HNHacker News
TopNewBestAskShowJobs

aslewofmice

82 karma · joined July 28, 2011

[ my public key: https://keybase.io/3neat; my proof: https://keybase.io/3neat/sigs/KLB9A9xQDyDgl4X9eaADv1Gp-6A3822nRcCl14pZWOc ]
submissionscomments
aslewofmice··on Astra for Coding: Why Are We Doing This Again?
found this talk to be quite complimentary to the article: https://www.youtube.com/watch?v=eEBv0STiYhI
aslewofmice··on Palantir deployed a predictive policing system in New Orleans
private data-driven policing will end up reinforcing any institutional racism under the guise of math
aslewofmice··on Leading 'anti adblock' provider gets hacked- pushed malware to end users
So the attacker got the password for a work email (and let's be honest, it was likely a shared account amongst a department not an individual) that was used for the CDN account hosting their serve code, where the attacker appended a malware download link to their script running on however many sites they work with.

And they were able to convince website owners to grant them access to visitor's connection in order to prevent people from blocking ads? And they were also able to convince them to pay money for this service?

aslewofmice··on Mockups for a free, ad-supported Uber service
I don't get the hate, I think it's a great idea. It's completely opt-in and both sides win.
aslewofmice··on Maintaining Digital Certificate Security
Would love to know this as well. I only have a high level understanding of the purpose of CA Certs, but beyond that I'm lost.

Ignorant questions ahoy:

1. Using Chrome, would you have to manually accept the MITM certificate? 2. Could such a certificate be valid across multiple domains? 3. Would it pose any threat to the computer if it was moved from the MITM network to an outside network? 4. What kind of potential problems could occur if I issued a self-signed certificate for my network?

aslewofmice··on Poor Kids of Silicon Valley
Because there's a scary proportion of people in here saying things like: - "how about they just move?" - "the guy is a construction worker? they're in demand, just go to a construction office and get a job" - "I don't get it. One person on video lives in nice bedsit (garage) and talks about homeless."
aslewofmice··on [BETA] Growth Hacking Dashboard with Awesome Features
What sort of awesome features? Show me why I should give you my email address.
aslewofmice··on Online Porn Could Be the Next Big Privacy Scandal
Access to IP address + browser fingerprint on two sites that you've recently visited. Doesn't seem that implausable with all the recent security breaches.
aslewofmice··on Quantifying Online Advertising Fraud: Ad-Click Bots vs Humans [pdf]
> Aren't most advertising campaigns focused on acquisitions these days?

Nope, much of it is branding. Some are focused on clicks, some are focused on viewability... it's sort of a turning point in the industry...

> No, and they are not focused on clicks either. The majority of the adspend* cares about impressions, viewability and lift. *display adspend

Most or not, it's still a significant amount. The clients you mention may be more concerned with impressions/viewability/lift, but they're still vulnerable to be gamed the same way as someone who cares about clicks. Viewability is already being manipulated by the same bots that generate fraudulent clicks. It's a great metric in theory, but take it with a grain of salt.

If anything, these companies (Moat, IAS, Oxford...) are the ones who should be most concerned about combating bots.

aslewofmice··on Quantifying Online Advertising Fraud: Ad-Click Bots vs Humans [pdf]
The problem with display advertising is that too much of the industry is focused on clicks. Anti-fraud companies can come up with ways to try to mitigate click fraud but it won't do much of anything as they can, and will be, gamed by black hats - there's too much money at stake.

I deal with it every day and the best method is to educate the client by explaining why a click is a poor indicator of performance. Work with the client to come up with measurable goals to track click-through/view-through conversions on these goals and ultimately try to measure impact on ROI. It's really not THAT difficult for most campaigns.

The most difficult part is that the client becomes aware of all those wasted dollars on previous campaigns that they thought were high performance because of a high CTR.

aslewofmice··on Quantifying Online Advertising Fraud: Ad-Click Bots vs Humans [pdf]
They will typically set up several generic websites with ads, and set their click farm loose to represent fake traffic while clicking on ads for X% of impressions. You could also be a mercenary and drive traffic to other website operators who want traffic/rev, or even dilute quality/waste spend on competitor ad campaigns.

Since these click farms are typically just infected computers, they can likely setup other tasks to monetize: DDoS, email, BTC mining, etc...

aslewofmice··on Show HN: Monthly earnings of 23 Twitch streamer
$2 is pretty good for rev share. Much of those impressions are clearing at $20+
aslewofmice··on Hardware startups should consider local manufacturing
thomasnet.com was decent for finding leads, but we weren't able to find a suitable manufacturer to get past prototype
aslewofmice··on The Fire phone debacle
I think they could succeed by modeling themselves after a Costco/Kirkland-type relationship
aslewofmice··on Show HN: Buy and Sell Retargeting Lists, Feedback Appreciated
Pretty vague. Retargeting on what - Display/Facebook/Email? How would a customer onboard these lists?
aslewofmice··on Farewell, Dr. Dobb's
But why serve house ads repeatedly when you can tap into programmatic exchange and monetize at least a portion of those impressions? Programmatic doesn't need to be first look on all impressions.

If I'm on drdobbs.com in one tab and only being served house ads, but in my second tab I have retargeted ads being served to me, that's lost revenue for drdobbs.com

aslewofmice··on Ask HN: Good advertising network for a site with 4M views per month?
What do you mean by discussion about software? Is the readership primarily programmers or is it software end-user discussion? Having a clear idea about your user base is step one, and I think that should be easy for you.

How many uniques per month are you seeing?

Have you considered video? You'll need to find that balance between user-experience and monetization.

Like someone else mentioned, you might want to consider looking into a proper Ad Server setup where you can then tap into the programmatic ad exchanges/networks and get more bang for your buck. DFP Small Business may be best - it's free up to XX million imps and you can manage AdSense through it as well.

aslewofmice··on Farewell, Dr. Dobb's
Were the ad buys primarily sold direct? Was the site connected to any programmatic ad exchanges in any way?

I visit the site and I see the same ad over and over (Interop Convention).

Did you have anyone dedicated managing ad operations for the site? We're you selling any of your users data points to third-party data providers?*

* For the people who hate the idea of a free content site selling your data, this is a good example of what happens.

aslewofmice··on Hackers strike defense companies through real-time ad bidding
Programmatic media buying in an open exchange model is vulnerable to this kind of attack vector, and the number of malvertisers is growing day by day. The ad industry needs to be quicker at adopting the private marketplace model in order to mandate a bit more transparency between the buyer and seller.

The OP article was a bit alarmist with the hackers singling out defense contractors. I think the real intent of the hackers/malvertisers is this:

>Invincea recently saw a malvertiser win a bid and delivered a Java exploit. This exploit copied a fully functional version of Chrome into the Java cache directory, and that version of Chrome launched in the background and proceeded to visit websites and click on specific ad banners. It is presumed that these ad banners paid revenue via referral bonuses to the malvertiser. By paying 65 cents to install a background web browser that does nothing but click fraud, the malvertiser is able to reap hundreds if not thousands of dollars in advertising referral income. It is a pretty good return on investment, which in turn allows the malvertiser to fund his micro-targeted malvertising attack campaign.

Just like Email several years ago, there's just too much accessibility and money out there for spammers and malvertisers to not jump to Display.

aslewofmice··on Hackers strike defense companies through real-time ad bidding
sitescout was mentioned
aslewofmice··on Modern anti-spam and E2E crypto
Direct email marketing
aslewofmice··on Sorting Out the Law Behind Phil Ivey's Edge Sorting Debacle at Borgata
It can't be considered marking cards because they are not physically altering them.
aslewofmice··on Chrome is blocking wired.com
Any chance it's related to this?

http://www.incapsula.com/blog/world-largest-site-xss-ddos-zo...

Security company found a vulnerable Alexa Top 50 site where someone was able to inject XSS code in the comments section creating "DDoS Zombies" of the visitors.

aslewofmice··on Oracle Buys BlueKai
$400M seems like a steal for Oracle. DMP's are finally becoming much more accessible to advertisers, agencies & publishers. We're only beginning to touch the surface for audience modeling capabilities and taking these learnings across multiple channels for direct targeting.
aslewofmice··on LinkedIn – Good or Bad?
Connecting with random people. Some people just seem to want to connect with as many people as possible. What’s the point? The connections you have with people you know just get lost in the noise. My policy is to only connect with people I already know.

This takes away the power that LinkedIn provides and defeats its entire purpose. LinkedIn isn't a network to meet your next potential friend - it's to engage with others in your industry and openly share your network in a semi-private manner. When I'm looking for a job, it's beneficial if the hiring person is just a 2nd connection away because then you can send them a PM. Send a short, friendly message and you're increasing your chance to be noticed.

If they don't respond, or accept your connection request, whatever - nothing personal.

aslewofmice··on Ask HN: How do you hack this hot weather?
Updated Satirical Answer: Move to San Diego where it's currently 72 degrees, lower cost of living than SF and a burgeoning startup scene.
aslewofmice··on Ask HN: This company links my home IP address to my employer. How?
Judging by the pixels on their site, they likely used Google AdWords remarketing: http://www.google.com/analytics/features/remarketing.html

If you used the same computer from work that you used at home, you were cookied from work when you initially visited the site. Then when you were browsing the internet at home, the ad that was served recognized your cookie ID as the same visitor who visited the site and they can purchase that impression and serve their ad.

aslewofmice··on GeoGuessr: Guess the location from Google street view
This is really quite fun, nice work!
aslewofmice··on Peter Corbett's Management Hacks
Guilty
aslewofmice··on Facebook Seems to be Down
Down for me, confirmed down for plenty of others on IRC and Twitter.
Page 1 of 2Next →