10 ms·
> At any one time, a publisher can be serving ads from a few exchanges, a few different private sellers, and custom built ads for brands. And these all are serv
by devishard 10y ago
> At any one time, a publisher can be serving ads from a few exchanges, a few different private sellers, and custom built ads for brands. And these all are served in different combinations across several different ad units on multiple pages. And some of those ad sellers may be backfilling with other ad networks, or maybe the publisher is backfilling certain ads from the ad exchanges at certain CPM prices.
So, don't do that.
> It's not that simple.
It is absolutely that simple.
Your argument is basically, "Their process is so complicated they can't avoid serving up malware." But that's not a justification for serving up malware. If your process is too complicated to avoid serving malware, then you need to simplify your process until you can avoid serving up malware.
You don't get a free pass on ethics just because ethics are inconvenient for your business model.
- Dylan16807 10y agoEspecially when an ad network that only serves images is easier to make than one that can serve scripts and sometimes attack the user.
- Silhouette 10y agoYou don't get a free pass on ethics just because ethics are inconvenient for your business model. I think calling this an ethical issue is quite a stretch. In many cases, we're talking about visitors who are not only enjoying the content from someone else's site completely for free, but also employing tools that actively modify the intended presentation of that content to the detriment of the host site's operators. And now you're saying that not only should the site operators make their content freely available and accept that some visitors will circumvent possibly the only way they have of generating revenue, those operators should also be actively responsible for vetting any third party content they incorporate within their site in case the third party is hostile and those visitors know enough to run ad-blockers but not enough to run anti-virus software? That seems a very short-sighted and one-sided position, entirely in favour of the party who isn't actually contributing anything in this scenario, and I see no ethical basis for that. Edit: For those who are downvoting, please consider that I did not disagree with the original premise I quoted. Obviously unethical business models are still unethical even if the ethical ones are inconvenient. What I'm asking is why we should consider it an ethical requirement for someone who is already generously offering their content for free and accepting that a significant fraction of visitors will circumvent their intended ad-funded model to also go to unrealistic lengths to vet any third party content they include for safety against arbitrary unknown threats that could change at any time without notice, all for the benefit of a visitor who is offering them nothing. I'm not sure whether someone operating a web site really owes their visitors anything in this scenario, other than perhaps a basic "good citizen" principle of not negligently serving up malicious content, and I don't see how operating within the same infrastructure as a huge number of other web sites could reasonably be considered negligent in this respect. Unless you think we should also close down all third party CDNs, image hosting services, caching services, web font services, and so on, the web is fundamentally a linked medium where sites can usefully be built by combining resources from other services, and naturally those other services will retain control of what they are hosting themselves. Making Joe Blogger responsible if some massive service's CDN version of jQuery got hacked doesn't seem like a good way to encourage Joe Blogger to spend their time sharing their writing with the rest of the world.
- pavel_lishin 10y ago> already generously offering their content for free If they're attempting to make money from ads, they're not offering it for free.
- Silhouette 10y agoIf a visitor is using an ad blocker, they're getting it for free anyway. As an ethical principle, I don't think you can have it both ways. Either the site operator is commercial, in which case ad blockers are unethical because the visitor is depriving them of revenue, or visitors are free to browse the content without obligation including blocking any parts they don't want to see, in which case why does the site operator owe them anything? In any case, even in a commercial transaction, there is an element of reasonableness to what is expected. If I buy a $50,000 car and it breaks down on the second day of having it, that's obviously well below a reasonable standard. If I buy a $10 toaster and it breaks after a couple of years because the crumb tray didn't quite fit? Maybe that's more reasonable. If I buy a $10 toaster and it catches fire and burns my house down after a couple of years because of a design flaw that the manufacturer knew about but didn't fix? Again, not so reasonable. In this case, we have a content provider who is making at best a tiny amount of ad revenue from a visitor, yet some people here seem to think there is an ethical obligation on that content provider to provide a literally impossible standard of monitoring of the behaviour of the ad networks anyway. As I've mentioned elsewhere, even the argument that they just shouldn't use an ad network in the first place doesn't really work, because logically you'd also have to apply the same ethics and accept responsibility in the same way for any other third party content, such as scripts hosted on CDNs. By the time you've finished knocking out any sort of third party hosting just in case a rare instance of malicious content slipped through the net, the web would be a much worse place.
- csydas 10y agoStrongly disagree since I feel there is misinformation and a very strange perception as to where the onus of protection should come from. The reason that the bad advertisement issue is such a big problem is that very often the anti-virus programs simply don't work on the malware being served. The exploits used either aren't in the definitions database or the AV has a blindspot. It's also very difficult to be running without an anti-virus on a modern computer. Windows Defender doesn't always rank the strongest, but it's certainly competitive with other AV solutions, and Windows will nag-nag-nag if you don't have what it considers to be an active AV installed. It's not the early 2000's anymore when you had to find a good AV - for the most part, if you buy a modern computer, there are AV protections in place already. As is such, these aren't users thumbing their nose at safety and running around unprotected, these are people who have a reasonable expectation to not be served malware by reading an article at Forbes. Simply put, regardless of how you're doing it, you should not be serving malware to people. If your site is the vector, you have a responsibility to deal with it, and ignoring this, as many sites have done, is an ethical breach. Malware can and does do harm, sometimes in the form of lost data and lost money. Ensuring you're not serving up malware isn't just in the lines of "good citizen", it's a duty to not harm - the people affected by the malware have no recourse in virtually every situation. If it's ransomware, they either have to hope that it's poorly made and gets broken, if their machine is otherwise unrecoverable, that data is lost. Forbes and the other sites that are proposed to be blocked may be getting fingered right now, but the complaint is a larger complaint about advertising; as participants who are not working to clean it up, I think users have every right to be upset and to call it unethical - the response that they're receiving is, well, no response. The websites don't care. All that being said, I'm actually fine with them putting up an ad-wall, as it kind of forces them to put their money where their mouth is. Part of the change that will need to happen is to show the sites that consumers don't want to put up with dangerous ads and to prompt action, and ad-walls pretty much force a boycott if users want to continue using adblockers. This will give them the metrics to see the effect that bad advertising has, and hopefully prompt change. But, I still think that you have an obligation to ensure your website is not a hazard, regardless of how it became one. "Everyone else is doing it" isn't a defense, especially when it causes real and immediate damage to potentially thousands of people.
- tracker1 10y agoIt isn't that simple, but it should be... This is a space ripe for "safe networks" and self-serve ad platforms to take hold.
- Silhouette 10y agoIsn't that space already occupied by sites like Facebook?
- tracker1 10y agoI mean safe ad networks, and self-hosted ad platforms, that are served via first-party.
- Silhouette 10y agoWhat would that look like for, say, a small personal blog that includes a few ads to cover the hosting costs?
- tracker1 10y agoWell, it wouldn't be the target for your small personal blog... once you approach it at a small business level, it means running server-side code do deliver ads injected into your content that reports what data can be reported upstream. It does mean more limited analytical data, but it would also mean better privacy constraints... it means moving the delivery to first-party servers, that can use other SaaS behind that. As to advertizing, it means delivering an image url, and a target url... no more leaps and bounds of JS, or for that matter layers of iframes.. TBH though, if browser vendors simply disabled JS, and iframes more than 3 layers in, and limit JS files to 3 max (100kb size limit) within an iframe, the advertizers would probably successfully self-correct..
- x0x0 10y agoWhat it also means is more publishers cut journalism/content, transition to buzzfeed style "news", or go out of business. Or really some admixture thereof.
- econnors 10y agoBut it's not the publishers process or business model that is causing the problem - it's the process of filling ad space that is broken. Sure, you could pick one ad network and micro monitor it, but you wouldn't make enough money to sustain quality content. CPM optimization is a requirement of the field if you'd like to profit enough to sustain quality journalism and not be the next you-wont-guess-the-top-10-craziest-things site. Yes, I think publishers have a responsibility to monitor their ads and keep their users safe. But I still don't think it's a black and white ethics situation. The exchanges and other ad providers need to fix their business model and not depend on publishers to filter the malware ads they're sneaking onto their page.
- devishard 10y agoYou're making 2 arguments here: 1. Publishers can't compete if they behave ethically. If this is true, then the solution is simple: if you can't run your business ethically then close your business. However, I believe that it's entirely possible for publishers to compete ethically; there are, for example, plenty of business models besides selling ad space. 2. Publishers are only accomplices in serving malware. We can't ignore publisher's role in serving malware and blame the ad networks. Both the ad networks AND the publishers are to blame.
- x0x0 10y agoSo stop going to those sites. Really; you voluntarily visit those sites. To quote you, "It is absolutely that simple."
- dcposch 10y agoSome of those sites have good information that you'll miss out on. I think there's an even simpler and more realistic solution: someone needs to make a Chrome extension that is like uBlock Origin, but unblockable. It should be: * an adblocker that also blocks tracking scripts * ...with no "acceptable ads" whitelist like Adblock Plus * ...open source * ...with workarounds for ad-blocker-blockers Here's how I think we can do that: we maintain a list of domains that are using ad-blocker-blockers, and for those, rather than blocking ads at the HTTP request level, the user agent loads them and simply doesn't display them. In principle, you can do this in a way that is completely undetectable by the site owner. There doesn't need to be an "arms race" between ad-blocker-blockers and the workaround developers--you simply win outright by having DOM look exactly the same as if it had ads, but rendering, say, a box with a tasteful light grey smiley face instead of the ad. (You can even make it so that canvas.getPixelData returns the ad that the page thinks it drew, but the actual screen output doesn't show it.) At that point, sites are actually incentivized to stop using ad-blocker-blockers, because the only difference they'll make is that site will load slower, since the user agent has to load and pretend to display all those extra resources. The user never actually sees the ads either way. -- For extra credit, this hypothetical browser extension can also simulate a click on YouTube's "Skip This Ad" button as soon as it appears, etc. You could even keep per-domain blacklists of bloat resources and simply not load those. That would make the internet feel a lot faster. A user with this extension would visit The Verge and instead of getting a janky 5 megabyte page load, they'd get a near-instant load with just the text and images. Finally, this extension could keep a mapping of desktop sites to auto-redirect to the lightweight mobile equivalent, with a body{max-width:800px} thrown in to keep things readable. I know I'd install this hypothetical extension immediately and never go back.
- x0x0 10y agoI already understand that you neither want to pay these publishers or see ads.