HN user

jdangu

415 karma

co-founder Confiant

Posts22
Comments92
View on HN
www.confiant.com 2y ago

The Yandex leak: How a Russian search giant uses consumer data

jdangu
199pts254
blog.confiant.com 5y ago

Malvertiser ScamClub Bypasses Iframe Sandboxing with PostMessage (CVE-2021–1801)

jdangu
2pts0
blog.confiant.com 5y ago

Malvertising: Made in China

jdangu
5pts1
blog.confiant.com 6y ago

Confiant And Protected Media Uncover Mobile Billing Malvertiser WapSiphone

jdangu
1pts0
blog.confiant.com 6y ago

Tag Barnakle: The Malvertiser That Hacks Ad Servers-Redirects Victims to Malware

jdangu
2pts0
blog.confiant.com 6y ago

Fake Celebrity-Endorsed Scam Abuses Ad Tech to Net $1M in One Day

jdangu
2pts0
blog.confiant.com 6y ago

Malvertiser ‘EGobbler’ Exploits Chrome and WebKit Bugs, Infects over 1B Ads

jdangu
3pts1
blog.confiant.com 8y ago

Uncovering 2017’s Largest Malvertising Operation

jdangu
7pts0
finance.yahoo.com 8y ago

How to stop rogue ads that can set you up for malware

jdangu
1pts0
github.com 9y ago

Show HN: Embedded Redis client for Redis

jdangu
2pts0
www.theregister.co.uk 10y ago

Video malvertising campaign lasted 12 hours? Try two months

jdangu
2pts0
blog.malwarebytes.org 11y ago

FlashEK Strikes Again via Google's DoubleClick

jdangu
1pts0
blog.malwarebytes.org 11y ago

Exposing the Flash EITest Malware Campaign

jdangu
1pts0
www.proofpoint.com 11y ago

Malware in Ad Networks Infects Visitors and Jeopardizes Brands

jdangu
20pts9
www.invincea.com 11y ago

Micro-Targeted Malvertising via Real-time Ad Bidding [pdf]

jdangu
2pts0
www.underdog.io 12y ago

Apply to New York City’s top startups in 60 seconds.

jdangu
2pts0
github.com 12y ago

Ads randomly playing in Pianobar

jdangu
1pts0
www.j-ro.me 12y ago

SWF Malware analysis - Deep diving into a seemingly innocuous ad campaign

jdangu
1pts0
www.revive-adserver.com 12y ago

Revive Adserver - The open source ad server formerly known as OpenX Source

jdangu
2pts0
melissallarena.com 13y ago

The Secret of Making Space (Even If Your Schedule is Crazy)

jdangu
1pts0
www.j-ro.me 13y ago

Nixing the Dataholic Sharing Widgets

jdangu
1pts0
www.j-ro.me 13y ago

Lifecycle emails with KissMetrics

jdangu
12pts8

As someone who authored some keygen templates in this list (circa 1999-2000), this music was not commonly properly sourced. Chip music had already turned classic and we would pick what we liked. Providing credits was best effort. At some point we were very happy to collaborate with a chip music artist who made a tune just for our template, this was more the exception than the norm. tl;dr: this archive doesn't carry proper credits to original artists. The demo scene is where it's at.

Anyone has more info on the performance recovery today? We experienced similar performance issues over the last few days with a seemingly complete recovery today (on a cluster of ~2500 HVM T-1s).

Everyone feels the pain:

Publisher gets paid on a $1 CPM basis while Cedato gets paid $5-10 CPM and pockets the difference.

Advertiser thinks they paid for quality video content preroll but it's actually a tiny rectangle normally used for "display" ads.

Audience is infuriated. Think about what happens on a 4G mobile plan now that VPAID has been fully migrated from Flash to JS...

Ad security is very weak by design because it allows any fourth-party to serve html/javascript on any website. As long as this is the norm, we'll be around to protect publishers and their audience. Beyond ads, everything we built applies to the web in general so if we ever run out of bad ads, we'll expand in different directions.

edited for clarity

That's not the reason, it's ad fraud. They are most likely paid on CPC (cost per click) and forcing clicks in a hidden iframe. Or they are "stuffing cookies" for an affiliation link, betting that you might buy on that store later on - and getting a commission out of it.

Awesome to see that subject #1 on HN.

At my startup Confiant [1], we block bad ads in stream on behalf of publishers. Cedato aka Algovid aka TLVMedia is one of our prime targets, we block millions of their ad impressions daily.

They are essentially buying cheap display ad placements to resell them as fake video preroll ad placements. They sell on video exchanges like AOL's AdapTV and others. To maximize their yield, they resend ad requests in a loop to multiple parties every few seconds until an ad clears, leading to this massive network load.

We're on a mission to drive them out of business (and we're hiring ;) )

[1] https://www.confiant.com (edit forgot link)

Legohead, my startup blocks just the unsafe ads without revenue impact for the publisher. One of our beta clients plans to reach out to their ad-blocking audience to re-enable ads once we're fully deployed. Maybe we can help? jerome at clarityad dot com, we're in private beta.

ClarityAd | New York, NY | Onsite | Full time

ClarityAd's software protects from bad ads. We run ads in our custom browser environment in the cloud to gather hundreds of data points. We assess security and compliance for billions of ad impressions daily. Our back-end stores this wealth of data in a way that's usable and efficient, allowing publishers and ad platforms to protect their audience in real time.

You will work with our VP of engineering and back-end engineering team and you will be directly involved in:

- Setting up a robust and highly scalable backend

- Optimizing database queries and caching as required

- Optimizing web server configurations

- And most importantly, participating in the day-to-day improvement and extension of our product functionalities, for all things backend.

We would love to hire someone with ad tech experience, but we’re ready to train newbies and give you a deep understanding of the ad serving stack and Real Time Bidding (RTB). This environment has grown to such a level of complexity and automation that consuming online media has become an exercise of frustration: Latency, invasive ads, privacy issues, malware/malvertising that exposes users to trojans, ransomware, botnets… The rational option for the audience is to rely on ad blockers. Our unique product suite makes it possible for publishers and ad platforms to protect their audience in real time. We have the secret sauce to disrupt this market for good, annihilate the bad actors and restore confidence in publishers.

We are passionate about solving these issues and we want to grow our team with people who share our vision and ambition.

We use: PHP, MySQL, PostgreSQL, Redis + Lua, Node.js, C++ (browser sandbox). Our infrastructure includes: AWS EC2 (thousands of VMs) / Route53 / ELB / S3 / Bare metal / lots of exotic hardware in exotic places with exotic vendors all playing nice with Puppet.

Bragging rights:

- We routinely are the 1st to report on-going live malvertising attacks to ad platforms, including to Google

- We increased our volumes by 20x last year and keep getting stronger

- We have have received mentions in Google’s Security Hall of Fame

- We're still an “engineer only” startup, even as our monthly revenue passed into six figures less than 3 years in.

Apply at jerome at clarityad com (co-founder / CTO)

ClarityAd | New York City | On site or Remote

ClarityAd's software protects from bad ads.

We would love to hire someone with ad tech experience, but we're ready to train newbies and give you a deep understanding of the ad serving stack and Real Time Bidding (RTB). This environment has grown to such a level of complexity and automation that consuming online media has become an exercise of frustration: Latency, invasive ads, privacy issues, malware/malvertising that exposes users to trojans, ransomware, botnets… The rational option for the audience is to rely on ad blockers. Our unique product suite makes it possible for publishers and ad platforms to protect their audience in real time. We have the secret sauce to disrupt this market for good, annihilate the bad actors and restore confidence in publishers.

We are passionate about solving these issues and we want to grow our team with people who share our vision and ambition.

We use: PHP, MySQL, PostgreSQL, Redis + Lua, Node.js, C++ (browser sandbox). Our infrastructure includes: AWS EC2 (thousands of VMs) / Route53 / ELB / S3 / Bare metal / lots of exotic hardware in exotic places with exotic vendors all playing nice with Puppet.

We value diversity and we’re not looking to hire candidates whose experience is a perfect match to our tech stack. We expect you to bring your own background and experience to the problems we are solving.

The position is open to remote candidates in eastern time zone from USA or Canada. Half of our team is working remotely and we meet every 6 weeks in person.

http://stackoverflow.com/jobs/117807/senior-software-develop... or email me jerome [at] clarityad.com

We (ClarityAd) do this for major ad platforms. We use a mix of static and dynamic analysis to assess risk. We've been able to detect and stop major exploit kit campaigns over the last few months. Ads have specific expected behaviors and their SWFs are not supposed to generate code dynamically.

Flash security has gotten so bad that security analysts can fully disclose a vulnerability patched only 2 months ago. There's been ~5 0day events since then so...

Companies like WhiteOps and formerly Spider.io (now Google) are doing this as-a-service to detect useragent spoofing for all browsers, with hundreds of data points (mostly to detect ad fraud)

A fully web-based proxy cannot accept connections as if it was an HTTP or SOCKS proxy. It has to use some hacks (typically using URL redirects) to route the traffic to you. Compatibility with JS/ajax-intensive web apps is quite tricky to achieve.

Glype [1] is an example of web proxy that provides rewriting and customizable plugins to improve compatibility with complex web apps. Not free software but comes with source code (PHP).

[1] http://www.glype.com

The buyer is actually not Alcatel Lucent (French-Canadian telecom infrastructure company). The "Alcatel" feature phone business was a JV with TCL (Chinese electronics giant), and Alcatel sold off in 2007. TCL retained the right to use the Alcatel One Touch brand (unclear for how long).

source: https://en.wikipedia.org/wiki/TCL_Corporation

My guess is that they have a script that observes ad placements and counts "non-impressions". Counting impressions at the site level is not the same as counting them at the ad server level. There are generally multiple ad servers daisy-chained into the ad tag, creating a lot of latency. It is very typical to lose 10% or more ad inventory simply because the ad can't load in time. If pagefair can't account for that, then the number is highly inflated.