Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It is interesting how this article starts. A guy has an app which drains users batteries. But it's not his fault of course, because it's the ad company. Except the ad company says it's not their fault, because the ad came from some other company.

This fingerpointing points to one of the core problems of the ad industry: They created a system where nobody knows who's responsible for anything, so malware and fraud has an easy time.

But this mode of thinking makes no sense. If you put ads in your app YOU are responsible. If you use an ad service from a shady company that outsources to other shady companies then you're still responsible.



Adtech companies know exactly who is responsible. Every ad on any serious network is approved before going live. Every single auction is logged, that's just basic tracking and necessary for billing anyway.

The problem is that there are no serious consequences in this industry. Ad fraud isn't a technical problem, it's a business problem, one that most companies are not incentivized to solve or prevent.


I work for a publisher and basically these ad networks say "you'll lose 50% of your revenue if you implement 'safe frames' in Google AdManager 360. We have some publishers who do it but basically no advertiser wants to run ads in a safeframe."

So you're saying the standard practice is to let the malicious ad buyers from your network run arbitrary javascript on our sites...

"Yes that's what our publishers do..."


SafeFrames are fine for most ads that are isolated in a box on the page, and those that wait for user interaction before changing dimensions.

The main issue today is because advertisers want viewability tracking (which safeframe has a minimal but poor API for) and they want it with their own independent providers. Also prebid.js used for header bidding does not support safe frames.

Things will improve though because IntersectionObserver is now built into modern browsers and even works in cross-domain iframes. There's also the Open Measurement SDK[1] from the IAB to standardize viewability finally, and Prebid.js is also working on using SafeFrames.

1. https://iabtechlab.com/standards/open-measurement-sdk/


If companies are "people" in the legal sense, why isn't there a 'corporate death penalty' for utter gross violations that would get real humans locked in a case for decades?

Is the CFAA only for fleshers? Why so?


I don't know about all that.

The "why" is because it's a 12-figure global industry including two of the most valuable companies in the world with unlimited resources and lobbying power, combined with highly technical mechanics and a complex network of business relationships that no politicians have any real understanding of.

I must add that there's also a (sometimes irrationally) strong reaction by those politicians and many others to working with anyone in adtech to even attempt to solve these problems which clearly doesn't help.


Because that legal fiction is only employed when it is convenient for the owners of the fictive "people" in question.


This is simply not true. I work for a top 3 major ad exchange, and there's only so much validation that can happen when you process 10s of millions of requests per second that have to leave your system in 40ms.


Like I said, this is a business problem. Those major ad exchanges should stop working with bad actors. 95% of ad fraud is coming from known sources and/or blatantly noticeable.


This is overlooking the problem of detecting that people are doing something malicious. There is a fairly large variety of unwanted behavior, both by the advertisements, and by the sites or apps hosting the ads.


That's covered under "no consequences". You don't need fancy tech, most of the malicious behavior comes from a limited set of bad actors and vectors. It's just not stopped because nobody cares to.


Sorry, but you genuinely do need fancy tech to detect it. There are multiple businesses that do nothing but that, plus teams at most of the big ad tech companies. You may notice this article cites Protected Media and DoubleVerify. You can't manually audit that kind of traffic volume.

Several of the ad tech companies have pressed law enforcement to prosecute some of these people, but mostly unsuccessfully. They're often in places that are difficult to extradite from like Russia, hiding behind some botnet: https://adexchanger.com/online-advertising/why-the-doj-final...


My point is that detection doesn't solve anything, it's treating the symptom. The solution is to stop working with bad actors, but nobody does that because it's easy money and there's plausible deniability by creating new companies, accounts, sites, etc.

Your 2nd statement is what I'm saying: no consequences refers to the lack of oversight, regulation and enforcement in the industry. That's why there's barely any prosecution. For example, Buzzfeed did an expose last year about Newsweek/IBTimes committing ad fraud, except it was already well known by everyone in adtech. People like getting paid and they're not going to stop on their own.

Btw, I personally know the founders of all those companies. If fraud was eliminated then they would go out of business. They're not interested in solving the problem even if they could.


Yeah, many supposedly legit websites (even large media companies) run these very scammy "man from YOUR LOCATION got rich in 20 days!" "one weird trick to get younger" ads that ultimately lead to some scam

But if you ask them, it's not their fault, but the ad company (Google), which in turn will point to a different company, etc

And in the end, people are scammed and Google gets a bit richer, but it's nobody's fault or responsibility


FWIW the companies responsible for those ads are Taboola, Outbrain, and Revcontent. I posted one especially egregious example last week on r/adops:

https://www.reddit.com/r/adops/comments/b0n57e/its_embarrass...


those are why I use ad blocking (hadn't heard of revcontent but def taboola and outbrain)

Man, yesterday I read a New York Times article in a view without ad blocking... I was actually embarrassed for them as a company. It's difficult to read an article when there are so many ads that there's doubt as to if there is more article below the next raft of ads.


Huh, you are right. Those scummy links at Washington Post are all Outbrain. I was mistaken then (because they use BOTH Google and Outbrain)


Google often has scummy ads as well. Haven't checked recently, but the ads on http://getpaint.net are often designed to look like download buttons to download the popular paint application.

Scummy AdSense ads are harder to pin down, of course, because of the live bidding and personalization.


Just check (3/22/19) and yup sure enough https://i.imgur.com/6SMBjDa.png . I find this is pretty common with many software websites that have ads, I'm really surprised paint.net doesn't switch to carbon or something.

EDIT: There's another one at the bottom of the page too. And they're randomized, some make it clear you aren't downloading Paint.net (such as the "Free Mac PDF Reader") but others aren't at all.


Why don't developers put a thick border with 'Advertisement' in bold around the ad space so that ads displayed doesn't look like they are native elements?


Because then they make less money.


It's fairly common for large media sites to use multiple ad vendors. WaPo isn't unique here.


Even responsible journalistic websites like Der Spiegel (insert comment about Relotius here) run ads like these, where the ads appear like "related articles" underneath serious articles...

And people ask me why I block ads.


I block, but some still get through. Ive got them blocked by a firewall and dns but parts go out of date. What do you use?


ublock origin + privacy badger has been virtually flawless for me.


Thank you


Even worse, I've seen several large media companies and news sites run ads on mobile that completely hijack the (Android, i.e. Chrome) browser and redirect to a third party landing page. They usually seem to get killed off eventually but every now and then they pop up again.

I'm not sure if these ads specifically target Android devices but it wouldn't surprise me.


Just as if you were to buy a child’s toy that has a secret embedded camera that streams to some foreign server.

It may be the manufacturers fault, but the person who sold it to you (the provider) is liable.

Should be the same here


I think it's a little bit more complicated. There's a point where this becomes somewhat questionable. Say the toy has a reputable certification and the company, up until now, never had any track record of mistreating their customers. In this case I'd argue the company is responsible, not the parent, and that it is actually worthy following through to find whoever acted maliciously rather than just picking the last person in the chain.

Now in the particular case of ads in applications, I think there are surely many developers who fail to do their due diligence when picking advertisement partners, but without a doubt there are also advertisement companies who excel at duping the developers they work with.


If you want to sell a product, you are liable for that product. It's simple.

Excessive trust is negligent. Let the market decide how to mitigate risk, but eliminating the risk creates opportunity for profiting from malfeasance.


If someone trades a product with a neighbor, are they liable since they sold it for a different form of currency? Or would this only be aimed at those who reach a certain level of trading/selling per year?


Right, and from the POV of the child, the parent is liable.


The child is crying, because the parent took the toy away.


Liable is a bit strong word here, liability without fault is mainly rejected concept in modern world.


If so, why is the retailer liable but not the parent?


I think retailer's liability here is also limited.

Imagine you are a shop selling cola in can.

If coca cola company put some unhealthy stuff in, you are not liable just for selling it. But if you made the stuff unhealthy because you stored it in direct sunlight long time, you are liable.


Because the parent is a natural person and the retailer is the last commercial entity in the chain. If the purchaser was a day-care center or other commercial entity, liability would be with them.


"without fault"? Is it reasonable to assume that a cheap internet connected toy with a video camera and microphone is secure enough to use without any precautions?


" secret embedded camera "

I bought "child's toy" and sold you "child's today", you expect seller to check every toy if there is "secret camera" ?


Yeah, I expect the seller to know what they're selling.


Interesting. So if you buy such a device for a gift, not knowing that it has a secret camera, and then decide you don't want it and resell it on Ebay, you'd agree that now it is you who are liable?


Sorry I don't have anything more substantive to add, but yes, I would be liable.


caveat emptor


This is settled now, everyone says google shouldn't have put a secret camera in their fancy thermostats:

https://news.ycombinator.com/item?id=19407147


> the person who sold it to you (the provider) is liable

I don't think that's true unless they knew it had this behavior or were negligent in some way.


That's how consumer law works nearly everywhere: every party has full (civil) liability over the outcome. The parties can then sue each other to settle it, without involvement of the consumer.


> or were negligent in some way

I'm not sure what to call allowing any old shit to run in your app under the guise of ads other than negligent. The fact that it's so common should not be an excuse.


Liability seems to be focused on pointing blame, and then based on that we decide who should clean up.

In situations like this perhaps it would be more productive if we had a system that focused more getting everyone to clean up and prevent this from happening again first, and then look at the liability part.

I do believe that this is the innate human response, the desire to "do the right thing". Most of us have the right mixture of nature/nurture to want to do that. But if the system doesn't enable that behavior or punishes that, that behavior will get suppressed and we end up in a miserable situation for everybody.

I dunno, it's not exactly an easy question or it would be solved already, and bad faith actors will exploit the goodwill of others too.


To me it feels like it's less of "nobody [in the industry] knows who's responsible" and more of "everybody takes responsibility for the earnings and nobody for the evils".


> If you put ads in your app YOU are responsible.

Take that line of thinking one more step. If a user installs a "free" app that is ad-supported, the USER is responsible.

I tell my kids this when they bitch about needing a new phone because theirs is too slow and the battery drains too fast. I say look at all the crap you installed on it. Clean it up don't be so dumb.


Lol, Did we have the same dad you sound like me talking to my kids. It is because we love them we don’t sugar coat it. But the issue I have is why are these ad companies even allowed to siphon information from a tablet my “child” is using. I know one needs to watch the internet that small children use. But if I have a tablet solely used for my kid to watch shows and perhaps play some educational games or coloring, what business does any company have sucking up data from that tablet. Surely just by the list of apps installed, all children’s games, indicates immediately that a kid owned the tablet but I suppose that Is just another data point they have and like.


That is all true but for practical intents and purposes you should probably make ad company responsible. It might seem a bit illogical but from practice standpoint, it is much easier to pursue and punish an ad company than to hunt each and everyone of its clients. Especially that they can just abandon the company and create new one, and it will be just cost of doing business, everyone of those shady players will have an ad shill company that can be replaced quickly in case of trouble.


Is there an ad network that doesn't use JS? You make a call to the ad network server, it returns an image, you display it in a native UIImageView (not a web view), and if the user taps it, you open a URL in a web view.

Unless the user taps the ad, no JS or HTML is involved, which eliminates the possibility of such tricks.

I looked for such a library a while back, but didn't find any.


Yes, you would think it would be that simple, but it’s definitely not.

Advertisers will give you double click (by google), atlas (Facebook), mediamind, etc tags m, to deliver as the ad. They will load in god knows what JS into their little space and (I cannot stress this enough), advertisers love their gimmicky little iteractable/expandable, engagement-filled ads.

To boot, they’re all laden with code to detect what publishers/sites/apps you’re displaying on, how much of the ad is viewable on screen and for how long, every scrap of code they can possibly fit in there to identify the user down to the finest grain they can manage.

You would think that things needn’t be this complex, but ad-tech companies have done a wonderful job of convincing advertisers that “targeted advertising is definitely better, and you definitely invest the extra cost in it, and definitely do all these other things because if you don’t then you’re totally falling behind your competitors, who are totally scraping every bit of data from their users, so you’d be a loser not to do the exact same thing and ~give all that dats to us.~ Sorry, make “valuable use” of all that data”.


Part of what js does in that ecosystem is support independent accounting for the advertiser of whether their ad was viewed and by who/what...which on the margins of course can still be tricked/gamed, but which for mainstream advertising is important.


>> But this mode of thinking makes no sense. If you put ads in your app YOU are responsible. If you use an ad service from a shady company that outsources to other shady companies then you're still responsible.

Then it comes back to the Play Store. They like having all those free apps. It makes users feel like their Andriod phone has whatever they need. Google needs to make apps searchable based on privacy settings. They need to encourage people to pay for user respecting apps. I'd happily pay a buck or two for lots of apps if only they didn't have add or try to get me to buy add-ons. Just give me upfront honesty about what I'm getting and I'll pay you for it. Stop hosting crapware in the app store!


Have you ever tried to convince someone to pay for something they believe they can get for free? The number of people who will pay monthly for user-respecting basic fundamentals like email is shockingly small.

How much do you pay for your email?


> How much do you pay for your email?

$50 year because I actually decided to put my money where my mouth is and actually pay for a service I use. I don’t regret it one bit.


Why would anyone pay for email when arguably the best in breed email service is free?

Why pay more for a worse product?


Gmail might have been best of breed in 2004 on the basis of its superior spam filter, but that's certainly not the case now. In fact, with the recent change to the UI, Gmail now loads incredibly slowly or not at all on Firefox. It's bad in Chrome too, but much closer to unusable on FF.

No other webmail service I've ever used has given me the lag issues Gmail has.


because fastmail is better than the free one. Just as good in the common use cases, they don't make me the product, and when in the rare case where I have a tech issue their support is responsive. There are a couple other paid email providers that I'm told provide services that are good.


I live this everyday. Our ad team blames the ad network they run on our products if malware gets through, rather than taking responsibility and banning the ad network. Or even better, taking responsibility themselves for selecting ad networks that run scams and malware.

To me, if an ad network allows crap through, we have to take onwership and penalize the ad network and move on. But there is no accountability. It's everyone fighting for that next penny.

No one in the supply chain takes responsibility for this. That's how I, someone who works for a company that has ad-supported products, runs an ad blocker at the router level in my home. If people are going to actively try to harm me and my family by hunting for pennies, I am going to seek protection.

And because no one takes responsibility for this whole mess, the whole house of cards will fall. More and more devices are coming with ad-blocking built in. If we can't responsibly create ad-supported businesses, how can we honestly expect people to want to see those ads?

Digital advertising is so divorced from making users happy.


> This fingerpointing points to one of the core problems of the ad industry: They created a system where nobody knows who's responsible for anything, so malware and fraud has an easy time.

They know.


This totally depends on unspoken agreement and assumptions.

- You invited me to dinner, went to shopping, bought some stuff to cook, one ingredient was bad, I got poisoned.

In my opinion, here you don't have responsibility, because you acted with your best knowledge and good expectations from shop.

This kind of stuff is happening on google a lot too, this is not totally about some small shady company, working with another shady company.


> - You invited me to dinner, went to shopping, bought some stuff to cook, one ingredient was bad, I got poisoned.

The difference is due diligence. In picking ingredients and preparing them the host of this dinner has most likely taken care to use what they have good reason to believe a reputable sources and methods.

People placing add on sites and in apps are doing no such thing for the most part - beyond concerns of outrageously illegal adverts or those that might otherwise offend their audience directly, they are simply picking the provider that is likely to pay them the most. This is insufficient due diligence so they shouldn't be able to pass the buck, but they can because there are so many levels of indirection in the industry it becomes difficult to prove who failed most.

There is commonality with your food example: the recent meat source problems in Europe when cheap horse meat was unexpectedly found in many places it shouldn't have been. This highlighted how little due diligence was happening at various points in that industry and the fact that the many levels of supplier supplying supplier supplying supplier made it easy for problems to go unnoticed as no one thought it was them that needed to check.


This isn't specific to ads. It's a problem either supply chain in every industry. It's why your clothes are made in dangerous sweatshops, why your electronics are made by dumping toxic chemicals in rivers, and why your chocolate is farmed by child slaves.


This happens all the time when a website serves malware through ads. The site will claim it isn't their fault, they aren't the ones serving the ads. And then they have the audacity to try and shame people for using adblockers.


The situation will never change for as long as """"""marketers"""""" continue to benefit from the big data collection it facilitates.


> This fingerpointing points to one of the core problems of the ad industry: They created a system where nobody knows who's responsible for anything,

This sounds like a lot of industries...


Nice Scotsman there.

> If you use an ad service from a shady company

And what if they aren't shady? Something large from a well known, non-shady company, like Twitter? Because that's who is mentioned in the article: Twitter's MoPub.

And is the reverse true? If you use these shady companies (Twitter and MoPub) are you contributing to the success of shady companies?

Bad advertisers are real, and they really exist. But trying to say that the person who relies on that software equally responsible as everyone down the pipe is a bit of a stretch. Otherwise, I could make the same extreme arguments about pretty much every tech company, big and small, and all the people that use them.

Even you.


This is why I use Brave browser. The internet needs ads but the ads should be whitelisted.


That wouldn't help here.

The problem being discussed here was adverts being run in the background of locally installed apps, not adverts in pages displayed by a browser.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: