Photos and Video Taken Inside Illegal Click Farms (2018)
core77.com
core77.com
It's shady as shit, don't get me wrong, but why illegal? It's like the old "enter as often" type of games. The rules were followed, but the "spirit" of the rules was not.
https://www.presstv.com/DetailFr/2017/06/13/525171/Thailand-...
So nothing about the farm, they just didn't pay their bribes.
I dont know, but I doubt intention to buy is the deciding factor. I would think that it becomes illegal when you are misrepresenting traffic to an advertiser. Especially if its a pay per click contract, and the group doing the clicking is acting on behalf of the company getting paid.
GP says "Click without intend to buy" -- Wow, that sounds like mis clicks could be a CRIME!
I cannot be too bothered with people gaming the sleazy business that advertising is.
Intent can surely make something a crime, that wouldn't be punishable otherwise. Giving someone with a peanut allergy something with peanuts in it is not a crime, unless you knew they had the allergy and intended to hurt them. In some states it's illegal to intentionally expose someone to HIV, but it wouldnt be illegal to expose them if you didn't know you had it. If you slip and fall at a store you can likely sue for damages, but it would be a crime if you intended to do it.
I cannot be too bothered with people gaming the sleazy business that advertising is.
Yeah, I don't feel bad for any of the players involved in that world.
I hire you to browse around my site clicking on ads to generate revenue for me -> crime.
If the ad networks care is another story. They make money either way on the short term :)
It might be pedantic to point that out... but intent matters.
[0] https://addons.mozilla.org/en-US/firefox/addon/adnauseam/
That would be when the company doing the clicking is profiting off of it, which in this case they are.
1. You create an AdWords account or something where you can be paid to put ads on your site.
2. You have tons of employees with different devices, probably on a range of VPNs or tor circuits.
3. They click ads on your site over and over and over again.
Just a hunch. I know this sort of thing is strictly forbidden in Google's terms and can certainly be considered fraudulent depending on who's asking.
Whether it's actually illegal or not is another matter, and depends on circumstances and jurisdiction.
Is it to defraud someone out of a marketing fee by pretending that your adverts are creating more engagement than they actually are?
Then that's fraud, isn't it?
The law looks at how a reasonable person would interpret what you are doing and what your intent is. It doesn't work on a 'clicking adverts without intending to buy is illegal' basis. So many people here misunderstand that.
In western common law practice, sure. But elsewhere?
The host presumably has some kind of contract they agreed to in exchange for getting ads and getting paid.
But if you're the same party displaying the ads, or working for them, then yes - you're intentionally defrauding the ad company.
It’s fraud.
Fraud goes all the way from simple operations where actual people in countries like India or Bangladesh are physically clicking on ads to sophisticated operations where bots generate human like traffic which is mixed with genuine traffic to avoid detection.
Did you have any experience dealing with residential proxy networks? If so, can you give some examples of any mitigations to inbound requests from those connections?
Also, we refrained from calling it fraud, the term was invalid traffic. This also accounted for things like someone double tapping on an ad instead of once, and so on. There is a good report by Alexander Tuzhilin [1] commissioned by Google when they were sued for charging for invalid traffic that might give you some more ideas.
I was curious, when you say block traffic, would you send 400s or silently just not record the crucial events? It seems like maybe tipping off automation would cause them to readjust. Perhaps they are not that determined?
Things such as a single device ID sending hundreds of requests in a minute or blacklisted IPs would be just dropped silently, no point in even wasting bandwidth to show an ad. For cuts of traffic where the clicks etc were outside of predetermined ranges, it would again be blocked and dropped. In other cases, where fraud happened before we could block it, there was a flag called 'billable' which was set to False so the advertiser wasn't charged for it.
Who were the fraud operators affiliated with / what was their incentive? Isn’t it the publishers that would see value, or perhaps a competitor trying to disrupt marketing efforts?
Do you see opportunity for innovation in traffic validation? Have you seen much in the way of training ML for this purpose?
At least Android provides a public API to measure trustworthiness, but if you are in the business of selling clicks you may also be in the business of turning a blind eye to fraudulent activity that makes you money.
At first I assumed it was conservative enough to fly under the radar. However, now that this network is so big, the pattern of this fraudulent behavior must be unmistakable. It is so simple.
The only conclusion I can draw is that the network is well aware of these bots, and so long as they don't draw negative attention, they are actually boosting "engagement" as the likes / follows do cause events that trigger people into revisiting the product--and ultimately reaching goals.
A 4 core i7 CPU + 32GB of RAM will run 4-8 Android machines, maybe a couple more. You can get 10 Android phones for ~$700.
Especially since you can acquire "barely working" phones. Broken camera? Not a problem. Broken audio jack? No worries. Cracked screen? Meh. No battery life? Doesn't matter one bit.
I imagine it's pretty easy to acquire hundreds of barely working phone for cheap if you don't care about using them as a traditional mobile device.
Can buy a used MacBook Air, sell the lcd assembly and keyboard/trackpad and already recover a big chunk of the cost. (If you needed an Apple device).
What year do you live in? These days even i3s come with 4 cores.
Just ignore the "i7" part if it confuses you. I've not had a desktop in over a decade, so I'm talking about mobile chips 90% of the time.
Check out Correlium https://corellium.com/
They operate in a sort of legal grey-area since you're not 'supposed' to emulate iOS so if you decide to use it, keep in mind it could all be shut down at a moments notice.
https://www.washingtonpost.com/technology/2020/12/29/apple-c...
Better wages in those countries would likely eliminate fraud like this. It's essentially an arbitrage opportunity to buy first-world denominated "attention currency" at third world click farm worker attention prices.
Also, if you can make a couple hundred a month. Then with just that info alone, there’s nothing but equivalent phones, an IP address, and bandwidth stopping you from doing that amount again.
I understand how this breaks ToS, but how was this illegal?
Of course, the police then thought they were running call center scams (which are illegal there) until they came clean about the operation.
The reason they were in Thailand is that there's less scrutiny there on SIM cards and low smartphone fees. Ultimately, though, KYC requirements do exist on Thai pre-paid plans (post-paid plans are effectively user-tied anyway) so they also got hit by the smuggling SIMs charge.
Ultimately, lots of illegal stuff going on. Just not where you'd expect.
https://www.bangkokpost.com/thailand/general/1272351/nbtc-al...
Why else do you think they were doing it? They just really like clicking things?
App developers can also achieve higher number of clicks by incentivizing users to click on ads by e.g., offering an extra life in a game if you click. This can drive up the click thru rate at the expense of lowering the rate of post click events. This is usually not allowed by advertisers but sometimes they are okay with it.
Also, not everyone minds some fraud. VC driven companies may only care about clicks or new user sign ups, regardless of how good the users are because that's the metric they are targeting.
That could bite them in the ass further down the road, when these bot farms are exposed by researchers. There was a few well researched bot farms on Twitter that are now defunct as Twitter dismantled them and now forces you to use a phone number to register an account, limiting attempts by people who want to create sockpuppet armies.
I always find it surprising how little small illicit operations usually make. At the high end this is only barely more than the US minimum wage (between three people). Amazing for where they live, but awful in the grand scheme of things.
Discussion on the Thailand one: https://news.ycombinator.com/item?id=14549291
Footage/discussion from another one: https://news.ycombinator.com/item?id=14430816
Video of one in 2019: https://news.ycombinator.com/item?id=20525356
And further news discussion from around that time: https://news.ycombinator.com/item?id=20488838