InstallMonetizer quietly starts editing website, privacy policy
withinwindows.com
withinwindows.com
PG: we never got an update after you said you were "investigating". Can you elaborate at all?
Don't expect that pg will come tomorrow and say "I investigated. Yep, they are morons. Don't use it!" Expect same changes and a blog post from InstallMonetizer saying "We appreciate the feedback of the community and to improve the product we ..."
From looking at this, it looks like maybe some of their advertisers did cross the line, but I don't think desktop app install monetization is inherently evil. It's slightly annoying that Oracle/Sun bundles the Ask Jeeves toolbar with Java, for instance, but it's not any more annoying than having to pay $6 to cross the bridge.
I don't really understand why YC would get behind such a business. Money isn't everything. I guess they want to disrupt malware with some new even more horrible malwares.
e.g. when you try to download/install Confluence, they cross-promote some other Atlassian products. It's not done too hard (and I can't find an example of it now). I've seen other "first party" examples of upsell where you are going for one product and add another product from the same vendor.
I've also seen lots of horrible malware, trash, etc. That's almost always what you see with PPI.
I think PPI is like banner ads were pre-Google. What we need is the "AdSense of PPI" to deliver really contextually relevant/well targeted PPI to users. The problem is I suspect this is really hard -- offering a $1-2 payout to put a crappy toolbar is nearly the optimum for any mass market piece of software. But, if you had more targeted software (say, an awesome reverse engineering tool), there would probably be related tools you could promote at the same time which would be win/win.
The irony is you're more likely to see this as a third-party service, since individual volumes on tools with niche userbases are really low, unless a publisher has a bunch of complementary products in-house. There's nothing specific enough for a Java JRE downloader to win out over a shitty toolbar. There isn't enough volume for a decompiler to pay someone in-house to go out and negotiate a deal with a fuzzer or something, so you either do nothing, or run shitty toolbars, or hope for a company who could provide really targeted PPI for smaller niche publishers.
I'm not saying InstallMonetizer is that now or ever, but if someone did that, I'd be really happy with them. It may or may not be a good business model, though.
We have Jenkins set up to input data into Jira, unfortunately that integration isn't entirely fantastic and doesn't always work as well as one would hope. Mainly because Jira's SOAP API is an absolute mess.
I'm surprised that YC would get involved in something as shady as this. Even if the company has good intentions, if it takes off then it's main customers are less likely to in the long run.
[1] - http://www.technologyreview.com/news/424241/most-malware-tie...
This isn't to say that these installers shouldn't be allowed to exist. Just that in general I hold YC to a higher standard. If they want to go that way, that is fine, just begins to change my opinion on the program.
Google ads are useful but almost always if you follow up you will end up paying a lot more vs scrolling down to skip the ads. Ads cost money and all and eventually someone has to pay that.
These days, searching for items and commercial topics, all I see is ads in the first page or two so for traffic ads are it. In fact, many times I click without realizing I clicked on an ad.
Low and behold traffic to other sites from Google is collapsing (1) and while good organic may cost money they should cost a lot less than $x to $xx for each click.
1 (for the second year in the row users are doing less desktop searches on Google and Google's ad clicks have increased by a lot so it's simple math)
Most definitely negative. It sounds like he's been monitoring their website, just waiting to follow up with this post.
"The change is a half-baked attempt to clear up whether information collected by its junkware installers is personally identifiable or not."
...
"Totally worth $500,000."
Well actually, they raised $500,000, presumably at a valuation at least several times higher.
Anyway, I'm sure they've gotten the message that they're being watched closely. I'd give it some time to see how things play out.
They don't even encrypt passwords, so God help those advertisers/publishers whose information they store...
(HN Geek Corner: curl "hxxp://www.haycfld.us/htmlscreens/OfferScreen_[1-1000].zip" -o "OfferScreen_#1.zip" -f
This will pull down all the bundles they offer. Interestingly, you'll find they only have 42 current advertisers... and not Norton/others listed on the site. So add liars to the list of words to describe this company.)
http://installmonetizer.com/AT_Help.php
5 of the 42 Offer Screens are duplicates / same company, so I only count 37 advertisers. That's assuming this is the entirety of the offers available.At least one of the offers "allows you to find retailers... by inserting contextual links on websites you are browsing". Another says "In order to keep software free, you will be served advertising through in-text and pop-up ads in your browser, they are targeted and relevant."
I'd love to know why this was funded.
Yes there is a difference. I teach people to work with computers, some are really clever and do amazing things, and some of them have trouble with relatively basic things such as navigating an "Open file ..." dialog window.
None of these people would have any problems grasping the idea of having the options 1) pay $6 and cross the bridge, or 2) don't pay $6 and find another route.
But neither the 7-year old kid, nor the grandmother will be able to figure out how to uninstall this Ask toolbar.
And maybe one Ask toolbar doesn't mess up your computer, but it is one more thing they did not ask for, and those things do add up to a slow and unusable computer.
That sucks. And here's the reason why it in fact is inherently evil: But even then, they did not ask for it, were never in the position to make an informed choice, and do not know how to revert the choice they did not wilfully make. It is preying on the weak.
I have seen cases like am 8 year old kid, who had just obtained his first PC (looked like it used to be a thin client, must've been real cheap, but not in terms of weeks pocket money!), it was infested with crapware, I swear I turned my back for a few moments and saw another toolbar had appeared. Unfortunately, as you probably know, fixing a computer like that takes a whole afternoon, but that's not the job I'm there for (I can make that kind of time to help out my parents occasionally but that's about it). This kid came from a low-income family, his two parents not exactly the brightest when it comes to computers either, so, what now? Breaks my heart, really. Paying someone to clean a computer is expensive, and they don't always do a good job either (or leave some remote desktop tool in place, etc etc).
How is this not evil?
If you want to make a non-computer analogy, how about being tricked into accepting some ridiculously overpriced service in a foreign country where you don't speak the language? Classic tourist con. Those who do speak the language say "No thanks", and walk away wondering what suckers fall for such an obvious trick.
They could combine the MAC with some other identifiers, like perhaps the product key from Windows or disk volume serials and hash that together.
So, in about three and a half days you could generate the whole space of MAC addresses (assuming that they only protect it with a single MD5 hash). You'd need about 1.7 petabytes to store it.
As an example, a $17 802.11n travel router I bought from Monoprice a few weeks ago uses 00-B0-C0 as the OUI, which has no corresponding entry in IEEE's OUI database. In the past, I've purchased cheapo no-name PCI Ethernet cards (usually with Realtek chipsets and lots of empty pads and/or through-holes on the PCBs where capacitors are supposed to go) which had similarly unregistered OUIs in their MAC addresses.
IMO Non-optional installation of adware/toolbars etc. crosses the line towards "evil" malware.
Forgive me if I'm missing something about TCP/IP, but why does that matter? Couldn't a man in the middle get your mac address anyway?
If not, I don't see this as such a flaw. I think they must have meant that they store it as a hash in the database. That way your data in their db is not linked to your true self/computer.
Second, MAC address is only exposed on the local network. It is not transmitted over the Internet, it's only at the link layer to identify nodes.