Google Says 5% of Visitors to Its Sites Have Ad Injectors Installed
techcrunch.com
techcrunch.com
Adwords is probably one of the main infection vectors for malware these days.
Previous rant: https://news.ycombinator.com/item?id=8879229
It's not about not wanting to support independent bloggers. It's about making sure that unsuspecting users don't accidentally download malware when they're doing something mundane like downloading their web browser.
In the age of the web, Adblock is the new anti-virus.
Also the javascript late load "oops click" tricks they're pulling to scam advertisers now (google search, youtube, bing search - all use late load javascript to get misclicks).
Same here. I couldn't be bothered to install AdBlock for many years, but the mandatory before-video ads were the straw that broke the camel's back for me.
> Also the javascript late load "oops click" tricks they're pulling to scam advertisers now (google search, youtube, bing search - all use late load javascript to get misclicks).
I've lost track of who is trying to scam who. The users are collateral damage anyway.
That's because people in general don't mind wasting a bit of screen space but the mandatory wasting of time is of a completely different order. Time is our most precious capital.
Of course, go back a year or so and everyone was screaming at ad providers for using blocking JavaScript.
On the other hand, it takes a long time, but they do learn to be more cynical about the Internet if they're exposed to its raw state.
My rule of thumb is "if nobody would write this without getting paid for it, then somebody probably got paid for it."
Do you have a source for that information?
It looks more like the OP's version to me, including 'softonic' as the third linked one. The top two are mozilla's (and I use an ad blocker so I don't see the ad).
On Chrome the first 6 links are mozilla's then the 'download sites' start.
The ads are not gone.
As I wrote in another comment, even YCombinator invested in a bundleware company and PG defended it, so I guess the problem is deep rooted.
Of course there is no way to tell Google that these aren't real sites (I tried) and distinguishing real text from Markov chains using a computer is hard.
I keep wondering what it will take for them to figure out bad content, both for the computer (javascript etc) and for people (english etc).
http://ipensatori.com/2015/03/20/google-update-to-software-d...
It downloaded very fast and I thought "well, maybe it's just an initializer that torrents the rest". NOPE. Within 30 seconds of the installer, it prompted to install an ad-bar in the browser. I quickly closed and researched for the official site.
It was scary, being a technical professional, and executing adware(malware?) installer while trying to install an open-source alternative to the most popular word-processor for a less-than-savvy family member.
It was the top result on Google at the time.
I worked at CBS Interactive when the Download.com installer/adware controversy erupted: http://insecure.org/news/download-com-fiasco.html
As you might expect, it was controversial inside the company as well. I guess things haven't changed after I left.
I think this issue must be solved on a regulatory level, i.e. Google (and Bing!) should be punished for providing malware links (and the actual providers of course).
Interestingly enough, the only commercial software that Linux people regularly install is it's own separate walled garden; Steam.
I can't speak for or against OS X, but with respect to Linux this is plainly false, unless by "Linux" you mean "Android" or by "walled garden" you mean "basic user authentication."
I was shocked, and to this day I find that utterly ridiculous.
A few years back I got a job to do a wordpress site for a client. However, I wasn't dealing directly with the client, I signed on through a friend who was a fellow staff member of a forum I frequented. He agreed to create their site despite the fact that he was almost entirely technologically illiterate. His skills were at the 'barely read email' and 'be puzzled by OSX window decorations' sort of level. So, I agreed to do the job.
After working on the site for a couple of weeks, one day I received a call from him. He was quite upset as he was seeing porn ads and random nonsense characters on the blog. I investigated and found no trace of ads or foreign code, using several devices and several separate Internet connections. However he could see the ads on multiple devices in his house. Attempts to get him to try another Internet connection like his phone service were unsuccessful. I was pretty sure there was nothing wrong with the site, which was hosted on my VPS along with a couple of other sites that had no sign of issues. However he grew progressively more worried that the client would see these ads on the page, which was live for some reason. I even engaged the help of 20 or so people from the forum to check and they all agreed that no porn ads were visible to them. However this just upset my friend more as he felt embarrassed, but still convinced there was a problem. I suspected he had a virus on the systems at his house (all Apple...) or his router. It ended up with me being banned from his forum and being forced to quit the job... Before finally someone reset his router and the porn ads disappeared.
So, content appearing from unknown sources has definitely caused me problems in the past.
The easiest way to get such trash on your computer is installing software from a commercial vendor. Oracle is one major source of headache, if you aren't careful you'll find your 'java' install also gives you a severe case of malware/crapware.
There are whole companies dedicated to this concept of piggy-backing junk.
Like Sourceforge? http://blog.gluster.org/2013/08/how-far-the-once-mighty-sour...
Then times got tough and sourceforge sold to new owners and that's when the trouble started.
Meanwhile, in the real world, Sourceforge injects adware in to downloads for open source projects. Trust is more subtle than open source/closed source.
I reworded it for generality, but specifically, "You can't trust anybody except open source repositories" does not imply "You can trust all open source repositories" in exactly the same way as, in more general terms, "You can't trust anybody outside of group X" does not imply "You can trust everybody inside of group X".
... including a YC company called InstallMonetizer: https://news.ycombinator.com/item?id=5092711
Downvoters are invited to explain what's wrong with this comment, I see installmonetizer as one of the low points in the history of YC and watsi as the high point, possibly the high point in VC investing in the last decade or more.
Just because YC has watsi doesn't mean they shouldn't have to explain why they're affiliated with InstallMonetizer, and justify their decision.
If I were in YC/PGs shoes I would have dropped installmonetizer the second I found out what they did but then again, I don't run the most successful start-up accelerator on the planet for a good reason.
In fact, I wouldn't have invested in them in the first place. But on the whole if you select for hackers driven to make money at any cost you can expect to get a rotten apple every now and then.
Whether or not YC should have dropped installmonetizer once it became clear what they were up to (if that wasn't clear from the application alone) is something everybody has to decide for themselves, for me it is clear that they should have.
Also, to their credit I haven't seen them invest in anything as shady as installmonetizer after that point so maybe some lessons were learned.
And is anyone really reading all of the code they run before they run it? With all of its third-party dependencies?
I don't think open source repositories are safer because they're open source, but precisely because there is no commercial benefit to shoveling BS into them. In fact, with the bigger commercial open source software, you often do see crap you don't want being included as a means to funnel users into commercial channels.
The only practical solution I can see is proper sandboxing of applications so you don't need to trust them in the first place.
> It just limits apps interactions with each other and the OS environment.
That makes a whole slew of modifications and tricks harder and/or impossible without having access to the sourcecode of the software, which is (on windows at least) not rare at all.
Any kind of interaction not explicitly allowed is then forbidden and the sandboxing will be a lot harder to overcome than two apps on the same machine talking to each other using a third.
Maybe some kind of unified app-to-app messaging protocol can take care of this, similar to how linux systems uses 'dbus' and the likes.
What I want is to retain the ability to repurpose the software on my terms. To move data in and out of the software whether software's authors like it or not. It's becoming harder each day, as more and more tools move to the cloud and turn into apps. I'm happy we still have userscripts in the browser but how long will it take before they get banned too?
This problem has many names. "War on General-Purpose Computation" is one of them, but I suppose the "professionalization of programming" is another. How long will it take before you'll need an engineering license to be allowed to use a compiler, or work with a Turing-complete language?
It used to be that you could get a lot of use out of a computer all by itself, nowadays that's changed and the trend to 'always on, always online' translates into having your machine potentially under attack 24/7.
Being vigilant against enabling the war on general purpose computation is very good, it is the biggest threat in the longer term and one of the reasons why I think that all these large silos are a very bad development.
I don't think we have much to fear from the 'professionalization of programming', not if the kind of code I see on a daily basis is anything to go by ;)
There have been numerous attempts at slapping a gateway on the ability to write software for the hardware that you already own, the only environment where this has taken hold is on mobile platforms, I sincerely hope that that is a development that we will sooner or later be able to revert.
But in order to revert it you'd have to come up with a solution for the pandemonium that would ensue if everybody and their brother would use the likes of 'download.com' or some equivalent to install their software from. Maybe something along the lines of apt-get for phones would be a starting point.
I don't know. Part of the answer likely lies in determining who the "owner" actually is. I want to be the owner of my computer, but business interests go against it. For instance, MAFIAA doesn't want me to be the owner, because they want secure means to enforce DRM on me. Other businesses would also like to be the owners, because they can monetize me better this way.
> I don't think we have much to fear from the 'professionalization of programming', not if the kind of code I see on a daily basis is anything to go by ;)
Let's hope so, but I think it naturally follows from Trusted Computing - the technology will enable proffessionalization. Because right now, there isn't much you can do to prevent people from getting their hands on a compiler and using it.
> There have been numerous attempts at slapping a gateway on the ability to write software for the hardware that you already own, the only environment where this has taken hold is on mobile platforms, I sincerely hope that that is a development that we will sooner or later be able to revert.
I hope so, but I fear we won't - that at some point a company will finally figure out how to lease PCs to general population instead of selling them. You'll get a nice, cheap laptop, but it will be locked down, equipped with trusted computing hardware (the company will be the trusted actor, of course) and require to connect to the Internet every now and then to verify everything is ok. Basically, what happened to mobile, only worse. And people will buy into it if the price difference will be significant enough. Actually, I'm not sure what's stopping companies now from doing this.
> But in order to revert it you'd have to come up with a solution for the pandemonium that would ensue if everybody and their brother would use the likes of 'download.com' or some equivalent to install their software from. Maybe something along the lines of apt-get for phones would be a starting point.
Yup. Crap like this is a huge problem, but I'm not sure if it requires locking things down. You can go the Apple way and aggressively verify every piece of software you allow in your repository. This makes you the trusted authority, which carries risks like abuse of trust, but solves the problem without heavy sandboxing.
So far I see the issue of distributed vs. centralized as a tradeoff between secure but inefficient, and efficient but with serious failure modes. I wish there was a way to capture benefits of both while avoiding the risks.
They'll give them away just to get you to be part of the ecosystem!
Apple does provide some verification services but the major reason the app store in its current form exists is as a choke point to extract revenues and as a way to remove any credible competition to Apple supplied applications.
The houses where I lived in Canada weren't locked, they didn't even have locks. In Amsterdam it would take about 6 seconds from the time you left to have your house burgled if you did that.
As far as it reduces your ability to tweak or repurpose your software: I don't think that it has to be that way but it will definitely be harder than in an environment of trust.
Maybe there is an easy way to get both ease of fiddling and very high security but I haven't seen anything like that yet. There are some interesting research projects revolving around 'capability based operating systems' and such, maybe that's where they key lies, or in some other development currently underway.
Example on Gentoo(ignore the over the top headline):
http://www.zdnet.com/article/linux-infection-proves-windows-...
Not to mention that the repos themselves have been having security issues over the years.
OSX still has very little adware attached to downloads, in my experience - plus there's the Mac App Store. It's pretty much just Windows users who endure that.
Installing "common" software is a doddle too, wth Ninite. You get Firefox, vlc, Dropbox, spotify, Skype (now in windows updates though) notepad++, up to date Java and .net run times, pdf reader etc etc. I set up the installer once about 3 years ago and the same one still works, with a one click update.
As someone who has used Debian almost exclusively for a few years now, I've got to admit that Windows 8 really does handle drivers nicely. Linux systems are generally pretty good about drivers these days, at least if you allow proprietary drivers, but nothing beats total out-of-the-box automation.
That is patently false.
Established profitable companies in a market with multiple competitors usually do not fuck with their customers, if they charge up-front for their product/service.
On the other hand, companies that give away stuff for "free" have to find unique ways to pay the bills (be it hosting fees, or hardware costs, or developer time, etc). In recent years the most common way is to create some way to essentially trick people into clicking ads.
Open Source repositories have not found any long term sustainable method to get compensated for their hosting fees or hardware costs. At the moment, they are run on donations - mostly from commercial vendors, universities and the like. At some point in the future, lets say if 500 million desktop users all start using those repositories, there will come a time when that cost is going to stick out on a balance sheet. I hope that they figure out a way to get paid for their efforts by then.
Lenovo (and lots of other hardware manufacturers) are proof positive that this is absolutely not the case. There isn't a windows machine bought over the years by my extended family that did not have a whole pile of junk on it right from day one including ad injectors such as described in the article.
Whether or not open source is 'viable' for large numbers of users is no longer a question that needs settling. For bandwidth we have torrents if need be.
Anyway, I view most comment sections as informal/idle chit-chat, and not courtroom/dissertation situations where everything needs to be cited and/or "proved". When I'm commenting I'm usually smiling to myself or amused, not angry or trying to "win" anything.
I've actually never seen an an freedom respecting project that included adware, and I can confidently say that the reason for that is that if a team were to do that, somebody would fork the repo and remove the offensive junk. As long as it gets caught, it's a self healing ecosystem. The same cannot be said for non-free software, as the pool of people who could find junk is so much smaller, but also because if junk were to be found by an employee, they'd have very little power to actually do anything about it.
Open source is volunteers, and when its not, they run on donations. When the donations stop, they stop. Some have found clever ways to make money, such as pay4premium or pay4support, but I've never seen ad injectors. Those come from third party distributors who aren't affiliated with the projects and can be avoided.
I've been told I could make $0.50/user based in the US per month. That would be a nice raise, for sure, but I'm not the type of person willing to sell out my users to make a little extra dough. Plus I am a user of my own extension, and I don't want ad-injection. And how long could one possibly retain users once you start injecting ads? Probably a steady decline until your left with the users that don't know where the ads are coming from.
Selfish plug to my extension here: https://chrome.google.com/webstore/detail/musicality-music-p...
I remember trying to track down a bug a few users reported, and I finally discovered that the users all had a specific piece of malware that replaced the javascript setTimeout function with a version that only took two arguments, which caused my code to break in frustratingly subtle and mystifying ways.
https://gist.github.com/fsaintjacques/e53eadd8b260a4105bbf
If you want to test the effect of it, copy/paste 'console.js' content in Chrome's console, I recommend to go into incognito mode:
https://gist.github.com/fsaintjacques/e53eadd8b260a4105bbf#f...
If they are outside the country, freeze their american bank accounts <i>and</i> the bank accounts of any business that advertises with these injected ads. Precedent: we already have laws that, for better or worse, require hardware stores to perform age checks when someone buy spray paint.
This isn't primarily a software problem. This is a problem because nobody is enforcing vandalism laws which encourages the adoption of "vandalism as a business model".
I see it as stealing the ad revenue from the content creator(which is often Google), which is the same as using adblock.
(the extension mentioned that ads were being used and you could also disable them)
"It’s also worth noting that ad networks often also don’t know that their ads are being used in this way."
So, ad networks don't know about a source that hits them with the 5% of the total throughput of Google's sites? Yeah right.The ad network whose script/iframe is directly injected onto the top frame can know fairly easily, since they know which accounts should be linked to which domains, however when these inevitably get resold, these subsequent ad networks have a much tougher time.
What ends up happening is that the first thing that gets injected is someone totally shady ad network that doesn't care, who will then resell it to someone slightly less shady, who will bundle it with a pile of other traffic, etc, etc, until it's been laundered enough times that it's hard to separate this out.
Obviously this is harmful to users because the implication is that the technique also requires SSL stripping, or trusting invalid root certificates like we saw with Superfish. It's also harmful to advertisers and ad networks because it pollutes tracking data and makes it hard to determine click fraud.
But let's not kid ourselves. Google does not care about the user. They simply have no need for ad injectors because they already have far superior methods of tracking us and invasively advertising to us (reading our email, watching our GPS location, knowing when we are home, what videos we watch, etc.) To google this is just a nuisance and they get some free PR for standing up to it along with a respected academic institution. Yay, google! Protector of users!
But wait. Isn't this exactly what Verizon, ATT, and Comcast are all doing? Verizon was modifying HTTP headers during the summer. ATT charges users not to inject tracking into packets. Comcast injects HTML into xfinitiwifi connections. How is this any different? Sure, tracking headers do not manifest themselves in annoying pop up ads, but they are still messing with user requests and have almost as many security implications.
If Google is going to take a stand against ad injectors, they need to take a stand against all packet injection. These scammy popups are just the bottom of the totem pole. If they could get away with what the big telecoms are doing, they would obvioisly do that instead.
- browser extensions
Also, Verizon and ISP's in general don't need access to unencrypted HTTPS data to track you. HTTP is an application layer protocol (top of OSI model), but your ISP can track you all the way down to the physical layer (bottom of OSI model). They still have all the metadata of your packets, even if they don't have the unencrypted content of them, because they literally own the wires/spectrum that your device used to send data. That means they can see when you use the Internet, what IP addresses you go to, how much content you send to each, etc etc. I don't think I need to explain to HN how much you can extract from metadata.
My point is that Verizon is not playing the game of injecting the actual ads you see. They inject tracking codes, or track you in other ways, but they still sell that data to the same advertisers who benefit from ad injectors. (Because ultimately, an ad is an ad, no matter how it got in your computer, and if you click it, the advertiser stands to benefit.)
Google should take a stand because the problem of ad injection is a symptom of the bigger problem, which is messing with user traffic in general.
Perhaps the solution is breaking up control of the OSI model. The companies running your cable should not be the same ones servicing you in the application layer.
I'm really curious how this all turns out. I can't imagine the deteriorating system lasting another 5 or 10 years. So what happens after? Clearly advertising has _some_ value, I loved BYTE magazine as much for the ads as I did for the articles, and there are under served retailers (a lot of Business to Business stuff) as the trade magazines take hits. So how do people discover this stuff? How do they find those opportunities when Internet ads are dead?
Or do we get to a more reasonable advertising load? Something without flash/js jiggling around and trying to get your cursor. How will sites let users know they don't allow "invasive" ads? How will users respond? For me at least I think it is the difference between Web 2 and Web 3.
I don't remember having any trouble discovering new stuff, rather the opposite, word of mouth and following links gave an endless stream of new and interesting stuff.
This site alone generates more info in that bracket than I can keep up with (even though I really try to).
I don't worry about finding content, but I do wonder how folks who have something cool will reach me.
Healthy ads ecosystem? WFT? The internet is inundated with garbage because of the perverse incentives wrought by ad-based revenue models, not to mention the other costs of advertising: https://news.ycombinator.com/item?id=8585237.
Google is to me and to a growing number of people an "unwanted ad injector" built into a vast number of web-sites which would, if Google and others didn't make it so easy to get ad revenue, be forced to do what you're supposed to do in a healthy free-market ecosystem: make products good enough that people are willing to pay for them.
The difference is that those websites willing allow ads of a specific type to be injected into themselves. The browser toolbars inject ads into everything, which is annoying (and breaks sites due to poorly coded injection).
I'm with you though—ads of any type are pretty annoying. But that's what adblock is for. :-)
I don't know where Trafficvance gets their traffic but it seems to be pop-over ads probably from some installed software. DirectCPV seems to be interstitial ads that the sites actually choose to use (think big news sites with an ad before you read the article). Most of them seem to be spyware/crapware driven. Those are the only two I've worked with in the past so I can't speak on the others.
Best way to avoid scams is common sense (if something looks dodgy, it probably is).
Bull. iOS is a HUGE chunk of web browsing and its immune from this stuff unless you jailbreak or are conned into installing a root cert and VPN.
You can't just download an app from the store or visit a site and find it installed like you can on a desktop.
Did they mean 'relatively benign'?
I think people has developed some kind of ad-blindness.
I remember a friend using facebook and some crazy and animated ads were taking 80% of his screen, I asked him "doesn't this bother you?" , he says "meh".
It doesn't effect me much, which must say something about the sites I read. But it is obnoxious as hell.
Where in the web page fetch/render process does this occur?
5% is a lot. If HTTPS reduces this number to 1%, it might be worth the change.
I am a layman in security and do not understand a lot of this. May be I missed something here. Is my question correct?
You're probably reading this page using https and there are quite a few extensions to modify the look and feel of hackernews.
Changing on-page content is just about the only reason extensions exist in the first place. Without that you could retire just about all of them.
[1]: http://en.wikipedia.org/wiki/Superfish#Lenovo_security_incid...