82 karma · joined July 28, 2011
And they were able to convince website owners to grant them access to visitor's connection in order to prevent people from blocking ads? And they were also able to convince them to pay money for this service?
Ignorant questions ahoy:
1. Using Chrome, would you have to manually accept the MITM certificate? 2. Could such a certificate be valid across multiple domains? 3. Would it pose any threat to the computer if it was moved from the MITM network to an outside network? 4. What kind of potential problems could occur if I issued a self-signed certificate for my network?
Nope, much of it is branding. Some are focused on clicks, some are focused on viewability... it's sort of a turning point in the industry...
> No, and they are not focused on clicks either. The majority of the adspend* cares about impressions, viewability and lift. *display adspend
Most or not, it's still a significant amount. The clients you mention may be more concerned with impressions/viewability/lift, but they're still vulnerable to be gamed the same way as someone who cares about clicks. Viewability is already being manipulated by the same bots that generate fraudulent clicks. It's a great metric in theory, but take it with a grain of salt.
If anything, these companies (Moat, IAS, Oxford...) are the ones who should be most concerned about combating bots.
I deal with it every day and the best method is to educate the client by explaining why a click is a poor indicator of performance. Work with the client to come up with measurable goals to track click-through/view-through conversions on these goals and ultimately try to measure impact on ROI. It's really not THAT difficult for most campaigns.
The most difficult part is that the client becomes aware of all those wasted dollars on previous campaigns that they thought were high performance because of a high CTR.
Since these click farms are typically just infected computers, they can likely setup other tasks to monetize: DDoS, email, BTC mining, etc...
If I'm on drdobbs.com in one tab and only being served house ads, but in my second tab I have retargeted ads being served to me, that's lost revenue for drdobbs.com
How many uniques per month are you seeing?
Have you considered video? You'll need to find that balance between user-experience and monetization.
Like someone else mentioned, you might want to consider looking into a proper Ad Server setup where you can then tap into the programmatic ad exchanges/networks and get more bang for your buck. DFP Small Business may be best - it's free up to XX million imps and you can manage AdSense through it as well.
I visit the site and I see the same ad over and over (Interop Convention).
Did you have anyone dedicated managing ad operations for the site? We're you selling any of your users data points to third-party data providers?*
* For the people who hate the idea of a free content site selling your data, this is a good example of what happens.
The OP article was a bit alarmist with the hackers singling out defense contractors. I think the real intent of the hackers/malvertisers is this:
>Invincea recently saw a malvertiser win a bid and delivered a Java exploit. This exploit copied a fully functional version of Chrome into the Java cache directory, and that version of Chrome launched in the background and proceeded to visit websites and click on specific ad banners. It is presumed that these ad banners paid revenue via referral bonuses to the malvertiser. By paying 65 cents to install a background web browser that does nothing but click fraud, the malvertiser is able to reap hundreds if not thousands of dollars in advertising referral income. It is a pretty good return on investment, which in turn allows the malvertiser to fund his micro-targeted malvertising attack campaign.
Just like Email several years ago, there's just too much accessibility and money out there for spammers and malvertisers to not jump to Display.
http://www.incapsula.com/blog/world-largest-site-xss-ddos-zo...
Security company found a vulnerable Alexa Top 50 site where someone was able to inject XSS code in the comments section creating "DDoS Zombies" of the visitors.
This takes away the power that LinkedIn provides and defeats its entire purpose. LinkedIn isn't a network to meet your next potential friend - it's to engage with others in your industry and openly share your network in a semi-private manner. When I'm looking for a job, it's beneficial if the hiring person is just a 2nd connection away because then you can send them a PM. Send a short, friendly message and you're increasing your chance to be noticed.
If they don't respond, or accept your connection request, whatever - nothing personal.
If you used the same computer from work that you used at home, you were cookied from work when you initially visited the site. Then when you were browsing the internet at home, the ad that was served recognized your cookie ID as the same visitor who visited the site and they can purchase that impression and serve their ad.