How to destroy a certificate authority in one month
cohost.org
cohost.org
Concerns about Trustcor (70 days ago, 36 comments): https://news.ycombinator.com/item?id=33541718
Mozilla moves to distrust the TrustCor CA (49 days ago, 64 comments): https://news.ycombinator.com/item?id=33813660
Mozilla, Microsoft yank TrustCor's root certificate authority (49 days ago, 354 comments): https://news.ycombinator.com/item?id=33810755
Linux Certificate Authority root stores have a too simple view of 'trust' (44 days ago, 118 comments): https://news.ycombinator.com/item?id=33876949
Being able to partially distrust a Certificate Authority is good (43 days ago, 14 comments): https://news.ycombinator.com/item?id=33890823
One of the key factors in Mozilla's decision was that this supposed operational independence was a lie, because Rachel herself was the Director/VP of Operations for both business units [0]:
> The same individual was responsible for the day to day operation of both TrustCor’s CA business and MsgSafe. They are listed on TrustCor’s website as the VP of TrustCor’s CA operations and the Director of Operations for MsgSafe. [2]
> ...
> [2] Rachel McPherson is listed as the Vice President of Operations, having “access-to and control-over the CA and CA Business Operations” in a company document submitted privately by Rachel to Mozilla. Press releases on TrustCor’s website list Rachel McPherson as MsgSafe.io’s Director of Operations, e.g. https://web.archive.org/web/20221108224150/https://trustcor.....
[0] https://groups.google.com/a/mozilla.org/g/dev-security-polic...
Delisting a CA is a thing you can do. It is a serious thing you can do.
But the internet drama surrounding this, and some posts on the mailing list itself, were overly emotional.
"Ha! We caught you! You damned executive, you!" is not exactly the tone with which I'd want to conduct weighty matters.
It was like looking back into the early-90s, when pitchforks-and-torches-because-we-technically-can were the norm. I don't miss those days, and I'd thought the internet had grown up more.
Apologies in advance for being the no-fun police, but we're talking about destroying a business. Even if it's a shitty business, run by shitty people, trying to do shitty things... just don't fucking dance. https://m.youtube.com/watch?v=0k5aVLi_yhM
There were definitely some people on the mailing list who were less than professional (and of course on Reddit and HN), but the main decision makers were very careful and professional throughout. Rachel is the only one out of the core people involved who lapsed into immaturity.
But by Rachel's fourth reply(?), the response tone seems to shift. Suddenly it's okay for the peanut gallery to snark.
And I get it -- I probably couldn't have resisted a choice remark after being shoveled a load of what read like horsecrap.
But when "I’m not sure how exactly you’re involved in the CA community, do you represent a CA? A browser perhaps? Or any of the governing bodies? [...] Or are you concerned citizen consumers?" is responded to with "I think all of us are easily found via Google", that's less than the gravitas I'd expect.
And I find it fascinating HN cheered this one, when HN's 2nd favorite topic du jour is complaining about how large companies steamroll smaller entities whenever it suits them, without any standard process.
> And I find it fascinating HN cheered this one, when HN's 2nd favorite topic du jour is complaining about how large companies steamroll smaller entities whenever it suits them, without any standard process.
I think the main reason it drew so much attention is because the TrustCor rep made such a scene out of it. Evasion and deflection escalated into ad hominems and conspiracy theories. By the time it hit the HN front page, it was pretty obvious that TrustCor couldn't be trusted, so there wasn't room for any sympathy.
Better to do a happy thing with a smile on your face, and a grim thing with no expression at all.
While you may not like the tone of my comments, was there anything that was factually incorrect? I saw BS answers and called them out.
Specifically as to her question:
>Thank you all for chiming in. I’m not sure how exactly you’re involved in the CA community, do you represent a CA? A browser perhaps? Or any of the governing
I mean... yeah. I've been doing Open Source security since 1998. https://seifried.org/lasg/, https://seclists.org/bugtraq/1998/Apr/. in the last decade I was one the CVE Board (resigned), still on the CWE/CAPEC board, I do the https://opensourcesecuritypodcast.com/ (350+ episodes). I was 1/3 of oss-security mailing traffic for a few years thanks to being "the CVE assigner" and such.
If you look at the rest of the dev-security-policy@mozilla.org list posters it's the same 2-3 dozen people posting for almost a decade (myself included, going back to 2010 or so, I have a spreadsheet somewhere but it's easy enough to confirm).
Again: a CA should be like a bank, well run, regulated, and trustworthy, they should not be toppled over so easily by a group of random Internet volunteers. I would also point out that Microsoft retroactively removed them:
https://groups.google.com/a/mozilla.org/g/dev-security-polic...
so say what you will about my tone, but the facts are the facts.
Also if anyone is interested we're looking at other root CA's, theres a few more that appear to be less then ideal. Heck within the last 3 months we've also had:
SERPRO with MASSIVE problems (assigning certificates to URLs, "Bennar" and so on), they actually withdrew from the process because they need time to clean up their organization. https://groups.google.com/a/ccadb.org/g/public/c/Mux855BsRg4
bjcn.ca with again, spyware concerns and some other potential issues, https://groups.google.com/a/ccadb.org/g/public/c/o9lbCbr92Ug... and there's a nice summary from 2 days ago:
=========================================================================================
Summary of Discussion and Action Items
Discussion Item #1: A concern was raised about BJCA’s Beijing One Pass software, which apparently facilitates client access to a digital portal or platform. It was noted that BJCA had attempted to address suspicions about the software in Comment #15, that the software was needed to support a USB token and to install another certificate chain, and not the two above-referenced roots.
A follow-up question was whether a security report concerning the software would be made publicly available.
BJCA Response to Discussion Item #1: “This report is a communication document between our company and the competent government department, and it is not suitable for disclosure or submission to Mozilla because it involves confidential information. And because the security incident does not involve the certificate chain of the root inclusion case submitted to Mozilla this time, we made a clarification in the Mozilla root inclusion case by disclosing the main points of the report.”
==========================
Discussion Item #2: Two components were also mentioned: wmControl.exe and zfkeymonitor.exe.
BJCA Response to Discussion Item #2: The “suspected spyware behavior indicated in the report was caused by one of the drivers, wmControl.exe. This program is a driver provided by the USB Token manufacturer, Its software behavior is different from spyware and does not have malicious behavior. It is intended to ensure the normal use of this type of [device] in the browser. In addition, the USB Token for digital certificate corresponding to the driver wmControl.exe is an old version device, and its driver has been deleted in the new version of the certificate environment software (version >= 3.6.8)”. Concerning zfkeymonitor.exe, BJCA responded that their software did not include the zfkeymonitor program.
==========================
Discussion Item #3: Clarification was requested about root certificate installation by the One Pass software.
BJCA Response to Discussion Item #3: BJCA reiterated that their software did not attempt to install the two roots, but stated, “in order to improve the user experience, the BJCA certificate environment software chooses to skip user confirmation during the installation process, which may cause doubts for users. At present, we have plans to adopt advanced options in the new version of the software, allowing users to choose whether to confirm the installation, and support users to choose to add certificates and updates to the current user's personal storage instead of the computer's trusted root or trusted third party storage. No doubt that there is an obvious contradiction between convenience and security, which could improve the software security but degrades the user experience and increase our operation costs.”
According to BJCA, it maintains two separate systems:
a global, public-trust system that meets international standards (WebTrust, CA/Browser Forum, etc.) and issues and manages SSL/TLS server certificates; and
a national system that follows Chinese standards and issues and manages personal certificates, enterprise certificates and equipment certificates (e.g., Beijing One Pass software and certificate).
BJCA acknowledges that both systems are under control of the same legal business entity, but for the latter, the software is not part of the global, public-trust system.
BJCA says it “will also refer to the recommendations of experts, learn from the best practices of the public trust system, continue to innovate, practice corporate social responsibility, and strive to build a safe and reliable of cyberspace.”
========================== Conclusion
We thank community members for their review and consideration during this period. Root Store Programs will make final inclusion decisions independently, on their own timelines, and based on each Root Store Member’s inclusion criteria. Further discussion may take place in the independently managed Root Store community forums (i.e., MDSP).
=========================================================================================
If anyone is interested, we're looking into what can be done around the root certificate world, if you're interested feel free to reach out to me at kurt@seifried.org (I'm still in the exploratory phase, e.g. can anything actionable/useful be done, and so on).
So first off -- thank you for spending your time on something critical to the internet! I don't, and so my words/critiques are cheap.
Here's a couple questions I'm honestly curious about, from someone more tuned to the mores and social currents in the groups. And especially now this has fallen off the front page and is less visible.
DISCLAIMER: Neither of the below seem applicable to this situation in question. It definitely seemed the right call, for the right reasons. These are asked about NEXT time.
1) Do you believe the process, as it exists today, is resistant to accusations of bad faith, especially if a few participants are semi-captured into playing along at the onset? (I.e. the "create a lot of smoke and imply there's fire" scenario, perhaps by a commercial competitor with social connections in the group)
2) One of the comments noted that there wasn't a policy for the squishier corporate/organization expectations, which led to subjective judgement calls on whether legal/corporate/ownership structures looked right. Is this accurate? And if so, what are your thoughts on if their lack is a problem or not (including historical situations where it's said this also happened)?
2) As I've said, CA's should be above reproach. A CA involved in any way with spyware has a clear conflict of interest that can (and has) resulted in major security problems for users (e.g. MitM interception).
Also a lot of this gets worse the more you look:
Asking HOW we are supposed to review these documents and confirm that the auditor is indeed a valid auditor, for example results in, well, no answer. Examples:
https://groups.google.com/a/mozilla.org/g/dev-security-polic...
https://groups.google.com/a/mozilla.org/g/dev-security-polic...
On 2, agreed on the above reproach. But defining that across international and multiple legal jurisdictions, corporate structures, ownership structures, etc. seems... complex. And honestly, not something I'd trust myself with (as a primarily-SWE).
And the external audits don't attest to corporate structure, do they?
2) Correct but there are also many CA's that have managed to do a good job here. Why should we allow poorly behaved CAs in when it affects potentially billions of devices and people?
As for the external audits correct, they are very narrow in scope, there are also no requirements around change of control (e.g. company A buys an existing root CA).
Outrage culture manifests commonly in nerd culture as this kind of rage.
Especially people like Kurt Seifried who appears to have no relationship to any of the browser vendors or parties involved. Just some random person demanding answers from Rachel as though he is a prosecutor.
It doesn't seem to me like a public mailing list is necessarily the best way to handle this given the seriousness of the topic and the business impact to the company involved.
yes we can trust Mozilla and the other browser vendors to do the right thing. we already trust them very explicitly when using their software.
but the public by default approach is pretty good for these things. IETF, NANOG and other big org lists are also public. yes as all mailing lists there are occasional flareups. (and yes browser vendors or various CA/B forum members can still start a shadow list to conspire)
... but the business impact happened when they did the not-the-right thing, to minimize their impact they could have declared this an incident, suspend issuance, withdraw from the trusted set and apply again later. they again did the not-the-right thing by trying to bullshit their way to minimal impact.
it's not exactly virtuous, but quite understandable to throw a few rotten eggs. (and the list could be CA/B members & candidates only).
If anyone is interested, we're looking into what can be done around the root certificate world, if you're interested feel free to reach out to me at kurt@seifried.org (I'm still in the exploratory phase, e.g. can anything actionable/useful be done, and so on).
It is just a mailing list. No one has to take commenters seriously. I found the tone here by the cimmunity to be quite fine. But even if it descended sitnificantly, became much less professional, I wouldnt be happy per se but I would not until a long long descent begin to question the value of the open process. It is up to the reader to figure out what credentials people have; as Kurt said, you've got to do your own searching to find out. That there is noise in the channel (in this case it did not seem to come from the community) is not something we should restrict the processs to avoid; it is something we must allow & be able to be tolerant & resillient to.
The business is the unimportant part
Yes, and that's good. Their business was our trust -- every one of our devices -- and they made it clear they didn't deserve it.
Yeah, the 90s, back when anti-trust was a thing and big companies occasionally actually got punished in meaningful ways for shitting all over society.
Sure, it was just a small fish, but it's still deeply satisfying to see someone fail to get away with it because it's so rare.
"Saying that would have gotten her company destroyed even faster, but I think she would have been right."
If you are also a sucker for some fun internet drama, definitely follow the dev-security-policy@mozilla.org mailing list.
But yes, we who are already subscribed will enjoy the sporadic, but colourful drama that brews there.
They weren't untrusted just because of the behaviour. A really important dimension is that TrustCor certificates were only being used for very limited purpose. The actual decision is a a cost vs benefit analysis from the point of view of internet users. Because there's so little benefit, it takes only very little untrustworthiness before the best course of action is to distrust.
I don't think we should be going towards LE/ISRG being the only organisation allowed to issue certificates for "cost vs benefits analysis" of allowing other entities to issue certs. It would be a single point of failure and a massive target for various non-state and state actors.
Since their only known benefit was issuing certificates in support of a quite-possibly-shady email system, I'm comfortable with saying that the cost-benefit analysis comes down firmly against TrustCor.
Can somebody explain the significance of the malware being unobfuscated, and why that's apparently more concerning than if it had been obfuscated?
In other words: it suggests that the CA and the malware creator are one and the same, which was then further substantiated by their shared executives, addresses, etc.
This suggests that the relationship between MsgSafe and Measurement Systems was not a typical "oops, we added a library that turned out to be malware" relationship. Instead, they seem to have had access to the raw source code, rather than the packaged binaries, which in conjunction with other evidence indicates a close degree of collaboration between the malware developers and MsgSafe. It's not a smoking gun, but it's enough to warrant distrust.
Rachel’s suggestion in the thread is that the other examples of this SDK that have been observed obfuscated are much more recent, and that perhaps obfuscation was something the company has started doing more recently.
* Developing and implementing a robust security infrastructure
* Completing an application process
* Undergoing an audit and validation process
* Obtaining accreditation from a recognized organization
* Maintaining compliance with accreditation requirements.
and then: * On average, it can take several months to a year or more to complete the process of becoming a CA. This includes the time required for developing and implementing the necessary policies and procedures, completing the application process, undergoing the audit and validation process, and obtaining accreditation.
Wow, throwing away several months to a year of effort. It truly is something that takes time. I guess, a determined adversary will play the long con.The summary of the public discussion is worrying:
Summary of Discussion and Action Items
Discussion Item #1: A concern was raised about BJCA’s Beijing One Pass software, which apparently facilitates client access to a digital portal or platform. It was noted that BJCA had attempted to address suspicions about the software in Comment #15, that the software was needed to support a USB token and to install another certificate chain, and not the two above-referenced roots.
A follow-up question was whether a security report concerning the software would be made publicly available.
BJCA Response to Discussion Item #1: “This report is a communication document between our company and the competent government department, and it is not suitable for disclosure or submission to Mozilla because it involves confidential information. And because the security incident does not involve the certificate chain of the root inclusion case submitted to Mozilla this time, we made a clarification in the Mozilla root inclusion case by disclosing the main points of the report.”
==========================
Discussion Item #2: Two components were also mentioned: wmControl.exe and zfkeymonitor.exe.
BJCA Response to Discussion Item #2: The “suspected spyware behavior indicated in the report was caused by one of the drivers, wmControl.exe. This program is a driver provided by the USB Token manufacturer, Its software behavior is different from spyware and does not have malicious behavior. It is intended to ensure the normal use of this type of [device] in the browser. In addition, the USB Token for digital certificate corresponding to the driver wmControl.exe is an old version device, and its driver has been deleted in the new version of the certificate environment software (version >= 3.6.8)”. Concerning zfkeymonitor.exe, BJCA responded that their software did not include the zfkeymonitor program.
==========================
Discussion Item #3: Clarification was requested about root certificate installation by the One Pass software.
BJCA Response to Discussion Item #3: BJCA reiterated that their software did not attempt to install the two roots, but stated, “in order to improve the user experience, the BJCA certificate environment software chooses to skip user confirmation during the installation process, which may cause doubts for users. At present, we have plans to adopt advanced options in the new version of the software, allowing users to choose whether to confirm the installation, and support users to choose to add certificates and updates to the current user's personal storage instead of the computer's trusted root or trusted third party storage. No doubt that there is an obvious contradiction between convenience and security, which could improve the software security but degrades the user experience and increase our operation costs.”
According to BJCA, it maintains two separate systems:
a global, public-trust system that meets international standards (WebTrust, CA/Browser Forum, etc.) and issues and manages SSL/TLS server certificates; and
a national system that follows Chinese standards and issues and manages personal certificates, enterprise certificates and equipment certificates (e.g., Beijing One Pass software and certificate).
BJCA acknowledges that both systems are under control of the same legal business entity, but for the latter, the software is not part of the global, public-trust system.
BJCA says it “will also refer to the recommendations of experts, learn from the best practices of the public trust system, continue to innovate, practice corporate social responsibility, and strive to build a safe and reliable of cyberspace.”
========================== Conclusion
We thank community members for their review and consideration during this period. Root Store Programs will make final inclusion decisions independently, on their own timelines, and based on each Root Store Member’s inclusion criteria. Further discussion may take place in the independently managed Root Store community forums (i.e., MDSP).
I get the same feeling when I read the paroxysm about HN at the top of the page.
https://web.archive.org/web/20230120013024/https://cohost.or...
really quite amazing to read
the whataboutism starts about 50% of the way down
It's to say "sure we shipped spyware to android, we're guilty of what we are accused of, but google does it too and steals all the same information, but from even more people"
> I don’t think merely being critical of Google (even in disparaging language) would result in them risking their appearance of impartiality.
But saying "yes, we shipped the malware you claim we did" would have gotten them removed quickly, which is again what I think the actual suggestion was.
That doesn't seem very much like a "high road" to me.
Not what the article says. Here's the exact statement: "most of the people on that mailing list work either for or with Google"
> and further imply that their involvement with an open standard is actually a ploy to secretly benefit their advertising business
Also not what the article says. It's implied there's a conflict of interest, which is true, but not some kind of secret ploy.
I seem to find myself much more on the fence about this topic than the average person, but I will say I think the correct decision was made. No doubt can exist about a CA's trustworthiness. From what I gathered there are some serious unaddressed issues.
-The email system provided by Trustcor is NOT e2ee. By default the mail-service DOES allow trustcor the possibility of viewing the email, which is in direct contradiction to their documentation.
-They claim the closest association trustcor had to magsafe was "shareholders of shareholders" but given their own statements this seems to be misleading, if not completely false. (correct me if I am wrong)
They say that they are no worse than other CAs and their downfall was due to the attention the process attracted and liken it to "...a public interrogation held in a town square." I think I agree, but I also think that maybe this level of investigation should be more common.It's going to make the already rocky CA/Browser/User triad even more fraught with dangers.
If you mean becoming a CA that browsers list in their trust roots: you need to obey the CA/B baseline requirements[1], which are reasonably onerous given the position of extraordinary trust it affords you.
There are other requirements for other kinds of CAs as well (for example, codesigning in Windows).
[1]: https://cabforum.org/wp-content/uploads/CA-Browser-Forum-BR-...
You also need to have some reason for browsers to care about your certs. Being available and interested in the 90s was good enough, but these days the route is probably pay an existing CA to cross sign your CA (which requires that you follow all the same rules as if you were in the trust stores), wait for usage, and then apply to be in direct.
In combination with my PiHole setup at home, all my devices have names and SSL certificates, protecting them from being snooped on by things like my Chromecast!
Is this an attempt at humor (in which case, I don't get it), or is the author serious?
And to be fair, Hacker News is a diverse community, not a monoculture. It's entirely possible not to see the worst side of this place, depending on where and how often you post, and it's entirely within anyone's rights to dismiss criticisms of the community (although I think that would be a mistake.) But that reputation also isn't entirely unwarranted.
I'll be in the stocks if anyone needs me.
It's like living in an apartment with a pest problem. It doesn't matter how much you spray, you still have a pest problem.
Judging a community by posts that are moderated away seems like the wrong way to go about things. By this standard almost any community is horrible $bad_thing. It's just that on HN you have a bit more transparency than many other sites. If you don't want to see that stuff then don't turn showdead on.
Now, I have my own criticisms of HN, and some (but not all) align with yours. But I don't really want to go in to details about that as I feel that's moving the goalposts from the claims made in the notice: "full of sexism and racism", "hang out with white supremacists", and that "the main moderator approves of it". "Out of touch elitist silicon valley nonsense" is not the same as any of that.
> this place looks like a den of alt-right creeps and incels
But it's not. There sure are some of those people, and their posts rarely do well (i.e. they're typically downvoted, certainly not the top post).
A lot of people might say the same about America. And many people in America would view that with consternation.
It’s ironic, because I’d bet many of the people tarring everyone on HN with the same brush would be the first to resent being lumped together with their fellow citizens.
Also, with all due respect, your comment reads aggressively, as an attack (my apologies if this wasn't intended as such), so I suspect you're going to get some strong reactions.
Just like that "if you're from HN you're bad, go away" banner. For what it's worth, I've also seen a few examples of groupthink bigotry, and I felt certain resemblance.
Oversimplified summary of the complaint as I understand it: HN’s moderation policy is “thoughtful debate.” Marginalized groups do not appreciate their human rights being treated as being up for debate, politely or not.
"Mis-informed cis people" is quite a different thing than "human rights being treated as being up for debate".
No idea what they mean. I read HN all the time, and haven't seen anything remotely like sexism, racism, or white supremacy.
But when anything gets posted that can be linked to race, or celebrates some minority, or talks about the climate I notice a disturbing amount of people crawl out of the woodwork and post some truly awful/ignorant things.
But some days I wonder if I really want to hang around in a space where comments about "race realism" and obviously willfully ignorant climate change denialism are tolerated.
(like you said they usually get downvoted into oblivion, but not consistently enough for me to be comfortable that those people aren't still a fairly large minority of those engaging in discussion on this site).
More like "the reputation of this community has with mega-narcissists who lack the empathy to cope with the fact there are people in the world who don't quite see things the way they do, and can't stand forums that allow people to voice opinions they don't like".
There are plenty of thing I don't especially like about HN, but "filled with literal white suprematists" is not one of them. I'm sure you can find the occasional post here or there that gets by unnoticed in some little seen thread, but that's certainly not the norm.
However, when political discussion does happen, I tend to see a very wide diversity of political opinions on HN. There's a decent number of users who are generally against any sort of feminism, LGBTQ, anti-racist views, quite alt-right feeling, and there's a decent amount of overlap between those views and libertarians. However, there's also plenty of people with very opposite opinions, very left wing, pro feminism, pro LGBTQ activism, pro anti-racist activism, etc. Kinda like Reddit, you get all ends of the political spectrum. It does have probably the most "Bay Area libertarian bro-ey vibe" of any online community I spend significant time in, and while I'm personally not a fan of that viewpoint, I also think it's only one of many viewpoints on this site.
I've encountered the odd bit of really nuts racism that doesn't get moderated/removed, even if flagged (example: https://news.ycombinator.com/item?id=31722179), but that's rare, and I think that more falls through the cracks vs. dang literally being a white supremacist.
I'll see and report spam accounts. The usual response is that those already were autokilled, or were killed shortly after I emailed (and prior to the moderators' response).
You'll also see dang occasionally commenting on autoflagged "green" (new) accounts. E.g.:
<https://news.ycombinator.com/item?id=23686501>
<https://news.ycombinator.com/item?id=10638699>
<https://news.ycombinator.com/item?id=22377470>
An overview of how/when accounts are killed and what notice is given is here:
I'd disagree with characterising everyone who uses the site like that, but also don't agree with people who think the comment quality is flawless.
I have quite often seen COVID-19 disinformation upvoted here, as well as many other conspiracy theories unique to a particular subset of the population.
I have often debated whether I want to remain part of the HN community—it is often toxic. But I also don’t want to cede space to people whose worldview is inimical to my own, so I stay and argue against the worst parts of it.
JWZ also provides some very colorful images if you link to his site from here. I think "techbro man children" is his commentary.
And from Twitter before the fall, HN was known for alt-right hard libertarian hypercapitalist hellscape.
So having this person be hard negative here is not at all surprising.
As much of a childish reaction as I feel her response is because she saw HN in site stats, I instantly won't read won't she wrote because of that.
That's what she means by "nazis at the bar". It's some woke meme that says it's not possible to discuss anything with people who you disagree with, because you'll instantly become exactly like them.
That's all craziness of course - some sort of personality disorder in which basic empathy is lost and the way other people's minds work is badly misunderstood. These sort of people can be dangerous to those around them, and probably need psychiatric help, but it's not formally recognized as a disorder.
Yeah no, that's exactly what this is regarding. Anyone who doesn't think exactly like me is a Nazi and because you tolerate people that don't think exactly like me you're a Nazi too.
The plain and simple fact is that different communities have different threshholds for what sorts of opinions they find acceptable. The person who posted the article considers Hacker News to accomodate unacceptable opinions. Instead of just noting that fact and moving on, you've decided to get angry on the internet about "woke people." It's really weird, since their opinion doesn't affect you or Hacker News in the slightest.
So, what's the problem here? A blogger is mean?
see how fluidly you move between naziism as an analogy and asserting that it has a literal meaning such that the "war" about that has been over for decades? nobody here is a literal nazi not even close, so this whole argument is meaningless.
> the people who do not like assholes stop coming around
the whole point is that actually no, it is possible for people to strongly disagree yet stay talking and adults do so all the time.
Although it is true that "nazi" was historically thrown around a LOT, especially during the 90's and earlier 2000's, with things like "Soup Nazi" and grammar nazies. Charlottesville was really the wakeup call that no, there are real white nationalists, neonazies, and similar, and they will attempt to take over at all costs.
And in the occult, there is Norse religion called Asatru - or faith of the Aesir. Unfortunately, groups like "Asatru Folk Assembly" are literally neonazi front groups, that peddle Asatru but with a racial purity identity. The anti-racist Asatruars have had to fight against real neonazies getting your group, "peacefully" suggesting racial purity, inviting more like them and running off the anti-racists... And after a bit, your group is now a neonazi front. This is a literal thing that happens.
These types are not to be tolerated, discussed with, or anything outside of running them off the moment they appear.
Some examples are any threads where the author uses nonstandard pronouns, such as this one from a few hours ago. Some people have terrible takes, and the proportion of them compared to places like for example reddit is higher https://news.ycombinator.com/item?id=34446673
> [Google is a] company that also distributes spyware, because they don't check what their ad customers are doing very well and let them run random JavaScript on random web pages.
Is this true? While it's absolutely the case that websites have very little control over what ad content is displayed (see, for instance, the work of https://checkmyads.org/), I don't think I've ever seen evidence that ad publishers, or anyone in that massive ecosystem, can inject arbitrary code, running in the browser's context, into websites who monetize through Google AdSense script tags alone.
Of course, Google touches other parts of the pipeline, and I'm sure that in their trillions of transactions, they have unknowingly participated in or facilitated transactions that route/suggest malicious ads to other AdSense-like ad-embedding or tracking solutions that might have RCE vulnerabilities. But it seems a bit of a stretch to call this "distributing spyware," any more so that it is to call a customs official who misses an illegal package a smuggler.
I worked for an SSP, and always loved the data we got back from DMPs categorising the same user into "segments".
Sometimes they were a man, until five impressions later they weren't, the guesses at age varied significantly also.
That said, none of those DMPs were Google. I believe that they'd actually be able to correctly segment you, because, well, it's Google, one of the companies putting the brightest minds of our generation to work on the problem of optimising CTR.
The basic summary as I remember it is:
Website A has a deal to show DoubleClick ads.
DoubleClick can choose to directly show an ad from their network, or sell the spot to another smaller ad network.
There may be multiple layers of reselling here.
Someone signs up to some tiny ad network that is just happy to get customers and don't care too much about vetting.
That someone probably uses a stolen CC to buy ad space, and because you can inject JavaScript as part of your ad, this person injects some malware.
There was a bunch of pretty high-profile cases of this happening on major websites (NY Times and Wired, iirc). Some were done using flash, back when that was a thing.
I've personally witnessed it three times over the years because it usually ends with all users of the targeted sites being pushed to malware sites. Yes, it's happening via Adsense, and usually takes 1-3 days to stop. See also this article, that was one of the waves I dealt with: https://www.seroundtable.com/google-adsense-hijacking-19709....
I'd love to see if there was anything from the post-Flash era, but this certainly answers the root question.
MapQuest is my favorite one for malicious Google Ads, because it basically targets seniors. (This is a double whammy for Goigle distributing malware because these are usually pushing malicious browser extensions served by the Chrome Web Store.)
Google allegedly delists these when it finds them (usually after a ton of people have lost their crypto or whatever), but it keeps their profits from doing it.
Is this still possible? What measured does Google take to limit what advertisers can do?
P.S. in addition to internet points, you’d also be providing important information for anyone who cares about privacy and security. But I’m a little cynical, so did you hear about the Internet points?
It depends on what types of ads you allow. Sourcing a javascript from Google is always at risk of whatever Google wants to run, but some ad types include advertiser javascript in the creative [1]. There's controls in place to reduce the chance of malicious code, but that doesn't eliminate it. (Plus or minus when they serve ads from other exchanges, as others noted)
[1] https://support.google.com/admanager/answer/3180782?hl=en