7 ms·
How eBay Worked With The FBI To Put Its Top Affiliate Marketers In Prison
- curiousdannii 13y ago"So eBay installed a tiny “gif” file on its homepage. A gif is simply an image file. This one was so tiny no one could see it. It sat there invisibly."
- dopamean 13y agoBrilliant writing.
- AJ007 13y agoI would suspect the idea started out just as one of wondering how flawed eBay's affiliate tracking system was. Then, they figure well may be I'll be able to do this a few weeks or a month, they'll kick me off and I won't get paid. But, that doesn't happen and instead commissioned account reps (I am assuming they are on commission) keep encouraging it. A lot of things fall under wire fraud rules. A lot of very common and routine business practices qualify as wire fraud. The fact that that is the only charge is very telling.
- Sujan 13y agoDoes anyone get what the author actually means in the "invisible gif" paragraph? Makes no sense to me how this could actually have helped to decide if the traffic was real or malicious :/
- unreal37 13y agoSo the accused were placing an unrelated widget on other people's sites and adding the eBay cookie as part of the payload. The user never actually was directed to eBay. So say eBay notices they are serving 1 million cookies a month to users, but only have 50,000 visitors relating to those people on their homepage. That's how they know this was cookie stuffing and not legitimate traffic.
- Sujan 13y agoSee https://news.ycombinator.com/item?id=5651510 https://news.ycombinator.com/item?id=5651510 - just doesn't work that way afaik.
- unreal37 13y agoI don't think this description is accurate. It makes no sense for an invisible iframe to display the entire ebay homepage to the user - people would notice 100's of server connections and an extra 1MB download for a page view. More likely they found the one Javascript file on ebay that creates the cookie, and ONLY loads that Javascript.
- Sujan 13y agoWell, I know that's how _lots_ of people did it in 2003/2004. The guys I hang out with (ahem...) were some of them. In the more shady parts of the internet it's actually still quite common today. Nobody notices anything.
- noonespecial 13y agoFor the hack to work, the victim's computer had to get a cookie from ebay. The widget caused this cookie to get downloaded to the victims computer, but only this cookie. Normal visits from legitimate users get everything on the page. Adding a small invisible file meant that a normal user would get this file as well as the cookie but the malicious widget would only grab the cookie. Finding out how many IP's were legit vs bogus was then a simple matter of going through the http logs making sure all gets of the cookie had matching gets of the gif. Cookie gets without gif gets were fraud.
- Sujan 13y agoWith cookie-stuffing the cookie is normally "generated" by loading a page in an invisible iframe. The loaded page is actually the same you would land on if you clicked normal advertising, with "everything on the page" - including an invisible gif. Visibility or Invisibility of the iframe doesn't change anything to the loading of this file. That's why it doesn't make sense to me. Or did they use another method to place the cookie I don't know about?
- kybernetyk 13y agoYou could trigger cookie setting with the img tag. <img src=http://affiliate-link-to-ebay.com> http://affiliate-link-to-ebay.com> would set the cookie on most browsers. I don't know if that works anymore because my "affiliate" time is well long over but I guess this loophole has been fixed long since. IIRC iframe was a little problematic with some websites as they had frame break out scripts [1] - so you had to be creative. The golden wild west times ... I somehow miss them. Money was lying on the information super highway - you just had to pick it up ;) [1] something like http://www.thesitewizard.com/archive/framebreak.shtml http://www.thesitewizard.com/archive/framebreak.shtml
- Sujan 13y agoEbay didn't use frame breakers, so much I know ;)
- a5seo 13y ago
- kreilly 13y agoI suspect this was 1x1 image pixel similar to what is routine practice in online advertising to track site visits.
- xSwag 13y agodomainx.tld cannot set a cookie on ebay.com. Did they just iframe ebay (with affiliate ID) and get caught? Or did they use some other method?
- ianhawes 13y agoIframe of the affiliate link. eBay sets the required cookies.
- thetrumanshow 13y agoWait, so they just rendered an iframe of a random product on ebay that contained their affiliate information on a bunch of widgets they hosted ... and this lands you in prison? Lets imagine I publish an eBay widget (I don't) to promote products I think people should buy. Lets say the widget just renders products in my sidebar. Lets say thousands of blogs then install this. Would I be then bound for prison? I'm struggling to understand this murky situation based on how you described it.
- sledmonkey 13y agoFrom my limited understanding of cookie stuffing you are trying to get the ebay cookie on someone's computer without them knowing and without actually promoting anything for ebay. In your example you would actually be promoting ebay products although i'm not sure if that is sufficient to be legit. Haven't looked at the ebay affiliate terms in a while but you might be limited to placing cookies only when they click through in a link.
- speeder 13y agoTheir widget did not advertise eBay at all, and when clicked it lied to eBay claiming someone clicked a eBay ad, when the person probably only wanted to see the widget about page or something like that.
- chopsueyar 13y agoI'm assuming it would be a hidden iframe and then trigger an actual click on an ebay affiliate link, so it would appear the user has clicked the link. Your hypothetical scenario is actually showing products. According to the article, it seems eBay's gripe was that once the cookie was placed, the transparent .gif on their homepage was never triggered, so these affiliates were not sending traffic to eBay, but randomly waiting for these eBay users to purchase something from eBay. This method was actually used by several successful affiliate marketers, now considered "industry veterans", in the early 2000s for Amazon.com and other big affiliate marketing programs. It would eventually get one kicked out of the affiliate program and the violator would not receive any of their commissions, but this is the first I have heard of the FBI federally prosecuting affiliates for cookie stuffing.
- rwmj 13y agoMore accurate to say to "put two fraudsters in prison". Hopefully they'll keep on putting fraudsters in prison.
- deleted 13y ago[deleted]
- thetrumanshow 13y agoI agree, but the line that defines fraud is scarily unclear, IMO. Should the Airbnb founders be sent to prison for spoofing interest in Craigslist ads and breaking their TOS? If the consensus shifts to yes, then our industry will become a very scary place to invest time and energy.
- milesskorpen 13y agoWhile that line might be vague, are you arguing that this example _isn't_ fraud? I'm sure they violated the affiliate network terms of service — which is one thing if you're an individual user, but when it's a business contract, terms become much more important. Moreover, these guys had to know they were in violation of the spirit of these programs — affiliate marketing is _marketing_, which they were doing none of.
- thetrumanshow 13y agoHeh. Nope, not _arguing_ that, because arguing what constitutes fraud and what does not belongs ONLY to the administrators of said governing laws. If I were presiding over this specific case, and had a breadth of understanding that confirmed they were cookie-stuffing beyond a doubt, I would move to convict them. I do think the line that separates a civil matter and a criminal matter is unclear at times. Further edit: Oh, were you asking if I thought the Airbnb behavior an example of fraud? Well, now I guess I do... based on what I read today. I still think its a civil issue, but it doesn't matter what I think. Prosecutors be prosecutin'.
- milesskorpen 13y ago
- belorn 13y ago> Much of Hogan's apartment was a clutter of screens, hard drives and keyboards — which the FBI confiscated. That must have been some very advanced and dangerous looking screens and keyboards. Why do we still accept this kind of confiscation of unrelated goods, while throwing big objections if the police had confiscated jewelery, clothes, or anything other non-connected but expensive items? By now, for all the tons of electronic items confiscated during raids, has any single screen or keyboard ever been part of the evidence provided to a court?
- deleted 13y ago[deleted]
- Sujan 13y agoProbably not, but for example some police officer is probably still very happy about one of my monitors I used on my gaming machine when I was 14 ;) (And yeah, I'm totally ok with it)
- mikeash 13y agoI'm sure a lot of laptop computers containing screens and keyboards have been used as evidence. It may be a little too much to ask FBI agents to only take that which contains data, when it's not necessarily always completely apparent.
- readme 13y agoIndeed. Newer computers can look like a plain old monitor and have an entire system onboard. This is typically obvious when it's a mac, but would an FBI agent pick out this System76 computer as not being "just a monitor"? Who knows (https://www.system76.com/desktops/model/sabc1 https://www.system76.com/desktops/model/sabc1)
- kposehn 13y ago"The problem with affiliate marketing is that there isn't much money in it." A better statement would be: "The problem with the eBay affiliate program is that there isn't much money in it." This is not a problem with affiliate marketing in general.
- AznHisoka 13y agoActually there's a bit of truth in it. The dirty secret is that 90% of affiliate revenue is generated by coupon sites. For the most part retailers are giving away money that they probably would've generated any way w/o the affiliate.
- smackfu 13y agoReally? I would think the big dog for affiliate payments is Amazon, and they don't really have much in the way of coupons.
- AznHisoka 13y agoAmazon has a 24-hour cookie. So you get paid even if someone clicks on your link and buys something else later in the day. I wouldn't be surprised if this accounted for a huge majority of their affiliate payouts. Cases where someone buys a product directly from Amazon after reading a review are a minority, imo.
- makomk 13y agoYeah. At one point I was seeing pop-up ads on some sites that were simply random searches on Amazon - I assume they were trying to take advantage of Amazon's affiliate scheme.
- unreal37 13y agoI can remember talking with the Amazon Affiliate people in a conference call 10 years ago. They have been leaders in this game a long time, and I can believe they have tightened their security on fraud as tight as it can go.
- robk 13y agoExcellent. Fraudsters deserve jail time. Cookie stuffing is clearly fraudulent.
- celticjames 13y agoShocked to learn that Brian Dunning has done this. I've been listening to his Skeptoid podcast for years. I always pictured someone of modest or middle class means because he solicits donations to help keep the podcast going. I didn't think he was also making millions from fraud. Ironically, 'consumer frauds' is one of things he has listed on his website as a target of his skeptical inquiry. Found this blog post with court documents and background: http://www.skepticalabyss.com/?p=291 http://www.skepticalabyss.com/?p=291 EDIT: Found this old blog post by Brian Dunning: http://skeptoid.com/blog/2011/10/05/a-partial-explanation/ http://skeptoid.com/blog/2011/10/05/a-partial-explanation/ "Cookie stuffing refers to a web site writing a cookie to your browser without your knowledge or permission. ... It’s a scary-sounding term, but it’s fundamental to the way Internet advertising works. ... Cookie stuffing is more than just a standard practice; it’s an essential component of the mechanics of serving ads effectively."
- qeorge 13y agoWow, that's a whopper. (the bit about cookie stuffing being normal) As I understand it, they would do something like this: on every 1 of 10,000 page views (to Digital Point's forums, or other sites), they would embed a page from eBay (as the source of an image), which had their affiliate code in it. The visitor was none the wiser. Keep in mind digital point gets a ton of traffic. Though only a small percentage had a cookie dropped, it added up to many. Purely through coincidence, some of these people would later buy something on eBay in the next 30 days, earning them a commission. Its hard to argue they earned the commission, TOS or otherwise.
- Matsta 13y agoAhh this brings back some memories. The articles mentions the guy who made the cooking stuffing software. He was pretty active on a private part of a forum I'm still part of. Anyway eBay went after the forum as well, and promptly deleted his account and all the threads mentioning eBay. They also moved their servers offshore and deleted pretty much every thread that mentioned eBay in it. I do remember he wrote a massive long thread about how the FBI raided his house and seized all his computers. He said the FBI agents weren't even told why they were conducting a raid on him and actually felt kind of sorry for him. He charged a pretty hefty price for the software ($500/month for the basic plan), but it was pretty advanced. They figured out that they could spoof referrers in flash, so rather then have a 1x1px image file, it was a tiny .swf file. People were banking on that though, eBay first, then Amazon. You could buy shitty porn traffic and parked domain traffic for literally $1-2/1000 uniques visitors and stuff them all with cookies. It was also round the same time Craigslist cracked down on affiliate marketers. People were literally getting hundreds of conversions a day on rebill offers like credit ratings and dating verification offers. One guy fled to South America so Craiglist and the FBI couldn't find him as he was literally making 6 figures a day. I probably have said too much, but now everyone is pretty smart now. Facebook were the last ones to smarten their act up since their whole system/backend had so many loopholes in there it wasn't funny. Plus their security team only worked Monday-Friday, so if you noticed up until 2012, there would be a bunch of spam on your feed during the weekends.
- unreal37 13y agoI also tend to believe that these companies sanctioned this activity until they were against it. A year after they claim to have started investigating it, they invite one of the guys to a private dinner where he is the only non-eBay employee in attendance, and treat him like a king. Its a contradiction. Very interesting stuff. That must have been a fun forum at the time, when easy money was to be made like this. Thanks for the insight.
- corresation 13y agoI also tend to believe that these companies sanctioned this activity until they were against it. Why? It provided absolutely no value to them. Actually worse, it cost them affiliate fees on sales that rightfully would have been affiliate fee free. There is no scenario where it makes sense that eBay (edit: wow originally wrote Amazon) would endorse this. they invite one of the guys to a private dinner where he is the only non-eBay employee in attendance, and treat him like a king. Have you considered that maybe his sense of truth is a little skewed?
- alanlewis 13y agoMy takeaway from this is: stay the hell away from affiliate marketing.
- hackerboos 13y agoNo just don't commit fraud.
- kposehn 13y agoBest answer I've seen yet.
- mmanfrin 13y ago'Top Affiliate Marketers' is linkbait. He committed fraud. Cookie stuffing is illegal from any angle.
- ChrisNorstrom 13y agoReal Quick: Just wondering, what if you made a browser extension that replaced all the links a user saw on every page they visited to affiliates links from Amazon and Ebay? Would that work?
- magikbum 13y agoTheir whole story reads as an elaborate squeeze page. "Earn $10 Million a Year on Ebay now!"
- dude3 13y agoAnd the bankers.... O yah nothing happens to them. 28 million wasn't enough apparently
- driverdan 13y agoI came really close to getting into cookie stuffing back in its heyday. I'm really glad I didn't. No one gave a second thought to it 5 years ago. I never once saw the words "fraud" and "cookie stuffing" on the same page. Around that time I worked on finding ways to do untraceable cookie stuffing. Bouncing people through SSL to kill the referer, using Flash, etc. I even found a security hole in IE that gave me access to cross domain iframes. That was killer because you could load another site in an iframe then use JS to click an affiliate link or manipulate the page, making it appear completely legit. Luckily it never went past research. I registered a domain and planned on creating a cookie stuffing service but never finished it and never did any actual cookie stuffing.
- cpncrunch 13y agoIt just sounds like ebay's affiliate scheme is/was wide open to abuse.