Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I guess it's good for security... but if your computer can be hijacked by loading a website, you're going to have a bad day even if you're blocking ads. For example, I would bet hacked websites are a much more common malware vector than ads.


With the proliferation of real-time auction and backfill ad networks, the ability for a bad user to inject javascript or malicious Flash ads into the ad creative space carried on major sites has grown dramatically over the last few years.

It's hard to even tell who is serving up your ads sometimes without pulling out wireshark or some kind of HTTP proxy to look at the request chain.


Again, though, if an ad blocker is the only thing standing between you and a zero-day, you need to immediately stop what you're doing and patch your browser.

It's true there are bad actors taking advantage of ad networks. There are bad actors hacking Wordpress installs too.


I don't think you know what a zero-day is or if you do I would be interested to know what is standing between you and one. By definition there is no patch for a zero-day.


At the very least, we didn't want users being infected from ad blocks that we, were ourselves, serving up! :-)

But I'd argue it's one less vector for infection, and an important one at that.


Google search and most browsers will protect users against known malicious websites that has been hacked. They can't do that with malicious adds.


They can and do. If a site runs a malicious ad, Google will flag the whole site.


Perhaps there are other ways to meaningfully compromise site security? It's not just a zero day that breaks out of the web browser sandbox and installs a rootkit, it's the hostile javascript running in the context of the page that might not be properly scoped and ends up stealing information straight out of the DOM (or stores or whatever.)


Yes, but that does not mean it does not happen and when a very large website gets used to deliver malware through advertising it can be very effective. Such as this top10 dutch website:

http://blog.fox-it.com/2012/03/16/post-mortem-report-on-the-...


I would bet that malicious websites advertised in google ads are more common because they require less efforts and because I had to deal several times the aftermath of people clicking the first link in a google search for the flash plugin which turned out to be a google ad for a malicious website serving malware infected flash installer.


iirc flash ads with malicious payloads were the vector used to infiltrate the networks of NYC and other newspapers by Syrian Electronic Army, Anonymous and other public scale hacks.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: