4 ms·
I see, so as long as the code can be looked at, it can be circumvented?
by mtgentry 11y ago
I see, so as long as the code can be looked at, it can be circumvented?
- MichaelGG 11y agoNo. So long the code is executing on an uncontrolled device, then you cannot guarantee it'll execute how you intended. So if you make a device, like an iPad, seal it to prevent hardware tampering, and ensure no user-triggerable bugs exist, you're all set. There's also remote attestation, like Intel SGX might start to bring. But on existing general-compute devices like PCs, it's a hopeless battle.
- eru 11y agoAnd even on a sealed iPad, a user could just use a piece of cardboard to cover the portion of the screen showing the ad.
- gregmac 11y agoIn a way. An extreme could be not loading content until the ad is loaded, and there is some type of check to verify that it did actually load (not blocked). If someone is determined enough, they could simulate the ad being loaded (eg, maybe it actually IS even loaded, but the DOM element is hidden in one of dozen different ways which the ad-loaded-verification code doesn't check for). Essentially the problem boils down to running code (HTML, Javascript, CSS, and even Flash) in an untrusted environment (the user's browser). The site sends the user bits of data to be displayed, but there's ultimately no way to know if the user's browser ACTUALLY displays those in the browser window, let alone to the user's eyeballs. As a content provider, you can get very, very clever, but you can never get to 100%, and there will always be a motivated user to work on an adblocker that circumvents everything. It's really not any different from DRM (as someone else in thread pointed out). The movie/music/TV/games industry has spent billions of dollars coming up with various schemes of DRM, yet you can still download basically anything (stripped of its DRM, of course) within days of release, if not earlier.