Websites routinely access the same urls over and over in a single page session, especially with aggressive ad refresh. Normally you only incur the first request as load, not the subsequent ones.
HN user
jdangu
co-founder Confiant
To measure network load, open dev tools, uncheck "disable caches" then clear your browser cache then load the page. Screenshot indicates network cache is disabled so the stated number is inflated.
Since this is taking off, Confiant is hiring in engineering and security to work alongside Kaileigh on projects like this. jerome at confiant. Pardon the plug.
As someone who authored some keygen templates in this list (circa 1999-2000), this music was not commonly properly sourced. Chip music had already turned classic and we would pick what we liked. Providing credits was best effort. At some point we were very happy to collaborate with a chip music artist who made a tune just for our template, this was more the exception than the norm. tl;dr: this archive doesn't carry proper credits to original artists. The demo scene is where it's at.
Chrome's protection only works in cross-origin iframes [1] and has been in beta for years. I haven't checked in a while but can't find a source that confirms that it went live.
Forbes serves a large portion of their ads in same origin iframes and so is not fully covered by this protection.
[1] https://blog.chromium.org/2017/11/expanding-user-protections...
Author here, we don't know their profit, but we estimate that they've spent about $220,000 through 2017, which is fairly cheap if you want to blast 1 billion malverts across the interwebs.
Anyone has more info on the performance recovery today? We experienced similar performance issues over the last few days with a seemingly complete recovery today (on a cluster of ~2500 HVM T-1s).
Everyone feels the pain:
Publisher gets paid on a $1 CPM basis while Cedato gets paid $5-10 CPM and pockets the difference.
Advertiser thinks they paid for quality video content preroll but it's actually a tiny rectangle normally used for "display" ads.
Audience is infuriated. Think about what happens on a 4G mobile plan now that VPAID has been fully migrated from Flash to JS...
Ad security is very weak by design because it allows any fourth-party to serve html/javascript on any website. As long as this is the norm, we'll be around to protect publishers and their audience. Beyond ads, everything we built applies to the web in general so if we ever run out of bad ads, we'll expand in different directions.
edited for clarity
it's fraud.
That's not the reason, it's ad fraud. They are most likely paid on CPC (cost per click) and forcing clicks in a hidden iframe. Or they are "stuffing cookies" for an affiliation link, betting that you might buy on that store later on - and getting a commission out of it.
Awesome to see that subject #1 on HN.
At my startup Confiant [1], we block bad ads in stream on behalf of publishers. Cedato aka Algovid aka TLVMedia is one of our prime targets, we block millions of their ad impressions daily.
They are essentially buying cheap display ad placements to resell them as fake video preroll ad placements. They sell on video exchanges like AOL's AdapTV and others. To maximize their yield, they resend ad requests in a loop to multiple parties every few seconds until an ad clears, leading to this massive network load.
We're on a mission to drive them out of business (and we're hiring ;) )
[1] https://www.confiant.com (edit forgot link)
yup, we detect and block most sleazy ad tech schemes through the daisy-chain of third parties. Agreed on UX improvement with ad blockers, we're doing this selectively on behalf of publishers.
We're doing exactly that at my startup Confiant [1], blocking bad ads in stream on behalf of publishers. High quality content websites don't want to ruin UX with bad ads.
Legohead, my startup blocks just the unsafe ads without revenue impact for the publisher. One of our beta clients plans to reach out to their ad-blocking audience to re-enable ads once we're fully deployed. Maybe we can help? jerome at clarityad dot com, we're in private beta.
ClarityAd | New York, NY | Onsite | Full time
ClarityAd's software protects from bad ads. We run ads in our custom browser environment in the cloud to gather hundreds of data points. We assess security and compliance for billions of ad impressions daily. Our back-end stores this wealth of data in a way that's usable and efficient, allowing publishers and ad platforms to protect their audience in real time.
You will work with our VP of engineering and back-end engineering team and you will be directly involved in:
- Setting up a robust and highly scalable backend
- Optimizing database queries and caching as required
- Optimizing web server configurations
- And most importantly, participating in the day-to-day improvement and extension of our product functionalities, for all things backend.
We would love to hire someone with ad tech experience, but we’re ready to train newbies and give you a deep understanding of the ad serving stack and Real Time Bidding (RTB). This environment has grown to such a level of complexity and automation that consuming online media has become an exercise of frustration: Latency, invasive ads, privacy issues, malware/malvertising that exposes users to trojans, ransomware, botnets… The rational option for the audience is to rely on ad blockers. Our unique product suite makes it possible for publishers and ad platforms to protect their audience in real time. We have the secret sauce to disrupt this market for good, annihilate the bad actors and restore confidence in publishers.
We are passionate about solving these issues and we want to grow our team with people who share our vision and ambition.
We use: PHP, MySQL, PostgreSQL, Redis + Lua, Node.js, C++ (browser sandbox). Our infrastructure includes: AWS EC2 (thousands of VMs) / Route53 / ELB / S3 / Bare metal / lots of exotic hardware in exotic places with exotic vendors all playing nice with Puppet.
Bragging rights:
- We routinely are the 1st to report on-going live malvertising attacks to ad platforms, including to Google
- We increased our volumes by 20x last year and keep getting stronger
- We have have received mentions in Google’s Security Hall of Fame
- We're still an “engineer only” startup, even as our monthly revenue passed into six figures less than 3 years in.
Apply at jerome at clarityad com (co-founder / CTO)
ClarityAd | New York City | On site or Remote
ClarityAd's software protects from bad ads.
We would love to hire someone with ad tech experience, but we're ready to train newbies and give you a deep understanding of the ad serving stack and Real Time Bidding (RTB). This environment has grown to such a level of complexity and automation that consuming online media has become an exercise of frustration: Latency, invasive ads, privacy issues, malware/malvertising that exposes users to trojans, ransomware, botnets… The rational option for the audience is to rely on ad blockers. Our unique product suite makes it possible for publishers and ad platforms to protect their audience in real time. We have the secret sauce to disrupt this market for good, annihilate the bad actors and restore confidence in publishers.
We are passionate about solving these issues and we want to grow our team with people who share our vision and ambition.
We use: PHP, MySQL, PostgreSQL, Redis + Lua, Node.js, C++ (browser sandbox). Our infrastructure includes: AWS EC2 (thousands of VMs) / Route53 / ELB / S3 / Bare metal / lots of exotic hardware in exotic places with exotic vendors all playing nice with Puppet.
We value diversity and we’re not looking to hire candidates whose experience is a perfect match to our tech stack. We expect you to bring your own background and experience to the problems we are solving.
The position is open to remote candidates in eastern time zone from USA or Canada. Half of our team is working remotely and we meet every 6 weeks in person.
http://stackoverflow.com/jobs/117807/senior-software-develop... or email me jerome [at] clarityad.com
This is because video ads use an obnoxious ad API called VPAID [1] that is mostly used to track viewability of video ads (which in turn conditions the billing event for advertisers). This is most effectively done with Flash and so 90% of video ads use Flash if given the opportunity.
[1] http://www.iab.net/guidelines/508676/digitalvideo/vsuite/vpa...
Devs talking about fixing bugs in narrator, the earliest TTS engine in home computers: https://github.com/amigasource/amigaos/blob/master/v40_src/w...
We (ClarityAd) do this for major ad platforms. We use a mix of static and dynamic analysis to assess risk. We've been able to detect and stop major exploit kit campaigns over the last few months. Ads have specific expected behaviors and their SWFs are not supposed to generate code dynamically.
What do you mean a "pick-your-target problem"? I was referring to responsible disclosure.
Flash security has gotten so bad that security analysts can fully disclose a vulnerability patched only 2 months ago. There's been ~5 0day events since then so...
Flash fell for a PCRE-related exploit in March. http://googleprojectzero.blogspot.com/2015/02/exploitingscve...
I don't know why you're implying malvertising only hits random jackasses. Google has been hit several times by exploit kit-based attacks over the last few weeks.
Companies like WhiteOps and formerly Spider.io (now Google) are doing this as-a-service to detect useragent spoofing for all browsers, with hundreds of data points (mostly to detect ad fraud)
A fully web-based proxy cannot accept connections as if it was an HTTP or SOCKS proxy. It has to use some hacks (typically using URL redirects) to route the traffic to you. Compatibility with JS/ajax-intensive web apps is quite tricky to achieve.
Glype [1] is an example of web proxy that provides rewriting and customizable plugins to improve compatibility with complex web apps. Not free software but comes with source code (PHP).
The buyer is actually not Alcatel Lucent (French-Canadian telecom infrastructure company). The "Alcatel" feature phone business was a JV with TCL (Chinese electronics giant), and Alcatel sold off in 2007. TCL retained the right to use the Alcatel One Touch brand (unclear for how long).
And Scala (a global leader in digital signage software) started out in 1987 on Amiga and only moved to PC in 1996 when Commodore went bankrupt. https://en.wikipedia.org/wiki/Scala,_Inc
Thanks for sharing! Can you tell us more about MaxTraffic.com?
My guess is that they have a script that observes ad placements and counts "non-impressions". Counting impressions at the site level is not the same as counting them at the ad server level. There are generally multiple ad servers daisy-chained into the ad tag, creating a lot of latency. It is very typical to lose 10% or more ad inventory simply because the ad can't load in time. If pagefair can't account for that, then the number is highly inflated.