The Return Of The Pop-Up Ad
SYFer writes "Shortly after upgrading my Macs to OS X 10.3.8, I noticed that I was getting pop-up ads on Safari. It had been so long since I'd seen a pop-up, I completely forgotten how annoying they can be. I went over to Apple's Support site to see if there was a relationship, but learned that the timing is just a coincidence (even though there's a lot of the usual FUD and flailing of arms in the discussion forums). In fact, it turns out that the pop-up advertisers (what's the proper denigrating term here?) have finally defeated the pop-up blocking functionality found in many browsers. MacFixIt is running a front page article on the topic and says 'Contrary to initial reports, this problem isn't limited to Safari; subsequent reports have noted pop-under ads victimizing a number of browsers that provide pop-up-blocking features, including the latest versions of Safari, FireFox, Mozilla, OmniWeb, and Camino.'"
I've been coming across popup ads in firefox even with popup blocking on for a couple of months now, though luckily not too many.
The Farewell Tour II
...it's time for the return of my shotgun to active duty.
I tolerate text ads because something has to pay for the web, but popups and other abusive ads (like the huge flash ads in the slashdot TEXT ONLY service) just get blocked. The fuckwits deserve not to get any ad revenue for pulling stupid tricks like that.
Beep beep.
I've had this trouble too just recently. I get one off and on at this site: http://www.scienceblog.com/cms/index.php.
Call me crazy (ok don't) but I thought I had spyware. I certainly don't. I'm running Firefox 1.0.
Hopefully they don't catch on too quick.
UID 1000000 is just around the corner.
it turns out that the pop-up advertisers (what's the proper denigrating term here?)
Poppers? Plippers? Flippers? Flappers? Wippers? Snappers?
Sorry, kinda high on Red Bull right now.
I enjoy large posteriors and I cannot prevaricate.
...am I lucky.
Lynx is, and continues to be, the ultimate browser for ad-less internet browsing.
Take that, 21st century!
In any event, it's going to be something of an arms race between advertisers and pop-up blockers. Ideally, these jerkwad marketers should realize that people using pop-up blockers do not want to see their ads and display them to someone else who does want to see them. If they can find anyone like that.
How am I supposed to fit a pithy, relevant quote into 120 characters?
-- Note: These Comments are Generated by ME! Not You! ME!
Why do advertisers/companies think that annoying the hell out of people is a good way to make money?????
the macfixit article mentions that these are pop-under ads. i definitely have noticed a few of these in the past week, using firefox on windows...
it really confused me, since like the submitter, i havent really seen anything like it for over a year...
It's sorta like this:
"SCREW YOU, POPUP-BLOCKING BASTARD!! Now buy our cheap cameras.
Hmm...
Drudgereport seems to pop for me on Firefox all of a sudden. It just started happening w/in the last week.
-- jimmycarter
So....how long before firefox develops a popup blocker blocker blocker?
I think I just confused myself. Yikes.
Lately I've been hearing complaints by people using Firefox of some sites having pop-ups come up again. The biggest complaint coming from people that visit The Drudge Report. I too have seen them.
However, ever since I started using the Adblock extension, as well as keeping an updated list of definitons, I haven't had these problems lately.
How does defeating a measure designed to block your ads make good business sense? Does forcing your ads upon someone known to hate your approach produce good results? Does irritation equal a higher rate of return because people who hate your ads see them and have a change of heart? Do they say, "Hey, I had no idea those hateful ads were so interesting and useful to me. I think I'll buy their product."
Cuz my instinct is that when a person takes active efforts to banish you from their lives, forcing your way into their living rooms isn't a cost-effective approach. But hey, I don't work in advertising, as anyone who reads my About page on the headlines site knows. I like advertising in its place, but c'mon, if I kick you out of my house, stay there, please.
The Internet ad industry is causing an arms-race they won't be able to win. If the increasingly popular pop-up (or pop-under really in this case) blockers start getting defeated, that is just going to force the average browser user to start using a custom Hosts file of some kind to block nearly all ads. There isn't too much the ad industry can do about that, IMO, with the possible exception of making the ads come from the same server as the content. This will be okay for some sites, but I can't imagine too many people will want to give up that much control over their sites.
(But maybe that control is the ultimate plan of the ad industry - it would really make things easier on them...)
There is no excellent beauty that hath not some strangeness in the proportion. -- Francis Bacon
So....how long before firefox develops a popup blocker blocker blocker?
Blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, pop-up, pop-up
Blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, blocker, ARGH! Spam! A spam!
(apologies to weebl)
I've also recently encountered more pop-ups in Mozilla and at first attributed it to the Macromedia Flash plugin. The following page from Hindustan Times (often linked from news.google.com) puts up a pop-up ad that is quite effective -- centered and blocks most of the content such that you have to move it or click it or close it (no chance to have it pop-under). See it/slashdot it here:
Gurinder Chadha believes Austen was a Punjabi in her previous birth!
Linux at home
I sent them a brief email: I received an email from them soon after that they had sent to their advertising partner, TribalFusion:
Needless to say, I was very impressed, am browsing Macslash again, and have yet to see any more of these pop-ups.
-Paul
A not-terribly-computer-savvy friend of mine is having problems with his AOL email.
So I suggested he sign up for Yahoo mail, because all the people I know who use it find it perfectly satisfactory.
He can't get signed up for Yahoo mail. I tried coaching him step by step over the phone. I can't be 100% certain of what's happening, but as I followed through the same steps on my own browser, he ran into troubles at exactly the point when Yahoo popped up a confirmation screen on my browser.
I'm about 95% sure he has popup blocking enabled and that's what's preventing him from signing up with Yahoo.
Of course, he doesn't know what a popup blocker is, or how to control it.
So, these days there are probably users who are suffering both from the new popups and from incompatibilities caused by the use of popup blockers.
"How to Do Nothing," kids activities, back in print!
Just turn off javascript in the browser you use. If a site requires javascript then don't go there.
That is not a viable option. 95% of the sites I (and almost every other web user) visit use javascript in some way, shape, or form. I don't want to take the mindset of "Flash is evil, images are a waste of bandwidth, java is pathetic (even though it is, but that's beside the point). The Internet is full of crap so I should just use Lynx." I like to see things other than plain text and images. I can deal with a couple of pop-up ads here and there until the next version of Firefox comes out.
--guru
They may use javascript, but that doesn't mean it's necessary. I've been surfing without javascript (or java, or flash) for many, many years now, and there are only a select few sites that even have reduced functionality because of it.
Netflix, for instance, requires javascript only to allow you to rate films, and works perfectly without javascript other than that.
The only place where javascript is usually needed is with drop-down lists, which is rather stupid, as a single button next to the drop-down would eliminate the need for javascript for them.
If you find a site that needs javascript, complain loudly to the webmaster, and you will see it change, most of the time.
Slashdot gets worse every day... Pipedot: News for nerds, without the corporate slant
I'll second the recommendation of others here: block the ads at the DNS level. Windows users need to add entries to their local hosts file. Myself, running Unix at home, I use a three-step approach. First is a very small web "server" running on a scratch server. It's only job is to respond with a "404 Not Found" to any HTTP request (it does SSL and listens on ports 80 and 443). Second, I create a wildcard zone file for BIND that returns the address of my 404 server for any name in or below the zone's root. Third, I modify the named.conf file for the copy of BIND that serves my network, pointing each domain that's a problem (eg. "fastclick.net", "doubleclick.net") to the wildcard zone. Presto, as far as everything on my LAN's concerned any hosts in or under the domains I list now belong to me and my 404 server, not the companies who registered them. This can obviously be worked around by using IP addresses instead of hostnames in URLs in the ad HTML/JS, but nobody's doing that yet and if they do I can deal with it with some appropriate IP-level redirect rules in my firewall.
Advice to obnoxious advertisers: we control the clients, not you. If we don't like what you're doing, we'll do something about it. If you make it too hard to do something about it and won't change your ways, we can make you cease to exist. And with a Linksys router with custom firmware and configuration the non-geeks can get a turnkey solution too.
A solution to this is to install the AdBlock extension for Mozilla/Firefox. Once you've done this, grab this list of search strings. Once you've done this, import the text file and you should be home free. Try to keep that file updated as it should be a good starting-off point, but will become outdated as time goes by.
I haven't tried this with the specific examples referenced here, but it ought to work in general in Firefox and other *zilla browsers.
1) Type about:config in the URL bar
2) find dom.popup_allowed_events
3) change the value to the empty string
Now no events allow popups by default. That means if you want to let a site pop up a window from Javascript you will have to whitelist it.
This blocked the popups on drudgereport.com for me when I tried it a few months back. I don't leave this setting on, for now, since I prefer to choose not to frequent sites that maliciously abuse me with ads. However, if it starts to become a regular nuisance, I will set Firefox back to this aggressive anti-popup setting. After all, nobody really NEEDS to use Javascript popup windows, and if I can see where a legitimate site is trying to do so, it only takes a few seconds to whitelist them in FF's popup blocker.
Well, here is what I do in Firefox. I haven't received any pop-ups (yet). In the options dialog, under "Web Features" you'll find that on the far right across from the "Enable Javascript" checkbox is a button that says, "Advanced."
"Allow scripts to: " (remove check marks next to the following)
- "Move or resize existing windows"
- "Raise or lower windows"
- "Disable or replace context menus"
I also uncheck "Hide the status bar" but that's a personal preference.After unchecking those along with having the pop-up blocker enabled I no longer get any pop-ups. And I really don't see unchecking those having any profound viewability problems on the web. If a site needs to resize your window, it's usually because they want to open a pop-up along side it. :P Same goes for raising/lowering too.
1. Get an old POS PC from a trashpile
2. Install Smoothwall on it. It's free..
3. Install Ad Zapper following THESE directions.
Any and ALL system that you connect into your lan will have ads blocked whether they want to or not.
> Your ID is not low.
:D
Neither is yours, you newbie!
Haven't you heard of gmail?
Are you really going to complain loudly to the webmaster of every little javascript-based site you want to use and wait for them to redo the site?
Do you realize that many sites are actually faster with javascript on, because there is a non-trivial application running on the client site, and it needs to download no (or very little) data for many of the requests, as opposed to loading the whole damn page every time you want to change the width of a column in a table?
Wouldn't that also block user-initiated javascript popups? Many sites use these legitamately (though they are annoying).
This post written under Gentoo-linux with an SCO IP license.
In my opinion, here is the proper way to deal with this and any similar scourge:
1. Install Privoxy. It writes every bit of HTTP activity to its log file.
2. Wait for a pop-up ad to appear.
3. Immediately consult the Privoxy log file. Determine what URL the pop-up came from.
4. Block out the entire domain from which the pop-up came from. Use whatever IP blocker you like best: Your DNS relay, your firewall, your hosts file, or Privoxy.
5. Repeat as needed.
In the back of my mind I keep thinking there was a law on the books about people taking control of a computer without the users consent. Now it seems to me that circumventing a pop up blocker to open a new window violates this law and the advertiser and possibly the website could be held liable.
I know this law is on the books maybe someone could point it out.
This is very useful. It's worth noting, also, that removing all "allowed" popup events doesn't completely kill your ability to use sites that need popups...it just causes Firefox to warn you that it has blocked something, allowing you to adjust settings for that site.
Seems to have fixed all those new popups for me.
I am right there with you. I'm sorry, but there just aren't any websites that are so important to me that I feel the need to beg for bullshit by turning on a bunch of pointless features.
The very concept of a pop-up blocker is stunning to anybody who has been using the web since before Javascript became common. (To say nothing of the folks who have been using the Internet since before it had websites on it!) I can think of very few features that were so bad that users begged for ways to prevent the feature from being used... And said feature wasn't removed from the product!
Can you imagine if car makers started including bombs in all their cars, and you had to get or make a special explosion-blocker? You'd think that it would occur to the manufacturer to just not install the bomb, rather than working on the ultimate explosion blocker!
I'm using more exclamations points than is my habit, but only because I find the situation so excrutiatingly baffling. If, in IE6, MS had simply not bothered to include the code to open new windows automatically, the world would be a better place, and few people would have felt the need to switch to better browsers. Any sane web designer has come to realise that their user's hate popups. Further, any sane web designer has to deal with the fact that their 'legitimate' popups are likely to be blocked. Thus, any sane web developer should just stop using popups as part of the actual site, so all popups can be assumed ads, and we can just abandon the feature entirely.
To quote Mr. Jeff Foxworthy's guide to UI design... When you have features that make front page news when they get used, because your users hate those features so vehemently, you might be a bloat-peddler.
Why do we want to surrender functionality? Don't give up the web to those that abuse it. Kick them off it by boycotting. Google has almost singlehandedly re-launched the dotcom boom by getting the eyeballs of people who choose to reward good sites and ignore bad tactics such as pop-ups, excessive banners, animations, and blurring between content and advertizement. You have the power to determine content. Don't bow out by surrending both the content and the functionality.
Hi! I just heard about this site from some of my hacker friends, and just wanted to say hi to you people!
If you want to curb the popups until Firefox releases a new patch, you can set dom.popup_maximum to 1. This will keep 99% of legit items that pop up working while limiting the amount of popups you have to take care of yourself.
Actually no, they're not.
The DNS Service in WinXP and 2000 Pro are simply caching services, you can disable them and have DNS still work. I do at home here because I have a DNS caching server on the gateway machine so I don't need another cache, it does speed things up in the proper configuration.
I too noticed this, but contrary to most, realised that they must simply be doing what has been possible for a long time but which no one had really bothered with, with the exception of porn sites and other spyware "value adders", until now.
Basically, it just uses the age old technique of using the document.write method, but obfuscated, to write other, obfuscated tags which are not recognized by the blocker as being new script tags, which themselves call a new obfuscated pop.js code that actually, in yet another round of obfuscation, produces the actual pop-under code: In essence, if one can block any request for the server of the obfuscated pop.js, or pop.cgi or whatever code, one will be in peace for a while. This can be done via adding the following lines to the hosts file on Windows (C:Windows(or WinNT)\System32\drivers\etc\HOSTS) or on Linux or MacOSX (/etc/hosts) or simply via your firewall software, which I'm sure we all use, don't we?
127.0.0.1 www.fastclick.net
127.0.0.1 media.fastclick.net
I have the code from the above server, as used by scienceblog.com, but I won't post it, as it's copyrighted, because the last thing I want is some internet low life trying to sue me for their own low life purposes.
if you see PopUps in Firefox, please file them here : https://bugzilla.mozilla.org/show_bug.cgi?id=25383 1 (no link, Bugzilla doesnt like /. links)
Go look at Google maps and Gmail. You can do some really good stuff now with Javascript, particularly as you can make a request back to the server with it and update part of the page without a reload.
Like any web tech it can be abused, but if you are a half decent developer the reason you are putting in JavaScript is to make the app a better experience for the user.
Maybe you want a world of basic pages and lots orf reloads, but most user seem not to.
In August of last year, I made this demo, which shows how to easily popup a full-size page. This is done by submitting a form on onLoad, which targets a new frame. Works in Safari, but not in Firefox.
http://tom.lightheadsw.com/etc/safaripopup.html
Sig Nature
https://bugzilla.mozilla.org/show_bug.cgi?id=17607 9
- go to about:config
- right-click and select New/Integer preference
- make a pref called "privacy.popups.disable_from_plugins"
- set the value 2
Now plugins are treated just like javascripts trying to open popups--they get blocked by the popup blocker. You have the option then to show the popup or to allow them for that site if you want.
A week ago I had problems getting Firefox to close.
Turns out some site had opened a popup window offscreen. I tried to adblock the contents from - wonder what it was - 888.com or something.
Thank heavens that it opened offscreen. Otherwise I might have actually seen the popup. (What's the point of opening popups offscreen anyway? I just got spam that was titled "Do not read this" or something like that.)
If there's some way to disable java/javascript/plugins per-website, please let me know.
Most pop up windows these days are let through by the browser if the user first clicks on a link or something to open the window. I've seen some web pages where they will capture the clicks for the entire document then open a pop up window.
Norton Internet Security does exactly this, and has done for many years.
Switch off all the "intelligence" of the package, like auto-program recognition, and set the firewall to "paranoid plus" (only specific ports to specificcally permittied programs) and then set the defaults to non-script/activex/java, etc.
Works for all browsers, since it installs an invisible proxy (not as bad as it sounds - none of my *really* weird software conflicts with it, and software doesn't need to be proxy aware), and all traffic is rerouted through that, so it appears like a secure TCP-IP stack. Damn bulletproof, in my opinion.
Winds up the GF, who has to ask me to relax the security on a new site occasionally (twenty seconds click-work), but that's a small price to pay knowing that only sites that prove trustworthiness to me get to use flash/java/script/activex/cookies/popups.
I'm *not* affiliated with Symantec, and the only downside with NIS is their new fetish with key-based software activation, which means I'm looking for a similarly-accomplished alternative firewall package for this reason only. But I've not found it yet.
flashblock replaces all flash with an (F) icon, which can be clicked, enabling the flash to play. 99% of the time i don't want flash, but in the case of strongbad, of course, i click :)