Letting ads run arbitrary JS is the policy, right? It's not like that's a requirement to make the internet work, that's just a Google policy that trades money for user experience.
Letting ads run arbitrary JS is the policy, right? It's not like that's a requirement to make the internet work, that's just a Google policy that trades money for user experience.
I mean, anything on the Web can run arbitrary JS. The entire point is that it's a sandbox environment where arbitrary JS can't do any harm (excluding cases where vulnerabilities are found).
If you're not comfortable with arbitrary JS running on your computer, you'd have to either (a) not use the Web, (b) disable JavaScript, or (c) only visit sites which you have vetted and deem to be trustworthy. None of those are particularly practicable.
Most of us operate on the generally-reasonable assumption that the sandbox is effective, and therefore that we're OK to [click on that random link from HN like you did just now / open that news site which pulls in a bunch of tracking scripts / etc].
Either way, this is not somehow a problem that's specific to Google Ad Manager in any way at all. I don't know what else you could really expect of them.
> I don't know what else you could really expect of them.
Your option C is basically how it must work, and mostly does. To be safe online we go to sites we trust. When Google delivers malicious JS through ads, the site operator probably doesn't know Google has harmed the user on their behalf, so their trustworthiness becomes moot. Is there some "safe ads" codeless option for site operators who want to protect their users while still showing ads? Has Google made site operators aware they occasionally deliver malicious JS to users?
I'm fairly confident in saying that nobody, but nobody, only goes to sites they trust. Come on. You're on HN: do you mean to tell me that you never click to open a link from a post unless you've pre-vetted the website and know it to be trustworthy? That's simply not a practicable model.
And every site pulls in JavaScript which, to you, is arbitrary. You don't know that they won't add a new third-party script, and you don't know that any given third-party script won't change. You don't know that transitively for the scripts loaded by the scripts. Etc etc etc. Nobody can practise the approach you are setting out here, not both diligently and honestly.
Your complaint here is just about how the internet works. It's absurd to expect Google to vet the JavaScript that all of its users host, as much as it's absurd to expect Squarespace or Weebly or even AWS or Cloudflare to do the same. The model of the internet does not and cannot rely on any and all JavaScript being vetted for 'malice' by a trusted party before being loaded. It relies on the JavaScript runtime being a safely isolated sandbox where malice or the lack thereof doesn't matter either way.
A bunch of us were working on a project where ads would be fully declarative, and so no longer able to run arbitrary JavaScript, but this received very little interest outside of Google (advertisers didn't want to move to a new format, publishers didn't care) and we moved on.
(Still speaking only for myself)
Twitch shows that people are very willing to pay for content. I'd very much be happy to if that removed all of the spam.
And for sure, I appreciate being able to buy stuff online. But I seem to be able to do that without viewing ads! Amazing!
No offense but I've heard people who work at ad companies repeat this like a mantra, and it's a false dichotomy, akin to a coal company who dumps slag in rivers saying, "Well we think it's better than letting everyone freeze to death." We're not asking Google to stop advertising altogether and close up shop, just to make the internet ad ecosystem a little less awful and Orwellian.
I think my parent was: "No one needs ads. Not arbitrary JS ads, not declarative ads, not personalised ads, not any ads."
I agree with you. I spent a large part of 2018-2019 trying to make ads declarative, and am now working on (among other things) increasing the isolation of conventional ads [1] and implementing cross-site advertising without cross-site identity leakage [2].
But it sounds like you and my parent have very different views: there's a lot of space between "ads should be a lot better" and "ads should not exist".
Not my money. Why should I care about lawsuits between advertising networks and their advertisers, regulators and so on?
You don't need to. But the person is asking why Google is or is not doing a particular thing. So it is their interests that are relevant to the current discussion, not yours.