Google will require proof of identity from all advertisers
nytimes.com
nytimes.com
Wouldn't a some kind of certified bank card be an even better proof of corporate identity than a copy of someones ID?
IDs needs to be verified against articles of incorporation. For larger companies it will definitely be a hassle to get the CFO to submit their proof of identity for a purchase that is normally delegated way down in the organisation.
https://www.blog.google/products/ads/advertiser-identity-ver...
The document states that you have to show that you are an authorized representative of the company. I am not that familiar with US law, but in many countries that means one of the signatories of the company, usually someone like the CEO or the CFO.
My point is that it makes sense that you are able to show that you have the right to act on the company's behalf in this matter. I just think that since the company trusts you with it's credit card and there already are systems in place to authorize expenditures, it would be logical to tie the proof that you represent the company to the card in this case.
How long until we see people signing up for Google ads using someone else's passport, W9 and what not?
This won't last very long.
Or you could just use Edward Snowden's passport, or any of the other thousands of people's IDs that have been compromised.
https://www.theverge.com/2014/2/24/5441386/ethical-hacking-o...
I suggested using corporate credit cards instead since there are already security mechanisms in place to handle those.
But it obviously require some form of trust in the entity you are interacting with.
Don’t wanna use ID? No problem - sign additional tokens a bit like ssl certificate chain works.
I'm really glad they're finally doing this, but it still feels way too irresponsibly late considering the amount of damage they've caused.
But contrary to popular opinion, tech companies are not a branch of the police force. So they have no obligation to help the police prosecute people without a warrant.
FTFY. They may not have a legal obligation to help prevent or prosecute crimes, but there is definitely a moral obligation to not knowingly allow your product to become an easy accessory to crime. Lots of tech companies abdicate that moral responsibility.
The technology definitely exists to limit this, and many car companies already offer such safety features.
lol so a tiny crypto exchange can req. ID docs but a huge trillion dollar company will take years>
In addition to needing to verify orders of magnitude more entities, google likely has many layers of both human and technical abstraction to deal with.
Google already had a "Verify your local business" option, I wonder if this data was integrated into AdWords accounts as well. https://support.google.com/business/answer/7107242?hl=en It seems like this data should already be on file and verified if you are business advertising with AdWords.
Hell if they were to try to codify such requirements it may not even survive the supreme court.
Not making an airtight detailed argument, but I feel like you must be misguided because your tone suggests that a massive societal upheaval is necessary for the sort of controls we already take for granted in certain areas.
And they were clearly sending these out in waves, I wouldn't be surprised if the project took 3-5 years from "Oops, we aren't doing enough KYC and our parent bank just got hit with another multi-billion dollar fine" to completion.
I'm only half joking. If parts of the process can be outsourced in a responsible manner, I can't see why Google wouldn't.
In turn, it makes efforts to police fraud more effective, because the cost each time a fraudulent actor's credentials are burned higher.
For every single HTTPS transaction (and there may be dozens involved in even fairly mundane seeming activities) the browser is able to compare the SAN dnsName (or rarely ipAddress) to the host named in the HTTPS URL. It does this unblinkingly every single time, and if it fails then (in the best case) the transaction just fails entirely or (in the less good legacy case) there's some sort of "Oops, something bad happened, don't trust this" behaviour.
But whereas SAN dnsNames and ipAddresses are something a machine can compare to the host in a URL, the EV identity is something only humans have opinions about and humans don't want to make dozens of such decisions when they click on a funny video of a cat.
Is it OK that this funny cat video is from "Alphabet Inc." ? How about "XXVI Holdings Inc." ? Why is that OK but "Funny Cat Videos Ltd." isn't? How about "You Tube" of Austin, Texas, is that OK? How do I know? More importantly why is it suddenly my problem when the computer was previously able to get this stuff right?
One of the most obvious things to do if you suppose that well, any fool can get the DV certificate for realbank.example but that's fine because only the Real Bank can get an EV certificate for Real Bank and that'll protect you is this:
Mallory gets an account with Real Bank and watches protocol flow. They don't care about most actions but are very interested in login timing. Mallory obtains one of these certs for realbank.example but for an organisation name they control like "Mallory Inc."
Now Mallory MITMs a valuable customer of Real Bank. During login they passively pass back and forth every step until the POST where the customer's password and OTP code are supplied. For that POST Mallory interposes supplying that Mallory Inc. certificate. The browser has no idea what "Real Bank" is but it can see this is a realbank.example certificate, so that's fine, the password and OTP code are delivered to Mallory.
Probably this works seamlessly, and Mallory steals the customer's money with no evidence of how it happened.
BUT if the customer was really trying hard to obey this crazy "Check EV because that's secure" they will see this - but only when their page renders, which is after their password and OTP code were delivered to Mallory.
They get to excitedly tell their bank that they've detected a successful attack - after it worked. If they're lucky the bank might even give them the money back, but probably not because it looks exactly like they're committing fraud.
Security based solely on automation will continue to fail and lead to exploit after exploit because it ignores the human factor, despite that being the primary place security breaks down. It's refreshing to see proof of identity requirements finally coming to ads, and hopefully it will lead to a change in understanding, that PKI is also useless without EV.
The honest truth that people seem to fail to understand is that security doesn't scale. The more you scale, the worse your security is, and that will always continue to be true. The more manual, the more humans required in a process, the safer it will be.
Security based on the automation works really well. How well? Google drove phishing of its employees to zero. Not just technical employees like my friends, but random sales people and other non-tech roles, because they were mandated to use Google's security that relies on automation and not a vague human judgement. They don't need to know why it's safer, they don't need to pay attention in a class, the automation doesn't care why they aren't supposed to give their Google credentials to "Oogle" or "Goggle" or "Gøøgle" it's just designed to not work when things don't match.
I'm not a Google employee, I'm just a user, let's walk through what happens to see how automation saves us every single time, resolutely and without fail.
I visit google.com which is really Google and I sign in. I am prompted to press the button on my Security Key (a physical object). Since I'm at google.com the Key will present credentials for google.com proving I've still got that key to google.com
Later I am fooled (maybe by a malicious ad) into visiting a site that is not google.com but I think it is, my adversary is very sophisticated and resourceful. The site looks 100% the same as the real one, but of course this is not google.com. It might be anything else except google.com, but for the sake of clarity let's say it's crooks.example
I try to sign in. The crooks have two options:
1. They claim to be google.com, which they aren't, the automation rejects this and they get an error, if they like they can present me with the error, but neither of us can do anything with it except say "Huh, that's an error".
2. They admit they are crooks.example, which is true. The Key happily gives them credentials for crooks.example, because that's who they are. But these credentials are useless for attacking my Google account, why did they bother getting them?
Notice there's no human judgement involved. This system is equally happy to present credentials to nazi-scumbags.example or cat-videos.example. But what it refuses to do is give the nazi-scumbags.example credentials to cat-videos.example or vice versa no matter how much the user is convinced it's fine. There's no "Are you sure?" dialog, there is no "Press OK to proceed" step, it just does not work.
An insistence that we should just add more humans, like at Southall, is simply motivated reasoning, and has no basis in the observed facts. Automation works. You should resort to human judgement when automation isn't an option, it should never be your first choice.
It's funny Google solved the problem so well for itself, despite it's utter inability to do it for others. The challenge is preventing phishing of Google employees is a single domain problem. Google knows everything about Google.
But Google woefully fails to have a solution that even starts to work for consumer Gmail or other companies they export their services to. My Gmail account got a phishing email today from Google Forms about a transaction. Google didn't understand it was spam, it came straight from Google, but it was definitely a scam.
Another great example is Google Voice, the source of 9 out of every 10 spam calls I receive. I could write a single line filter that would block all of the spam calls: I'd block all calls from my Google Voice number's own area code (which is different from my own real area code). But Google doesn't give me the tools to do that, it uses it's own automated system, fails spectacularly, and my spam calls continue. Automation has failed because one competent human wasn't allowed or empowered to act.
Automation can get things right 95% of the time, but will never understand the other 5%. And the big problem is, Google refuses to adopt human judgment: It insists automation is good enough, and rarely allows you to reach a human at all, even in an appeals process. When Google's automation decides to cut you out of their system, when it fails to judge correctly, you're just gone, often with no recourse.
Security Theater, just like everything.
and here I am with my GPU's heating my apartment with Deep Fake scripts to pass Binance Fake-YC after buying FULLZ off of Empire when I could just be paying people in the tents outside of the ground floor apartments.
I always felt like I was getting out of touch after the guy was passing out 'Elitest Tech Scum' collectible pins at Zeitgeist, but I thought it was just ironic until this very moment.
It would be an obvious self-serving thing to say, for anyone opposed to similar regulation in other industries, but is it true?
Saying a system isn't perfect isn't the same as saying it has little effect overall.
If the banking system wasn't well controlled, why would people complain so bitterly and frequently about the effect of sanctions?
In the past few years we've seen bad actors basically automate their process. They expect to be banned. They spin up an account, run scams and malware, get blacklisted, rinse and repeat with a new domain, account, and just enough changes to beat the automated filters within an hour later.
What this does is add a ton of friction to that game. It doesn't even have to be perfect to make a huge difference, it just needs to be difficult to rotate at scale.
Why does anyone need to know who paid for all advertising?
But it's not just about you. Speech, however it gets categorized, affects people and influences society. You can still say what you want (to the extent allowed by ad platform rules and legal limits on commercial speech) but you should also be accountable for what you say.
It’s a feature of a society
Society can set rules on how it’s used. And it pushes “unspoken ones” constantly.
There are exactly zero laws of physics that dictate the mathematical shape of our finance system. It’s all human negotiated grift to funnel the value of effort at scale into ephemeral objects we fetishize collectively
Like sky wizards
This isn’t sitting in a room talking to your friends about whatever you want
Anyone can still do that
Politically, free speech to me is emitting whatever syntax I want, and not obliging others to any discoverable semantic meaning they find, and having the same returned
Too often free speech = I’m owed being who I want 24/7 in all contexts
That’s a gross over simplification. Such a life is impossible to achieve without society picking up a whole lot of burden
And really to regurgitate your last line: why do you care how private entities choose to do business?
Therefore, a harm reduction justification is insufficient as it presumes there is some benefit worth the harms being introduced. In fact, there is no benefit and Google is only reducing harm slightly.
That's not a fact, that's your opinion. Advertising is a form of communication and like most communication, the person originating the communication often has a goal or desired outcome in mind. That you or me might not like their goals or the message that they communicate doesn't mean that no one finds it valuable, nor does it mean that we should ban all communication.
So what? It's still "an attempt to psychologically manipulate the public". Advertising is adversarial, it's fundamentally bullshit.
Leela : Didn't you have ads in the 21st century?"
Fry : Well sure, but not in our dreams. Only on TV and radio, and in magazines, and movies, and at ball games... and on buses and milk cartons and t-shirts, and bananas and written on the sky. But not in dreams, no siree.
How is that "a socially beneficial activity"?
So does a persuasive essay, but I don't see any calls for bans for those.
So is what you just wrote. Should we ban discussion on HN because it is (or can be) adversarial?
Advertising on the other hand is one-sided. If there was a universal ad platform where people could vote on ads (where overly negative feedback would get the ad taken down) and comment below them then it wouldn’t be that much of a problem.
Finally HN is something you choose to participate in in your own time. Advertising doesn’t give you a choice on whether you want to see it.
Most ad platforms allow anyone to submit an add. Most add platforms are moderated.
> Advertising doesn’t give you a choice on whether you want to see it.
Of course it does. When I'm reading a book I don't see advertisements. They aren't beamed into my brain, they're the price of admission for certain services I gain value from
I can submit another ad but I can't make it appear right below the previous ad I would like to "comment" on.
> Most add platforms are moderated
What about fake technical support numbers, or the variety of scams/quack products on Facebook that make impossible claims and prey on the vulnerable/stupid?
> When I'm reading a book I don't see advertisements
When I take public transport I see ads regardless. Same applies to a lot of services that are near-essential nowadays. Certain government agencies sell your details to spam operations (also a certain form of advertising) and you can't opt out. Most commercial products include spyware which track you and rat you out to ad platforms regardless of whether you even see any ads directly.
Also with a restaurant sign there's a business behind it with someone that can be held accountable for it. If you see an obvious scam or a fraudulent service advertised you can complain to them or the authorities and get it shut down. With online ads they can be purchased either completely anonymously (maybe even with a stolen credit card) or by a shell company somewhere on the other side of the world where you would have no recourse.
Most ad groups have regulations on what ads can and cannot do.
> With online ads they can be purchased either completely anonymously (maybe even with a stolen credit card) or by a shell company somewhere on the other side of the world where you would have no recourse.
Check the thread you're in. It's about an ad network addressing this specific problem.
How do you explain Facebook ads for scams that claim price X but actually hammer your payment cards with multiple X * 10 charges until it declines? A friend got caught by that, we ended up doing a chargeback but Facebook didn't get punished in any way despite their complicity in this fraud.
How do you explain tech support scam ads?
How do you explain "chumboxes" like Outbrain/Taboola as in here: https://www.theawl.com/2015/06/a-complete-taxonomy-of-intern... (the image URLs are broken, you need to manually get the image's URLs, change the protocol to HTTPS and open the resulting link to see them).
Maybe some ad groups have internal regulations, but I as a user have no control of which ad networks I'm exposed to. On the other hand, in the street, all businesses have to comply with local laws and given that I don't see scam tech support banners or credit card scams advertised on storefronts I guess the laws are working, and if they aren't, laws can be amended if there's enough public support for it (some locations completely banned billboards for example).
> Check the thread you're in. It's about an ad network addressing this specific problem.
"Google will suspend the accounts of advertisers that do not provide proof of identity, including W9 forms, passports and other personal identification and business incorporation files"
Seems like a pretty low bar to clear with either forged documents (again, someone already breaking the law with scam or spam ads isn't going to be deterred by this), paying vulnerable people in a slum for scans of their passports or just using a string of shell companies to muddy the trail.
I'll also note that you're now no longer arguing that advertisements are unethical, but that online advertisements are unethical, and not because they're "an attempt to psychologically manipulate the public" as was originally stated, or even because, as you originally claimed "Advertising doesn’t give you a choice on whether you want to see it."
We've moved the goalposts quite a bit. And I'm not interested in an in the weeds argument about the challenges of online fraud prevention. It won't be fruitful for anyone. I've proven my original point: you don't line online advertisements (and that's OK!), but you also don't have a clear reason that they're uniquely different than any other form of advertising, and you don't believe that advertising, in general, is unethical.
> In the mid-twentieth century, courts applying the antitrust laws held that such persuasive advertising is anticompetitive and harmful to consumers, but the Federal Trade Commission (FTC) was unable to pursue an antitrust campaign against persuasive advertising for fear of de-priving consumers of advertising’s information value. Now that the information function of most advertising is obsolete, the FTC should renew its campaign against persuasive advertising by treating all advertising beyond the minimum required to ensure that product information is available to online searchers as monopolization in violation of section 2 of the Sherman Act.
~ "The Obsolescence of Advertising in the Information Age" https://www.yalelawjournal.org/article/the-obsolescence-of-a... https://news.ycombinator.com/item?id=22991286