Online ad giant Adform was hacked, proving once again why ad blockers are needed

this.weekinsecurity.com

193 points by speckx 6 hours ago


strictnein - 5 hours ago

Probably should just link to the security researcher's post, since it's far more informative:

https://doublepulsar.com/adform-compromised-to-serve-crypto-...

CM30 - 34 minutes ago

It's definitely proof that dynamic ads added via an external script library are a massive security risk, that's for sure. Even if the provider doesn't actually get hacked like Adform here, you're still banking on them being able to reject/filter out malware and malicious ads, which plenty of 'credible' networks seem completely unable or unwilling to do.

Going online without an adblocker just feels like playing with fire, especially nowadays.

__MatrixMan__ - 2 hours ago

Ads are malware. It's not really surprising when they're found to be bootstrapping other malware.

werds - 5 hours ago

Are the crypto addresses known/recorded anywhere? would be interesting to see on the blockchain how much was stolen this way.

tamimio - 5 hours ago

Ad blockers at dns level too, not just browsers. A lot of people don’t even know how to block them, check your parents or kids (or non technical people in general) phone and you will see how they are riddled with ads. I had a dns blocker installed on my parents phones and in around 6hrs it blocked 10k queries from 3 apps only..

functionmouse - 5 hours ago

I have a feeling everyone with understanding of the situation or even a vague malaise opening a news article and being bombarded with popups that intercept their attention knows why ad blockers are needed, and any perceived "discourse" to the contrary is one sided, from the ad agencies and media platforms that largely and subversively direct the narrative.

It's getting harder by the day to tell sentiment apart from narrative.

shevy-java - 4 hours ago

The sad thing is that we need adblockers in the first place.

Granted, even in the 1990s there were ads; I remember blinking banners and what not. But often the underlying website was still fine as such.

Fast forward some years. Now if you look at e. g. medium.com but many other websites, you are CONSTANTLY bombarded with pointless pop-ups, slide-ins, and pester-naggers. No I do use ublock origin (it works on thorium by default) so I only get very few ads, but many websites just pursue a strategy to piss off visitors. I do not understand this. If you want anyone to read your content, do not pester them at all. Nowadays when a slide-in appears that sneaks through ublock origin, I don't even let ublock origin block it, I just insta-close that tab. Cookie accept banners fall into the similar category, though some add-ons help with that.

cyanclouds - 4 hours ago

Finance and Media = annoying ass industries

Think of a typical news site with millions of ads flying in as you try to read - they are the causers of this shit ad world

Look what happened to YouTube after the news showed up there.

Look at the clusterfuck that is housing and banking.

Compare how any other vertical is ran by the main players vs Finance and Media - the two most shittily ran industries in the West.

TZubiri - an hour ago

until the adblockers are hacked

nashashmi - 4 hours ago

Websites being hacked does not necessitate ad block. It necessitates better browser security. The title here is fallacious. I say this in all fairness as someone who uses adblock extensively, where I don't even like cookies being held by ad companies.

jimt1234 - 4 hours ago

Browsers should not have access to the clipboard.