12 ms·
That doesn't work because it's not the ads themselves that serve the malware, but the page the ads point to. Changing that after the review is done is trivial,
by Chabsff 4y ago
That doesn't work because it's not the ads themselves that serve the malware, but the page the ads point to. Changing that after the review is done is trivial, and asking landing pages to never change is simply unreasonable for a vast number of reasons.
- JohnFen 4y agoThat's why I included "vet the advertisers". It's not just the ads that need to be examined, but the people putting the ads up.
- shadowgovt 4y agoWhat major city would you recommend Google employ at 100% to vet enough advertisers to support nearly 30 billion daily ad impressions? Or, alternatively, should there be a few tens of thousands of firms allowed to advertise on the Internet and the rest of us can just pound sand? (... actually, now that I think that "out loud," a distributed trust model would be an interesting idea. Google, instead of vetting ads, could vet trusted ad resellers, and knock entire resellers off the network that failed to do due diligence. The resellers would be responsible for policing their various houses and if you didn't like the terms one provided you could go to another. This is, perhaps, one of those situations where more middlemen would be desirable).
- JohnFen 4y agoI already mentioned that it doesn't scale. The real issue, IMO, is that Google's business model is just fundamentally bad. But Google is large enough that it doesn't matter. They're like a large industrial polluter poisoning the lands and arguing that there's nothing they can effectively do about it because addressing the problem would be bad for their business.
- shadowgovt 4y agoWell, their business and the business of everyone that advertises online. So it comes back to "Should we all pound sand because of a (statistically) few bad actors?" Firefox advertises at the top of "download browser." Should we cede their ability to be found to whoever Google thinks should be at the top of that organic result? Because by user numbers alone, it probably won't be Firefox!
- JohnFen 4y agoI think a strong case can be made that if a business cannot operate without causing harm to unconsenting others, it should not be operating. > because of a (statistically) few bad actors? It doesn't actually matter how many or few bad actors there are. What matters is how much harm is being done. I'm not sure what your point is about Firefox, but in general, it doesn't matter if mitigating the harm Google's ad system does adversely affects Firefox or any other advertiser.
- shadowgovt 4y agoWho are the unconsenting others? The people who chose to trust a Google ad? I'm not sure what consent means if it doesn't mean "user clicked on a result after asking Google for results." The backstop here is the user doesn't come back because they got screwed by Google, not that some third-party makes that decision for people. But yes, I suspect if Google can't get on top of this problem they'll lose their leadership position in search.
- JohnFen 4y ago> I'm not sure what consent means if it doesn't mean "user clicked on a result after asking Google for results." First, I'm talking about ads, not search results. Although Google conflates the two as much as they can get away with, and people often get confused as to which is which. I can't imagine how clicking on an ad can be interpreted as consent to being exposed to malware. In order to be considered "consent", the person has to be fully and accurately informed of what they're being asked to consent to. > The backstop here is the user doesn't come back because they got screwed by Google I truly wish we lived in a world where that could be expected.
- tracker1 4y agoIt can scale just fine... Green certs for SSL have been able to scale just fine... why, you pay for it. Advertisers should have to pay for verification.. it doesn't have to be an excessive fee, and can be connected to a bank account in good standing. Holding an amount in escrow during the first year could help as well. Why shouldn't advertisers have to clear the same hurdle as opening a bank account in most western countries?
- cycomanic 4y agoWhy should we care that it's not profitable for Google to do so? I would argue they are facilitating illegal activities, so why shouldn't they financially (and maybe criminally) liable? If that destroys their business model, why should we care?
- manigandham 4y agoAdtech veteran here. That's not how the industry works. All ads on major DSPs already require approval before they can run. Advertiser accounts too, especially at scale. While there are plenty of technical openings for fraud and malware, the vast majority is from known actors that can be resolved through business practices. A trillion-dollar megacorporation with hundreds of thousands of employees has more than enough resources to handle this. The reason it doesn't is because of the flow of money and incentives across the vast supply chain from advertisers and agencies to vendors and publishers.
- shadowgovt 4y agoAdtech veteran here (from the other side). The trillion dollar corporation has vast teams and assets invested in this project. No temporary monetary incentive is worth the risk of being seen as a likelier vendor of malware than quality searches. But the opposing operators get more and more sophisticated, countermeasures that work to half decade ago get circumvented, and the arms race continues.
- ineptech 4y agoLacking a technical fix, isn't this fundamentally a KYC problem? There's an arms race of fraud against banks and financial companies, but it seems like they're managing okay.
- shadowgovt 4y agoYes. Holding online advertising to KYC standards would lock most advertisers out of the ecosystem. But most aren't bad actors.
- manigandham 4y agoWhy would it lock out most advertisers?
- shadowgovt 4y ago
- cscurmudgeon 4y agoThese are good candidates for automated systems and LLMs (if they are as good and general as they say they are in Google's papers).
- godshatter 4y agoThey could make a bot that trawls the add URLs every so often and if it detects malware activity it could put a strike on the account associated with that ad. A few strikes, and they are banned and their ad account closed. It wouldn't be perfect, but it would help take out the worst offenders.
- shadowgovt 4y agoThey have that and they currently use it. It does take out the worst offenders. But Google had to down on the order of some million accounts in 2021. The crawlers hit rate is probably not enough to keep up with this problem.
- rtehfm 4y agoI mean they _do_ have VirusTotal to compare hashes to. It's obviously not fool-proof but it's an option.