Ad blocking has become a safety issue. My parents are at an age where they fall for things. If a malicious ad pops up and offers to install McAfee, some other form of crapware, or outright scamware, they'll click that ad and install the thing. Then I'll get called over when the computer starts acting screwy. If Google, MS, etc. had ever gotten together and developed a way to filter malicious ads out of their own ad services, maybe we wouldn't be having this conversation. They didn't do that and probably never will.
If my parents get a new machine, the first thing I do is uninstall or, at least, delete the icons for Edge, Chrome, etc.. On goes Firefox, uBlock Origin, and a couple other extensions. They don't care what browser they use. They can't even name it. I just try to make sure they use a browser that isn't horribly unsafe.
We should all do this for people we care about. Don't ask them what browser they prefer. Odds are they don't know or care. Don't try to convince them to install Firefox themselves. They won't. Just do it for them. Think of it like picking up a rusty nail that's on their lawn. Sooner or later they're going to step on that thing if you don't.
My favorite story of just how little people who aren't as tech savvy don't differentiate between different parts of the browser UI (which naturally leads to clicking things that are best left unclicked) is when my grandmother told me her "internet was broken" and asked me to fix it. I was mentally preparing for a call to Verizon or something, but no, when she finally showed me, it turned out that one of the bookmarks on her toolbar in Safari had gone missing (presumably she accidentally deleted it). After I added it back and she clicked it to see that it opened properly, she was satisfied that I had fixed the internet. To her, when she opened Safari, it was all just "the internet"; she didn't differentiate between the local browser UI and the web, let alone different elements on a single webpage being from different sources.
It was even worse in the 90s/00s - on Windows, the IE browser icon was literally labeled “The Internet”
iirc there was a story in The Onion about someone who “accidentally deleted The Internet” on their Windows system and the whole Internet stopped working. They were so sorry, maybe it was in the Recycle Bin, there was still hope for the world, lol
This, Jen...is The Internet.
https://youtube.com/watch?v=iDbyYGrswtg
There’s this: [All Online Data Lost After Internet Crash | The Onion](https://youtu.be/lvpuT3aoypE?si=UI8wTzkNXdEKMO4x) which is pretty funny but doesn’t contain the idea of moving the internet into the trash bin… I feel like I remember that from somewhere too though
This isn't about users not being tech savvy enough. Ad Blocking has always been a safety issue. Many of the ransomware infections in enterprises were actually drive by ad driven exploit networks.
Sandboxes get better, yeah, but this is akin to leaving your door open in a neighborhood with violent crime and then saying I built this awesome laser guided Kevlar chamber that scans introducers upon entry instead.
Low resolution conflation of things is a very understandable outcome. It’s a lot of vocabulary to absorb to speak precisely about UI in general. I’m glad your grandmother has someone like you in her life.
My girlfriend worked in IT and people would frequently complain that Microsoft was down whenever something went wrong.
The better thing would be to hold Google directly accountable for every malicious ad they allow through their network. If they cannot do that, they should not be in business selling ads then.
Yes, that means amending the law (in the US). But the law as it is written facilitates crime.
This. There should be no intermediary liability protections for any paid or monetised content: as soon as a platform is either charging for placement or paying the creator, they should be treated as a publisher and held responsible.
Agreed
It's not just malicious software ads, they also sell ads to entities mitming every government service.
Not just the networks (although preferably also the networks) but also the publishers.
If a newspaper took money to advertise blatant, obvious scams, I assume a judge would consider them at least partially responsible for restitution, if not an accessory to the crime. Looking away really hard (and delegating the task of looking away really hard) shouldn't get you out of this.
Hold the publisher responsible, they can then hold the platform responsible, thus creating a market for platforms that actually fight scams. Right now, there is limited incentive to fight scams, as the scams still drive revenue. If you take money for it, you should be responsible for it.
Given the colour of the text, I just wanted to say that I agree 100% with this:
> If you take money for it, you should be responsible for it.
If they don't want to take responsibility then they should guarantee that the responsible party have provided valid credentials that can result in their being held responsible.
That would clear up the quagmire that is internet advertising pretty darn quick.
I am working on a hobby project to help me manage my Toastmasters clubs and Id love to get it into more hands because its genuinely helpful but more hands means more maintenance and opération costs. I asked Claude if I could charge for it and it basically said that as long as its a hobby project Im safe but once I start charging, then the Toastmasters organization could sue me or issue a cease and desist for using their IP to make money without permission, which makes sense. It did advise me to talk to a lawyer which I haven't done, but assuming it's right, then financial incentives causing other parties "harm" (for some definition of the word) are illegal.
In other words, I think the law wants what you and OP said to be true, but seems like it doesn't apply once you get big enough. Anecdotally, Amazon and Walmart and other big retailers seem to not be held responsible when they sell goods that dont work as advertised or even actively harm people.
This kind of thing has come up before with "murder for hire" advertisements [1]. The publishers were only found liable when the advertisement was very explicit. Seems like the bar is quite high and courts are currently unwilling to impose "undue burden" on publishers.
1. https://en.wikipedia.org/wiki/Soldier_of_Fortune_(magazine)#...
How do you figure out what is a malicious ad? That seems really difficult at scale.
If you're asking socially, you don't, that's the benefit of writing laws instead of programs.
If you're asking technically, well, google made over 400 billion dollars last year, they can spend some of that to figure it out.
Or stop serving ads. Just because it's difficult to do safely doesn't mean you get to just do it anyways because there's profit involved.
"At scale" sounds like an assumption that costs must decrease as income increases.
That's not required. Google could employ proportionality as many people reviewing what they advertise as, say, National Geographic Magazine.
You start with the obvious cases of sending you to a domain that serves malware, sure there will be instance of fraud that will slip trough, but lets not let best be the enemy of good
This is bad enough for Americans, but things are a bit worse for those who aren't.
If my government tries to regulate, tax, or otherwise annoy one of these corporations, their billionaire owner will deposit a few million into the right campaign fund and the Big Cheeto will tariff us, threaten to invade us, swear at us, send us ambassadors who swear at us, or start trying to rename bodies of water. (He'll probably do that anyways.) In general, it's bad enough for our business that we usually just let these companies do what they want and hope that, someday, the U.S. will regulate them properly. That's unlikely to happen anytime soon. (Note: Even Democrats get nasty when their campaign funding is threatened.)
In the meantime, look out for the people you care about and support anything that pries your data out of American fingers.
Idk if apple can validate each and every apps before publishing to appstore, why can't google and facebook validate each and every ads?
But they don’t. Google and others do vet ads, but when they don’t host them, the ads can change based on who is looking (clean ads for Google! Not for you!).
Google didn’t have this issue until they bought DoubleClick (text ads and they hosted). And they had pretty good privacy as they didn’t want to share shit.
After DC it all went to hell.
> But they don’t. Google and others do vet ads, but when they don’t host them, the ads can change based on who is looking (clean ads for Google! Not for you!).
That sounds like a problem that Google should have already solved. Maybe that's why "Don't Be Evil" got the boot.
> the ads can change based on who is looking (clean ads for Google! Not for you!).
How is that even allowed?
Define "validate". App Review is really only good at catching things that make Apple uncomfortable for financial reasons, or make their attorneys worried (trademarks, copyright, etc.) The sandboxing is what makes the App Store pretty unsuitable for distributing actual malware (the kind that can do stuff to your device without you knowing).
Well if they cannot technically differentiate malicious, then they should drop that business niche. They receive money for that, similar as selling stolen goods.
Cause that would cut into their profit margins, and section 230 absolves them of liability
Newspapers and magazines didn't sell ad space to obvious crooks back in the day. Scammers didn't have tv ads. Obviously there was somebody watching them. The trashy scams were reserved for the real scummy publishers: comic books.
X-Ray specs that didn't even work.
Scammers had entire TV networks.
https://en.wikipedia.org/wiki/Christian_Broadcasting_Network
How would one hold Google accountable? By fining them $1bn? $10bn? $100bn? To them it is just the cost of doing business.
We're beyond holding huge companies accountable. The only way they could be held accountable is if there was personal risk involved for the CEOs. There isn't.
At this point, breaking them up into smaller companies. Then start fining the individual companies so the balance sheets feel the fine more. Increase the fines exponentially for each violation.
The other option is jailing those who direct companies to break laws. It works for criminal organizations, why doesn't it work for companies?
If a scam ad is found, at the very least, require them to disclose business records to show how much money the scam ad made (revenue, not profit), and make them repay it. Leave it up to the platform whether to recoup the paid-out share from the publisher or not.
If they are caught doing it repeatedly without taking adequate measures to stop it, treat them as an accessory to the crime.
> There isn't.
Not with this attitude.
I hate these comments. What meaningful thing is this person supposed to do?
In the US, the government is _owned_ by corporations. To pretend otherwise is naive.
If I am the evil corporations owning the state I would love to make all citizens pathetic cynics who think they have no capability for change and therefore bears no responsibility.
Well I guess you are the smart one who will win! Put us all to shame, please.
Put execs in jail for enabling fraud
> How would one hold Google accountable? By fining them $1bn? $10bn? $100bn? To them it is just the cost of doing business.
Percentage of global gross revenue like the EU's GDPR does seems to work effectively enough for a scare tactic.
all of this seems a little like second-level nonsense.
it's like ... "when my vacuum cleaner takes pictures of my wife naked, it should use HTTPS when uploading the pictures to the cloud"
But … it really should
I mean, maybe we can try going after the scammers.. but we can’t even stop scam callers and junk mail
In Japan, the identity verification is quite strict to subscribe to a voice/text capable phone line. Still yet to get robocalls or spam texts. I'm sure they exist, but despite handing out my phone number to city hall and countless private businesses, I have yet to receive one.
On the other hand, enabling my Verizon eSIM is a surefire way to receive hourly "Potential Spam" calls, despite giving nobody outside of direct family my US phone number. Thankfully, I've convinced enough of my family to use Signal and we call/text through there instead.
Nowadays, I only turn on the Verizon line if I have to receive an SMS one-time code or call my broker.
Don't think the U.S. will ever solve this problem; people will just say something about privacy, the country's "too big" to combat spam at scale, etc. It's also too easy to get a phone number anonymously. A frequent phenomenon I've witnessed is that when someone blocks a phone number, the same caller contacts them again from a different number with the same area code.
You can stop junk mail for $8: https://news.ycombinator.com/item?id=47619939
Sorry, no solution for spam calls/texts.
Sadly does not apply to political organizations, which is probably the largest source of spam “mail” (to mention nothing of text/sms spam). The amount of crap stuffed into my mailbox every election season is insane.
Generalize this.
Every landlord should be directly accountable for all crimes committed by their tenants.
Every telco should be directly accountable for all crimes committed by their customers.
Meta should pay damages when their users stalk and harass people.
There are levels to this though.
You wouldn't hold a landlord accountable if it was a surprise that a crime took place, but if they were aware that some of their tenants were committing crimes and just "choosing not to ask about it," they could reasonably be called "accountable."
Telcos are regularly asked to give up information regarding crimes committed by their customers, see the Patriot Act for details - in some sense, we as a country have decided to hold them accountable for this (though, not spam).
Meta have been involved in a whole list of litigation that is at minimum adjacent to stalking/harassment, if not directly involving those things. I would need to look up to be more specific, though.
I know what you're trying to say, but you're saying it terribly.
If Ad Platforms don't want to be held responsible for the fraud that their platform literally delivered to the victim, then they should have KYC for all of their Customers that pay them money to deliver advertising to their victims. That way, shock fucking horror, someone or something might actually be able to be held responsible.
And if the argument is that there are many ways that scapegoats can be used and shell companies setup to avoid actual responsibility, then we'll know more about the next layer of regulation that's required.
Or we just give up and say that fraud is OK (which, I believe, is the current thinking in the US).
Try generalizing the argument without changing it substantially, then we'll talk.
A problem is that the platform owners argue that this kind of stuff is why they need to put up a security gate that prevents you from installing whatever you want on your own device while also allowing you to install the malware from the ads (... maybe because they want to control what you can install more than they care about the malware?)
> On goes Firefox, uBlock Origin, and a couple other extensions. They don't care what browser they use.
I did the same with my mom, but then her broker and doctor's websites started complaining that they will only run on a supported browser, i.e., Chrome.
I've gotten her to still use Firefox for most other things, but it's not easy.
A user-agent spoofer like Chrome Mask is helpful here:
https://addons.mozilla.org/en-US/firefox/addon/chrome-mask/
It's off by default and has to be turned on per site, but will automatically stay on for subsequent visits. Test the site with it to be sure it works for your mom. Most sites that insist on enforcing Chrome-only user-agents run just fine on Firefox. I've encountered a few that run even better on Firefox than they do on Chrome.
You can try Brave, it's Chromium under the hood so it's usually accepted and has built in ad blocking, and a one click way to turn it off for a specific site if you have an issue.
[flagged]
Did you try spoofing the User-Agent?
> If Google, MS, etc. had ever gotten together and developed a way to filter malicious ads out of their own ad services
This is the crux of it.
If they can't block scammers from their own platform then they should be fined out of having the platform in the first place. The profit they make should easily cover it - unless they like profiting from promoting scams, in which case they should be fined out of having the platform in the first place.
It's not just elderly parents. I've sat in on many an incident where skilled people in accounts or HR similarly saw and ad and thought "I have to do this thing", leading to compromise.
Evidently whenever money and safety are opposed, money wins every time.
Ad blocking is existential for Google. If everyone blocks ads, Google stops existing. They will do everything they can to prevent it, without going so far they stop existing for regulatory reasons either.
I'm looking forward to an AI product that filters all consumed Internet content to remove ads.
Now _that_ would be a killer feature.
It's not just Google, the Internet stops existing.
I know people have rosy eyes for a BBS/IRC comeback, but that will never happen.
By and large, people don't care about having to look at tide and Toyota ads to watch YouTube.
No it wouldn't.
Your bank, school, doctor, and government would all still have websites. Companies would still sell things online. Video calls and chat systems would be there. All the websites run by donation or self-funding would be unchanged. Without ads, the worst parts of the internet might stop existing though.
> It's not just Google, the Internet stops existing.
Uh? No?
The internet existed before being overrun by corporate presence. It still does. Advertising pays a lot, but take the ad money away and let it scale accordingly.
The worst thing about the modern internet is people's innate expectation that others will work/pay to entertain or inform them for free.
What existed in 1993 was a cultural blip, it's never coming back, so let it go.
> What existed in 1993 was a cultural blip, it's never coming back, so let it go.
Ha! I am under no illusion it is coming back. But even though it flows like the unstoppable tides, ad money is not a requirement.
I love Brave's seemingly easy and automatic ad blocking, but turning off shields for important things like banking and government sites is a chore. I struggled with domain whitelisting (if I'm honest I gave up on it some time ago as the recipes I found online didn't work). So I can't recommend it for less technical people. It's a step away from being the easiest way to control all that annoying content that comes at you when you're trying to do something else.
Tangentially related, but has anyone else noticed a big increase in fraud attempts over the last year or two? I hardly remember any a while back, but I've gotten probably a dozen calls this year that go "hey this is AmEx please confirm your credit card number" or some such.
It's partially a product of the widespread availability of LLMs. Criminal organizations that would previously have been limited by the language fluency, scale, or technical competence of the labor available to them can now use LLMs to supplement their operations. It's also helping them target new populations that you're more likely to be in alongside traditional victims like the elderly, the desperate, previous victims, etc. They're pretty slow to adopt new technologies, so scam usage is still ramping up.
Phone call scams seem to ebb and flow depending on which 'sucker lists' you're on. Online scams appear to be persistently on the rise, both against consumers and organizations (businesses, non-profits, and governments). I suspect that LLM-AI will be a boon for scammers of all sorts, but particularly for phone and video-call scammers.
Every now and then I hear advice to the effect that saying even a single word to a robocaller will get your number flagged for more, so you should just answer silently and hang-up. Whenever I follow that advice, I get more and more calls. Then I start engaging with callers to waste their time and resources. I press numbers, try to get to speak to a human, and then generally mess with them if I do get a human. That usually takes care of the calls for a while.
My credit card number is 1234 5678 abcd efgh.
What do you mean it has to be numbers? I can read it right here, it says abcd efgh.
Mine is actually all letters, it's G U L L I B L E. If you're having trouble remembering, I heard it's written on your ceiling right above you.
The problem is, Microsoft and Google themselves are doing shady things. A full screen advertising for using OneDrive on Windows and a full screen random request to use Google App when doing a Google search on Safari comes to mind. Apple is no different, when I press my Bluetooth button, it opens Music on macOS.
I’m sure we can find rather strange things going on Ubuntu too and bending the definitions a bit, there are several pleads for donation like on Gnome, Vim and Wikipedia that are a bit questionable.
They've all spent too long getting high on their own supply.
The longer a company is able to profits from something, the less they'll be able to see that it may even possibly be a net negative for society.
Google doesn't care about this. Try searching for a locksmith in your area on Google and the top results are all scans.
How would this scam work? Why would someone pose as a locksmith specifically?
They send out someone in an unmarked van who doesn't have a locksmith license (at least in CA these are a legal requirement and they are required to show it to you). When you ask to see it they tell you they keep it at the office for "safety". That was the extent of my personal experience.
I've read that if you let them work on your property, they will claim your bog-standard lock is unpickable, and charge you an exorbitant amount to drill it (destroying the lock) and replace it.
Almost everyone who calls a locksmith is in a hurry, dealing with something unfamiliar, so people are susceptible to this.
Instead of getting a local locksmith, it's a "lead gen" service which charges the locksmith $100 or something to get your info. They're placed on the map, but aren't actually there.
The only thing that should come up is actual local locksmiths.
To give my example, if you search for locksmiths or plumbers or any sorts of trades you'll land on a page for "small family locksmith in your small suburb name". Except the site has thousands of urls with the same exact content and pictures, one for every suburb in Australia. Gary the small business owner does not live in my street.
As far as I can tell its a national company with an overseas call center, the scam is that it looks like a local company - at least they can sell a lead gen to someone that can open my lock.
I've had this happen to me personally on vacation - we were locked out of our rental car, asked a person at the nearby place to call a locksmith to get me back in, and they didn't quote price over the phone. When they got there, they popped the lock and then wanted $200, cash only so you couldn't chargeback, which I learned after the fact is completely outrageous for that service. They had a lot of fake Google reviews that were glowing, overshadowed by the real ones calling out the scam.
I've heard worse happening in other cases where they drill locks and then quote much higher than $200 after they do it, it's sadly common.
$200 for an emergency specialty service is shockingly...fair?
That's exactly what I would think if I were in trouble and hadn't done any research, but in fact it is not. When I needed a locksmith a few years ago, at night, it cost $70.
The person charging you more than you think is reasonable in hindsight doesn’t make it a scam? It also doesn’t mean you can do a chargeback?
Specifically? Because it’s something people search for. Because it’s something people pay for. If the scammer can get you to pay for “a visit“ upfront, and never show up, they’ve made money.
>Ad blocking has become a safety issue. My parents are at an age where they fall for things. If a malicious ad pops up and offers to install McAfee, some other form of crapware, or outright scamware, they'll click that ad and install the thing.
I've been using the internet since the 80s. This has always been the case. Even before graphical browsers.
Bitcoin changed everything. It used to be if you hacked somebody's PC you got.... a hacked PC. Big whoop.
Bitcoin provided both a financial use for stolen compute and a bankless online international payment system for ransoms.
That's what turned the script kiddies into professionals. Malice and lulz were replaced with dollars and cents.
Nonsense. Before the advent of those first “you’re the 1000th visitor” banners or relatively harmless “worms” spready by literal .exe files sent by email in the early 2000s… most of the internet could be trusted by default.
And at that point the blast radius was so hilariously small, some rando compromising your computer was a nuisance versus a threat to your financial wellbeing.
Viruses were common on FTP sites and BBSs. They weren't all benign. DOS in particular had zero protections against damaging code. Bot armies hadn't been developed yet so malicious destruction was just as likely an outcome.
Yes, and what did the damaging code and viruses actually do in that era?
Software, OSs, and the internet at large were comically unsafe from a safety perspective. There was also a very high barrier of entry in terms of the skills required to take advantage of that, and very little incentive to do so compared to today or even 20 years ago.
If you got lucky, they just self-replicated onto floppies. Not so lucky, they would corrupt your hard drive.
Ad blocking has always been a safety issue.
> filter malicious ads out of their own ad services
It's worse than that. Google turned their exploit delivery platform into Google Tag Manager so they can be employed on more than just ads.
> the first thing I do is uninstall or, at least, delete the icons for Edge, Chrome, etc.
Does this run the risk of reverting with OS updates? History is full of OS vendors resetting defaults, whether that was maliciously intentional or inadvertently doesn't matter. If you set up Firefox as default browser yet the OS resets to using Edge, would your parents even notice?
Money from confused seniors getting scammed is a critical revenue stream. Without scams, ads are far less viable.
Raspberry pi + adguard + tailscale could be a good solution for you. Browser agnostic, you get an admin dashboard to manage the white/blacklists, see logs of the attempts and other goodies. Bonus, this combination works on mobile too. The only nit I have is that after restarting the phone, tailscale may not auto-start.
You could also set it up to be administered remotely so that you don't have to make that in person visit.
> They don't care what browser they use. They can't even name it.
You could even extend that to OS as well.
A few days ago, my mother asked me to fix her YouTube because she kept getting something telling her to update. I looked at YouTube on her iPhone and saw an autoplaying video ad that displayed an animated fake system style pop-up button, designed to look like an important iPhone OS security update. The ad even showed an animation of the button appearing on the screen, making it look even more like a real system notification.
This needs to stop.
Get Chromebook for them, I know it is backwards, but at least they won't install viruses.
The kinds of banner ads that exist now are atrocious, as bad as they have ever been. Anything that masquerades as a legitimate internet or site service should be banned, I really detest the ones that are simply some sort of fake captcha, sign in, etc.
They must pay the best because so many old forums that are/were near and dear to my heart use them to pay for servers, hopefully because they only saw the profit number and didn't consider the consequences, but you never know.
uBlock Origin lite is an mv3 extension and blocks ads.
> If a malicious ad pops up and offers to install McAfee, some other form of crapware, or outright scamware, they'll click that ad and install the thing.
This has been solved on iOS. It’s not an ads problem.
How? Can't apps link you to the app store where you have to make an in app purchase?
It feels weird that everyone is talking like Google has banned adblocking in Chrome, when there's dozens of adblockers still in the extension store, including an updated version of uBO that works 90% the same.
Ad-blocking is a safety issue, but luckily you can still block them just fine.[1]
The only thing this heavily neuters is tracking blocking, but no one admits that because they know, deep down, that ~0% of the non-tech crowd cares, so it's not as good at stirring up outrage as being dishonest is.
[1] If anything gorhill is to blame for the safety issue, since he refused to update his extension in-place, so any distant relatives will have the adblockers you installed for them removed, instead of updating to the fully functional Mv3 version.
> My parents are at an age where they fall for things.
If they're falling for things that they didn't used to fall for, that's sounds more like dementia than age.
Or maybe there are more things using the same tactics / scammer's reach keeps increasing.
My parents "fell" for fundamentalism early (as kids - raised in it), for televangelists in their 40s, and Fox News in their 70s/80s. Fox News so recently only because they didn't get it very often until about 10 years ago when they moved into a retirement home (didn't have cable before that).
Right that's why I qualified that with "things they didn't used to fall for".
There’s a long way between perfectly functioning and dementia. I want to say that I hope you never find out, but the twilight of life is tough either way.
"Being at an age" can include having age-related illnesses.
Right but an age-related illness that affects cognition is generally just called dementia.
Normal cognitive decline comes gradually with age to most people. Dementia is more severe, often more sudden, and can be caused by a host of things, from Alzheimer's to brain injury. Regardless, you're not going to take away somebody's computer because their brain isn't quite as sharp as it once was.