5 ms·
This is a really interesting observation. Can you expand upon what "shrinks the pool of competing bidders significantly" means? For instance, when creating an A
by hashtree 12y ago
This is a really interesting observation. Can you expand upon what "shrinks the pool of competing bidders significantly" means? For instance, when creating an Ad Words campaign, is there a setting/option that they must opt-in to and if they do not they won't be considered for secure-only advertising?
- taspeotis 12y agoI'm guessing it means that ads that lead to http:// http:// urls get binned.
- coldtea 12y agoNo, ads that originate from such urls get binned.
- Donzo 12y agoHere is relevant information about it taken from this page: https://support.google.com/adsense/answer/10528?hl=en https://support.google.com/adsense/answer/10528?hl=en "HTTPS-enabled sites require that all content on the page, including the ads, be SSL-compliant. As such, AdSense will remove all non-SSL compliant ads from competing in the auction on these pages. If you do decide to convert your HTTP site to HTTPS, please be aware that because we remove non-SSL compliant ads from the auction, thereby reducing auction pressure, ads on your HTTPS pages might earn less than those on your HTTP pages."
- Donzo 12y agoTo answer your question more directly: besides AdWords, Google manages the ad inventories of a dozen or so third-party ad networks. Lots of the display advertisements that appear on the web are served via these ad networks. Many of these connections are not encrypted and, as you probably know, if a single image on the page is not encrypted it jeopardizes the security of the connection. To maintain the integrity of the connection, the nonsecure networks are eliminated from the bidding process. Fewer bidders, lower final value.
- ptx 12y ago> if a single image on the page is not encrypted it jeopardizes the security of the connection But only in the sense that the article text could say e.g. "implement the authentication algorithm according to illustration #42" and illustration #42 could have been maliciously replaced with an image showing an incorrect implementation, right? A script served over an insecure connection, on the other hand, would give the attacker access to the DOM and compromise the entire page (and other pages on the site with AJAX). So does the fact that ads need to be served securely imply that they have the ability to execute JavaScript in the context of the page? By serving ads (whether encrypted or not) am I trusting every advertiser on the network with the session cookies of all my users, essentially allowing them to intercept communications between the site and its users?
- Donzo 12y agoI can't speak too much about this because it is on the fringes of my knowledge. All I can say is that I trust Google's systems to screen for malverstising. I remember there was an incident recently where one of the ad networks that they manage was serving malicious JavaScript, but they caught it pretty quickly and blocked that network from serving ads. I do not believe that I can improve on their systems.
- jimktrains2 12y ago> if a single image on the page is not encrypted it jeopardizes the security of the connection Or, you know, loading untrusted javascript onto your page could also jeopardize the security of your site.