3 ms·
Google is largely responsible for the situation we're now in. As the largest provider of ads on the web, they regularly turn a blind eye to malware advertising
by JacobJans 11y ago
Google is largely responsible for the situation we're now in. As the largest provider of ads on the web, they regularly turn a blind eye to malware advertising served by their network.
They simply do not take malware seriously. They continually let it exist on their ad network. As a publisher that uses Adsense I find this extremely frustrating. As example: I've spent quite a bit of time attempting to block ads that lead to the "ask.com toolbar." These are always deceptive. They confuse my visitors and then I hear about it.
Additionally ads where the only text is "Download Now" or "Read Your Private Messages" are clearly deceptive. And yet they're allowed.
There are so many easy ways Google could improve the situation. And yet, they don't. This is a serious problem, and it is only going to get worse until Google responds appropriately.
- morley 11y agoThe problem isn't Google or DoubleClick; it's a structural problem with the ad industry. Most sites that serve ads can't sell all their inventory directly, so they fill their remaining impressions with ad networks, who sell bulk inventory space. Those ad networks have the same economic limitations from selling all their inventory, so they need to sell _their_ remaining impressions to another network. And so on down the line. All it takes is for one ad network to get a little loose with their serving policy for a malware provider to make an in. And I can't think of a way for an upstream ad network (or even DoubleClick) to ban malware, without tracking down that errant provider. You can't blacklist a domain, because usually the ad network hosts the ad itself. And like it or not, ads have to run Javascript or Flash. It's a crappy situation to be in, but it's not any one actor's fault (except for the malware advertiser), and the fix isn't easy or else someone would have thought of it.
- coldpie 11y ago> And like it or not, ads have to run Javascript or Flash. They certainly don't need to run whatever arbitrary scripts the advertiser wants. The advertising network can provide whatever functionality the advertiser needs, there's no reason to leave this obvious hole open. The idea that I can pay someone some cash to put whatever arbitrary JS I want directly into Forbes's website is utterly ludicrous.
- derekp7 11y agoWhy do they need to run a script? Why can't ads just be a static image?
- tracker1 11y agoThen ads should be bucketed as such... Ads that are a link, and an image can be automated, or changed via the end user without intervention. Ads with JS, require going through automated testing (certain things like new Function, and eval are not allowed, along with `window[`, as well as creating a script tag, XHR, and some other bits... No remote content loading, beyond images, period... all content for an ad must be in a self-contained file, and can only exit via a window.goto that the ad-network injects for the purpose... A whitelisted subset of DOM interaction is all that is allowed, and the total payload of an advert must be under ???kb, something reasonable. Flash ads requiring a source inspection... All ads served from the network directly, not loading js/html/css or anything outside their network... It's easy enough to do this, and pass the cost of inspecting JS and Flash ads onto the customers... they can decide if they really need it. It becomes part of the cost of doing business... Banning interstitial ads, and those that take up more than half the screen.
- coldpie 11y agoThey have no incentive to improve because you continue to display their ads and do their work for them.
- JacobJans 11y agoThey absolutely do have an incentive to improve. Every time someone is deceived by an ad, or encounters malware via their ad network, that person is more motivated to install an adblocker and to tell their friends to install adblockers.