3 ms·
"can not" maybe... but it wouldn't be the first time a "trusted" company served malware. But the issue goes beyond just getting stuff from youtube directly. Th
by wernercd 3y ago
"can not" maybe... but it wouldn't be the first time a "trusted" company served malware.
But the issue goes beyond just getting stuff from youtube directly. They are absolutely a source of links to unsafe places - their advertisement platform serves ads that send you to places with unsafe javascript.
So even if you was correct about "can not" (which is obviously untrue)... they can and regularly do cause issue none the less.
And "but youtube" sidesteps the issue that ad blockers aren't just security from youtube. Youtube is one of millions of websites. Full of shitty websites with horrible security practices and awful practices around annoying advertisements.
- charcircuit 3y ago>So even if you was correct about "can not" (which is obviously untrue)... It is not obviously untrue. Internet ads with malicous JavaScript come from sketchy ad networks. YouTube does not auction its ad space to third party ad networks.
- aaomidi 3y agoGoogle search literally showed an ad for a fake keepass just a few weeks ago. https://www.bleepingcomputer.com/news/security/fake-keepass-site-uses-google-ads-and-punycode-to-push-malware/ https://www.bleepingcomputer.com/news/security/fake-keepass-...
- charcircuit 3y agoShowing that ad did not serve malicous javscript which is what we are talking about.
- mtlmtlmtlmtl 3y agoThat's what you're talking about. OP is talking about security in general. Phishing and honeypotting isn't malicious, in your mind?
- aaomidi 3y agoAlso even if YouTube doesn’t serve malicious JS, that doesn’t mean the website they’re advertising doesn’t. Malicious JS, to be fair, shouldn’t be able to do really any significant damage. However, it is the right of the user to decide what gets displayed on their screen and grabs their attention span.
- wernercd 3y agoAs others have stated, I'm actually focused on the bigger picture more than just "YouTube directly". Ad Blockers stop the secondary stuff (ad campaigns that YouTube serves sending you to unsafe places) as well as primary stuff (actual "malicious" JavaScript served directly from YouTube). (they also do stuff like block trackers and the like but those aren't the topic of conversation here precisely other than saying that Ad Blockers are a security measure on many levels - not just on YouTube proper) While the odds are low that YouTube itself will serve malicious JavaScript... the chance isn't 0. They have better security practices than other smaller companies but stupid or malicious employees exist and - as I think I said - things have been known to happen. Even with best practices stuff like supply chain attacks exist as do stuff like stuff injected into dependencies. So while there hasn't been an "actual" breach at YouTube (if you exclude their malicious ad campaigns which "only" direct you to unsafe places but aren't DIRECTLY served by YouTube)... the fact remains that interacting with YouTube (or anything on the internet) WILL lead to eventually to unsafe places. I have no problem admitting that YouTube is going to be better at not directly serving adware/malware/etc... but can you admit that that's not what I personally am focused on? My original statement that Ad Blockers are security is 100% justified based on the decades of experience at this point.