7 ms·
Leading 'anti adblock' provider gets hacked- pushed malware to end users
- 0x0 11y agoAnd then content makers are still scratching their heads on why people please won't stop using adblockers?!
- 542458 11y agoThis has nothing to do with blocking ads. You'd still be affected by this hack whether you were running adblock or not - the service is designed to be extremely difficult for adblockers to catch except maybe on a site-by-site basis. It's more of an argument for blocking all scripts.
- 0x0 11y agoI'd expect any decent adblocker to already have blacklisted this and similar services.
- DanBlake 11y agoThis is a service publishers use to show ads when a user has a adblocker enabled. It works on the most popular adblocker, adblock plus (firefox/chrome). Not sure if it works on ublock origin or ghostery/others, but those are still a small proportion of all adblock users. Noscript would have protected you though, which has a pretty large install base.
- Dylan16807 11y ago"ad blocking" includes "ad (blocking blocking )* blocking"
- redml 11y agoAdblock extensions block tracking as well as an extra perk, sometimes by default (ublock origin does). Ultimately their tracking script is a metric they're using to help sell their product/agenda to more users anyway, so its a form of advertising either way, or at the very least in a similar realm.
- x1798DE 11y agoTo be fair, I suspect that content blockers aren't puzzled as to why you would want to block ads. What they're trying to do is make it feel morally/ethically unacceptable to block ads. This is an example of them failing to live up to their role in the their preferred moral order (i.e. "you don't have to block our ads out of safety concerns because we'll safeguard them for you").
- 0x0 11y agoExactly. Adblocking is almost more important than regular antivirus these days. Arguing against adblocking while serving ads from third party networks with unverified javascript is like arguing that running antivirus software is morally wrong.
- viraptor 11y agoI completely agree everyone should be blocking ads for security, but this comparison is not right. Antivirus should already protect you from many known javascript-based malware. The difference is that antivirus will block (some of) the attacks being executed and let ads through. Adblock will block both normal ads and malware. That's why nobody ever argued that running antivirus is morally wrong.
- TeMPOraL 11y ago> Adblock will block both normal ads and malware. Normal ads are malware for the brain. It's just that this type of malware is legal and considered by many to be a respectable occupation.
- pjc50 11y agoPeople have argued against running antivirus: the desktop advertising industry. This is why "antivirus" and "antimalware" are separate products. This is the murky world of the "potentially unwanted program" (PUP). e.g. http://arstechnica.co.uk/information-technology/2015/05/sourceforge-grabs-gimp-for-windows-account-wraps-installer-in-bundle-pushing-adware/ http://arstechnica.co.uk/information-technology/2015/05/sour...
- deleted 11y ago[deleted]
- coldcode 11y agoAnyone else see a page with nothing on it on this site?
- have_faith 11y agoI get the page loaded fine but with no css or javascript (it's very snappy!). Will probably be back to normal soon.
- mintplant 11y agoYou might be using uBlock, then. For me it's blocking all assets on the pagefair.com site except the contents of the page itself. Temporarily disabling uBlock lets the rest of the page load.
- mschuster91 11y agoThis is the downside and the greatest danger with more and more centralized ad networks. Site owners: Market your ads directly or through smaller exchanges, and host them yourself. This is the only viable long-term option.
- Dylan16807 11y agoA big ad network is fine in theory, just stop using foreign javascript. Or any javascript.
- mschuster91 11y agoThe first iphone jailbreaks went via PNG/JPEG/PDF parser exploits. Disabling javascript does not protect you against a sufficiently malicious enterprise - and I'd label both the three-letter-agencies and the ex-Soviet mafiya as such. Both have been proven to use such tactics.
- seanwilson 11y agoThis would be an argument against using any site that allows user uploaded content, such as this site.
- Dylan16807 11y agoIf you want to be super-paranoid, only accept BMP or TGA with a specific color depth and no compression and validate the header before parsing. Or even accept only raw RGB data, 3 * width * height, and require the size be passed separately. Then convert it to png yourself. You can't prevent exploits from all angles, but you can prevent exploits from some angles.
- itake 11y agoIs it? I hypothesize that smaller exchange have less resources to develop secure systems. While they maybe smaller targets, I think their architecture maybe less robust. Hence why I trust gmail to run my email rather than rolling my own server.
- jmount 11y agoI think I saw this. I visited a legit science or business page (don't remember) and a windows said my "Flash player was out of date" and immediately started downloading a Windows ".exe" claiming to be a flash installer. I am on OSX with no Flash installed, so I know it wasn't Adobe's updater.
- samgranieri 11y agoThis happened to me too
- jmount 11y agoRemembered the url: http://www.kalzumeus.com/2015/10/30/developing-in-stockfighter-with-no-trading-experience/ http://www.kalzumeus.com/2015/10/30/developing-in-stockfight...
- notfoss 11y agoThey seemed to have removed the pagefair code for now.
- makomk 11y agoThey're basically selling a content-obfuscating anti-detection system for webpages as a service. Of course it's going to be abused to push malware. They're just lucky the attacker wasn't more sophisticated this time around.
- Tiquor 11y agoNo they aren't. They aren't even an "anti adblocking" tool. They replace ads with "acceptable" (as defined the ad block plus people BTW) ads for ad block users.
- r1ch 11y agoSeems like this could have been prevented if they supported subresource integrity.
- konceptz 11y agoThat could work but it would be tricky and possibly difficult for them to get right. The hardest part being registering valid content updates. I've seen integrity validation schemes work well for small enum lists but we'd have to know what the data set size is and the expected rate of change. This of course all before properly adding an SLA to their content providers. Certainly interesting but I think it may not be the easiest or best way to tackle this problem. I'd love to hypothesize about it if you want to suggest some workflows.
- garrettr_ 11y agoNot really. Since you need to know the correct hash ahead of time, Subresource Integrity works best when you're requesting a well-known piece of static data from a 3rd-party server, e.g. jQuery version x.y from a CDN. For a site like Pagefair (or other sites that serve 3rd-party scripts, like Google Analytics), the benefit of the web platform is being able to serve _dynamic_ data. You get to upgrade your software quickly and easily, without the friction of obtaining the cooperation of your website partners (1st party sites that included Pagefair's scripts) or end users. If you want to use Subresource Integrity to prevent this kind of a problem, you need to first devise a mechanism to communicate the correct expected hash from the 3rd party site to their 1st party customers in a trusted manner. This is non-trivial. It adds a lot of friction to Pagefair's software development and deployment processes (think about how you would implement A/B testing, for example). It's also not a guarantee - if your servers can be hacked, it's possible your "trusted hash communication mechanism" would be as well, unless you follow stringent security protocols (human confirmation for signing, offline keys, etc.) which would add even more friction. Of course, you would need cooperation and involvement from your first-party customers for SRI to be effective in the first place, and I don't know how many of them would be thrilled to have to devote engineering resources to fixing potential security problems caused by their partners... sounds like a good reason to consider switching to a competitor.
- onewaystreet 11y agoI've never seen a major website that uses anti-adblock. I've seen a few that display a message but none that actually stop you from viewing the site.
- craigds 11y agordio.com stops playing music as soon as it tries & fails to play an audio ad. You can refresh the page to continue with the next song though. Since it seems to play an ad after every song (?!) this basically prevents ublock users from using the free version of rdio.
- yeukhon 11y agoI don't know the algorithm, but how it figures out that the audio is an ad? Sounds like a page or a different url is used playing the ad?
- craigds 11y agoYes. The ads have urls like http://cmodmedia201.live.streamtheworld.com/media/cm-audio/cm:d55b9957-1363-41ab-f094-97ddd3943134.mp3 http://cmodmedia201.live.streamtheworld.com/media/cm-audio/c... whereas the song content is served from a different host entirely (m.cdn2.rd.io). Presumably this is just because the ads are served from an external ad network, not rdio itself. You can see the ad request failing in Chrome dev tools, and the console tab shows "net::ERR_BLOCKED_BY_CLIENT".
- pavel_lishin 11y agoHulu does something similar, but sometimes it shows ads, and sometimes it tells me that I need to disable ad-blocking software. I just refresh, and it usually works. I'm not willing to disable Ghostery and uBlock, though; 12 things blocked by Ghostery and 31 by uBlock - I don't need any of it, Hulu, thanks.
- vonklaus 11y agoI will never understand how that company makes money. If you can get users to pay you for your content, then don't try and sell your users time to someone else. Horrible value proposition and if you have to block that much stuff they likely sell your data as well, not to mention many premium clients are shittier than the pirate sites. Hulu value proposition: * Pay for content. * Still have to watch commercials. * Have data about my usage sold to highest bidder. * Video client that is not as good as putlocker (or whatever the cool kids are using these days) it is owned by nbc, disney and fox. they still don't get that you can sell content, sell ads, or sell nothing. Very little overlap.
- aslewofmice 11y agoSo the attacker got the password for a work email (and let's be honest, it was likely a shared account amongst a department not an individual) that was used for the CDN account hosting their serve code, where the attacker appended a malware download link to their script running on however many sites they work with. And they were able to convince website owners to grant them access to visitor's connection in order to prevent people from blocking ads? And they were also able to convince them to pay money for this service?
- deleted 11y ago[deleted]
- gorhill 11y ago> The attackers then immediately performed a password reset to hijack PageFair’s account on a Content Distribution Network (CDN) service that we use to serve our analytics javascript tag. They modified the CDN settings so that instead of serving PageFair’s javascript, it served malicious javascript. It would have been nice that the article spelled out the exact hostname from that CDN, to find out whether it is blocked by default by blockers.
- deleted 11y ago[deleted]