Block YouTube ads on AppleTV by decrypting and stripping ads from Profobuf
ericdraken.com
ericdraken.com
> Exploit a Protobuf Flaw to Easily Remove All Ads by Changing One Byte
He's intentionally corrupting the tag on one field of the protobuf. The "flaw" is apparently that Protobuf ignores tag numbers it doesn't recognize. But that's not a flaw, it's a core design feature of Protobuf, designed to allow extensibility.
> Notice how the Protobuf response payload is 1.87 MiB? As I said, Google makes it computationally expensive to decode, alter, and re-encode without the C++ source proto files, but a quick linear scan takes no effort at all.
1.87MB is not that big, and presumably these messages only come through occasionally, not in a constant stream, so I'm a bit perplexed about the purported performance barrier here.
The text seems to be claiming that Protobuf encoding is designed to be expensive to decode, but it's actually the opposite, Protobuf is intended to be efficient to decode.
He says you need the source proto (schema) files to make it efficient, but this isn't really true, you can decode directly into UnknownFieldSet easily enough.
Or better, he could have written his own fake .proto schema that covers just the one field he is aiming to remove. This would have been much less error-prone than the string-scanning approach which could accidentally match other data where the same byte sequence happened to appear by coincidence.
> While computationally expensive, decoding, editing, and re-encoding without the original schema leads to a modified encoding. This is likely because we cannot detect if ZigZag encoding is being used, or if a number is an int32, int64, sint32/64, varint, etc., plus the order of object fields is normally non-deterministic. Here is some Protobuf trivia on the matter:
I think he's misunderstanding here. The point is that the Protobuf encoder is allowed to encode fields in any order, hence decoding and immediately re-encoding a message can lead to different bytes. But, the receiver is supposed to treat the message the same regardless. It's unlikely that the YouTube app is going to notice if the field order changes.
(I used to work on Protobufs, a long time ago.)
“1.87MB is not that big“
I have lived in rural communities most of my life and unless I’m on my own Wi-Fi, this actually is a big file to download. Maybe they have a workaround for mobile? Mostly I just want to add that rural Wi-Fi still struggles with Web 2.0 architecture. More often we’re operating on 2-4G speeds.
Although if you’re in any kind of metro area with a population that supports better infrastructure, 1.87MB has mostly become a small file size. Except maybe at 6pm when everyone on your cable trunk is streaming content. :)
You’re right about 2MB being a large payload in some network configurations, but I think it isn’t that big in Youtube’s context.
Now we have proper internet I don't but don't for a second doubt that a sizable portion of the internet still suffer from slow speeds, even those living in developed countries.
My ISP when I talk to them about their speed issues "Well, 7mbps is all you need to stream Hulu", which is.. a terrible response. Want to do something else while streaming? What if _two_ people want to stream? What if I want to stream a video while my partner is playing a game online?
Ads are simply a _HUGE WASTE_ of my bandwidth, so I filter as much as I can.
Yet for some reason I will not place 9 unneccessary bricks in my car, nor tolerate them if I discovered them already there.
Is the "some reason" irrational?
1) what. is. in. that. game.
2) what do you do if you’re charged $1/gb and want to play forza? Sit in a Starbucks for a whole day?
A lot of very high resolution textures mainly. Also very detailed 3D models and audio recordings of 100s of cars.
2) what do you do if you’re charged $1/gb and want to play forza? Sit in a Starbucks for a whole day?
What was old is new again. I remember going to the library with a stack of 3.5" floppies and downloading stuff there.
It's more likely that people play console games they can buy on disk at walmart. Another alternative would be to use a pirated version that is highly compressed with extra crap removed. For instance fitgirls has a version of forza that is only 67GB. There are times when it might actually make sense even to buy a game to support the dev AND still pirate it.
So what can we do about the situation. Obviously we can continue to expand faster internet but as developers maybe we should offer our own compressed version if we can't bring ourselves to economize in general. For instance some games that top 100GB have 10s of GB of uncompressed audio that could profitably be reduced. We can ensure that locale specific content like languages can be disabled. We could break levels into content packs that can be downloaded AS the game is used. Maybe that 120GB can be reduced to 60GB of which 20GB needs to be downloaded immediately to start playing? How many users play some of a game and move on? My bet would be a LOT.
I preinstalled it on my Xbox just before release, and it had a >20gb day one patch, as I recall.
4G speeds are completely fine for watching video - I do this often in very rural locations using a Verizon hotspot (4G only). Sure, less than that is problematic for video, but 1.87MB is still small over 3G.
1.87MB is definitely not small over a bad 2G link that you’re sharing with other people.
It’s not rare. Ubiquiti is very popular for setting up point to point links getting a single internet connection shared amongst a bunch of rural homes.
Also, this isn't my understanding of what "mesh networking" really is. It's just providing RF access to a single wired access point. But it could be that I don't understand what mesh networking actually is.
It's humorous if you ask them if they have a wire and wired device to test they frequently act as if you asking them if they have a vacuum tube or a teletype. Meanwhile they frequently struggle with wifi configuration problems with devices that are 3 feet from one another.
I would never want to be that dependent on first-level helpdesk to solve my problems for me.
This. It's the same sort of error as when people refer to the web as "the internet" -- which common even on HN.
Shameless plug: I wrote a project to generate source proto files from binaries called protodump [1] - it regenerates all the message/field definitions (including the original names). It would just require pulling the binary off the AppleTV box
As for this specific context, presumably at least the bulk of the fields are shared between YouTube clients across architectures and platforms - it might be easier to just run the dump against binaries extracted from the YouTube apk than getting the specific Apple TV YouTube app binary. (For iPhone, you can just make a full iTunes backup but for Apple TV I imagine you’re going to need to do some forensic binary spelunking.)
https://github.com/protocolbuffers/protobuf/blob/main/src/go...
This takes advantage of the fact that such descriptors are commonly compiled into programs that use protobuf. The descriptors are usually embedded as constant byte arrays. That said, not all protobuf implementations embed the descriptors and those that do often have an option to inhibit such embedding (at the expense of losing some dynamic introspection features).
You can write a simple protobuf decoder in a couple hundred lines of code if you don't want to pull in the full protoc dependency: https://github.com/kubernetes/test-infra/blob/master/guberna... https://github.com/kubernetes/test-infra/blob/master/guberna...
How do you solve it? Is it just heuristically checking where if the varlength byte sequence itself contains tags, it's likely to be a message?
What and understatement. For those unaware, Kenton made protobufs to what they are today.
Protobuf was my first dip into what are IDLs; it seemed like a magical idea at the time (having discovered protobuf ater writing my own rudimentary IDL first, protobuf was amazing).
In this case, getting a reply straight off the source.
Since Cloudflare employees are known to lurk here, I'd like to know: is this considered a false positive, or working as intended?
"Regimes" sounds pejorative but in truth, companies have a duty and in many cases a legal obligation to protect their networks. Prima facie, I don't see any reason at all why interception of traffic in this circumstance is "bad," except maybe a potential for political misuse like any other written medium.
I actually think the reverse would be substantially worse: if _only_ the public trust chain was valid in major browsers, we would be completely hosed and there would be no distinguishing factor at all between remote attestation and trust.
Thus, corporate TLS interception is, at worst, a necessary byproduct of a very well chosen tradeoff.
> The term "Cyber Monday" was coined by Ellen Davis, and was first used within the ecommerce community during the 2005 holiday season. According to Scott Silverman, the head of Shop.org, the term was coined based on 2004 research showing "one of the biggest online shopping days of the year" was the Monday after Thanksgiving (12th-biggest day historically). Retailers also noted the most significant shopping period was December 5 through 15 of the previous year. In late November 2005, The New York Times reported: "The name Cyber Monday grew out of the observation that millions of otherwise productive working Americans, fresh off a Thanksgiving weekend of window shopping, were returning to high-speed Internet connections at work Monday and buying what they liked." At the time, a lot of people had slow Internet at home. The idea for having such a holiday was created by Tony Valado, in 2003 while working at 1800Flowers.com, and coined "White Wednesday" to be the day before Thanksgiving for online retailers.
Greetings from a country whose (almost) entire IP space is blacklisted by Cloudflare!
> Software engineer from Belgrade, Serbia
greetings from the other side of the world, commandline brother. I did not know of this tool, but I do now. Thanks
Sounds like something that would be "trivial" to defeat, by means of "emulating" other TLS implementations more closely?
what else do you MITM for?
Once the requests leave the computer and travel onto the internet destined for another computer, then of course "MITM" makes sense as a concept. We all want to prevent that.
The computer owner controls the proxy and it's the proxy, not the untrusted application, like a "modern" web browser for example, that handles authentication of the remote peer. Compiling and fully controlling a "modern" browser is a PITA. Almost no one does it, even software developers. Instead people beg for an advertising company or their partner to make changes to a browser. That does not seem to work. Sometimes when people complain it stops the company from making undesired changes. But only temporarily.
Whereas compiling a proxy is easy and the user can fully control it.
Having used many different applications that implement support for TLS, I actually trust the proxy's implementation more than most applications. It's arguably easier to audit one program, the proxy, than it is to check every application to make sure the developer didn't make a mistake when adding TLS support. I recall socat as one example. That mistake went undetected for a long time. Elinks was another. At the time, it was dropped from OpenBSD ports as a result.
[1] https://reshade.me/forum/troubleshooting/8746-reshade-v-5-8-...
www.digitalocean.com
arstechnica.com (Amazon)
git.kernel.org
cdn.netbsd.org (Fastly)Googling this, development ended in 2004? An informed summary of the current state of play would be interesting, since a lot of different "continuations" of it seem to be around. Also, is it Windows-only? (I've been casually looking for a simple proxy that would enable injection of local links into remote content.)
The readme goes on to say: "Privaxy is also way more capable than DNS-based blockers as it is able to operate directly on URLs and to inject resources into web pages."
Can’t Wine help with this?
Regular http gets redirected to proxy, non-standard traffic needs to be explicitly allowed out.
What works are browser based ad-blockers and app patchers like ReVanced. As my savings have gone up, I've relied more and more on just paying for ad-free services like YouTube Premium, Hulu, Netfix, and Max for the cases those 2 can't handle.
It works really well and is simple to manage. It runs on my mobile devices easily.
I turn it off occasionally to shop, but immediately turn it back on as the internet is a whole different place without some sort of robust ad blocking.
It’s nice to see the logs fill up with blocked telemetry and other crap all day.
Because they're often ads made to look like search results. Pi-hole working as intended.
That's my experience anyway. My family network is behind a pi-hole and rarely if ever does an intended website visit break as a result.
I use a layered approach. I’ve been using Pi-hole for 8-10 years, don’t remember, with about 1-2M in the block list.
In addition, I use uBlock as well as pfsense with pfBlocker-NG for blocking countries and other features.
They all work well together. Sometimes I have to bypass them, when I momentarily use the ISP’s Wi-Fi router directly.
It’s been working fine.
https://github.com/deetungsten/webui-privaxy is the dockerized fork of https://github.com/Barre/privaxy
I really don’t like hardware becoming waste because we don’t have a better iot cert pool update story
I trust YouTube to know how to bake their own cert and trustworthy tls libraries into their apps but I’m not sure if that’s common in other apps
At that point, cut all its connections from the Internet and use it as a dumb panel. Many people will say you should have never connected it in the first place anyway.
You can alway use a streamer box (custom Linux one, Apple TV, Fire Stick, etc) to give it "smarts".
https://sick.codes/extraordinary-vulnerabilities-discovered-...
If there are known exploits for the TV (a bunch are now running old and unpatched Android), the answer is easy enough (root it and do what you want - though that opens different and maybe easier options for ad stripping), but I’ve heard of it on Apple TV where jailbreaking isn’t so easy. Perhaps MDM deployments?
Looks like it uses the method in this article https://developer.apple.com/library/archive/qa/qa1948/_index... but i have not (yet) tried it
TL;DR it involves using Apple Configuration to make a custom mobileconfig profile to point to your proxy and then also installing the certificate with the same method.
I have it working for a few TV Everywhere compatible apps, but some are proving to be more difficult than others. I may have to do some other TLS inspection with mitmproxy and figure out what needs to be removed with the custom uBlock filter syntax option.
WireGuard doesn’t actually use AES, as far as I know.
In general, it seems like the author somewhat overestimates the CPU requirements for TLS encryption (or equivalently underestimates modern single-board computers):
> The CPU requirements to decrypt and re-encrypt HTTPS traffic greatly exceed those available to Raspberry Pis.
I'd be really surprised if MITMing TLS on an RPi 4 was actually infeasible, even when using RSA cryptography purely in software.
There are Android phones still in use with weaker CPUs than that of the RPi 4, and these use TLS too.
The CPU requirements for TLS are extremely dependent on the desired bandwidth. At even higher bandwidth, offloading onto accelerators becomes important to be able to do it at all. The cost of handshakes is also nontrivial, and can limit the number of connections per second. For a single device, rarely a big deal. For an entire network of devices, it can be a bigger problem.
That's a lower, not an upper bound.
An RPi 4 can encrypt/decrypt AES-256-GCM at more than 300 Mbit/s, according to my rough measurements. That's per core, of which it has four.
RSA can be much more expensive, but that's besides the point – the author was claiming that AES-NI makes a meaningful difference here, which I'd really doubt even in the case of TLS. (As mentioned above, it can't help at all for Wireguard.)
Which only matters for multiple concurrent connections... a single download would still be a sequential task on a single core at 300Mb/s, which I would find to be an unacceptable bottleneck on my gigabit connection.
In reality, it would probably only be 300Mb/s for up to 2 connections, since it needs to both decrypt and reencrypt, which could be parallelized onto 2 cores, otherwise 150Mbps for 4 connections if each connection was handled only on a single core.
Either way, it would not be possible to MitM 1Gbps of traffic on a Raspberry Pi 4, with the numbers you provided, only 600Mbps total, and only across multiple connections. It would be an extremely noticeable bottleneck.
If you've got a Raspberry Pi 4 as your proxy, aren't you already struggling to pump more than 600Mbps over your network? Even if so, are you really pulling down more than 300Mb/s over a single TLS connection?
Even in that scenario, AES encryption/decryption can be parallelized (https://github.com/gurupunskill/parallel-aes).
To me, it seems like a pretty narrow set of scenarios where you'd not have the processing power to decrypt/encrypt at the speed of your network.
The Pi 4 is capable of a full gigabit connection, unlike previous Raspberry Pis. So, no, not fundamentally.
> To me, it seems like a pretty narrow set of scenarios where you'd not have the processing power to decrypt/encrypt at the speed of your network.
The whole scenario was set up by the comment at the top of this thread: "I'd be really surprised if MITMing TLS on an RPi 4 was actually infeasible, even when using RSA cryptography purely in software."[0]
I consider it "infeasible" if it is a significant bottleneck on the network. It could be infeasible for multiple reasons, as you're alluding to, but that only strengthens my argument.
> Even in that scenario, AES encryption/decryption can be parallelized
An AES implementation that no one uses is not a very compelling argument, except as a hypothetical. Do trusted AES implementations do the encryption in parallel? That's all that matters, IMO.
The entire whole scenario is hypothetical!!!
Yes, there aren't a lot of AES implementations that use CPU & GPU for decryption, but if you're setting up a multicore network device a CPU parallel AES implementation isn't unreasonable.
> I consider it "infeasible" if it is a significant bottleneck on the network.
So there's a lot of vague terms and hypotheticals, as you say.
I would presume it is possible to have a network where data over even a single connection traveled so fast over a Raspberry Pi 4, where you had no access to a parallel implementation of AES, where the performance impact of routing everything through the Raspberry Pi were deemed acceptable, but the consequent slowdown in performance might be deemed "infeasible" by some, yet if you were to drop in a comparable device with an AES-NI capable CPU, the consequent ~4x performance improvement would allow for it to be deemed "feasible". Another "feasible" solution would likely be to spend roughly the equivalent of two months of what you were paying for the Internet connection on the bottleneck you've created in your network.
Yes, it's possible to construct the necessary hypothetical, but it's not exactly a common scenario.
I do not agree at all. Some people may actually want to use the technique detailed in the article.
Most people do not have a powerful, enterprise-grade router they can run software on, so they would reach for another device. A Raspberry Pi is frequently used for PiHole and similar functions, so it is logical that someone would reach for a Raspberry Pi 4 here.
What part of this seems hypothetical?
An AES library that might not even work (since no one actually uses it), let alone is likely difficult to integrate into the software stack described in the article is extremely hypothetical in a way that the actual project would not be. That parallel AES implementation is not some proven library with great documentation... it's a random github repo that hasn't been updated in 5 years. If the feasibility of the project depends on that, that seems like a bad place to start.
> where you had no access to a parallel implementation of AES
You don't. Unless you're saying the author has already integrated this into the described software stack? And proven that it works.
> yet if you were to drop in a comparable device with an AES-NI capable CPU, the consequent ~4x performance improvement would allow for it to be deemed "feasible".
That does not seem hypothetical. That appears to be extremely real. Of course, the speedup would likely come from multiple factors, not just AES-NI, given that you can't find a Raspberry Pi with AES-NI to have a pure apples-to-apples comparison.
> Yes, it's possible to construct the necessary hypothetical, but it's not exactly a common scenario.
I have no idea what you're talking about. This scenario is not convoluted like you're trying to make it out to be.
> An AES library that might not even work (since no one actually uses it)
The library I provided was the first result I got when I searched for "parallel AES", and it's not used because there aren't a lot of scenarios where people need the extra performance extracted by splitting workloads between CPUs & GPUs. Ways to improve the parallel processing of AES was still the subject of some research a decade ago, but there's not a question as to whether it is feasible today. There's just not a lot of call for software that does it because aside from brute-force attacks, in practical scenarios the hardware is already fast enough.
> You don't. Unless you're saying the author has already integrated this into the described software stack?
So now the scenario you've got here is someone with requirements and means at their disposal to regularly pull down data over a single connection at gigabit speeds from the Internet, but doesn't invest in their network proxy enough to get hardware that can decrypt at performance that was available for commodity hardware over a dozen years ago, who is hacking away on a Raspberry Pi to MITM their Internet access, interpret layer-7 protocols, develop software to manipulate those protocols in ways that don't break the functionality they require but do break ad platforms, but don't have the resources to swap out their encryption library?
I give up. You win.
For YouTube videos!?
Encrypted Client Hello / Secure SNI / Encrypted SNI prevents the hostname for each connection from leaking in plaintext. DNS-over-HTTPS prevents anyone on the local network from snooping on the DNS lookup to realize which connections are for a given domain name. I guess a sufficiently advanced implementation would stop MitMing a connection once it is not talking to YouTube, but as a broader ad-blocking technique, this would apply to more than just YouTube.
Even just focusing on YouTube, lower bandwidth means that you have longer pauses when you skip around any video that isn't super short, as it attempts to buffer that section of the video.
True, but almost nobody uses that yet. Youtube certainly doesn't.
> DNS-over-HTTPS prevents anyone on the local network from snooping on the DNS lookup to realize which connections are for a given domain name.
The author of TFA is MITMing their own Apple TV. In that scenario, they could just configure their own DNS proxy as well. But given that there's no eSNI, it's not even necessary.
And even if you'd need to MITM all flows to and from YouTube on your local network – that would still be only a few Mbit/s per device, given YouTube's (non-premium) potato-quality data rates.
But the bottleneck is usually in terminating and establishing SSL connections?
62 messages per second means that you have 16ms to do 5 things: decrypt the TLS, parse the protobuf message, filter the message, encode the protobuf message, encrypt the TLS traffic. If you take more than 16ms, you cannot achieve 1Gbps.
We've already established[0] that you can't even hit 1Gbps with just the TLS traffic. The protobuf messages might be fast to parse... but they will still slow things down even further.
Probably not, but if you've only got a single Raspberry PI core at your disposal and you're trying to pump 1000 Mbps of network traffic through said Raspberry PI, you've already got significant challenges.
> 62 messages per second means that you have 16ms to do 5 things: decrypt the TLS, parse the protobuf message, filter the message, encode the protobuf message, encrypt the TLS traffic. If you take more than 16ms, you cannot achieve 1Gbps.
Let's just say you have a system that can do all that in 16ms. I would estimate significantly less than 1ms of that time would be spent parsing and encoding the protobuf message.
It would just be nice to see a representative benchmark on a Raspberry Pi 4.
I generally agree with you on that point, but I don't consider anything a "given" on something as weak as a Pi.
It's a "given" in the sense that it's a "given" that Raspberry Pi 4's can saturate a gigabit ethernet network.
I don't agree, but for argument's sake, where do you draw the line? What is acceptable? 10Mbps? Each person would have a different answer.
Upload congestion, together with massive Bufferbloat powered by horrendously configured CPEs, is what makes home internet connections feel slow most of the time.
I guess the only way to do that would be to dump the flash memory, replace the CA and reupload the dump to the device?
A good write up here for ways to try to intercept IoT devices without any hardware/firmware job: https://robertheaton.com/2019/11/21/how-to-man-in-the-middle...
The only relevant thing to repeat here might be this
> if you can’t get access to your IOT device’s hardware in order to add a new root CA to it, your journey mostly ends here. Don’t lose hope though. Leave your setup running for a while and see if anything strange happens. When I attempted the above process on my baby’s crib, the device refused to trust Burp’s certificate and so refused to complete a TLS handshake with my laptop. But after a minute or two of repeated failures, the crib started sending out some of its system status data over plain, unencrypted HTTP!
The point of TLS is to prevent that... You'd be relying on implementation flaws if it were ever achieved.
Frankly I expect the days of being able to install our own trusted certificates are numbered on the few devices that do currently allow it.
For iot security reasons, namely trying to stop persistence of exploits, secure boot features on arm processors will become widely used. Think of it like TPM chips. This will make it much harder to “own your” device.
Instead, why don’t we attack the advertisers? YT/Google only appear to track “clicks”, but does it actually track purchases as well?
In theory, if there are enough fake (bots) and real users clicking through ads but not buying anything. Then that should burn through the advertising budgets. Over time the marketing departments should see that clicks are at an all time high on X platform but conversions are a small percentage of those “clicks” or impressions. Thus pulling out from the platform all together.
> New Goal: Let’s trick YouTube into believing I am a 70-year-old male living in Italy.
Once I somehow convinced ad targeting I was in the market for $500 machine washable silk pajamas for my mistress.
Best ads ever, though I wonder what they were paying per impression.
After switching to Apple TV, we mostly get incorrectly geo-targeted local ads. It’s better on average, I guess.
i am not sure how one could possibly characterize that as a "flaw," since protobuf is a field-numeric length-prefixed protocol in the first place. it makes a (reasonable) assumption that bytes won't be messed with over the wire, leaving integrity to the reader, so even if this _was_ a flaw, it would be a flaw in the YouTube app for iOS, not in protobuf...
since it isn't a flaw, it isn't an "exploit," unless you are referring to the fact that youtube's protobuf exchange on their iOS app isn't checking hashes for returned payloads.
i suspect after this post they will
There's also this bit:
> Google makes it computationally expensive to decode, alter, and re-encode without the C++ source proto files
Yeah, it's computationally expensive if you use unoptimized Python code to do it. If you write your code in C (or another compiled language) then scanning 1.8MB of protobuf code should be trivial, with or without the proto source files.
I'm pretty sure that making Protobuf files hard to decode without sources is not a design goal. If it was, they did a pretty lousy job.
The author seemed to have parsed the protobuf data by converting it all to a huge hierarchy of thousands (millions?) of Python objects. Of course that is slow and takes a few seconds. That's so many allocations!
But if you are just looking for a specific tag, there's no need for that, I'm pretty sure you can parse protobuf in place without allocations, which would be a million times faster. You could maybe even do it in Python with reasonable speed.
Required fields were a feature of Proto2. In proto3 syntax (latest), the required field concept was dropped because it caused issues with protocol evolution and was easy to misuse.
In essence, because of the backward and forward compatibility guarantees supported by protobuf, a "required" field must be required for the entire lifecycle of the protocol.
For these reasons and others, protobuf takes a stance where unrecognized fields are not necessarily errors. If it took a strict stance and failed in this condition, the presence of new fields in an "evolved" protocol would be an error which would break forward compatibility; old clients would not be able to communicate with new servers, and vice versa.
Protobuf guarantees that new fields will not break forward or backward compatibility.
This is why parsing unknown fields in protobuf is a feature, working as intended, not a flaw. In some language SDKs for protobuf I believe you can customize this behavior but it really isn't a good idea.
This is also why the app authors might want to consider a hash instead. Tampering with the payload would break the hash, and without the schema, the author would not necessarily know where the hash was situated in the payload to fix it, or even that one is present at all. The complexity of recalculating the hash (assuming they find it) vastly multiplies the attacker's burden at little cost to the application; adding a few rounds and a salt, for instance, would make this kind of attack significantly harder to pull off.
It's not perfect security, but it would certainly be better.
Protobuf does this so you can do `deep.dotted.paths` and you won't get null exceptions (probably a side effect of starting partly in Java). The leaf fields end up as empty strings, `0`, `false`, or an empty array for repeated fields.
It's a neat trick to get it to ignore a field, just not a "flaw." It's actually a compatibility feature in disguise.
(So it might be pretty hard to detect, versus the potentially-legitimate case of just not having any ads to show.)
I would think that a dummy object would be trivial to detect.
Is it ever reasonable to assume you have a properly decoded empty array because a user tampered with it, instead of that being what the server gave back to you?
If you have to choose between (a) the app shutting down or (b) the user not seeing ads bc the ad array is empty, you are probably going to pick B.
Haven’t found the most elegant way. Probably the path of least resistance is getting a separate router and connect the devices AppleTV, firestick, etc to that. But then you’re going to be constantly swapping networks if you wanted to use a different app with location.
But even that feels weird because you’re paying monthly for a smart dns service just to appear in a different geolocation. There has to be a better way.
You get native player and no ads.
In my spare time I got to the point in the article of trying to figure out which URLs are ads and blocking those with a pihole in section 4.11 and failing miserably. Cool to see some techniques I would never consider, and they work!
From personal experience, we programmers/hackers sometimes like to make things more complicated than they need to be just for the fun of it (and learning experience too!).
it's a bit like inspecting source on a banking website, altering the balance html, then expecting the displayed value to reflect actual account funds
Makes it kind of hard to digest, impressive as the material is
Completely unaffiliated, just a happy user.
https://github.com/yattee/yattee
and using either
https://github.com/iv-org/invidious https://github.com/TeamPiped/Piped
as backend is a nice alternative.
Both those links are to alternative YT frontends, though?
Is there no risk running an MITM proxy, even if self hosted, that can see all your financial and other important private communication?
I know a couple mentioned here are open source, but are they guaranteed to be safe? How do I know which one (s) are good to use and can be trusted.
I want to rub it based on this thread, but have the above concern.
MITMProxy is a pretty well known and trusted open source project, but I wrote my own proxy to keep Apollo alive.
Does that make it guaranteed to be safe? Not really. I'd personally trust our TLS stack over most IoT TLS implementations, but Chrome/Firefox/Safari will do a better job at e.g. revocation checking. That being said, I'd argue that this is unlikely to be the weakest link in your threat model.
“ This unboxing and setup has been fun, but I’d like to block all the bad traffic on my network. I’ve been using a workhorse of a DNS-level adblocker called Pi-Hole on a… yes, Pi, but it would be nice if I can reclaim that wee bit of hardware for something else and use a comparable add-on module in pfSense. Let’s explore that now.”
So basically that was only doing DNS level blocking. This article is about traffic decryption and manipulation.
It is “protobuf” with a T, not “profobuf”. I know the typo is in the headline on the original article, but it is bad to spread it, and it looks bad on the front page here.
If you don't mind that users can see what you're leaking to the server from their device, or sending to their device, then please don't use certificate pinning, or at least make it an option...
Not sure which side you're on here
Those that know what they are doing (i.e. tinkering with the app to find out what makes it work or to modify it), and those that have no idea what any of this means and that get instructed by scammers on the internet (e.g. phone support scams) to do so.
I’m all for privacy but that is regulated via other means — the law.
(Some people are unable to afford it but that's an entirely separate social problem, and it would be unusual for somebody with the skills demonstrated in the article to be struggling to earn a living wage.)
What I would be interested in this protobuf inspection approach for would be implementing some decent parental controls. I would very much like to be able to enable/disable individual youtube channels. Currently all I can do is switch the whole site on and off. I have all the necessary infrastructure already, so I might give it a try.
but if I must take an alternative position: the last time I used youtube without premium (which happens sometimes because its not so smooth to log in if its a temporary session); the number and length of the ads was absurd, multiple levels of unskippable ads, minutes long, with volume that is much higher than the content itself. Awful experience and I can see why people who don’t have the free money want to lower it a little.
Thats of course not including sponsored content which contains an ad inside the video itself- even YT premium users get those.
Besides these days it's barely a monopoly with TikTok.
"anyway, you can switch from the high end monopolist to the low brow monopolist so I don't see what you're complaining about" Yes, you don't.
the right to wear hair-shirts is not the only principle that counts.
The only part of Youtube that I find valuable is the content. Not the UI, not the comments, algorithm. Free content hosting is nice, but it's not the only platform hosting videos for free.
If I wanted to pay for a streaming service, it'd be Nebula (https://nebula.tv/), because I know it benefits creators.
But I'm never turning off the adblocker, thank you.
You're only looking at this from your own point of view. The content producers are looking for monetization options, and youtube is the only game. Nebula might be sufficient for some small amount of content producers, but it's unlikely to hit mainstream, and not enough people want to pay.
It's unfortunate, but ads are the only game in town on the internet atm.
I'm using NewPipe (https://newpipe.net) on Android TV which provides an ad-free YouTube experience just like the Android phone version of NewPipe. Piped would also work on an Android TV browser like TV Bro (https://github.com/truefedex/tv-bro).
The legitimacy of ad blocking is well-established. People have been using DVRs, VHS players, and tape recorders to capture and consume ad-free broadcasts for decades.
I follow a wide variety of channels, but there are maybe a dozen to 20 that I would consider essential. Maybe 3-4 are on Nebula.
I think for a lot of viewers and creators, YouTube is simply inevitable at this point.
Huh? Ad revenue and Premium subscription also ends up as direct payouts for YouTube creators, what are you talking about? Why the need for this BS?
How is this any different from changing the channel, leaving the room, or just hitting the mute button and closing your eyes in the scenario of "regular" TV when adverts or any other content you don't want to see appears? Compelled consumption should be illegal.
If you created a painless, super easy way to remove all ads, i'm sure that TV channels will also find it hard to sell to advertisers, and thus, their revenue would decrease.
I always found it bizarre that other people did not do the same
Since ad sections are your typical break from a program to get to the fridge or toilet or whatever, the DSP transform makes sure you still hear the ads and pick up dialog even when far away from the TV.
Downmixing audio so that you can both hear dialogue and not lose eardrums to music and 'splosions seems to be an intractable decades old problem for the movie industry but it sure as hell been solved a dozen times over by the ad biz.
It was very shocking to go from 75dB to an ambient 30dB or something like that out in the countryside. I'd have much preferred to talk over or zone out over the commercials without the suddenly shocking lack of auditory stimulus!
We had that almost 3 decades ago:
https://www.orlandosentinel.com/1995/09/20/with-this-vcr-com...
I watch TV on my tablet now, streamed from a Raspberry PI with a TV Hat. Again, I activate the popup player, start browsing, maybe checking HN or whatever. I put the volume off. Maybe I start doing something else. The advantage of a tablet is that I can bring it with me wherever I go in my house. The TV, not so much. I rarely switched on my TV in the past two years.
Of course on cabled channels, they get part of the fee of your package.
There is no "compelessed consumption", there is available package "this for free with ads", or "this for a fee", you're free to chose the one you want or neither.
I'm certain your company whichever it is would have an issue if I wanted to use its services but then run away when it came time to pay the bill.
Now before you dismiss this as childish and/ or obnoxious: please consider the point. We cannot gloss over _what_ we "have" to watch and not just that it's an ad.
It is true that things have to be paid for and I am 100% for this. But if you want me to basically degrade myself in order for me to get to watch your content, then wtf?
But the most important issue is that as long as malware can spread through ads (https://en.m.wikipedia.org/wiki/Malvertising), everyone should be blocking all ads.
In fact, not blocking internet advertising is a security risk.
If they get their house in order my opinion may change, but there's currently no business reason for them to change their existing lax systems; no pressure or threat from regulation to hold them liable for what they allow on their advertising networks.
Or should we just continue consuming people's services and effort while blocking what's sometimes their only revenue stream?
I'd rather not use a service if it has ads and I can't remove them, instead of block them and make everyone else's experience worse.
That didn't last long...
Still doesn't protect you from in-video sponsorships (skullshare, OstVPN, etc.), product placements, etc. Some creators especially do these because it protects them from platform demonetization risk.
Same shit with paying for cabletv & movie theatre tickets. If anything, people that pay are their most valuable targets for ads.
Even a newspaper that I sub to runs ads and a zillion trackers against me. Ugh.
I get where you're coming from, but the platform could more to protect paying members from this. E.g. creators with over $x revenue must tag promos so the platform ships them for paying users
But now they have ads.
Also, YouTube is a video streaming monopoly, if it didn't exist there would be a significant chance of new streaming platforms to succeed, but given that it captured the marked such chance is unlikely to exist, monopoly that they achieved hosting videos free of ads (or very light on these) and now that they have the control want to force people to pay or watch a ridiculous amount of ads.
I listen to news and podcast-esque things in the car going to work or school drop-off / pick-up, on the way to sport etc. I'd begrudgingly tolerate the ads if the app background-played but it doesn't without paying for premium. I'm somewhere on an "entitlement" scale here, but background-play being a premium feature really feels like it's stretching the friendship.
So... alternative front-end it is. Great experience and no ads to boot.
The said ability exists on the YT website if you use desktop mode on the mobile browser.
Imagine Youtube preventing you from adjusting the volume unless you paid. This is similar.
Do you know that the paid version has this exact feature? This is a limitation of the ad-supported version, because advertisers are paying to actually have people watch their ad.
I already pay Google much more than I care to and am willing to in the form of my privacy and personal data because of the ubiquitious surveillance that Google performs on as many people as they possibly can.
If I could cut Google out of my life I would do it in an instant, but I can't because they won't allow it. In lieu of that I take whatever I can from them.
“To steal from a brother or sister is evil. To not steal from the institutions that are the pillars of the Pig Empire is equally immoral.” -- Abbie Hoffman
And I dislike YouTube's hostile ad escalation in recent years. One ad - fine, two ads - hmmm, three ads - what the hell. Unskippable ads. Inappropriate ads. Loud-ass eardrum ripping ads. Ads even on Premium.
They've tried? It seems like it would be pretty easy to detect ad sequences in larger channels.
I really dislike the attitude of defending megacorps and worrying about their bottom lines, especially anti customer ones like Google.
Things cost money. Every monetizing strategy involves users paying for it or the company making money from the users indirectly. OP mentions both of these. So tell me, what's a monetizing strategy other than these that works?
People consumed videos online at a very limited scale before YouTube, and those videos were usually hosted by few, generous individuals. Even if every user in the world decides to contribute 50% of their device storage for a decentralized streaming platform, I doubt it would even fit a small part of all videos in YouTube's catalog right now.
I really dislike the attitude of hating megacorps without really proposing any viable alternatives.
Consider a freemium model without the threat of adxtortion, obviously this would require youtube to offer a significant value add and/or premium content besides trying to be a monopoly and gatekeeping eyes. Make it purely subscription based (e.g. Netflix before ads). Ask creators to pay for the blue checkmark. Make it a loss leader. Plenty of adult streaming sites manages to do just fine without youtube style invasive ads. I'm sure much smarter people can name countless other ways as well, it also does not need to be a 1-1 alternative either.
This. PeerTube can provide similar benefits without centralization.
I remember I had this discussion after a school political debate in the 90s, with (adult) actual politicians. Textbooks at the time were not publicly funded, and naturally the textbook companies jacked up prices for their captive audience forced to buy their books.
This one party had the "brilliant" idea of ad-funded textbooks. I asked, if the textbook companies currently take $50 for the book, if it was instead funded by say McDonalds ads, how many extra burgers would each student have to buy that year? They didn't have any good answer to that.
It's the same as blocking YouTube ads; Google still pays the creator as if you had watched the ads, so your video playback is being subsidized by Google's ad business profits.
When you choose not to block ads, you aren't "supporting creators", you are supporting Google shareholders.
Google's shareholders might, for a while, for the sake of "control". But either way, it's not sustainable. The anti-adblockers are right about that part. They're just wrong that watching ads without spending a ton of money on the products help matters.
See here (picture gallery): https://johannes.freudendahl.net/2019/01/werbung-in-romanen/
The introduction goes like: "Only Kirk kept helping himself, because he was convinced he would need strength for the upcoming events." and then below the black bars the actual ad: "The reader should do same bla e.g. soup bla takes just 5 minutes etc"
Just some anecdote.
What about fair advertising? The main problem here nobody dares to talk about because dealing with it would undermine the very essence of capitalism: unlimited growth, is that there is no way to have fair advertising exactly as there's no way to have a fair use of any resources. Once you allow anything to be used for profit, it will be abused from the strongest players at the expense of the others until the last drop. It would be extremely easy to put well defined limits on how much advertising can be shown, and make the Internet a better place, but no way, it's anti capitalistic and therefore a no-no. Ad blockers weren't born the same day advertising came to the Internet, and many years passed until someone realized we needed them; that was the day surfing became such a horrid experience thanks to unlimited, pervasive and ever growing advertising.
edit: and, by the way, I still have to see some company going bankrupt because of ad blockers.
Why are you defending a multi billion dollar company from something that the users aren’t obliged to do in the first place?
People using their excess Internet connectivity, they already pay for for other reasons, to share content with others.
It works for socially disadvantaged, too.
I learn so much from the people who spend hours and hours making videos every month that I am more than happy to pay a measly $13 or whatever it is every month to YouTube.
https://www.theverge.com/2021/8/2/22605455/youtube-premium-l...
No, paying Nebula as an alternative to paying Youtube doesn't work for many viewers because most creators who create good content are not on Nebula. E.g. Many popular channels with worthwhile info such as Applied Science, Technology Connections, 3Blue1Brown, etc are not on Nebula.
Also, many people who use Youtube for learning DIY repair, hobbies, coding, etc and Nebula doesn't really cater to those genres. E.g. I watched some videos about configuring Unifi networks and then some tutorials on installing some flooring. These types of videos are not on Nebula's platform.
There is a huge variety and scope of educational material on Youtube and platforms like Nebula/CuriosityStream only have a fraction of that.
I've had college students build better apps for homework. It's insulting considering the rather high price of a service.
Plus paying for youtube premium does not remove the sponsor ads inside videos.
Also I feel like the algorithm has gotten worse and worse? I personally don't like to support that.
30 second un-skippable advert to see a 7 year old 45 second clip? I press "back" and watch neither.
Thinking of supporting creators: I looked at Nebula a while back as an alternative; I think there was some UX issue back then, but they've likely improved it and I should look again.
If the ads were silent banners changing the aspect ratio of the videos, I wouldn't mind them.
This is an interesting idea. It is already used to some extent in live football matches broadcast on TV. The sidelines have their ads replaced. I think your idea is a good one and deserves some testing by Google/YouTube.There are dozens and dozens of different creators of videos that I watch each month, so if I only used Patreon most wouldn't get anything from me.
They're an ad company. They pay the creators per impression even if you block the ads. Blocking ads harms Google, not the content producers.
Spotify suggestions and playlists weren't a seller feature for me for years. Maybe I'm missing out on a few podcasts.
Adblocking Google is morally right.
All ads should be blocked. I do not consume ads, and am not interested in paying a ransom to hide them.
Ad companies have been tilting the agreement attention for content ever more in their favor in aggressive and privacy harming ways. They long ago broke any moral standing.
The content creators need to seek a better deal, they’re getting screwed by Google too.
Ad supporters talk like blocking ads is literal theft, which is absolutely laughable. It's further away from theft than piracy, which is also in no way literal theft.
If I'm watching traditional non-demand television, and I go to the bathroom or change the channel during an ad, am I stealing from the network or the show? Hell no, that's ridiculous.
I would agree with you it's ok if there was no way to _otherwise_ pay for the service. If they push a only ads-supported version, and I have no choice but see ads, and I don't consent to the impact of ads on my brain, it makes a case for blocking ads being ethically correct.
But since there is a choice on how to pay, I find reasoning is no longer ethically right. You can choice to pay with your attention and brain, or to pay with hard cold cash, so the argument of ads being shoved down your brain no longer holds. You can choose to not see ads and pay for the service, and you chose to steal.
And you can make the argument that stealing is ok since you steal from the bad guys, but then you don't get to complain when others may steal from you - we're all "the bad guy" for somebody else
Me taking a copy of Shrek 2 at the local store and not paying for it is theft: the store can no longer benefit from Shrek 2.
Google can re-send the exact same bytes to someone else. All I've costed them is what it costs to send those bytes over. But then, would you consider going into a store, loitering for two hours, taking the sellers attention (therefore, costing them time that they cannot use to sell things to other customers) then leaving without buying anything theft ? Most reasonable people would say no. We'd all agree it's a dick move, but since corporations are not people, it doesn't matter.
I think the sooner we move from ads-supported models to pay-per-use like Netflix, the better we are - those that can afford will consume the best content, and the rest will stick to public domain.
The ad industry is a scourge on humanity, and its gormless defenders are willing accomplices.
Google did everything in their power to force themselves into every aspect of our lives and leaving no alternatives, or destroying them, or buying them. Now they get to deal with the consequences
Otherwise you're just rationalising freeloader behaviour.
I'm saying Google _deserves_ to have freeloaders milking them for every bit they can. So does Meta, Microsoft, Apple, Netflix, Amazon...
The content creators I support get their money on Patreon or whatever fundraising platforms they use. Same things for my favorite journals. The others ? Well, I don't care enough about them to think that I would pay for them. Maybe others will. And if they don't, well, they'll stop.
Why not get your content from ad-free platforms?
It would be, if Google didn't have a chokehold on most of the internet. Sure, Nebula exists, I can watch three creators there, woohoo. Let me go on Dailymotion too for those sweet 2005 videos.
Google did everything in their power to force themselves into every aspect of our lives and leaving no alternatives, or destroying them, or buying them. Now they get to deal with the consequences
The reason most publishers post on YouTube is because they depend on the revenue from the YouTube network.
If you don't want to watch ads, fine, but you are expressly violating the wishes of the people who are creating the content and then rationalizing it to yourself. The fact that you still rationalize not buying the ad-free premium offering is the kicker.
It costs creators literally nothing to upload an mp4 file to a second website and it would create market forces where youtube now has to compete for views with those alternate platforms (even if it's fragmented). But they're not doing it. Okay, so then I need to use youtube, doesn't mean I need to give google my payment information to pay a fraction of that money onto creators and mainly further their adtech
The ad industry brought the current situation on to themselves.
Am I not telling them with my wallet to develop other ad-free solutions that I will pay them and the content creators money for?
> They pay the creators per impression even if you block the ads. Blocking ads harms Google, not the content producers.
Blocking ads and refusing to pay any money into the YT ecosystem decreases the revenue per viewer which will eventually reduce the amount of money YT pays to creators and/or increase the price they charge to YT premium subscribers.
Youtube specifically has a plethora of useful information made by normal people. You can find hundreds of thousands of videos, in most languages, about doing most basic and complex repairs for almost any model of car made in the last few decades, for example. It is essentially a giant public library.
Sometimes this is a publicly tradable for profit endeavor, sometimes it is private or perhaps non-profit(all profits have to be distributed back into the corporation), or even an actual public corporation(often called a town or a city,
What, precisely, is the “threat” that Google presents that does not rely on a government to be the muscle. Are they going to cancel your Gmail account? Cut you off from YouTube?
Surely if they actually are as powerful and dangerous as you think they are you wouldn’t use their stuff at all. But then I guess they wouldn’t be all that powerful if you could just stop using them…
Try that with Google, PayPal, Amazon, Apple, or any number of other companies when an error they've made but refuse to even explain, much less fix, threatens to wreck your livelihood.
To redress grievances with my government, I don't need to make the front page of HN or go viral on Twitter. We don't go a week around here without another front-page lamentation to appeal for noblesse oblige from one of these intentionally-faceless megacorps. That's not how you should have to deal with a company you're doing business with... but it is how you deal with a dictator who leaves you no other choice.
"Does entity X have a monopoly on violence?" If yes, they are a government. If no, they are not.
Whether X is nice or mean, important or unimportant, is irrelevant.
Oh and I'll be downloading my videos for offline viewing and listening to ad free unrestricted music as well.
ID EXT RESOLUTION FPS CH │ FILESIZE TBR PROTO │ VCODEC VBR ACODEC ABR ASR MORE INFO
────────────────────────────────────────────────────────────────────────────────────────────────────────────────
233 mp4 audio only │ m3u8 │ audio only unknown Default
234 mp4 audio only │ m3u8 │ audio only unknown Default
599 m4a audio only 2 │ 1.05MiB 31k https │ audio only mp4a.40.5 31k 22k ultralow, m4a_dash
600 webm audio only 2 │ 1.27MiB 37k https │ audio only opus 37k 48k ultralow, webm_dash
139 m4a audio only 2 │ 1.67MiB 49k https │ audio only mp4a.40.5 49k 22k low, m4a_dash
249 webm audio only 2 │ 1.86MiB 55k https │ audio only opus 55k 48k low, webm_dash
250 webm audio only 2 │ 2.44MiB 71k https │ audio only opus 71k 48k low, webm_dash
140 m4a audio only 2 │ 4.42MiB 130k https │ audio only mp4a.40.2 130k 44k medium, m4a_dash
251 webm audio only 2 │ 4.71MiB 138k https │ audio only opus 138k 48k medium, webm_dash
Hm ... no mp3 (my car accepts mp3 only) and the bit rate is not very high. Is youtube music that bad?Both AAC and Opus fix some of MP3's inherent design problems (like imperfect handling of short sharp transients no matter how much bitrate you throw at it), so the only reason to continue using MP3 is for compatibility with old devices.
Since downloads aren't an official part of Youtube's offering, they don't have to care about old offline-only hardware players only supporting MP3, either and anything that's modern enough to still support either a Youtube app or the website will also support either AAC or Opus.
> the bit rate is not very high
There's also a high bitrate available, but only for subscribers.
Sorry, was that supposed to be a gotcha?
Paying for things you use is how you signal you like the product. The insane contortions people resort to in order to justify piracy boggles my mind. You either pay by watching ads or you pay the premium price. No one is entitled to YouTube. YouTube has to be paid for in order for it to exist and the creators to make stuff. That is the reason to pay for premium.
This is their job, after all.
[1] also, if tracking can help to replace idiotic ads like that with ones for some b2b software product I’d actually be interested in knowing about, please track me.
They still haven't appeared. When I consider what I trade for the ads I'm getting now, it's no where near good enough. My data is valuable and Google et al just aren't offering enough in return. The only place I ever see decent ads is on Google's search page.
I think the reason we see shitty ads like the belly fat ones, is because Google isn't actually trying to serve us first. Their main concern is ad dollars. So even though Google knows you watched a video on changing guitar strings an hour ago and now you are standing in a Guitar Center, instead of showing you an ad for guitar strings, you're going to see an ad for belly fat because that advertiser is willing to pay a fraction of a penny more.
So to answer your question about why you should care - it's because you are greatly overpaying for the service you are getting. Of course there are other reasons too - avoiding ads containing malware is one. Protecting yourself from tyrants is another. If you are socially or politically active, you may not trust that the government now or in the future can resist grabbing the data that shows you support abortion rights or attended a BLM or LGBTQ march or were part of the crowd on Jan 6.
Let me ask you this - if you learned the tracking is actually a person on the other side of the planet watching in real time, everything you do online, every conversation you have, every site you visit, and mix it with the data they can get from your phone (location, phone calls, music preferences, who you are spending time with, etc...) and they manually log it into a database, would that change how you feel about it?
If I added up the total ad time I’d have to see on a free account, the math would heavily favor paying to not see them vs my (or really most software engineers at the level of YouTube I consume)’s hourly rate.
It’s made decisions much easier for me if I take my hourly post-tax rate and compare it to services I’m using. If math works out, it’s generally worth it.
I’d love to fight the good fight against ads and stuff, but between working 9-5 and a side business, relationships, hobbies, I just don’t have the time.
I appreciate advertising money pays the salaries of people in such companies, but there are other less intrusive ways. Since I've grown up with the evolution of internet advertising, my brain is wired to just ignore it. I can't saying I've knowingly be influence by any form of internet advertising, ever.
A better solution for all concerned would just be to watermark a corner of a video with 'sponsored by company X' than the hours of human effort wasted in squeezing 30 seconds of adverts into everything, and the effort of people to block and get around that.
Oh, that's OK, unknowing influence will do.
The way you phrase it makes it seem like you think they slapped ads on something that would have otherwise been a free gift.
No
this is false. if they can’t show the ad they won’t pay the content creator.
I agree with OP that the $13 I spend on YouTube is easy money. Would happily spend that amount or more on an alternative.
I wouldn't support them that way. They shaft creators in every way possible.
You should be subscribing to Patreons and their video subscriptions. YouTube Premium is NOT the way.
So have 100 different Patreon subscriptions each month? The minimum pledge is $1. What if I watch 200 different YT creators? What about the short videos? Should I create a new Patreon subscription for each individual creator I watch? What if my interests frequently change (they do). Should I spend hours per month managing individual Patreon subscriptions?
The original post is about blocking ads. Blocking ads reduces the amount of money going to creators. Now you are saying that paying actual real money to not see ads is also not the way.
> They shaft creators in every way possible.
I guess this could be true that YT "shaft[s] creators in every way possible". If this were true, I'm somehow guessing that not basically everyone would show their videos there, don't you think?
There's a balance here; being universally against ads (which quite a few people here are) while also refusing to pay anything for content is not a congruent view.
At a very minimum there is considerable costs associated with delivering the video content, as most of us know.
And for the record, I do patronize the creators whom I watch lots of consistently.
The fact that content creators are still using Youtube doesn't mean Youtube is not shafting content creators. Youtube has killed most of their competitors so it's not like content creators have other options right now, but I suspect new competitors will show up if Google continue to enshitify youtube.
Source: I'm a full time youtuber, I have done Patreon for over a year, and I have friends who are also full time youtubers.
Keep your hand in the adblocking world because it's morally right.
People can do two things.
If you're talking about them building a secret extra profile about you with those things turned off, then they wouldn't need you to login for that.
If you don’t use an account you can create a fresh container every once in a while and start the game anew and you can choose to not associate it all with your identity.
You can ‘pause history’ which means ‘If you turn off your YouTube watch history and have no significant prior watch history, YouTube features that rely on your watch history to give video recommendations, like recommendations on the YouTube homepage, are removed.’ it doesn’t mean they don’t store it.
Google stores everything and deletes nothing. If you don’t want Google to keep track of information, you have to make sure they don’t have it and never get it.
This would be a clear GDPR violation. This isn't the 2000s or 2010s any more.
Because what happens over time is that some new feature or service comes along that you have to also opt out of.
even if you uninstall, remove from history in the app, and remove from Google account history, future API calls reflect that you've installed the app before.
Afaik From ad revenue channels get 55%. They also get money from premium subscribers depending on how much time they spent on channel. I wouldn't call it peanuts.
Louis Rossmann:
> If you gave a creator even $1 as a donation that is more than they will make from you watching years of ads on their content.
I just don't feel like paying 100 different youtube channels $1-$2 each every year.
They say they pay out 55% of ad revenue per video and 55% of subscription revenue.
Assuming 10% of video creators have successfully set up monetization (I made up that number), then they are only paying out 5.5% of ad revenue, since (as far as I know) the unclaimed ad revenue is not pooled and the distributed proportionately to other accounts.
It’s unclear if they put YouTube premium revenue in per-creator buckets in the same way as they do ad revenue. If so, then they would only be paying out 5.5% of subscription revenue in my 10% example. If, on the other hand, subscription revenue is split amongst just the monetized creators that you personally watch, then they would be paying the 55% their marketing department likes to brag about.
I haven’t been able to figure out which way they do the accounting.
However, as of 2021, over their service lifetime, they paid $30B to creators. Their 2022 revenue was $29B
So, they’re definitely keeping the vast majority of the combined ad and subscription money that comes in the front door (or revenue exploded in 2022).
Support page clearly explains about revenue sharing, I don't see anything about pooling:
https://support.google.com/youtube/answer/72902?hl=en#zippy=...
If you ever tried to self host you'll know just how expensive that is.
Youtube is actually one of the good companies out there when it comes to paying creators a fair share. No other company that I know of pay creators this well, and it is probably a big reason for their continued success.
It's not only more effective, but also doesn't support Google (main player in the ad industry)
Something that costs rather steep amount of money?
Youtube is one of the best things on the internet. The shame is that it's centralized with a single point of failure.
The upsides of youtube are enormous - people learn a lot there. It's not just nerds learning about stuff, but everyone. How do I fix this thing on my car, etc? People show and tell about all kinds of topics. This is making people more knowledgeable and capable on a citizen level(!)
The written word champions here will have to realize that for some, videos are a superior medium for transmitting know-how.
The obvious reality here is that RandyLahey1989 from Halifax probably isn’t going to start a Substack about snowmobile repair, nor would anyone read it if he did, but his video on replacing the carb in a 2011 Switchback has hundreds of comments thanking him for his help. Wouldn’t you agree the internet’s a better place for giving Randy the chance to share his domain knowledge (and get paid for it)?
I seriously think the “everything should be an article” crowd is a bit disconnected with how the average person prefers to create. The future of consumption is video for a growing majority of internet users, one would be a fool to pretend otherwise.
I’d want the summary and images to be verbatim from the video, but for it to strip crap like “hey, it’s been a while since I made my last video, as you can see behind me, nessie the cow is caught in a tree in my vertical farm wall again, which you can see another video about. Today, we are going to explain how to open this laptop, but first I’m going to talk about [product placement]”
We deserve butter! https://butter.sonnet.io/
Also you have more control over where the money goes with Patreon, and they’re far better corporate citizens than google.
> Disclaimer: I want to support content creators, so to be fair, after a few months of blocking YouTube ads, I am now paying for YouTube Premium; Just because I can break something, doesn’t mean I need to.
Did you even open the article?
>https://xn--rr6sn-uxa0n-t8gz-vg6i.googlevideo.com/initplayba... &orc=1&oeis=1&c=IOS&oss=1&oda=1&oad=5500&ovd=5500&oaad=11000&oavd=11000 &ocs=700&oputc=1&oses=1&ofpcc=1&osbr=1&osnz=1&msp=1&odeak=1&odepv=1 &osfc=1&id=58cc678216d6aaca&ip=121.35.98.26&initcwndbps=2125000 &mt=1640373902
This is one of the many things that make it _exactly_ like malware. Ads are delivered the same way malicious code or artifacts would be delivered to your device.
Weird-ass random subdomains, obfuscated query params -- no legitimate service that works for the user's benefit should behave like this.
But it's googlevideo.com. I know this is Google/YouTube's domain so the rest doesn't matter.
The fact of the matter is these techniques are well established black hat ways of preventing the user from discovering what you're doing on their device.
And I won't even call them "obfuscated" -- it's just a batch of switches and plain IP and ID hash.
But it's a google ad, how could it link to a scam that looks exactly like my bank's website?
Those days are gone as the distinction between ads and malware becomes a technicality.
> In fact, the YouTube app is zippier because fewer connections are made to ad URLs in the first place.
I swear on LG TV that webOS runs at a smooth 60 FPS when it's not connected to Wi-Fi and slows down as soon as it phones home for whatever telemetry and ads LG intend to serve me...
The solution: I set up a query param that would disable google tag manager. All of the crazy tracking and telemetry stuff we didn't control was the biggest issue.
I am not sure who is to blame, but I guess there is no way we can get the simple web we loved back.
Failing all engineering effort, they could have use a beefer CPU...
In my experience, there was a noticable performance improvement as well. Bootup times alone are probably 2x-3x faster.
[1] https://www.reddit.com/r/LGOLED/comments/1571djx/guide_how_t...
I commented about it a while back here: https://news.ycombinator.com/item?id=34374725
I’ll just block ads, alphabet is doing fine anyway.
But as the OP says…the problem is that this is not feasible on mobile or TVs.
On my tv… i purposedly picked a tv without any form of smart feature, and have a small nuc to use the aforementioned proxy.
It's maddening how people just refuse to understand the GDPR. This is likely partly due to intentional misinformation campaigns from the spyware (i.e. advertisement) industry. And then the cargo cult takes care of the rest.
The general gist of GDPR is that if you're not doing some shady shit that your visitors wouldn't want you to do, you don't need a consent. As you said, it has nothing to do with cookies.
And yes, Google Analytics etc are shady shit that your visitors wouldn't want you to do.
Also most of the nags you see all the time are illegal for any sane intepretation of the law. But the regulators just don't care to enforce the law at all. So if you want to do shady shit, just do it without adding to the insult with having to bother with your illegal nag.
If you watch and enjoy YouTube in any capacity you should be ensuring that the creators get paid otherwise you’re robbing yourself of content.