← Back to context

Comment by cwnyth

7 hours ago

The better thing would be to hold Google directly accountable for every malicious ad they allow through their network. If they cannot do that, they should not be in business selling ads then.

Yes, that means amending the law (in the US). But the law as it is written facilitates crime.

This. There should be no intermediary liability protections for any paid or monetised content: as soon as a platform is either charging for placement or paying the creator, they should be treated as a publisher and held responsible.

Agreed

It's not just malicious software ads, they also sell ads to entities mitming every government service.

Not just the networks (although preferably also the networks) but also the publishers.

If a newspaper took money to advertise blatant, obvious scams, I assume a judge would consider them at least partially responsible for restitution, if not an accessory to the crime. Looking away really hard (and delegating the task of looking away really hard) shouldn't get you out of this.

Hold the publisher responsible, they can then hold the platform responsible, thus creating a market for platforms that actually fight scams. Right now, there is limited incentive to fight scams, as the scams still drive revenue. If you take money for it, you should be responsible for it.

  • Given the colour of the text, I just wanted to say that I agree 100% with this:

    > If you take money for it, you should be responsible for it.

    If they don't want to take responsibility then they should guarantee that the responsible party have provided valid credentials that can result in their being held responsible.

    That would clear up the quagmire that is internet advertising pretty darn quick.

This is bad enough for Americans, but things are a bit worse for those who aren't.

If my government tries to regulate, tax, or otherwise annoy one of these corporations, their billionaire owner will deposit a few million into the right campaign fund and the Big Cheeto will tariff us, threaten to invade us, swear at us, send us ambassadors who swear at us, or start trying to rename bodies of water. (He'll probably do that anyways.) In general, it's bad enough for our business that we usually just let these companies do what they want and hope that, someday, the U.S. will regulate them properly. That's unlikely to happen anytime soon. (Note: Even Democrats get nasty when their campaign funding is threatened.)

In the meantime, look out for the people you care about and support anything that pries your data out of American fingers.

How do you figure out what is a malicious ad? That seems really difficult at scale.

  • If you're asking socially, you don't, that's the benefit of writing laws instead of programs.

    If you're asking technically, well, google made over 400 billion dollars last year, they can spend some of that to figure it out.

    Or stop serving ads. Just because it's difficult to do safely doesn't mean you get to just do it anyways because there's profit involved.

  • You start with the obvious cases of sending you to a domain that serves malware, sure there will be instance of fraud that will slip trough, but lets not let best be the enemy of good

Idk if apple can validate each and every apps before publishing to appstore, why can't google and facebook validate each and every ads?

  • But they don’t. Google and others do vet ads, but when they don’t host them, the ads can change based on who is looking (clean ads for Google! Not for you!).

    Google didn’t have this issue until they bought DoubleClick (text ads and they hosted). And they had pretty good privacy as they didn’t want to share shit.

    After DC it all went to hell.

    • > But they don’t. Google and others do vet ads, but when they don’t host them, the ads can change based on who is looking (clean ads for Google! Not for you!).

      That sounds like a problem that Google should have already solved. Maybe that's why "Don't Be Evil" got the boot.

    • > the ads can change based on who is looking (clean ads for Google! Not for you!).

      How is that even allowed?

  • Define "validate". App Review is really only good at catching things that make Apple uncomfortable for financial reasons, or make their attorneys worried (trademarks, copyright, etc.) The sandboxing is what makes the App Store pretty unsuitable for distributing actual malware (the kind that can do stuff to your device without you knowing).

  • Well if they cannot technically differentiate malicious, then they should drop that business niche. They receive money for that, similar as selling stolen goods.

  • Cause that would cut into their profit margins, and section 230 absolves them of liability

I mean, maybe we can try going after the scammers.. but we can’t even stop scam callers and junk mail

  • In Japan, the identity verification is quite strict to subscribe to a voice/text capable phone line. Still yet to get robocalls or spam texts. I'm sure they exist, but despite handing out my phone number to city hall and countless private businesses, I have yet to receive one.

    On the other hand, enabling my Verizon eSIM is a surefire way to receive hourly "Potential Spam" calls, despite giving nobody outside of direct family my US phone number. Thankfully, I've convinced enough of my family to use Signal and we call/text through there instead.

    Nowadays, I only turn on the Verizon line if I have to receive an SMS one-time code or call my broker.

    Don't think the U.S. will ever solve this problem; people will just say something about privacy, the country's "too big" to combat spam at scale, etc. It's also too easy to get a phone number anonymously. A frequent phenomenon I've witnessed is that when someone blocks a phone number, the same caller contacts them again from a different number with the same area code.

all of this seems a little like second-level nonsense.

it's like ... "when my vacuum cleaner takes pictures of my wife naked, it should use HTTPS when uploading the pictures to the cloud"

How would one hold Google accountable? By fining them $1bn? $10bn? $100bn? To them it is just the cost of doing business.

We're beyond holding huge companies accountable. The only way they could be held accountable is if there was personal risk involved for the CEOs. There isn't.

  • At this point, breaking them up into smaller companies. Then start fining the individual companies so the balance sheets feel the fine more. Increase the fines exponentially for each violation.

    • The other option is jailing those who direct companies to break laws. It works for criminal organizations, why doesn't it work for companies?

  • If a scam ad is found, at the very least, require them to disclose business records to show how much money the scam ad made (revenue, not profit), and make them repay it. Leave it up to the platform whether to recoup the paid-out share from the publisher or not.

    If they are caught doing it repeatedly without taking adequate measures to stop it, treat them as an accessory to the crime.

  • > How would one hold Google accountable? By fining them $1bn? $10bn? $100bn? To them it is just the cost of doing business.

    Percentage of global gross revenue like the EU's GDPR does seems to work effectively enough for a scare tactic.

Generalize this.

Every landlord should be directly accountable for all crimes committed by their tenants.

Every telco should be directly accountable for all crimes committed by their customers.

Meta should pay damages when their users stalk and harass people.

  • I know what you're trying to say, but you're saying it terribly.

    If Ad Platforms don't want to be held responsible for the fraud that their platform literally delivered to the victim, then they should have KYC for all of their Customers that pay them money to deliver advertising to their victims. That way, shock fucking horror, someone or something might actually be able to be held responsible.

    And if the argument is that there are many ways that scapegoats can be used and shell companies setup to avoid actual responsibility, then we'll know more about the next layer of regulation that's required.

    Or we just give up and say that fraud is OK (which, I believe, is the current thinking in the US).

  • There are levels to this though.

    You wouldn't hold a landlord accountable if it was a surprise that a crime took place, but if they were aware that some of their tenants were committing crimes and just "choosing not to ask about it," they could reasonably be called "accountable."

    Telcos are regularly asked to give up information regarding crimes committed by their customers, see the Patriot Act for details - in some sense, we as a country have decided to hold them accountable for this (though, not spam).

    Meta have been involved in a whole list of litigation that is at minimum adjacent to stalking/harassment, if not directly involving those things. I would need to look up to be more specific, though.