4 ms·
So many media sites have a ton of javascript widgets: ad networks serving third-party ads serving third-party tracking scripts, recommendation tools, analytics,
by dkoch 13y ago
So many media sites have a ton of javascript widgets: ad networks serving third-party ads serving third-party tracking scripts, recommendation tools, analytics, etc. It really increases the attack surface.
How do publishers know that the scripts that go on their pages are safe?
- ihsw 13y agoThat is the risk you take with ads, and to answer your question: they don't know if it's safe. Frankly it would be nice to not run third-party scripts completely outside of your control, but ad networks would never comply with such a one-sided relationship.
- ISL 13y agoNever is a challenging word to say. Once upon a time, banners were only images. On at least one site I frequent, the served advertising images are gifs.
- theg2 13y agoIt's a constant battle between so many internal groups about what should be on a news site. Editorial wants the new cool startup storytelling platform , marketing and advertising are using various ad networks and platforms, countless social networking platforms and apis, 3rd party software to manage live streaming, publishing, or what have you. And behind that is a usually under resourced development team trying desperately to grow the network while re-working old code projects rushed together because of some breaking news story. In my experience, working for a news agency is a careful balance between trying to establish solid software engineering practices, rushed prototype code, and sysadmin with large amounts of social thrown in just to keep it interesting.
- chongli 13y agoHow do publishers know that the scripts that go on their pages are safe? They use technologies such as Google Caja to control access to the global object.
- seliopou 13y agoPublishers should use AdSafe[1], which is a system for sandboxing widgets. AdSafe provides widget authors an API for access object properties and the DOM, as well as a static check to ensure that widgets are using this API properly. Given that the static check passes, and the library implementing the API is correct, then your widget is properly sandboxed and attacks like that can't happen. Check out the AdSafety paper[2] for more details about the extent to which AdSafe has been verified. Disclosure: I'm an author on the paper. EDIT: Here's a great talk by Arjun on AdSafety: https://www.usenix.org/conference/usenix-security-11/adsafety-type-based-verification-javascript-sandboxing https://www.usenix.org/conference/usenix-security-11/adsafet... [1]: http://www.adsafe.org/ http://www.adsafe.org/ [2]: http://cs.brown.edu/research/plt/dl/adsafety/v1 http://cs.brown.edu/research/plt/dl/adsafety/v1
- bentlegen 13y agoAFAIK, there was nothing vulnerable in the widget itself: the hackers accessed Outbrain's admin panel, and changed the content of their recommended links to point to their website instead. The hackers posted screenshots of accessing the admin panel: http://mashable.com/2013/08/15/outbrain-hacked/ http://mashable.com/2013/08/15/outbrain-hacked/
- seliopou 13y agoWhat was reported[1] was that certain stories were redirecting users to the SEA's site. This implies that they weren't just rewriting recommended links, but were changing the code of the widgets, which resulted in that behavior. [1]: http://www.politico.com/blogs/media/2013/08/washington-post-hacked-170594.html http://www.politico.com/blogs/media/2013/08/washington-post-...
- bentlegen 13y agoAh, you're right. This screenshot actually shows the HTML they injected: http://rack.0.mshcdn.com/media/ZgkyMDEzLzA4LzE1L2E1L3RpbWVzYWZmZWN0Ljg0OWQ0LmpwZwpwCXRodW1iCTEyMDB4OTYwMD4/ac8169ff/d19/times-affected-outbrain-admin-panel.jpg http://rack.0.mshcdn.com/media/ZgkyMDEzLzA4LzE1L2E1L3RpbWVzY...