Security / Safety concern, please help!
Hello, everyone!
First off, Iīve read a lot in this great forum and am particularly happy to have an opportunity to open my own thread. I couldnīt find any information regarding this particular topic, so here it goes. I hope this serves to clarify things for me and others with the same question.
I have developed and run a couple of websites for a magazine publisher, with very segmented public for almost two years now. In the past few months, all the hard work is paying off since there are people interested in running banners and adds on the sites.
One particular agency sent me a flash banner wrapped on a tag that requests a javascript from an outside server. The script executes on the visitorīs machine, leaves a couple cookies and does nothing mean in particular, but the fact that the script resides OUTSIDE my server is concerning me a bit, so I said I wouldnīt allow it.
I am getting yelled at from all directions, with people saying that this is a common procedure in internet advertising, and that no one has never heard of such concern...
A little explaining:
The flash banner is just a simple animation, but the tag that calls the flash banner also requests a javascript from the server nspmotion.com (which I eventually found to be property of AdMotion, a large internet add monitoring company).
The mentioned javascript writes a cookie on the userīs machine EVEN IF IT IS NOT CLICKED, which makes me even more pissed, and from there on, it tracks user behavior.
I honestly donīt believe AdMotion to be running crap code, but regardless, I donīt feel comfortable allowing them to decide WHAT and WHEN code runs on sites which I am ultimately responsible for.
So, here are my questions in simple terms:
1. Is it okay to allow a script that I have NO CONTROL OVER to run on my site?
2. Is the running of remotely hosted scripts a commonplace behavior for sites with paid ads?
some considerations:
Yes, I have analyzed it, and it doesnīt do anything mean, but it can be changed at ANY time, since it is hosted elsewhere.
I believe that I am responsible for the content I provide inside my website (including add banners with potentially dangerous code), and therefore should not leave an open door for some tracking company to evaluate my viewerīs behavior.
|