Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - The Ethics of Adblocking
Articles

The Ethics of Adblocking

ISBuzz TeamBy ISBuzz TeamOctober 12, 2015Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
The Ethics of Adblocking
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Adblocking is becoming a more and more contentious topic in recent days. Publications, understandably, do not want people to block ads – they derive much of their revenue from them. Users find them to be intrusive and often feel that they impede their usage of a site; and, given the recent meteoric rise of malvertising, ads can often become downright dangerous. Where is the balance between the desires of publishers and the safety of users?

Malvertising is the way that criminals leverage ad delivery networks to push their malware onto end users. This is made possible by both the multiple parties involved in the delivery of ads (which involve the publisher’s server to the ad network to the delivery edges, to the people buying the ad space, to the companies that market ads, and finally to consumers), and the complex nature of the network itself.

Ad networks are built to streamline operations as much as possible, to ensure that money gets from point A to point B quickly and efficiently, with as little friction as possible.

ImageAd networks have chosen to prioritize the speed of ad auctions and capability of delivery, as well as the feature set of ads, over everything else – and understandably so, since this is what makes them money. The faster and more feature-rich an ad can be delivered, the more it is worth to a publisher (for whom it is a ‘premium’ client) and to a business purchasing the space (because it’s a ‘premium’ ad slot).

The spread of these ‘feature rich’ ads then becomes something of an arms race – after all, how is a plain old text or simple picture ad going to get noticed when your competitor has figured out how to get auto-playing video to load over the content, and made sure that viewers have to take positive action to dismiss it?

But these feature-rich ad slots amount to remote code execution capability. They allow an ad provider to execute any program they want to within the browser environment of the consumer.

Ad networks, of course, claim that they want to ensure the safety of customers and insist that they ‘inspect’ ads – but the prevalence of malvertising in the market provides many examples to the contrary.

How do criminals bypass the checks that ad networks have supposedly put in place to prevent this? Often, it is accomplished by compromising the accounts of ‘trusted’ ad buyers. Businesses buying ad space are no better or worse at securing their credentials than any other user; they can lose control of their ad accounts just as often as anyone else loses control of a Facebook account or an email inbox.

Once the account has been compromised, the ‘trust’ that the ad network has in the client can be used by the malvertiser to speed their revisions to the original ads past verification – it would be prohibitively expensive, after all, to have someone manually review every change to an ad for every purchaser of ad space. Automatic review can be fooled fairly easily as well – signature-based detection fails if there’s any change in the malicious payload. Manual review can also fail easily enough if the malvertiser sets up a page that looks like a legitimate one, and then changes the content after it has passed review.

So how can this be changed?

On one side, ad networks seem to want to change this by fighting against adblockers – entering an arms race where they try to detect adblockers and either obstruct them or guilt people into disabling them.

On the other side are the various programmers who either despise the ad-cluttered user experience and those concerned with security, who are very highly motivated.

This is not a fight that the ad networks are likely to win.

Alternatively, ad networks could try to work with the adblockers – for instance, by delivering known-safe ads.

The only way to really guarantee safe ad delivery is to vastly restrict the content to plain text or static pictures only, with regularly audited links to specific whitelisted domains. Then Ad networks should also provide random spot checks afterwords as well, to ensure ongoing compliance.

Sure, these ads are not nearly as interesting or “premium” as the feature-rich ads that are desired, but a ‘boring’ ad that is delivered is far superior to a feature-rich ad that is blocked and is never shown.

Ad networks need to judge what is more important: making their ads intrusive and feature rich, or accepting that users need a safe browsing experience and require assurance from the networks that their computer will not be damaged by malicious ads.

As far as my networks are concerned, my terms are simple: if you cannot ensure that your ad network is delivering safe content, then I will block you by any means available. This isn’t negotiable – the safety of my users comes far before the profitability of your network in my estimation. If you can guarantee that you will only show static pictures and text, with carefully vetted and audited links, then I’ll unblock.

This is not a negotiation, mind – these are the terms that any decent administrator will demand. After all, the ad networks need my users a lot more than my users need any ad networks.[su_box title=”Eric Rand, Security Consultant at Brown Hat Security and was guest blogging for AlienVault” style=”noise” box_color=”#0e0d0d”]AlienVaultAlienVault’s mission is to enable organizations with limited resources to accelerate and simplify their ability to detect and respond to the growing landscape of cyber threats. Our Unified Security Management (USM) platform provides all of the essential security controls required for complete security visibility, and is designed to enable any IT or security practitioner to benefit from results on day one. Powered by threat intelligence from AlienVault Labs and the AlienVault Open Threat Exchange—the world’s largest crowd-sourced threat intelligence network — AlienVault USM delivers a unified, simple and affordable solution for threat detection, incident response and compliance management. AlienVault is a privately held company headquartered in Silicon Valley and backed by Trident Capital, Kleiner Perkins Caufield& Byers, GGV Capital, Intel Capital, Sigma West, Adara Venture Partners, Top Tier Capital and Correlation Ventures.

AlienVault, Open Threat Exchange and Unified Security Management are trademarks of AlienVault. All other company and product names mentioned are used only for identification purposes and may be trademarks or registered trademarks of their respective companies.[/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}