The NSA and CIA use ad blockers
vice.com
vice.com
It's almost always not the big sites that have malware in their ads, but the shadier parts of the Internet --- which people may inevitably need to visit at some point, even deliberately.
I wouldn't be surprised if they started recommending you whitelist JS next. That would be really "disruptive to the internet as we know it" --- and might actually make things better overall, as in returning to static text/image ads and pressuring sites that have no business being a SPA to go back to static content. Of course, I suspect the huge company whose name begins with G would not like that at all and will try its hardest to fight against it.
No way in hell I'd recommend this to anyone who isn't tech aware though.
It seems like server-side, dynamically generated static content would have at least been explored more than it seemingly has.
I always assumed this was what Google was always trying to eventually get to with AMP.
In the current model they have last second auctions with the ad going to the highest bidder. It's hard to reliably screen them in that kind of situation. I find it quite scary to have someone not very tech smart download software without an ad blocker - you get one proper download link and about 10 ads saying download here linking to malware.
Admittedly, this means you need an army of ad moderators, but that's not a hard problem. Social media giants already use an army of underpaid moderators for moderating their platforms, so seems like it's just table stakes for running a platform. Screening ads should be a cakewalk compared to moderating social media.
Google Adsense is not always the highest-paying option for a given impression
There are entire companies that do nothing but figure out quietly, without the publisher's having to do anything, what will pay most at a given moment
I had already edited my post to change "DoubleClick" to "Google Adwords" and I got the product name wrong!
In fact, they do. Creative review is part of most ad platforms. Contextual categorization isn't possible without knowing what the ad is about (and the content it's going to), to various degree.
That would prevent not only most exploits (especially once you re-encode the images), but also simple badly written ads that drive up CPU usage. But it's easier, and allows more middlemen, to simply allow the next party to hand you arbitrary code that may or may not be put into an iframe that may or may not be sandboxed.
As a developer in a corporate environment? I'm always downloading, installing, etc...
Non-tech smart users? It's hard enough on some sites that your average cybersecurity researcher with a decade of experience is going to have a hard time!
The last piece of software I occasionally visited sourceforge to get was WinScp, and actual SSH on windows means I no longer need to do that (I was only ever using because it was the easiest way to do it given no CLI option). 15-20 years ago quite a bit was on there though. It was the proto GitHub which wasn't in any position to respond when GitHub came to prominence.
Sales: We cannot change our processes, Bro! I mean Mr. CEO you don't want to lose money do you.
CEO: I like money. IT go see HR for your mandatory teambuilding course for harassment of the sales teams.
Sales: Thanks for taking care of that sir. See ya at the club tonight.
Maybe so. And maybe I'm all right with that. The ad-supported internet has turned into the ad-on-every-square-inch internet. We get lots of great content for free, but the amount of ads are overwhelming, distracting, annoying, and eventually disgusting. (Not necessarily the content of the ads, just the volume.)
Back to security: We have come to the place where really interesting content that asks you to turn off your ad blocker is now a phishing vector.
Ad providers? You mean Google which provides the majority of the ads. I’m really surprised Google hasn’t done more here when major security companies are recommending denying Google their primary source of revenue.
I have used Google Ads, and think the ads themselves are quite secure; I am less certain about the advertiser websites (though it seems Google does some sort of link-testing/screening). What are you suggesting Google has failed to do?
I think the problems with ad security are on smaller platforms/networks which are willing to host less-secure ads, and I'm not sure what Google could do about them.
That's what I call this: reading an advocation FOR ads. Ads being great and wonderful instead of -- at best -- a necessary evil.
It's solid policy. The problem with ads in this regard is really that they allow random strangers to run code on your machine. That's never a good security practice.
If an evildoer with a browser 0-day wants to target me, without an ad blocker any of a thousand companies can pay a few cents to have their javascript served to me. If I run an adblocker, there are a lot fewer ways to get their code in front of me.
A statistical argument, in other words - that being exposed to code from 10 vendors is safer than being exposed to code from 1000 vendors.
Browsing sites at work is a frequent reminder of why I block ads at home.
Besides that it also makes for a more pleasant experience and saves resources too.
Never looked back.
If the local newspaper has a local ad in a local website, the ad blocker will probably not pick it up :-P
Yeah auctioning your ad space in milliseconds is cool and maximum profit. I don't care.
-- Douglas Adams
It turns out that sarcasm is sometimes not obvious to everyone. My apologies.
You are correct. They cannot be trusted. The entire history of advertising and advertisers is evidence that they cannot be trusted. They cannot be trusted to self-regulate, to follow voluntary codes, or even to form an industry regulating body (sorry, UK, you know it's true).
And yes, Google is an advertising agency... which spends up to $20MM a year on federal lobbying.
The ad industry had the opportunity and the ability to address this problem, but (for short-term reasons) they decided not to. This is the long-term result. They did this to themselves, and now they deserve to suffer the consequences, up to and including a fiery death for the industry as a whole.
Nordstrom, etc. don't need to suffer as a result of this, they can simply observe the online ad industry and make a decision about when to stop using it -- perhaps in favor of something new and different, or perhaps not. Print ads still work just fine.
The Times, etc. charge for access, are happy to sign you up via web form, but then force you to call them if you want to cancel. As far as I'm concerned, they shouldn't be running online ads at all anymore. If ad blocking becoming prevalent hurts them, too fucking bad.
Online ads is snakeoil
There's also the question around whether the levels of fraud mean companies buying targeted ads are ever getting what they paid for [3] - Uber cut $120m of $150m ad spend without any impact on installs (which is what they were trying to drive)
[1] https://www.theregister.com/2020/07/03/stop_tracking_increas...
[2] https://digiday.com/media/gumgumtest-new-york-times-gdpr-cut...
[3] https://indica.medium.com/how-uber-discovered-that-80-of-its...
> Online ads is snakeoil
No doubt in my mind. I helped start a webshop in 2009 and got to see it first hand:
We used a service called Kelkoo and according to their dashboard almost every customer we had came through them.
We were suspicious so we cut them out for a couple of weeks.
Turned out sales hardly dropped at all.
We had good luck with Google ads back then but I don't for a second think Google doesn't happily fleece advertisers:
As I've said a number of times before I have been targeted for scammy dating site ads for a decade, more specifically from around the time I started dating my wife and until our youngest was about a year old.
Google knows fairly well I'm a conservative Christian who has had no problem getting a date the usual way, but has had no issues showing me these ads, probably because they pay most pr impression.
This was back when I felt I owed site owners to not enable adblock all the time so I tried a number of times to report the ads as irrelevant. Problem is, when I reported Polish girls as irrelevant, the next ads was for Ukrainian girls, then Thai girls, Chinese girls, Taiwanese girls, Filipino girls and I don't know what else until it went full circle and started on Polish girls again.
Not a bad word about people from those countries, but I was already married and Google know very well since I look for family holidays, toys and food ideas for families with kids.
Point is it seems that relevancy doesn't count anything now that advertisers pay for impressions instead of clicks.
>...I was already married and Google know very well since I look for family holidays, toys and food ideas for families with kids.
It's interesting you describe Google as "knowing" information about you. Google may have the data, but a human did not read it to develop some understanding of who you are as person. They just ran it through some software based on the targeting criteria they have.
I would guess that advertisers didn't set their ads to exclude married men who are Christian with children, just because that's a very specific profile to care about--they might just set it to target men of any age and be done with it. Or it's possible that married, Christian men with children are one of the most profitable targets for scammy dating sites, and either the site creator or the targeting software are going after them specifically.
Nobody wanted to target a well paid dev with small kids and holiday plans except the cheapest of the cheap?
The explanations I find more likely is either
- my account got grouped up with a demographic 14 years ago when I worked in an environment that certainly did have those kinds of signals and that signal was too strong.
- scammy dating sites like expensive credit cards pay extremely well and Googled fudged their data to make me fit the criteria.
The idea of targeted/effective/meaningful ads and taking as much as you can in advertising dollars from a customer are fundamentally at odds with each other.
The gist of it was - they accidentally disabled digital advertising for a few months and found that disabling it had no effect on the metrics they were tracking.
For example, any old-people products would greatly benefit from the typical inability of the old to install ad-blockers in the first place (nothing against the old, of course).
As a conjecture, it's possible that online ads is anti-commerce - as in those who put money into it die. Over the last 10 years, it's very obvious that internet focused non-tech companies do very poorly in the long run.
However, if you want to cannibalize an industry's profit margins to squeeze in front of your competitors advertising in many forms will remain productive. I think we almost need a cartel-like system that says "Okay video card manufactures - enough with the advertising... nobody impulse buys video cards so each sale you gain through advertising is just coming from one of the other company's pockets (or your own)."
Check your state and local laws. It is illegal in California. If they have the means to provide signing up for service via online, they are required to provides the same way for cancellation under California law.
Change your address to California and you should see a section to cancel your subscription.
No, they decided to become the security risk and monetize it. They are inexorably linked to the problem.
I’m not in an ad industry.
So now she runs ad blockers galore and pihole across all devices. So far no porn ads in her email.
And no I did not ask if any of her browsing behavior would lead to such ads. She's a tiny old blonde Christian lady that...wait also a church donation site gave her porn ads too. Maybe I should avoid checking her history.
So yes, do enforce ad blocking on your network, if able. It will save a few calls and probably embarrassment as well.
The problem is this: ads are basically browser-injection-as-a-service, as in injecting code into websites of your choice, targeting audiences of your choice. Browsers mitigate this problem somewhat by sandboxing cross-site stuff in the webpage, and ad networks theoretically scan the payloads for malware like miners, but those tests aren't hard to work around. So ads can basically run whatever they want within the little aperture of an iframe that they get.
If there's a zero-day like the Internet Explorer JPEG renderer zero-day (https://www.kb.cert.org/vuls/id/965206), then the ad networks are basically broadly targeted zero-day-as-a-service.
Ad blockers aren't a bad first line of defense for this.
Excellent description!!
It is exactly what they do, and directly implies the failure and remedy modes.
Many websites used to just run ads that were directly negotiated and paid for by the company. eg: Plenty of Fish used to do that and they sold for $575M .
When I left reddit, for the longest time I still didn't run Adblock because as a shareholder it still felt hypocritical.
But a few years ago I couldn't take it anymore -- the web go so awful with ads on it became unusable. And so I relented and went full Adblock. And life got a lot better.
(I did however whitelist reddit and a few other sites that I like whose ads are bearable)
The guardian has a supporter tier. Some local news stations where I live have memberships with minor benefits.
Yes, it did.
I have subscribed (and might still be subscribed) to several news magazines and papers, though not my local. It's kind a circular drain of "lower pay > lower quality > fewer subscribers > lower pay".
Now I block ads and trackers with great zeal. Google's most of all. Surveillance capitalism is bad for almost everyone. Advertising is a mind virus.
is best for mobile
What do you meany "use". It's totally unusable even with full adblock
This is what I use.
Moreover, just because you're not capable of perfectly adhering to a set of principles doesn't mean that it's not worth trying. "Oh, I know that I'm not going to be able to uphold every single commitment I make, so I'm not going to worry about upholding any of them."
The thing about pointing out hypocrisy is that you're actually lending authority to the person you criticize, you're saying that you believe in the side he's revealed to actually support.
Reddit shadowbanned my account sitewide. That's enough reason for me to never, ever view Reddit without an adblock.
What's especially puzzling is that FB allows image uploads as an ad response unless the advertiser was smart enough to disable it.
Also it appears Twitter does it as well - so many promoted tweets are just roasted in the replies.
It's vexing.
Is that the case ? We (rsync.net) used to advertise on reddit quite a bit and we would have sponsored posts that had a proper comment thread and Q&A, etc. - I thought it was fantastic.
So this is not even an option anymore ?
I like how some websites e.g. news websites, put up a message that they depend on ad revenue and ask for adblockers to be disabled, I did it for some websites where I like the content, but then I also feel I am perhaps very unlikely to click on any of the ads (at some level I suppose my mind has learned how to focus on the content and ignore the ad space e.g. on google search I remember I had developed a habit of scrolling down and ignoring the first few ad results without actually consciously doing it). So, considering I am way less likely to click on an ad, perhaps I am not actually hurting the business, or maybe actually helping improve conversion if I can go that far :)..
All of the little guys like me who tried to run a Goggle Ads and Microsoft Ads campaign know that we can spend a few thousands dollars without a single impact on sales.
Then the salesman from Google calls you and tells you it’s because you’re doing it wrong. Try such and such keywords. Link to your payment button to see your ratios! Try to optimize for CTR and EWQ and ASDF (not the strange proximity between those ideas and random letters on a keyword). It must be you. It must be YOU!
The business is to make the business owner believe as long as possible that it will work.
To be scrupulously fair, the business is to make store owners believe that they are getting exposure, regardless of whether they actually get sales. Much like snake oil salemen, it's prefectly fine (nice, even) if the patient improves; that just means a chance to sell them more and 'better' snake oil ("brand maintainence", I think they call it) later.
I use adblock every fucking day. The internet is simply unusable without one.
https://yewtu.be/watch?v=hn1VxaMEjRU
And advertising is marching under the rat's anus banner.
I say mods should be either full employees or volunteers, you can't mix between the two.
I am a firm believer that there are ways to do ads in a manner that respects the end user, is not obnoxious as well, and isn't privacy invasive. And this applies to both buy and sell sides of the industry.
But much of the space is garbage and in some cases malicious, so I block ads with a prejudice, run NoScript on Firefox on desktop and mobile, etc. It's a PITA, but a better experience overall.
It is a bit amusing to watch the changes Reddit is making to "improve the user experience" though, when to people in the industry, it seems like fairly transparently telegraphing development of surfaces for new ad placements or signal collection for targeting models.
What pisses me off is Reddit leadership can't seem to just be transparent about it.
Only a matter of time before applications begin to roll their own encrypted forms of DNS in order to circumvent ad blockers.
DNS filtering and blocking is a very powerful tool great for bypassing many features/pitfalls of the internet.
I do this; no machine other than my 2 DNS servers are permitted to make outbound DNS requests (they are transparently handled by my LAN DNS).
The real annoying change is the transition to DNS over HTTPS. The canary domain[1] is useful but apps are obviously free to ignore it.
[1]: https://support.mozilla.org/en-US/kb/canary-domain-use-appli...
I've seen it as high as 73%.
So, while I use an adblock list with my unbound caching DNS server, it only works with devices which honor the local network DNS settings, which are becoming fewer and fewer thanks to the efforts of the major players to _HELP_ everyone with DOH. A protocol without an easy way to MITM/filter the requests even when the user wants it.
I co-develop a FOSS DNS + Firewall for Android that prevents apps from doing their own DNS over HTTPS / TLS / QUIC by blocking all connections to IPs that the DNS client (embed within the firewall) hasn't resolved itself or the TTL of whatever answer it once resolved has expired. Something similar to this could and should be implemented by other firewalls, too. The result of such a blanket setting is devastating though, as some apps (like Telegram) refuse to do plain-old DNS and hence refuse to connect at all (so, one may have to selectively allowlist certain IPs / apps). This also has a happy side-effect (or annoying side-effect, depending on how one looks at it) of breaking apps connecting to static IP endpoints (ex: Orbot connecting to Tor bridges).
I think it's currently this:
https://raw.githubusercontent.com/StevenBlack/hosts/master/h...
I run my own resolver (unbound) that I point all of my networks/devices to.
That resolver has, as its upstream, my nextdns.io account address. nextdns has the pihole/ublock lists built-in.
So you get to run your own DNS server, you don't have to implement any of the blocking yourself, and you just point your upstream to the address you get when you sign up.
I'm quite happy with this setup ...
Plus (getting back to the topic at hand), having adblock for all your devices is so ... pleasant. You forgot how jarring and upsetting (and LOUD) advertisements are. Having them puncture your DNS adblock while using Chromecast is like getting a wet slap in the face.
I expect there are probably umpteen different ways to block ads with a little digging, although I can't vouch for any as I don't have a Chromecast (or TV) myself.
FWIW, a while back I reached my eye-twitch limit with Raid: Shadow Legends (deeply impressioning irritating ads: ...why...?), and so I stared at YouTube's load process to try and figure out if I could viably block everything.
The technique I ended up using exploited the fact I was running within a Chrome extension and overloaded JSON.parse (lmao), and was specific to the HTML delivered for desktop, but has worked for months.
I reckon it's quite possible the data sent to Chromecasts is similar enough that you could viably block it by MITMing the device then rewriting the JSON (or possibly gRPC) responses being sent to it.
Using YouTube Vanced on a no-name Android TV stick might be an alternative. (Untested but should presumably/theoretically work.)
This won't prevent OPs concern with apps doing DNS over HTTPS, would it?
> No way to bypass the DNS at that point via the firewall.
Some apps do not even do DNS and connect to static IPv4s and IPv6s straight-away. Even if IPv4 is limited, plenty IPv6 to go around than an ip-table can handle.
Plus the fringe benefit of blocking malicious domains that may execute code in browsers of course. The real headline is probably - The NSA and CIA Blockers Chunks of the Internet Because the Internet is So Dangerous.
I'll just plug https://useplaintext.email as a great resource. The main recommendations are... opinionated (this site is run by Drew Devault, after all), but the instructions are very useful. I personally use thunderbird.
(al)pine has never done this to me.
27 years and counting ...
On the other, policing, controlling and maintaining healthy markets is a primary government function. When the cops are afraid to look at a market for fear it will interfere with their jobs, that strikes me as a government failure reinforcing a market failure rather than attempting to fix it.
The NSA and CIA are intelligence agencies, not cops. Their mandate is foreign, not domestic (despite not always acting like it).
I think that speaks volumes about the security of advertising online.
Nowadays, I use Safari with Ghostery lite and Adblock Plus. I won't go back to web without a blocker.
Isn't it about time we change the financial model of the internet? Or should we just let humanity suffer through this non-value adding ritual?
Personally I've never bought anything directly because of web ads. I understand that some people do and that some people find them beneficial. But I believe the cons outweigh the pros this time.
I don't claim to have a solution, but it annoys me when we all agree that something sucks yet do nothing about it.
You definitely want to block Google Backdoor™, a/k/a Tag Manager, which allows ad vendors to inject Javascript onto the pages of others. This is a known attack vector.[1]
It seems to me that the latter type open up a vast new attack surface. These addons have full access to every piece of data flowing through a logged-in webpage. All your Gmail, all your bank, all your Hacker News.
How am I supposed to believe that these addons are themselves not sources of malware and vulnerability? They need to have the same standard of transparency and testing and supply chain security as the browser itself.
I’m willing to believe that Mozilla and Google and Apple will not willingly introduce vulnerabilities into their browsers, but the vendor of BlockUrAdsPlus or whatever? No way.
The adblocker publisher went rogue, and he started getting porn popups. I don't know if they got hacked, or if that was the plan all along.
My thinking of 'deny all' is something like facebook where everyone seems to like to embed little bits into their pages. But I used to also use facebook. So if I made it work for one I would accidently make it work when I did not want it to on external sites.
I have been using it like this for so long I hardly even notice it anymore though. But that is just me. If I give this sort of solution to anyone I usually just give them an adblocker. That gets most of the silly things.
HN is one of my main news sources and due to its link submission nature I frequently visit sites I have never visited before. It seems like 90 percent of submissions need at least one round of whitelisting just to see the text content. And frequently a second or third round to get embedded code snippets or other relevant content to load.
It's tiring and I noticed that I frequently just give up and copy paste the url into an alternative browser without blockers.
I run PiHole in a GCP container for my wife and I to WireGuard into… am I running “wide scale blocking” in my network?
https://www.techdirt.com/articles/20160111/05574633295/forbe...
Professionals use ad blockers for obvious reasons.
Not sure how todays safety is in that regard.
Any site you visit could be compromised, but since the only 100% safe course of action is to completely disconnect from the web, blocking the most obvious vectors entirely seems appropriate. Of course, not only are ad networks vectors for malware, they don’t even serve a useful purpose to you that might justify the risk.
Browsers have gotten better and updates have gotten much faster, so less of that is drive by virus infections by exploiting the browser, but there's still cases of "Pick some users that you think are (a) real users and (b) naive enough" and serve them a exe download that contains a virus.
I had one user that was hitting tech support scams monthly. He would go to Google, search for Amazon, then click the first link on the page (which always had the little Ad word next to it).
For a project that didn't directly make money (there are some 'cloud' offerings now), Safe Browsing probably was a very high return on investment.
I know that's incredibly naive, and simple wish fulfillment, but damn the ad industry has made the web into a nightmare. I'm tired of playing the game of trying to decide which domains I need to temporarily allow to see the content they put out there for free without being tracked across the web. I'd rather go back to the "Punch the Monkey" days of online advertising.
Edit: or 3, use a metric for campaign success which doesn't rely on knowing how many impressions your ad got
raspberry pi-hole at home, brave browser, adblock youtube, ublock origin, modified hosts file on my computers.
Skip
"Please use the original title, unless it is misleading or linkbait"