FBI recommends using an ad blocker (2022)
ic3.gov
ic3.gov
POV:
If you don’t mind, I’m truly curious why you don’t Adblock? There’s no wrong answer here. ;)
I quite like Ka-block
Apple gobbles personal data too and processes it and sells it etc. They are simply rather better at looking ... friendly. They really are very good at that.
Disclosure: I work at Apple, and have seen zero evidence of anything but trying to make things continuously more secure and private. This in fact makes my job (machine learning) much harder because I don’t have user datasets to leverage.
What data and how do you know? This seems to be a popular talking point, but I’ve yet to see evidence. It doesn’t make that much sense to frame Apple’s privacy stance as similar to Google’s or Facebook’s. Apple isn’t an ad business, and Google and Facebook are, plain and simple.
I don’t work for Apple, and I don’t use an Apple laptop or desktop, but I don’t buy this Apple is as bad as businesses that are primarily built on ad revenue and are actively eroding privacy. I’m sure they’re not perfect, but I feel like Apple is relatively serious about privacy, making real changes that generally protect consumers, and setting a better example than many big tech companies. Are you sure they don't look better because they really are better?
Then why do they push their crappy browser on iOS which doesn't allow ad-blockers?
So? That’s true on Android too. If you want to use a browser with an ad-blocker, you can on iOS, just like on Android. What’s your claim again?
Android partisans will answer questions the way Android partisans answer questions I.e. buy Android.
Even Google (the biggest ad-tech company) isn't that bad: they obviously don't make an ad-blocker themselves, and they've worked against ad-blockers in the Android Chrome browser, but they don't do anything to stop users from installing an alternative browser which supports ad-blocking. You can install Firefox directly from the Google Play store. (Note that the same is not true for ad-blocking alternative YouTube clients like ReVanced or SmartTube, but you can't use those on iOS either of course. And even here, while Google won't allow them in the Play store, you can simply install them directly from the .apk files, something you can't do on iOS.)
By preventing users from exercising choice, Apple has taken on responsibility for them not being able to avoid ads.
Safari does take active steps to prevent tracking that Chrome does not. Apple has not actively worked against ad blockers the way Google has. And Apple also allows you to install a different browser on iOS, Google doesn’t get any gold stars for not preventing third party browsers on Android.
Google has a conflict of interest between your privacy and their primary source of revenue. That’s not true for Apple. Google isn’t that bad?!? Hahahaha BTW you moved the goal posts, the claim you were implicitly defending was that Apple was collecting and selling private data themselves. Nothing in this thread so far backs up that claim.
Does it? Then why do all the iOS users complain about having to watch YouTube ads? Sounds like it doesn't allow good ad-blockers.
>And even if they didn’t, there’s an absolutely massive difference between not being able to block ads and being the company both selling the ads and the browser that is engineering away your privacy.
This is completely wrong. If (for the sake of argument) iOS definitely didn't allow ad-blocking, then that makes them worse than Google, and it does mean they are "actively working against ad-blockers". If they weren't working against them (in this scenario), they wouldn't disallow them.
>And Apple also allows you to install a different browser on iOS
No, it doesn't. It only allows re-skins of Safari.
>Google doesn’t get any gold stars for not preventing third party browsers on Android.
Yes it does. Let me know when I can side-load an open-source ad-blocking YouTube viewer app on iOS, or even just installing the browser of my choice (not a re-skin).
>Google has a conflict of interest between your privacy and their primary source of revenue.
Sure, but they also allow you freedom with Android devices, and that's something you'll never get with Apple.
> the claim you were implicitly defending was that Apple was collecting and selling private data themselves.
I never defended that particular claim. I only made my own tangential claims.
This is irrelevant, you’re confusing the engine and the browser. Chrome on WebKit is not a re-skin of Safari, it’s a Google browser, and it’s Google’s choice to not support ublock Origin on iOS, but nice try. Plus you missed the news that non-WebKit engines are now allowed in the EU and it’s only a matter of time before it spreads.
Google has announced their intention to stop serving YouTube content to anyone using an ad Blocker. Maybe soon you’ll see first hand how misguided and silly your argument against Apple is.
> Does it? Then why do all the iOS users complain…
Weird, it seems like we just had this conversation. That question was asked and answered. Did the fact that Apple does allow ad blockers, and the difference between the YouTube app and the browser not make sense the first time we talked about it?
BTW, the first Google autocomplete response I get for “how to block youtube ads on” is “Android”. That is evidence that more Android users complain about YouTube ads than iOS users.
P.S. who puts the ads on YouTube that you’re complaining about and makes them hard to skip or block? Oh, right, Google.
What I would admit is that Apple is maybe not as motivated to protect your data from unintentional leaking. Without user data, Google would be almost nothing. So they have to be extremely careful to maintain the trust of their users. For Apple (or Microsoft) their business is still sizeable enough with out user data.
I do have other browsers, but I only use them for specific needs. Like I keep some version of a Chrome-based browser around solely for if I need to Chromecast something. Other wise, I do not enjoy using third party browsers like Chrome, Firefox, etc., which I use at work all day.
Safari's web developer tools are not my favorite compared to other browsers, so I try not to develop much with Safari other than testing.
I also have a low threshold for obnoxious sites, and will just bail and not return if I get annoyed.
One store kept popping up that I was not familiar with. So I clicked eventually, and did some online searching about the company to make sure they are legit.
Turns out they are a local independent store. I've made two purchases from them since, and price compared against them for other purchases. Their ads are more likely to catch my eye in the future now.
"naturally"
A) Want me to pay to view a one-off article B) Want me to not see any of their content cause its ad infested.
To be fair, if Firefox's Reader Mode doesn't suffice as a bypass, then I really don't bother coming back.
Or do you not use any blockers at all?
Especially at work most sites I visit aren't ad infested hellscapes, like StackOverflow and its relatives are not ad infested, neither is wikipedia, etc.
Yes, you have to write a pattern. It saves you money while not supporting the erosion of autonomy. What's better than free vegetables? Delivery.
I'm away from my computer right now but I'll copy one of mine later/reply with it. The edit window here is unfortunate.
Eradication/filtering:
##a[href*="eng-leadership.com"]
Shown, but blocked on-access: ||eng-leadership.com^$document
To keep the hacker spirit alive, I leave the reader with an exercise. Consider other approaches or HTML tags. Anchors aren't their only vector, hence the document method.HN has a 'hide' button that could be leveraged for nicer integration, removing related widgets.
Solving my problem the "hacker way" would essentially be reimplementing Kagi, or hosting a service to do it. I already host Open WebUI and that is really moving along; maybe it can replace my Kagi needs someday, but for now I am pretty happy with continuing to use Kagi.
Again, my ultimate goal really is autonomy. There is still hacker spirit in your approach, fighting the status quo. It has my general support, even if I'm not a customer
I just wanted to remind people to look more nearby/within, too. This isn't a battle won once
That alone is worth the price of admission
There is a lot more going on beneath the surface of just "annoying ads in my face" which need to be accounted for, since browsers do not ship with effective, granular security controls.
Usually if I'm on somebody else's computer it's because they need me to fix things for them, or speed things up or 'make it better' which means it's getting adblock. The amount of modals and tricks and things they fall for especially my elderly neighbors or people wanting their business laptops setup especially Windows that have jank ass webpages that have the 'Download' link be some arbitrary .exe for something completely not what they wanted to download put something on their system is crazy.. hell even Youtube is giving people scams.
I just fixed some women's sobriety center's computer for free and their user account had some anti virus secure browser opening 20+ 'browsers' on boot for 'AG' free anti-virus.
Never had an issue with ublock breaking anything important for me. Air travel, hotels, ordering things online, if something says disable my adblocker I close it out and never go to that domain again.
To each their own though. I don't do ads though and will save every soul I can. Ad-tech is cyber terrorism at this point, and I stick to my guns.
In that situation of using someone else's device, I've had to move windows half off the screen to be able to concentrate on an article when the ads on the side were constantly distracting me.
Not only that, but you're wrong on a technicality too - > and every single one of those ads were programmed by... a software engineer!
Many ads are designed by creatives and placed and run by dedicated non-software engineering people, including deciding how many are run and their placement (i.e. bombardment or not). Sure engineers programmed the platform, but then you're just blaming the post office for the content of the mail, or the ISP for the content of the internet. What do you expect the software engineers to do? Limit 1 ad per page programatically and then every software engineer on earth must agree to enforce that limit and no matter how much pressure their superiors put on them, everybody holds the line?
This is not a rhetorical question, How do you expect all software engineers to be unified on a single solution to ad bombardment, given the internet is international, driven by market dynamics and capitalism and a non-trivial number of programmers are beholden to tyrannical managers because of their life situation (it can still be a minority, and ad bombardment emerges)?
By developing a consensus that it is not ok to do that type of behavior (bombardment of ads, surveillance capitalism, etc) and changing the culture
Changing bad behavior by corporations (esp. adtech/advertisers) is likely to be about as successful: it's not going to be done by "changing" the culture, but only by changing the laws, and then enforcing those laws and punishing offenders. Just like a rapist sees nothing wrong with raping a person, or a serial killer sees nothing wrong with murdering many strangers, or a "porch pirate" sees nothing wrong with stealing your Amazon delivery, an ad-tech corporation sees nothing wrong with feeding you psychologically manipulative advertising and blatant malware in search of profit.
No. They did not. They explicity said "mostly works".
> but this is blatantly false:
Of course it is. You set up a blantantly false strawman. Please don't use obviously piss weak rhetorical tactics, they make you look bad.
> every country has prisons with many criminals
And every country has varying incarceration rates, they are not all equal.
What should be looked at is countries by cultural attitudes towards crime and incarceration rates .. and the harder question of just how innately criminal imprisoned people are in various countries and whether they are just there from systemic features of a culture.
Again, there are no one size fits all answers and people aren't homogenous.
That was my exact point with the previous post blaming "software engineers" for ads.
Who said that police are not part of the culture?
I'm not arguing whether or not we need police, I'm arguing that if we come to a consensus (i.e., we agree that surveillance capitalism, etc, is not ok), then we can stop the problem. That may mean we even criminalize certain behaviors if we believe it is necessary. But the foundation is consensus. So let's do that- I firmly believe that surveillance capitalism and the bombardment of ads is not ok. What about you?
That sounds cool...but such coordinated, idealistic behavior never occurs in human beings.
See? That logic doesn't work so well. "Software engineers" are not a singular entity nor a homogeneous group. To maintain the status quo, it doesn't take more than just a few SWEs willing to implement ads and/or invasive tracking.
The people on this site are a group of humans uniquely equipped to actually speak and interact with the people responsible for this bullshit.
> The people on this site are a group of humans uniquely equipped to actually speak and interact with the people responsible for this bullshit.
There's not any method whatsoever for the people on this site to force all ad software developers to stop developing ad software.
I guess all the cybersecurity engineers should just quit because they're the ones to blame for all the malware...
Similarly, the only reason humans work as police is because humans commit crimes. So humans are really to blame for this problem.
I feel the same way about software for war fighting, which obviously has higher stakes. The profession itself doesn't push back on the ethics of it AND individual practitioners are actively developing death-dealing software.
You're acting like the profession has some kind of central authority. It does not. It's like asking for agreed-upon ethical standards for dog walkers; you're not going to get it, because there's nothing resembling a centralized organization, nor any kind of licensing for this profession.
>I feel the same way about software for war fighting,
If you want to eliminate software for war fighting, this is a fool's errand. Weapons for war are absolutely necessary, unless you want to be a victim to some dictator who doesn't agree with your ethical principles. History is full of examples of peaceful people who couldn't withstand an assault by other people who didn't believe in peace. In fact, I'd go so far as to claim that eliminating warfare (and the military apparatus for it: armies and navies etc.) is impossible as long as separate countries exist. Only if we manage to either conquer everyone or get everyone to agree to join a single planetary government can war really be eliminated. And that assumes that hostile aliens won't ever be a problem.
Even if there was some centralized group that created an ethical standard for conduct, do you really think that that would escape the influence of software companies like Google, Facebook, Amazon, etc. that have a vested interest in advertisement? Or that every software engineer would follow such a standard of conduct?
Members of a minority group, such as race or religion or sexual orientation are generally members of that group by birth, not by choice.
Members of the group 'software engineers' are members of that group by (career) choice.
Your key point here is a tautology; it doesn't really lead to any insight.
Here's a particularly salient critique of these very same FBI recommendations, from my article:
> The FBI suggests “Before clicking on an advertisement, check the URL to make sure the site is authentic. A malicious domain name may be similar to the intended URL but with typos or a misplaced letter.” — this is useless advice in the face of unverified vanity URLs
But it's funny I remember adsense fighting the bs fraud ads on the internet, only to become the bs fraud themselves..
I think the issue here is we have allowed online platforms to reap the rewards of scale without requiring any responsibility of serving a billion+ people. Internalize rewards, externalize responsibility.
Link fraud is entirely preventable in an automated fashion. They just need to start enforcing their own policies.
Validating ownership of 'display URL' domains via DNS would completely eliminate the issue. It's quite simple.
In other words, there is code in the backend checking that all tracking/-ware has run on the browser, and refusing to let you login unless you let it all run, while none of it is necessary (as evidenced by older versions - and other sites - accepting only the top site being JS-enabled).
"We either track the living shit out of you, or you don't access the essential services you need, even though technically it is not needed."
Things like this are why I worry a bit about the proliferation of things like WASM, while JavaScript isn't great, it actually gives a great amount of control to the end user, to both see, understand and the ability to actually modify what is running in their browser. With WASM, all of this becomes highly impractical. Instead of a (semi-)readable, modifiable block of interpreted code, with the ability to inspect and modify the state at almost arbitrary points, you just get opaque binary blobs that you basically can't do anything with. As more and more sites switch to using compiled WASM blobs for their logic, it will become increasingly difficult to observe or modify any behavior of these websites as an end user.
The original Google site hit the perfect pitch, where they set a few unobtrusive ones out of the way alongside your results screen. Ironic they pioneered and eventually normalized what is now an epidemic of user-hostile spam all over the web. I feel as a whole we lose a lot more productivity and focus to this than we gain in economic activity.
For your nostalgia and/or despair, I found a chronological list of screenshots: https://scaledon.com/the-evolution-of-google-ads/
Can someone please explain these two sentences to me?
https://www.microsoft.com/en-us/edge/learning-center/using-a...
https://support.microsoft.com/en-us/office/supported-browser...
The counter-argument that they don't need to know their customer/ad and are just dumb-pipes doesn't sit well with me: Them having awareness of ad-content and display-context is ostensibly part of their business model.
P.S.: I don't mean just liable for a part of the damages, although that would be a good start. I mean that if your Aunt Tillie gets served an ad of "Your computer is infected, click here to contact a Microsoft Technican" there should be some negative repercussions for the company, even if your Aunt Tillie is secretly the hacker BakinC00kies and spins up a honeypot.
The FBI now recommends using an ad blocker when searching the web:
https://news.ycombinator.com/item?id=34916239
734 points | 2 years ago | 430 comments
When situations like this happen, I mostly place the blame on ad companies. It’s their product, so it should be their responsibility to prevent abuses. But there is scant regulation, and the ad industry itself has little concern for privacy and data protection. Why would it waste money being proactive and effective against malicious ads?
It is nice to see the government recommending ad blockers. However, it bothers me that it is up to us, users and customers, to deal with the negligence of ad companies.
YouTube/hulu/disney+ still cut to ads instead of displaying them around the border of the content.
Carl’s Jr/Brawndo still haven’t purchased the FCC.
We are pretty close though.
They still need to make people actually think that adverts are good
I tried pihole maybe 8 years ago, and it just broke too many websites for me to leave it on for my wife. It really frustrated her.
I've been running pi-hole at home for three or four years with minimal issues.
The times when I have seen issues, I just go to the admin webpage, disable blocking for some period of time, and try again. And it's almost never Pi-hole causing the issue unless I'm trying to click on an affiliate link[0].
I mention this not as something your wife might do, but to clarify that pi-hole (with default settings) almost never blocks anything I click on, and when it does, I'm almost always glad it did.
As such, assuming your wife isn't clicking marketing/advertising/affiliate links, pi-hole should be just fine for your home IMHO. As always, YMMV.
The gold standard which works as an extension in both chrome and Firefox is uBlock Origin, annoyingly not to be confused with uBlock.
https://addons.mozilla.org/en-US/firefox/addon/ublock-origin
https://chromewebstore.google.com/detail/ublock-origin/cjpal...
Also be aware that Google continues to add restrictions to extension permissions such that uBlock Origin may not be as effective as it once was.
That's fine. I don't use a Google made browser, so this would not affect me at all. It would also be very easy for this to not affect you too if you just had the courage to stop being a sheeple
So for them, it's better than nothing.
You would expect that the people who have the ability to write perfect selector rules to block ads and understand how all of this works would be the first to use them. But no.
I find it baffling too.
I can't remember the last time I noticed that the ad blocker even existed on my machine. Occasionally some clever site will basically say "if you can see this, we're supported by ads and could use your help" -- but it doesn't break things and I don't see ad links in search results.
Governments should start holding companies that sell ad space responsible for the ads they run. There's no way any company with the resources of Alphabet or Meta should be serving up phishing ads in their search results.
The fact that Google is presently trying to degrade the performance of ad blockers with Manifest V3 is not a good look. This is why we have consumer protection laws.
Yeah, good luck doing that with all the various tracking links that mask the actual domain. Sometimes I try to click on links from legit account related emails that are blocked by UBO for being part of a tracker/ad network.
I know perfect is the enemy of good and defense in depth and etc, etc, but this advice just seems crap.
If you've ever looked for a recipe, you'll know how many obstacles there is without ublock. My hate is towards these type of websites.
This may be sadly outdated. Android Chrome and iOS Webkit probably account for majority of traffic nowadays, and neither allows adblock extensions.
https://apps.apple.com/us/app/adguard-adblock-privacy/id1047...
Or does unlock origin lite cover everything?
I was thinking continent specific ad blockers etc
Manifest v3 fucking sucks, and people will probably need to go to system-wide ad blocking such as AdGuard to block ads using all the filters, as v3 limits the number of filters you can use.
Also, people who use adblock are antisocial.
Also, I'd be mortified if I visited a web page, then the site told me that I cannot continue because I have adblock installed. I wouldn't want that to happen to me even once.
I've noticed an increase in sites that do what you describe, but so far I've responded by no longer hanging out on those sites, and that feels OK.
The only sites that break are streaming sites. Which is expected, I mean they need to make their ad money and they sell ad-free tiers.
All except paramount plus, funny enough. Yes, you can get ad-free paramount plus for half the cost if you just use ublock origin! I guess they forgot to put in that little bit of logic.
It's an uncommon practice in my experience, and it's easy to understand why. 90+% of websites nowadays are click farms - their content is totally interchangeable with, if not plagiarized from, hundreds of other sites. The one site that implements an anti-adblocker measure simply gives up a portion of its traffic to another site that doesn't. The far more lucrative strategy is to try to subvert the ad blocker, which many sites actually do.