back
103 comments
Probably should just link to the security researcher's post, since it's far more informative:

https://doublepulsar.com/adform-compromised-to-serve-crypto-...

The bitcoin wallet swap thing that these malware scripts often push, how effective is it? It just seems so niche, if I'm doing stuff with my crypto wallet, I'm more likely to do it from my phone where I wont be copying and pasting to and from a web browser, maybe a webview if anything? I always double check the characters match up anyway... I am just shocked the level of effort for the most niche hack.
It sounds a little implausible at first, but Adform serves like a billion views on European consumer websites. For example, a state gambling monopoly: https://mstdn.social/@GossiTheDog@cyberplace.social/11701780... The attacker only has to get lucky once
Another comment noted over 100,000 USD passing through an associated wallet. I don't know how much work went into this but my hunch is it has paid off pretty good even compared to legit tech work.
It's definitely proof that dynamic ads added via an external script library are a massive security risk, that's for sure. Even if the provider doesn't actually get hacked like Adform here, you're still banking on them being able to reject/filter out malware and malicious ads, which plenty of 'credible' networks seem completely unable or unwilling to do.

Going online without an adblocker just feels like playing with fire, especially nowadays.

   > Going online without an adblocker just feels like playing with fire, especially nowadays.
It feels more like having casual unprotected sex. Easy to do in the moment, easy to ignore the risk, painful if "it never happens to me" doesn't come up cats eyes this time.

If we called the first programs that self-propagated worms and viruses as per the real world analogy, then I think it's time we rebrand adblockers as "condoms".

Why would they? What's your recourse as a consumer if they fuck up your hardware? In the extremely unlikely event you manage to get it in front of a Court, they could point to the 3 other ad networks also present on the same page, and to the wider internet just infested with the fucking things. Odds are incredibly long you could even prove you were infected with whichever virus, and then what do you get? A few years of identity theft protection, a new phone if you're VERY lucky?
Google can't do it, with their resources.

If Google can't do it, no one can. Unless Google don't care enough, but even in that case, why would anyone else bother if the consequences cost less than the monitoring?

As far as I can tell right now, the consequences cost nothing.

Ad blockers at dns level too, not just browsers. A lot of people don’t even know how to block them, check your parents or kids (or non technical people in general) phone and you will see how they are riddled with ads. I had a dns blocker installed on my parents phones and in around 6hrs it blocked 10k queries from 3 apps only..
I personally also block access by web browsers to non-standard ports (aka not :80 or :443) via an app firewall (Little Snitch here). In this case it would have warned me when the compromised script would have called home to that endpoint on the non-standard port.

Gotta tackle such issues at different places all at once for sure. It's like wearing 5 digital condoms at once. Too bad there's still some leakage somewhere for sure. B)

DNS level is more secure but less effective because apps and website can serve the essential content on the same domain as the advertisement. It will also become less effective over time.

YouTube does this, so you need to use a browser-based ad blocker.

Let them eat cake. Setting up that ad proxy stuff is a bunch of work that many websites won't do.
I have a feeling everyone with understanding of the situation or even a vague malaise opening a news article and being bombarded with popups that intercept their attention knows why ad blockers are needed, and any perceived "discourse" to the contrary is one sided, from the ad agencies and media platforms that largely and subversively direct the narrative.

It's getting harder by the day to tell sentiment apart from narrative.

"You will be annoyed" and "you will be served malware" are two different classes of need. The first is enough to get me running Firefox/uBlock Origin on my own devices. The second is what got me to run it at work.
Nobody wants ads (*) but somehow they are never banned.

Makes you wonder, are we living in a democracy or not?

(*) shown at inconvenient moments and tracking the user; yellow pages were fine

The sad thing is that we need adblockers in the first place.

Granted, even in the 1990s there were ads; I remember blinking banners and what not. But often the underlying website was still fine as such.

Fast forward some years. Now if you look at e. g. medium.com but many other websites, you are CONSTANTLY bombarded with pointless pop-ups, slide-ins, and pester-naggers. No I do use ublock origin (it works on thorium by default) so I only get very few ads, but many websites just pursue a strategy to piss off visitors. I do not understand this. If you want anyone to read your content, do not pester them at all. Nowadays when a slide-in appears that sneaks through ublock origin, I don't even let ublock origin block it, I just insta-close that tab. Cookie accept banners fall into the similar category, though some add-ons help with that.

> Granted, even in the 1990s there were ads;

the ads in the 90s were served by the same server of the site you were browsing. those ads were images. today's ads are from 3rd party servers running arbitrary JS code that the server of the site you are browsing knows nothing about how it works. ads from the 90s while possibly obnoxious and annoying were not able to be malicious as ads from today.

I read an article a while ago about some scientist who decided that he wanted to go around investigating a certain species of leech that lives inside a hippo's butt, like attached directly to the colon. He suggested that, as big as the hippo is, it probably wasn't really all that aware that the leeches are even in its butt, but that's where the leech likes to be because there's a good source of blood there for the leech to feed on.

Now, the scientist is probably right, the hippo probably goes its whole life not really knowing that it has all these leeches in its butt. It might feel a little pain in the butt, but the hippo probably isn't concerned with why that pain is there, much less how or even if it can get rid of it, it's just something that the hippo has always lived with. The hippo accepts that one of the facts of daily life is that you just need to live with some pain in your butt.

Now, imagine (and believe me, this is a hypothetical), if the hippo let someone root around inside its butt and remove every one of the leeches, and even stop any others from attaching. It might take a day or two to get used to and get back to normal, but the hippo would wake up one day and realize that it no longer has a pain in its butt. It can still do everything it used to do, it can frolic in the water, it can roam around and find the tender little pieces of grass, it can do that thing where it poops and swishes its tail around to spread it all over its neighbors, and it realizes that it can do all of those things it likes without having that pain in its butt.

Now, maybe the leeches could talk. Maybe the leeches talk to the hippos and they say things like, listen, hippo, my life cycle depends on you letting me get into your butt when you're in the water. I need to drink your blood and drop out some eggs, so that other leeches can be born and start the cycle all over again. It's not really a big price you pay, I mean sure, there's a little pain in your butt, but I need you to do this. If you want to get in the water, it's just something you have to deal with. It's the price of admission. If you get in the water without letting me in your butt, it's like you're stealing the water.

I bet that the hippo would hear that, and would still want to continue going about its day without any pain in its butt. I don't think the hippo would feel very sorry for the butt leech. Sure, maybe the butt leech contributes to the aquatic ecosystem, maybe its eggs or the dead leeches get eaten by other things and fertilize the grass that the hippo likes to eat. But, if the leeches weren't there, the grass would just find other nutrients. Even though the leech is trying to argue that it's a necessary part of this ecosystem, it's actually just a pain in the butt. In reality, despite what it tells everyone else, the major beneficiary of anything that the butt leech does is the actual butt leech.

Anyway, I just had a thought that advertisers kind of sound like hippo butt leeches.

My least favorite ones are the ones that fit in the rails to the left and right of the content that scroll with you. You can't click anywhere without an accidental ad click. Using any device without ublock reminds me just how much better life is with it...
>>> Nowadays when a slide-in appears that sneaks through ublock origin

Does that really happen ? I don't know what this is

Note: I have Ublock set with no JS permissions by default, so maybe that's why i never see a slide-in menace ?

>If you want anyone to read your content

Reading the content is really not necessary, but the business is predicated on selling ads.

FYI Thorium is updated once every 3 months or so. Not exactly the safest thing in the world.
Ads are malware. It's not really surprising when they're found to be bootstrapping other malware.
Are the crypto addresses known/recorded anywhere? would be interesting to see on the blockchain how much was stolen this way.
The code in question is here: https://pastebin.com/raw/mc7psaNF

It appears to be normal Adform code plus two appended chunks at the end.

   Bitcoin: bc1qmplgt0hcg62jc2guz86wn2sms7tqrsulkkrrls
   Ethereum: 0xE7983E69df17079ADb0aD7b3458488Cac0dBc573
   TRON: TW4AgGnDc2Pk6YAynCtjCKzoKYWPg7nJe (?)
Edit: Activity for those addresses:

~$110k bitcoin

https://www.blockchain.com/explorer/addresses/btc/bc1qmplgt0...

~$55k in ETH

https://www.blockchain.com/explorer/addresses/eth/0xE7983E69...

Browsers should not have access to the clipboard.
You can disable it on Firefox by setting dom.event.clipboardevents.enabled to false. I haven't had any issues with it.

Someone shared the code in the comments, it uses 'copy' and 'cut' event listeners, so disabling this setting would have prevented the exploit regardless of an adblock.

It's you versus Google on that one. Who will win?
Nor USB devices, nor the screen size, nor ... They can access way too many parts of the OS. But almost nobody cares, as long as they have their shiny feeds and videos.
That depends. For my local use I want to access everything.

For external situations I agree. No clue why browsers started to sniff after people. I blame Google for that.

What?

If copy and paste is disabled in my default browser that would be something like 80% of my total of my total use cases for the clipboard in the first place.

Websites being hacked does not necessitate ad block. It necessitates better browser security. The title here is fallacious. I say this in all fairness as someone who uses adblock extensively, where I don't even like cookies being held by ad companies.
A secure browser that loads an ad doesn't prevent you from being surveilled. Tor mitigates this to a large degree but doesn't entirely eliminate it. The only real solution is to block ads altogether.

This is a silly distinction anyway. Blocking ads is an obvious first step to improving browser security.

>>Websites being hacked does not necessitate ad block

Their users do.

You are right, adware comes through ad systems regardless. Block everything regardless as well.
CrowdStrike Outage means we need better Windows.
indeed. the post may as well be, javascript must be disabled.
... proving once again why regulation of internet advertising is needed.
until the adblockers are hacked
AI is holy grail of adblocking !!
I think there are quite a few things that AI could work very well as a solution for... that it will never be used for because it would threaten industries that profit of the existence of the problem.

The parasite that is advertising, especially internet advertising, is one of them.

Finance and Media = annoying ass industries

Think of a typical news site with millions of ads flying in as you try to read - they are the causers of this shit ad world

Look what happened to YouTube after the news showed up there.

Look at the clusterfuck that is housing and banking.

Compare how any other vertical is ran by the main players vs Finance and Media - the two most shittily ran industries in the West.

The discussion around Ad blocking is, while definitely a needed discussion, is so rife with confusion, dishonesty and and self-serving ideology that we are going to kill the internet while being absolutely 100% sure that never giving compensation for value did not do any damage or play any part in making the internet suck.
Oh give it a rest.

You want to talk about killing a system... look at all the perverse incentives that pop up when companies are allowed to sell user attention instead of decent services and products.

If the modern social media internet dies because of ad-blockers... good damn riddance.

… or play any part in making the internet suck.

Right, it’s the ad-blocking that’s making the internet suck. You’re going to hurt your lower back carrying that much water.

I'm willing to go down that road to see where it ends up.
There is no discussion. My computer, my rules: no harassment and psychological manipulation allowed no matter how much your business model relies on it.