1) Google wants the most money, so they don't care to let dodgy ads thru.
2) There are more ads going out then can be reviewed, so they would rather have people report them, then they automatically reject the report until enough people report it, then an actual person may review it.
As to why Google doesn't use AI to review them? Google would rather use the AI in a way that makes them more money, than review ads and if AI decides to take them down then that's less money for Google.
(To be clear: I don't work for Google in any way, these are just my guesses)
I have reported so many of those dodgy, scammy, sexualized ads on YouTube, that YouTube/Google has removed the option to report advertisements from my account.
They don't care as long as they're getting paid and there's no immediate liability for them.
The funny thing is it used to be that people warned you not to go to dodgy sites as they were full of ads that were trying to steal your money or online identity.
It was mostly just scaremongering, but it never hurt to be careful.
Nowadays, Google will serve you those exact ads if you go to any major news outlet.
I've been on the same crusade, reporting all the scam/fake-ai/misinformation ads as possible, when a couple weeks ago they changed how you report. The ad will still play through as you're reporting it, and once finished reporting it still remains and you may see it again after a few swipes (YTShorts). It feels like they did this so they could get the money before removing it.
The web is becoming very hostile to ad blockers. I use a VPN and I've noticed more and more sites just being obnoxious with their popups and even just crashing the site completely in a loop (looking at you EuroNews)
It doesn't solve everything but the 'full' desktop version of the ublock origin plugin runs just fine in Android on Firefox. I can't even imagine using any other mobile browser now. I don't know what the situation is for iphone platform stuff these days.
This Even skimming the web could take up 1000X the hours I have in a day, and I really should spend more time exercising, and reading books, and with friends and family, and volunteering, and ...
I suspect it's not a real crash you're seeing, but rather a deceptive anti-adblocking script that redirects to a page that fraudulently claims to be a crash.
They sell bedsheets, with sort of a raunchy ad campaign.
I had a adblocker but wound up uninstalling it when it became more of a hassle than it was worth.
There may be gaps every now and then in block lists of ad blocking solutions, but besides that, you are using the wrong ad blocker. abp is not to be trusted to reliably block all ads it could. It has a different mission than uBlock Origin.
I think section 230 immunity shielding from from any liability is also very motivating. Google was born into a world where companies had 10,000s of support personnel, today there are companies with over a million employees, they could easily human-review every single ad and they probably would if they weren't able to divert that cost into profits without consequence. AI makes it even easier and cheaper but... why bother?
Then there's the profits from scams, Meta is the only one with the stones to admit they like scam ads because they make up 10% of their revenue. I doubt it's a massive coincidence all the other big platforms are overrun with scams they do as little as possible to police.
Does section 230 shield them from ads they select for display? Ads are not randomly hosted by random people and if you visit a random page those people uploaded, you see them. Google selects the ads they want to show you on search results, before youtube videos, or on third party websites. There's no "we don't know what that might be" going on at all -- they are running sophisticated algorithms to optimize the impact of those ads. Is that still be covered under section 230?
As someone who advertised with them, they do seem to have an AI reviewer, and it also has false positives that no number of appeals seem to resolve. So in these cases you want to pay them money for good ads, but you can't because AI says no.
Adding friction to the process (on the advertiser side) means less money for Google: 1) due to the cost of implementing the checking, 2) because some legitimate advertisers will be falsely denied, 3) because the scam ads were still paying money.
Not adding the friction doesn't seem to come with any serious downside. One would expect that it would, e.g. due to publishers removing the most profitable properties from the ad network or governments legislating this out of existence, but that doesn't seem to happen.
So, given these incentives, the outcome is inevitable.
If Google had to pay a massive fine for every scam ad that gets through, or was liable for the damages the ads cause, etc. - or otherwise had a strong incentive - suddenly there would be enough resources to make sure every ad is reviewed, advertisers that push scam ads get fully banned on the first offense rather than being given second, third, and fourth chances, etc.
> 2) There are more ads going out then can be reviewed
The "more than can be reviewed" might have been a logical conclusion in a purely human based workflow, even if you have the lowest cost per head click workers in like, an external contractor call centre type environment in Bangladesh.
As the author points out, the ordinary consumer class version of publicly available Gemini very accurately classifies the ad as malicious. I really doubt that there are THAT MANY unique new ads being submitted per day that they can't afford the compute to run them through a similar classifier.
this argument still adds nothing to discussion because companies clearly want to spend zero but earn everything, the only amount they are willing to spend is on lawyers working on shielding companies from any responsibility including obvious cases of negligence
Yes, and I've also seen the absolute shitflood of horrible ads. Every time I see somebody else's system that isn't running ublock origin or similar... They clearly are prioritizing the ad revenue over any actual "don't take a steaming dump on the Internet" ethical priorities.
I don’t think they want the most money. If they did, they’d have done this long ago. The trend we’re seeing is about them just struggling to meet their quarter over quarter and year over year numbers. It’s a short term driven change to strategy, they’re trying to fill the hole with something else (we all know what) before admitting it exists. If they said their golden goose was dying, the stock would crash.
> 1) Google wants the most money, so they don't care to let dodgy ads thru.
They have literally destroyed their own reputation, and all the reputations of legitimate products that might appear along these scams. Do you think anyone would want their car, smartphone, or tax software appear next to actual credit card scams?
TV has standards for decency, and factuality, and might ban entire categories of ads (financial services) altogether.
As someone who has worked for Google Ads, I should say that they do review ads with both AI and humans, and do spend quite a bit of money and energy on finding and stopping both bad-faith advertisers ("buy side", what we see) and bad-faith publishers ("sell side", more of a scam on the advertisers/google itself).
Is it enough? Probably not, based on this article. Are their policies strict enough? IMHO no way, considering Youtube left an ad up for "Ukranian women" in the early years of the war which wtf. But they certainly do try.
Like most businesses, the actual people involved are also well-intentioned, at least in the abstract; they wanted to make ads that sell products without annoying people. Obviously there's material conditions beneath and around all that, but we don't need to explain that part here ;)
> There are more ads going out then can be reviewed, so they would rather have people report them, then they automatically reject the report until enough people report it, then an actual person may review it.
If only there was a technology which could automate this... But we all know, AI is only used on users, not customers - and users get the two line perl script "AI" which says "We have reviewed your claim and decided to ignore it".
In underregulated capitalism, the reason is very simple: because they get away with it. This is why they despise regulation; it enforces accountability. Want to advertise? Ensure the ads are legit. It doesn't work when you say 'we didn't know beforehand' when a significant percentage is scams. That is when you start to curate the content beforehand.
In any other normal market, the middleman would be held accountable. Big tech? Not so much. We seen the slap on the wrist regarding Microsoft at the start of the century/millennium. We can also witness the same with regards to the garbage coming from China, where China doesn't take responsibility. Learned from the best.
There is going to come one day that companies (and any website owner) will wish they didn't use AI and instead used a simple (maybe even plain-text) website. That will come when people really need information from that website but can't get to it.
Heck, you can have your information as clear and concise as possible, but the moment I sense that "AI-generated" texture, I am immediately closing the tab. This is just extrapolating from how I feel about the bevy of obviously AI-Generated flyers and banners that have been gaining a lot of traction in real life.
I wish that was the answer to all of these people setting their spouse, their grandmother, their boss loose with LLMs to build sites. It should just be acceptable to have a simple site that conveys information well, and then we wouldn't need to boil the seas to generate pages of shiny slop.
Doubtful. This is just the cost of doing business. 99.9999% uptime for a fraction of the cost is totally fine for all businesses. Government should be the exception though.
Absolutely this. Although I like the shiny and polished looks, getting the info out is the most important, and it is hard yo beat pure black-on-white text
Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.
It is very challenging to distinguish individuals interested in privacy from bots acting maliciously or with reckless indifference. If you devise a way to do this more effectively than Cloudflare, you should start a business to sell this as a service.
My employer is a small business that has an e-commerce website that is attacked by fraudsters trying to validate stolen credit cards or obtain customer information hundreds of times per day. Operations like CloudFlare are the only way to foil these actors. Just trusting you is not a viable strategy.
I had this problem too for all my clients e-commerce websites, then solved it 3 years ago with very little code changes.
Happy to share it with you. Using small businesses for credit card testing is one of the most evil things on the Internet, so anything to stop it is worth it.
Your rate limits on adding and removing credit cards? Your input sanitization? Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?
There are many practical ways to handle that sort of thing that isn't Cloudflare. It just requires thinking and a bit of dev time.
t. Been there, done that, cartels used an app to try to launder money through loyalty programs. Management was deadset against doing the one single thing that would make it impossible to do that at scale.
Ulterior motives abound everywhere but especially behind people claiming X is the only answer. Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.
> Your rate limits on adding and removing credit cards?
All those requests will appear from different ip's and different browsers, made by someone who can spend months on trying to defraud you. How do you differentiate this from valid customer who happens to try to buy something between 20 tries by bots?
> Your input sanitization?
All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.
> Designing your system to not just disclose details around anything but that relevant to a logged in/authenticated user?
They can register as normal buyers.
> It just requires thinking and a bit of dev time.
And they can spend months trying to outthink you, then will drain your service in 4 hours when you are asleep.
> Management was deadset against doing the one single thing that would make it impossible to do that at scale.
So, did you actually ever implemented and checked a good solution? Cloudflare isn't perfect, but not everyone has resources to implement their own solution that is better than cloudflare.
> Fingerprinting is far more intrusive than just only allowing one to add at max 2 cards a day per user.
The fraudsters will appear as completely new users each time, adding only one card and making one purchase.
> All those fraud requests will give you valid credit cards which will work perfectly, but then defrauded people or banks will try to chargeback later.
How are they getting pass 3D-S?
If they are able to get past it, then your liability drops off.
Yes it could be designed better, but that is a separate discussion.
It doesn’t matter that they can’t get past 3D-S, because the whole point of what they’re doing is checking what security features are enabled for a card, and whether their address and other validation data will pass. The fact that the scammers are testing so many cards that fail gets you banned from those payments providers, whether or not any payments go through. And this is ignoring all the attackers using bots for other purposes such as taking control of the website to obtain user or client data.
The technique is simple: don't publicly serve expensive (CPU/RAM-wise) pages. A simple blog like the linked article can be 100% cached and served to anyone without needing CloudFlare.
Performance optimization for website already is a business. It's just that product managers mostly don't care and optimize for other metrics (eyeball retention, SEO, etc).
Don't listen to these hecklers, you have every right to your privacy, and should demand it. Anonymity is paramount if people want to be able to talk without repercussions. Gaslighting, heckling and other forms of harassment are to convince you to self censor. Don't take the bait. Ignore them.
> Because they slow down and often block access to websites, particularly for people that try to avoid being fingerprinted or otherwise tracked. Pretty evil behavior.
Bots and scrapers and hackers also try and avoid being tracked, which is by far a bigger problem for them and most websites than the 15 of us using tons of antifingerprinting techniques. Evil? No, that's silly.
Hanlon's Razor is especially effective at getting Good people to put out their own eyes to keep them nice and soft targets for the malicious. I'll take being a harder to find likable by people I have no desire to be liked by to make myself a harder mark. The honest ones will understand. The malicious were never worth being close with, and I'm doing the world a service by getting the borderline enlightened.
Sufficiently advanced stupidity being indistinguishable from malice is also something to keep in mind.
Getting past cloudflare can be a problem if you are from a less reputable country or a VPN or if you use a less conventional browser.
There is also a larger problem of a private entity being the MITM for a large portion of internet traffic. But i don't think this is the point GP was trying to make.
It regularly blocks me too. I've begun search Google for: what does [url] say about [search query]
It'll make a Gemini summary of the page, and can be prompted for more details. It's really the only use for Gemini I've found reliable. I'd still rather directly view the output of the scraper bot, though.
If anyone knows a good scraping bot that lets you view the output directly, without running it through an LLM, please let me know.
Most CF sites I try to visit only give me an endless captcha loop, so I cannot visit them at all.
I suspect it's simply because my ISP regularly rotates IPs, and so I unfortunately have to share "reputation" with other users who can't behave online.
I just had a look through my logs, and I've had over 90,000 requests from known AI bots over the last month. All this to a personal website that doesn't post very often.
And that's just known AI, I can't imagine what requests are pretending to a real person when they aren't.
I think it's also because the regular dating sites are setup to not find you a match, so by bypassing them (at least in a way), you have a better chance of actually going on a date.
To keep in mind is that this article talks about people who have had success using LinkedIn, I'm sure there are people who've tried it without success.
1) Google wants the most money, so they don't care to let dodgy ads thru.
2) There are more ads going out then can be reviewed, so they would rather have people report them, then they automatically reject the report until enough people report it, then an actual person may review it.
As to why Google doesn't use AI to review them? Google would rather use the AI in a way that makes them more money, than review ads and if AI decides to take them down then that's less money for Google.
(To be clear: I don't work for Google in any way, these are just my guesses)
reply