79 comments

[ 3.4 ms ] story [ 141 ms ] thread
(comment deleted)
In 3 party systems 2 of the parties benefit from fraud, that's why there's only the appearance of enforcement.
> Police got wind and arrested them

I understand how this breaks ToS, but how was this illegal?

They were Chinese nationals who were 'working' in Thailand without a permit. That's why immigration police arrested them.

Of course, the police then thought they were running call center scams (which are illegal there) until they came clean about the operation.

The reason they were in Thailand is that there's less scrutiny there on SIM cards and low smartphone fees. Ultimately, though, KYC requirements do exist on Thai pre-paid plans (post-paid plans are effectively user-tied anyway) so they also got hit by the smuggling SIMs charge.

Ultimately, lots of illegal stuff going on. Just not where you'd expect.

Offering someone a paid service to increase engagement on social media, and then doing that by having people in click farms to increase the engagement metric without actually increasing engagement is fraud. Of course it's illegal.
Who says the click farm was offering such a service? It seems to me the offer is clicking things repetitively for money. You can argue that in some cases the farm was an accessory to fraud in that it knew or should have known its clients were engaging in fraud (e.g. if the client is the app owner), is that what you're getting at?
> Who says the click farm was offering such a service?

Why else do you think they were doing it? They just really like clicking things?

They click things because people pay them to, for a variety of reasons. Were some of the people paying them engaging in fraud? Probably.
What makes these illegal? It's not some bot network being run from unsuspecting device owners. These are actual humans operating devices clicking on specific things they were told to do. Why has this crossed from gaming the system to illegal?

It's shady as shit, don't get me wrong, but why illegal? It's like the old "enter as often" type of games. The rules were followed, but the "spirit" of the rules was not.

I'm not familiar with Chinese or Thai law to know what is legal or not, but I would assume there is some kind of fraud. Especially for clicking on advertisements.
Is it fraudulent to click on advertisements without having an intention to buy the product?
(comment deleted)
This would depend on the country I'd imagine, but in the United States the answer seems to be "yes".

That would be when the company doing the clicking is profiting off of it, which in this case they are.

https://www.cheq.ai/click-fraud-illegal

Is it fraudulent to click on advertisements without having an intention to buy the product?

I dont know, but I doubt intention to buy is the deciding factor. I would think that it becomes illegal when you are misrepresenting traffic to an advertiser. Especially if its a pay per click contract, and the group doing the clicking is acting on behalf of the company getting paid.

Misrepresenting traffic to an advertiser is intention. Those clicks were intended to defraud the advertiser. Normal clicks from average joe are not done intending to defraud somebody.

It might be pedantic to point that out... but intent matters.

Right, but I was being even more pedantic when I quoted "intention to buy." That is to say, if I see an ad for something that I want to know more about, but I don't want or need, or cant afford, I have an honest reason to click on the ad even though I don't have an "intention to buy."
(comment deleted)
I dont know if intent by itself (without an otherwise punishable act) can be a crime. That would be a thought crime, wouldn't it?

GP says "Click without intend to buy" -- Wow, that sounds like mis clicks could be a CRIME!

I cannot be too bothered with people gaming the sleazy business that advertising is.

I dont know if intent by itself (without an otherwise punishable act) can be a crime. That would be a thought crime, wouldn't it?

Intent can surely make something a crime, that wouldn't be punishable otherwise. Giving someone with a peanut allergy something with peanuts in it is not a crime, unless you knew they had the allergy and intended to hurt them. In some states it's illegal to intentionally expose someone to HIV, but it wouldnt be illegal to expose them if you didn't know you had it. If you slip and fall at a store you can likely sue for damages, but it would be a crime if you intended to do it.

I cannot be too bothered with people gaming the sleazy business that advertising is.

Yeah, I don't feel bad for any of the players involved in that world.

I accidently click an ad -> not a crime.

I hire you to browse around my site clicking on ads to generate revenue for me -> crime.

That why I said that "click without intend to buy" can prolly not be a crime, where putting up ads with intent to have them clicked by yourself (or someone you pay for) IS most likely against the contract that you have with the ad network.

If the ad networks care is another story. They make money either way on the short term :)

Why do you think the people working in these click farms are clicking on the adverts?

Is it to defraud someone out of a marketing fee by pretending that your adverts are creating more engagement than they actually are?

Then that's fraud, isn't it?

The law looks at how a reasonable person would interpret what you are doing and what your intent is. It doesn't work on a 'clicking adverts without intending to buy is illegal' basis. So many people here misunderstand that.

Whose law? The US? Thailand? China?

In western common law practice, sure. But elsewhere?

Yes I think an equivalent 'fraud' law, sometimes called something like obtaining a valuable security or pecuniary advantage by by deception or something like that, is a basic part of almost all legal system everywhere.
Isn’t it like being a radio station with 5,000 listeners but claiming to have 50,000 listeners and charging advertisers on the basis of having 50,000 listeners?
Not quite, because in this case the 50,000 listeners do exist. It's just that 45,000 of them are shills paid by the radio station. But if the advertising contracts didn't exclude for that, then there's no grounds to complain.
At this scale, yes. If you pay me (say) $30,000 for advertising based on a commitment from me that your ads will be shown to enough people until you reach a certain number of click-throughs, but actually all of those are just my staff sitting there repeatedly clicking on them all day without ever buying your product, i'm pretty sure you'd be unhappy about that.

Whether it's actually illegal or not is another matter, and depends on circumstances and jurisdiction.

"Intention to buy" isn't specific enough. If it can be defined as obtaining money by deception, which seems like a pretty applicable description, the case for fraud seems strong.
No. Without an existing obligation, not at all.

But if you're the same party displaying the ads, or working for them, then yes - you're intentionally defrauding the ad company.

I would imagine it's something like this:

1. You create an AdWords account or something where you can be paid to put ads on your site.

2. You have tons of employees with different devices, probably on a range of VPNs or tor circuits.

3. They click ads on your site over and over and over again.

Just a hunch. I know this sort of thing is strictly forbidden in Google's terms and can certainly be considered fraudulent depending on who's asking.

It's not fraudulent for the clicker. It's fraudulent for the website host who hired the clicker.

The host presumably has some kind of contract they agreed to in exchange for getting ads and getting paid.

Lock me up. I have never bought via a clicked ad. Every click was accidental. I would eat a hotdog from a shady vendor in a back alley before buying anything from a banner ad.
Typically websites make agreements that advertisement networks will pay for the clicks.. if that website did so with the intention of "gaming the system", then they are in breech of contact, and typically there's a law somewhere that covers entering into bad faith contracts with the intent to take money without providing legitimate services...
Making paid 5-stars and upvotes is not done under business contract but under consumer "terms of service" right?
> What makes these illegal?

It’s fraud.

If its used solely by advertising resellers to defraud their publishers?
I wonder if everyone would click just for fun how it would modify the ad business....
If you use the word "illegal" in the headline, it clearly shows your affiliation. Yes, these people don't comply with the ToS. Yes, they abuse the apps and don't use them as intended. Does it make their activities illegal? If so, at what point? Is having two Instagram accounts illegal? Two, five, fifty? Where is the threshold and who decides about it?
Subjective but I imagine an awful lot of those phones were moped snatched its rife in SEA. and probably the cheapest way to buy phones.
How hard is it to emulate an iPhone or Android so you can do this on a computer? I would think it would be a lot easier to do this with one PC instead of hundreds of tethered phones.
I used to work on stopping this, its a cat and mouse game. Most datacenter IPs are already blacklisted, and this appears to be a low level fraud. But often it may be that you need physical actions also, e.g., an advertiser may pay for installing a game only if the player crosses the first level of a game. Either you build a bot which can do that or you use humans.

Fraud goes all the way from simple operations where actual people in countries like India or Bangladesh are physically clicking on ads to sophisticated operations where bots generate human like traffic which is mixed with genuine traffic to avoid detection.

(comment deleted)
How much did IP masking help in this situation versus the data analysis and identification of inauthentic use?

Did you have any experience dealing with residential proxy networks? If so, can you give some examples of any mitigations to inbound requests from those connections?

IP masking was applied very early but it did cut down a large number of requests, I am not sure how many though. Next were filters that would block devices sending more than a few hundred requests a minute or so on. These would be usually bots or compromised devices. Then we would look at cuts of traffic where the characteristics were outside of acceptable parameters and block those. E.g., say a particular OS, OS version, device model, request country etc. This could be made much more granular. If you see too high a CTR or too low a conversion rate, or abnormal time between ad being displayed and being clicked on (fraud clicks had a tighter distribution between request and click as compared to genuine clicks) or any other weird stuff, you could block that cut of traffic.

Also, we refrained from calling it fraud, the term was invalid traffic. This also accounted for things like someone double tapping on an ad instead of once, and so on. There is a good report by Alexander Tuzhilin [1] commissioned by Google when they were sued for charging for invalid traffic that might give you some more ideas.

[1] https://googleblog.blogspot.com/pdf/Tuzhilin_Report.pdf

Thank you for this. I’m more interested in it from the perspective of anti-web scraping algorithms.

I was curious, when you say block traffic, would you send 400s or silently just not record the crucial events? It seems like maybe tipping off automation would cause them to readjust. Perhaps they are not that determined?

Oh they were pretty determined. Sometimes when we would block traffic on particular cuts, we could see changes in traffic happening in as little as 30 mins which meant that fraudsters had automated systems responding to changes on our end.

Things such as a single device ID sending hundreds of requests in a minute or blacklisted IPs would be just dropped silently, no point in even wasting bandwidth to show an ad. For cuts of traffic where the clicks etc were outside of predetermined ranges, it would again be blocked and dropped. In other cases, where fraud happened before we could block it, there was a flag called 'billable' which was set to False so the advertiser wasn't charged for it.

I see.

Who were the fraud operators affiliated with / what was their incentive? Isn’t it the publishers that would see value, or perhaps a competitor trying to disrupt marketing efforts?

Do you see opportunity for innovation in traffic validation? Have you seen much in the way of training ML for this purpose?

It's doable, but I believe a bunch of old phones will come out cheaper (including on electricity cost) and more reliable (being proper devices in the eyes of ad networks, and having fewer crashes).

A 4 core i7 CPU + 32GB of RAM will run 4-8 Android machines, maybe a couple more. You can get 10 Android phones for ~$700.

True. I think the economics of how cheap smartphones have gotten is shocking.

Especially since you can acquire "barely working" phones. Broken camera? Not a problem. Broken audio jack? No worries. Cracked screen? Meh. No battery life? Doesn't matter one bit.

I imagine it's pretty easy to acquire hundreds of barely working phone for cheap if you don't care about using them as a traditional mobile device.

Or buy working devices and harvest the unneeded parts for resale.

Can buy a used MacBook Air, sell the lcd assembly and keyboard/trackpad and already recover a big chunk of the cost. (If you needed an Apple device).

And once you start looking to acquire hundreds of phones, you can buy a lot of old phones on ebay or the like for something like $1 a phone or less. Most probably won't work, but at scale, you'll end up with enough that are good enough for something like a click farm.
Why would an emulated phone need 4-8GB of RAM? A $70 phone probably only has 1 or 2 GB.
Worst case scenario overhead. Aka my normal situation, because I'm too lazy to use solutions better than Bluestacks on Windows :D
>A 4 core i7 CPU

What year do you live in? These days even i3s come with 4 cores.

2014, the last year Intel made any good improvements to their ancient architecture.

Just ignore the "i7" part if it confuses you. I've not had a desktop in over a decade, so I'm talking about mobile chips 90% of the time.

Rather difficult without an insider at Apple and Google. The fraud detection systems used are based on dozens of checks. I doubt even these real phones pass, since they likely have low uptime, they have never been in a landscape orientation or face down, few system settings are customized, etc.

At least Android provides a public API to measure trustworthiness, but if you are in the business of selling clicks you may also be in the business of turning a blind eye to fraudulent activity that makes you money.

I know a person who runs a bot on a social media app that does the follow / unfollow routine to boost an account. They've had this running for a few years.

At first I assumed it was conservative enough to fly under the radar. However, now that this network is so big, the pattern of this fraudulent behavior must be unmistakable. It is so simple.

The only conclusion I can draw is that the network is well aware of these bots, and so long as they don't draw negative attention, they are actually boosting "engagement" as the likes / follows do cause events that trigger people into revisiting the product--and ultimately reaching goals.

Illegal =/= Terms of service violation.
Different countries define "illegal" differently
Sure, but the vast majority of HN is US based and it's very important here not to perpetuate any notion that corporate wish lists are synonymous with the force of law lest we make any of our problems worse.
A lot of people here are speculating on what makes this illegal. The vast majority of the times, this will not be pursued by anyone if the operation is small time. If the operation is large, the actual reason for going after them may be things like money laundering, running a botnet by having unauthorized access to a device or things like that.

App developers can also achieve higher number of clicks by incentivizing users to click on ads by e.g., offering an extra life in a game if you click. This can drive up the click thru rate at the expense of lowering the rate of post click events. This is usually not allowed by advertisers but sometimes they are okay with it.

Also, not everyone minds some fraud. VC driven companies may only care about clicks or new user sign ups, regardless of how good the users are because that's the metric they are targeting.

> VC driven companies may only care about clicks or new user sign ups, regardless of how good the users are because that's the metric they are targeting.

That could bite them in the ass further down the road, when these bot farms are exposed by researchers. There was a few well researched bot farms on Twitter that are now defunct as Twitter dismantled them and now forces you to use a phone number to register an account, limiting attempts by people who want to create sockpuppet armies.

I know this is a loaded term, but I find it interesting that globalization plays a key role here. I would be surprised if the economics of click farms made sense without involving third-world employees generated ad revenue in first-world denominations.

Better wages in those countries would likely eliminate fraud like this. It's essentially an arbitrage opportunity to buy first-world denominated "attention currency" at third world click farm worker attention prices.

Right. And one way to combat that is IP geolocation, show your ads only to a first world audience. Of course, then a VPN or other IP spoofing techniques will combat that.
A friend-of-a-friend supposedly bought a bunch of cheap Android phones and ran apps that pay you to watch ads. IIRC it was only worth a couple hundred bucks a month.
The amount keeps going down. In 2012, you could make into the hundreds a day. In 2014, you could make over a grand or two grand a month. In 2016, $500 or so. Until you get to 2019 when the number became pretty low. And so on.

Also, if you can make a couple hundred a month. Then with just that info alone, there’s nothing but equivalent phones, an IP address, and bandwidth stopping you from doing that amount again.

> They reported that they earned USD $2,950 to $4,400 per month, which comes out to $35,400 to $52,800 per year.

I always find it surprising how little small illicit operations usually make. At the high end this is only barely more than the US minimum wage (between three people). Amazing for where they live, but awful in the grand scheme of things.

I'm always surprised of the opposite when I see malware operations get busted with 8 figures of profit. Should have stopped at 7 figures and no one would notice.
I think you are underselling the amount. $50K/yr is a fortune for the markets these operations run in (think random Thai towns/villages). It is approaching median wage for a family in a large US city.
I think the operative words here are "They reported". If you had a bunch of cops looking to extort you for a part of your operation's profits, how big would you make the pile out to be?
A buddy of mine does this for dating sites (don't ask).
And here I was thinking there would be pictures of animals being treated badly in farms -which the government passed a law to prevent journalists from taking pictures .
I'm kind of surprised we don't have robots that actually push physical buttons by now.