grads tell you it's totally necessary.
Because ads make money to all parties except the user.
[1] https://adsense.googleblog.com/2011/06/clarifying-our-ad-imp...
>While SafeFrame shares information with ad content served to its API-enabled iframe, the publisher chooses what to share and can protect sensitive consumer information like personal email addresses, passwords, or even banking information.
Docs for DFP: https://support.google.com/admanager/answer/6023110?hl=en Spec: https://www.iab.com/guidelines/safeframe/
I suppose the whole ban vs regulate issue is a matter of granularity. Regulation does impose a set of banned practices, but it's not like you make it out to be, where all 3rd party code would have to be banned.
The main issue is that we need to agree on what we are actually capable and interested in protecting, in an insanely fast moving industry. This is why motivated and educated policy makers are crucial to the problem. There's still to this day no where near the level of discourse on this subject that's needed happening in places with power to make a difference. Just like in the early days of the gold rush, I'm sure you could find countless cases of criminal shovel sellers.
But given the current ecosystem, this doesn't surprise me sadly. We (in the US) are locking kids up without parents for crimes they didn't commit. I suppose abusive or illegal ads aren't my biggest concern.
Let me just say: I don't know what harebrained regulation would come out of this, but I'm pretty sure I don't want it.
> Elect sane and involved policy makers to keep a watch on the market.
That's not a solution, that's a fantasy scenario.
If this means some services are no longer viable because they can't make ad revenue, then maybe that's a good thing. Nothing is free, and we still live in the Wild West with companies getting away with monetizing our information behind our backs to subsidize the service. It's one thing to "pay" me for the time I watched your ad, it's another thing to "pay" me for a profile of my activity on the site or sites, which has enough information, generally, to uniquely identify me, and contains demographic and personal information determined by black boxes.
My point here might simply be, if it's my information, I should be entitled to know how it's actually being used.
But the first action I'd hoped to see is to make devices like the Amazon echo, and google home illegal.
> Probably the clearest example of a place where there's a reasonable expectation of privacy is in the home. A person doesn't have to be a homeowner for the law to protect that expectation; tenants who rent their homes also have a protected right to privacy. Moreover, invasion of privacy doesn't just mean that someone physically enters a place where a person has a reasonable expectation of privacy. It can also happen if someone uses electronic equipment to monitor or record what someone is doing in the home. [1]
This also goes for guests of your home, so as far as I'm concerned, Amazon (or my friend, or both) are/is breaking the law whenever I enter a home with one of these things installed. The regulation should demand a Amazon (in this example) to explicitly state how they are protecting my rights given the presence of an active microphone in the home. As things stand they are clearly not respecting our privacy.
Even Apple, who makes a point about how "Hey Siri" works isn't completely off the hook. I'd be interested in talking about Japan-esque laws requiring a sound to be played when Siri is activated, much like how a shutter noise must be played when a photo is taken.
The point here is, it's MY LIFE, I should at least know what's being done with it.
1: https://injury.findlaw.com/torts-and-personal-injuries/what-...
In other words, if I defer any part of my services to a third party, I cannot do it anymore. Goodbye payment processing, fraud detection, spam/DDOS protection... the list is endless. Advertising is the least concern here.
See, that's the difficulty with regulation, you need to be very careful what is and isn't included. You don't want to accidentally prohibit crucial services. You don't want to burden business with liabilities by being vague. You don't want to leave too many loopholes or else your regulation does nothing but cause administrative overhead.
If you have so much faith in politicians to do go good job here, by all means, go out and lobby for this kind of regulation. Let's just say I don't share your optimism.
> My point here might simply be, if it's my information, I should be entitled to know how it's actually being used.
If you don't like your information being used for pretty much any purpose, don't give it to me. I can't preconceive of all the possible ways I am going to handle your data. Maybe I want to switch web hosts, or maybe I want to back it up somewhere else. Maybe I'm an idiot and I'll store it on a database with no password, exposed to the internet.
> This also goes for guests of your home...
Not necessarily. Depending on where this takes place, if you enter my home, I don't have to disclose that you're being video or voice monitored. Maybe you don't like it that way, but those are my rights trumping yours.
> I'd be interested in talking about Japan-esque laws requiring a sound to be played when Siri is activated, much like how a shutter noise must be played when a photo is taken.
This is a good example of a pointless law. Sure, the cameras make a "shutter sound" when taking a photo, but they don't make a sound when recording video. When Siri activates, it does make sound, but if you want to activate it by voice, clearly it needs to listen all the time for the keyword (or whatever sounds like the keyword). There's no way around that.
So, what are you going to do, require bright flashing lights on all cameras/microphones?
https://addons.mozilla.org/en-US/firefox/addon/umatrix/
You can combine it with custom CSS through stylus:
It shouldn't be up to users to audit every damn 3rd party url to protect themselves. You went to a single url the publisher of which should be completely responsible both morally and legally for all content. The end.
In other words, shut down all businesses that rely on third party advertisement. Got it.
You are aware the advertising industry was immense before the web existed and there was no such thing as a third party ad? Network television, cable, newspapers, magazines, billboards and so on. There is literally no reason for the internet not to be like that if we want it to be. Massively profitibable for ads. Less bulls&^t surveillance. None ideally. Yeah bad for google. I am entirely happy for google to go bankrupt if they can't make money without surveillance that should be illegal and is immoral and for which they do not have informed consent. If you work there and get fired, I'm only slightly more sorry about that than I am if phillip morris employees get fired as people stop smoking.
You 100% need surveillance in your business model and we shut that down, sure, go bankrupt. Good.
If browsers ban JS in ads, HTML based ads will rise in value.
How are you going to detect what third-party JS is an ad? That's basically the job of an ad blocker. Do you expect Google to ship an ad blocker that blocks ads of its competitors? That'll be a great antitrust lawsuit.
One targeted compromise of any of these scripts would be catastrophic.
Now imagine how many npm dependencies the backend or frontend has. How much do you trust marwahaha, yyx990803, or sokra?
Why did they register such a bizarre domain, that even calls out the exact owner? To avoid blocker-lists for all of 3 seconds? Why not a subdomain, or at least a domain that doesn't look like that?
And blocklist maintainers tend to immediately block root domains I guess. (At least I would if I saw an obscure subdomain from a party I want to block.)
just checked again and seems to be the same.
(also many top N companies do use 3rd party code, like React, but they usually re-host that themselves)
I still get messages along the lines of, "Your hard drive is full. Dropbox cannot synchronize until you free up some disk space," with 4 GB free, even though many users have complained loudly about that for years. The Dropbox client was also causing weird problems with dropdown menus in MS Office applications for a long time, which took forever to track down. That at least appears to have been fixed now, although I can't (or perhaps don't want to) imagine how it happened in the first place.
Dropbox does hard things, HN conventional wisdom notwithstanding, and they do them reasonably well. But they can be very slow to recognize when they're doing something wrong.
The bigger problem is that passwords aren't half the sensitive data on the web, they're just the example people are using because everybody knows they need to be protected.
If you protect the password from the script but it can still read your name and address, and your bank balance, and the private information you thought you were only sending to your spouse, have we actually solved the problem? No.
Twitter, AirBnb, Facebook, Google, Apple...
- Blacklist or whitelist access: <input type=password nojs> or <input type=password allowjs>
- Specifically set a method that is called upon form submission: <input type=password onsubmit=hashPassword> <script>function hashPassword(value){ ... }</script> The catch here is that the browser would have to error out on reassignment of the hashPassword global variable, since that is what malware would do. This sounds easy, but it might be quite a bit more complexity for the browser's JS engine, since it has to check every assignment in the global scope against a list of functions that are used for password fields.
- Only allow access from the code path starting with the form's onsubmit event, so <form onsubmit="return validate(this)">. The catch here is that most modern websites do $("#myform").onsubmit=function(){...} which any malware could do as well, so that would have to be disallowed. A lot of devs wouldn't be happy about that.
Though for backwards compatibility, the opt-in method would probably be the only candidate for actual implementation in the foreseeable future.
As far as I could gather they provided a script to their customers that added event listeners to everything on the DOM and sent it to their servers. As far as I can tell, they were going fast and loose. They weren’t interested in me, but I must say I wasn’t interested in them either.
Almost nobody actually cares about graceful degradation these days.
I find this happens with a lot of news sites. It's hilarious that a website made primarily for displaying text is absolutely defeated by turning off javascript.
NPR text only: https://text.npr.org
And although not news, Facebook has a secret no-Javascript version here: https://mbasic.facebook.com
I think you could quite sanely track a few sites, maybe the top 200 or 300... after that it'd get unwieldy.
And, for fun, on the other side I believe a few years ago google's in house public hosting of jQuery received a bad push and was serving a tainted package for a while... even the good actors can mess this up.
A peer vetting system might work well (like DNS) but it'd need a lot of careful thought.
For less popular sites, the user can add it manually, or the site operator notices their site is broken for increasingly many users and stops linking scripts from other domains.
> And, for fun, on the other side I believe a few years ago google's in house public hosting of jQuery received a bad push and was serving a tainted package for a while... even the good actors can mess this up.
That's an independent problem. You could have the same thing happen for actual first party scripts.
And in this context if they're really good actors then they fix it as soon as it's discovered, and if they're not then you take them off the approved list.
Stealing credentials through third party code is a relatively expensive attack. It has to be engineered for a specific site and then it needs to pass the auditing of the vector (i.e. the ad network, or the developers).
Once the attacker has achieved that, what do they get? The credentials for most sites are worthless. Of course some users might use the same password on multiple sites, but they had it coming.
Those sites that do have valuable credentials also have heightened security measures. If your bank is serving you ads on the login screen, perhaps you should use another bank.
There used to be starting projects which used cryptocurrency or some other token system to allow you to "load" your browser with credits, which then would get auto (or semi-auto) voluntarily distributed to the websites you read, which support this mechanism. But I think they haven't caught on. But essentially, I hope they come back.
In the mean time, I'm still waiting for a reasonable solution to block advertising and tracking scripts on the mobile - as e.g. I think no sane (and informed) person will use a closed source browser, e.g. Brave.
What’s the technical explanation how OAuth is safe in this context? If the DOM is accessible wouldn’t other things be accessible?
Rephrase: how would one make sure it’s protected.
One example: you've probably clicked the "login" (or register) link from a page that does have ads, and a malicious script could've hijacked that click and presented you with a perfect replica of a login (or register) page, and then captured your input. And I'm sure there are many other such tricks.
You will see the ad is rendered in a sandboxed iframe.
It's true that the ad-network can usually run in the context of the main page, but the ad itself cannot.
The ad network is typically fairly trusted - they are profitable businesses with a lot to lose to lawsuits if they store or leak your password.
It's the ad itself that you shouldn't trust - anyone with $1 can submit an ad. And that's why it's sandboxed.
This has been demonstrated to be wrong (see: every time there's malware on an ad network).
The malware has been in an ad creative, and those are sandboxed. The malware has usually exploited weaknesses in the browser, but if there weren't browser exploits, it still wouldn't get access to the host page.
Such browser exploits are getting harder to find with things like per-domain processes isolation in Chromium based browsers.
That said, Javascript(in browser) and Security are basically 100% opposites. If you can execute JS in a browser, you can do whatever you want to that page in the browser.
I don't disagree with your point, but there is another perspective that the mitigations aim to stop, which is cross-tab/window data gathering (and cross process), which is most of the point of Spectre and friends anyways, which is stealing data from some other process, not the process you are running under. Stealing from your own process is easy. Stealing from another process is supposed to be hard, and stealing from the kernel is supposed to be impossible.
Perhaps I overreacted, because at the time, the e-commerce industry didn't seem to care about the risk. Do they now?
I hope OWASP/PCI/GDPR have since developed opinions about third party hosted js on sensitive pages.
But for Goodreads, I'd be hosed as soon as I allowed the site itself:
> In the case of goodreads, their HTML contains javascript from the ad provider. Specifically, lines 81-145 of the HTML document returned by https://www.goodreads.com/ read:
However, it's more or less readable without allowing any scripts. So hey.
So was that a way to work around ad blockers?
They suggest mitigating this by putting ads in a sandboxed iframe (unlikely and probably not foolproof) and not having ads on a login page, but ads can probably still steal your credentials.
It should be obvious that loading untrusted third-party content compromises security, but apparently that is unimportant to sites that use third-party advertising services.