4 ms·
Putting up a captcha would be another option.
by stri8ed 7y ago
Putting up a captcha would be another option.
- gruez 7y agocaptcha on what, the site? since there's basically nothing authenticating the site to the adsense iframe/script, can't the attacker serve a cached version locally?
- stri8ed 7y agoAre you sure there is no authentication? https://www.seroundtable.com/google-adsense-verify-sites-26596.html https://www.seroundtable.com/google-adsense-verify-sites-265...
- throwaway2048 7y agoThat has nothing to do with the discussion at hand, and would do nothing to prevent a malicious ad clickbot
- stri8ed 7y agoTo actually enforce the policy described in that link, would require authenticating websites when rendering ads. Otherwise, one could just embed an ad from a different domain, and easily defeat this process.
- gruez 7y agoI'm not sure why the parent (throwaway2048) is getting downvoted over this. He's correct. The attack is as follows: You want to attack (send fake traffic to) example.com, but example.com has implemented a captcha system (think cloudflare interstitial). If you directed your bots to visit example.com, they'd have to solve the captcha to view the ads. However, there's nothing stopping you from solving the captcha once, getting the page source, and serving that to your bots. This works because example.com doesn't serve any ads directly, it only embeds a <script> or <iframe> element to adsense. Since the bots are under your control, it's trivial to set up the redirection (eg. hosts file or HTTP proxy). HTTPS isn't a problem either because you can MITMing yourself with a self signed certificate, which is not a problem either as you can get your bots to trust that certificate. From the perspective of the adsense script, it's impossible to tell whether the bot is visiting the real example.com or a fake version, since the browser is under the attacker's control. The only way to mitigate this attack would be some sort of one time use token that's generated server-side by example.com, and authenticated by adsense each time it tries to display an ad, which I doubt adsense supports.
- thrwaway69 7y agoOne solution could be some sort of DRM based device attached ad...but that will cause other problems.
- lexicality 7y ago"Nearly there - just complete this captcha to see our advert!"
- stri8ed 7y agoI mean on the page content. Using something like Google's Recaptcha would reduce friction for legit users.
- throwaway2048 7y agoHow would it "reduce friction for legit users"
- rbritton 7y agoI think there was a time that was true. Now reCAPTCHA is so prone to tagging someone as a bot if they employ any ad blocking or tracking prevention that it significantly interferes with web use. It's an overall harm to the web in my opinion.
- pier25 7y agoAFAIK attackers only need to actually access your content once and extract the ad embed. Please correct me if I'm wrong.
- pcr0 7y agoI think parent comment meant putting up a captcha on the website for suspicious traffic, the way Cloudflare does. I don't think anyone is silly enough to suggest putting captchas on ads.