Episode 11
Catching Ad Fraud, Phia, Honey, AppLovin and More...
with Independent Researcher Ben Edelman
Show Notes
Ben Edelman has spent two decades catching online fraud that hides in plain sight — combining software engineering, law, and economics to prove misconduct empirically rather than take companies at their word. In this conversation we get into the Phia shopping-plugin scandal, how it relates to Honey and Paypal that he covered after Megalag broke the issue on YouTube, the mechanics of affiliate fraud, and his recent investigation into AppLovin's apparent app install deals with mobile carriers.
In This Episode
- How Ben got into fraud investigation, and what keeps him motivated
- Phia's "cookie stuffing": how a browser extension can claim affiliate credit for sales it didn't drive
- Whether Phia's "December bug" oopsy explanation holds up, and Phia's earlier 2025 privacy “mistake”
- The Honey/Paypal parallels, typosquatting and the broader toolkit of affiliate-fraud techniques
- MegaLag vs. the mainstream media: how independent investigators break stories now
- AppLovin's nonconsensual install investigation he wants state AGs to look at
- What meaningful accountability looks like, and his advice to founders building in this space
Links & Resources
- Ben Edelman's AppLovin investigation
- Ben Edelman's site (full archive of his research)
- Ben's list of "Investors supporting spyware"
- Edge Shopping Stand-Down Violations
- Phia forced clicks and stand-down violations
- Honey stand-down violations and concealment
- Adware investors page
- "Spontaneous Deregulation: How to Compete with Platforms that Ignore the Rules" (HBR article about intentional rule-breaking as a business strategy)
- Rob Leathern
Chapter Timestamps
- 00:00Introduction and Background on Online Fraud Investigation
- 1:36The Origins: Gator Adware and Early Ad Fraud (2001)
- 3:10The Dark Chapter of VC-Funded Adware
- 4:54Transition to Independent Investigation Work
- 6:07FIA Investigation: Two Types of Violations
- 7:31Understanding Forced Clicks Through Analogies
- 9:50Debunking FIA's "Recent Bug" Defense
- 12:50FIA's Previous Screenshot Controversy
- 14:18The Current "Dumb Tech Cycle" and Screenshot Overuse
- 16:20Recurring Patterns: From Gator to Modern Shopping Plugins
- 21:11Startup vs. Public Company Misconduct Patterns
- 24:40PayPal's Due Diligence and Ongoing Modifications
- 27:24Media Resources and Technical Expertise
- 30:17Typo squatting and Google's Role
- 31:36The Ad Tech Attention Gap
- 33:34AppLovin Investigation: Install Helpers and Carrier Partnerships
- 34:21Wall Street Journal's Surprising Rejection
- 40:28Carrier Billing and Historical Context
- 44:42Advice for Founders: The Temptation and Risk of Cheating
Transcript
There may be transcription errors: we apologize for those in advance.
Rob: Hi, welcome to Won't Fix. I'm Rob Leathern. My guest today, Ben Edelman, has spent two decades catching online fraud that hides in plain sight — combining software engineering, law, and economics to prove misconduct empirically rather than take companies at their word. In this conversation we get into the Phia shopping plug-in scandal, how it relates to Honey and PayPal, and something he covered after MegaLag broke the issue on YouTube: the mechanics of affiliate fraud, and his recent investigation into AppLovin's apparent app-install deals with mobile carriers. You won't want to miss this one.
Rob: Thanks for joining us. Hey, Ben, how are you? Where are you joining us from?
Ben: I'm actually in Tokyo today. My kids said they wanted to go somewhere hot with good Asian food, so this place fits the bill.
Rob: Nice. I'm in San Francisco, so both of us are out of our normal locations. Thank you for taking the time. You can tell us more about the context of this recent investigation, but I also just wanted to chat with you at some point on this new podcast I started recently. So I'm glad you were up for it.
Ben: My pleasure. Thanks for thinking of me.
Rob: By way of introduction — tell us a bit about how you got into these kinds of investigations. Then we can talk specifically about Phia and that whole set of shenanigans, which I think has some really interesting learnings. But how did you get into doing what you're doing in the first place?
Ben: My story with respect to ad fraud begins in 2001 — not a typo. My clients, the New York Times, Washington Post, Wall Street Journal and a bunch of others — there were seven of them splitting the bill into equal parts — wanted to sue a company called Gator. Gator was adware. Maybe it was the first adware, and certainly the most famous of its day.
At the start of that litigation, Gator was looking in web pages for 300x250 banner ads, and also 160x600s and a couple of other sizes. They would reach into the publisher's website, take out the banner ad, and substitute their own banner ad, which they had sold through their sales force. The publisher would get zero for their hard work of paying journalists and editors and health insurance and the rest, and Gator would keep all the money. Nice little business for Gator; not good for my clients.
We got that shut down for my clients. And for the rest of the world — well, they hadn't hired any lawyers, they hadn't hired any technical experts, so they got nothing. That didn't work for me. I kept working on adware, made a little business of it for a while there, and on some level I never stopped. This is sort of the culmination of that — and I suspect not the last chapter in the book.
Rob: I remember Gator very well. I wrote about them when I was a research analyst at Jupiter, and I called that category "sneakyware" — because yes, adware is another way to put it, but everything they did was kind of sneaky and tricky. It was hard to uninstall, or maybe impossible, depending on your definition of uninstall. That whole category was a dark chapter, but it recurs in many different ways, and brings us to the present moment, doesn't it?
Ben: It was a dark chapter for some very famous VCs. I have a page on my site — I can give it to you for the show notes — where I chronicled which VCs had funded which adware vendors, and in which amounts. I think all of those investments were terrible. They lost a lot of money on it. I wish I'd been in a position to advise some of them on why they should keep their powder dry. Those adware companies all failed, so that's good. The long arc of the story does bend toward justice, as has been said, but it can take a while to get there.
Rob: Absolutely. What's that other category — deep packet inspection companies? That was another dark VC-funded chapter, wasn't it?
Ben: There are to this day some that will modify Wi-Fi in, say, coffee shops, hotels, airports, so that when you request Expedia.com it doesn't bring you to Expedia.com — it brings you to an affiliate link to Expedia. And if Expedia ever kicks out one of those companies, they can make Expedia unreachable. "Sorry, this coffee shop doesn't support Expedia. Would you like Booking.com?" It's nuts, the things you can do with deep packet inspection.
Rob: Maybe that's a story for another day. You mentioned the affiliate side — tell us more about this investigation into Phia, how you found it, and your interactions with the journalists who wrote about it.
Ben: I retired from big tech almost two years ago and decided I wanted to work on things that really mattered to me and have more control over it — a decision that I know rings true to you too, for broadly similar reasons.
I wasn't originally thinking I'd get back into affiliate. But when the YouTuber MegaLag had this amazing series on Honey, I started communicating with him after the first video, which was good, and together we did the work that's in his third video, which I'd like to think is better than good. That got me looking at the other shopping plugins too.
In some respects, shopping plugins are so much better than they were a decade ago — and we can talk about what's improved in this industry; it's nice to have things to celebrate. And then some other things are just totally messed up. There's no one guarding the hen house, and the fox lives inside the hen house at this point.
So Phia was on my radar when Bloomberg contacted me saying they were looking at certain problems with Phia. I said, well, that's interesting, but I've got some others — let me tell you about those too. And next thing you know, we had the story everyone looked at a couple of weeks ago.
Rob: This seems similar to the Honey case, in that it's basically claiming credit for transactions the partner didn't drive — writing over other affiliates' cookies. Is that the right way to think about it? Are they similar? What's different about the two cases?
Ben: They're both breach of contract, where the governing rules are embodied in a contract to which Phia and Honey are privy. The specific violations are partly the same, but Phia has more violations. Maybe Honey has some aggravating factors too, in the way they tried to hide what they were doing to avoid getting caught.
As to Phia, my article lays out two separate violations that I want readers to understand. The first is a forced clicks violation, which hurts the merchant. The second is a stand-down violation, which hurts other affiliates. Different practices, different harm, different likely dollar value of impact. In general, forced clicks is a higher-dollar-value attack than stand-down violations. Both are bad — breach of contract is breach of contract — but they breach different parts of the contract, with different victims and different amounts at issue.
Rob: I always try to figure out good analogies for explaining this stuff to regular folks. Is it like you're at the store, you go to check out, and the salesperson comes up and says, "Hey, can I just add my code to your checkout to get credit for having helped you" — when they never helped you navigate the store or pick out items?
Ben: That's sort of the classic forced clicks violation, where the salesman is at the very last step, when you're already sold, putting his code in. But you describe a salesman who is asking. In this case there's no asking. It's entirely invisible. You'd never know it happens unless you have some forensic skills to test — obviously, if you know how to test, you could find software to help you test and prove it.
It's as if the cashier in the store were slipping in the code of the cashier's friend, the salesman, and in so doing goosing that salesman's numbers. And it's not a victimless crime. A bad salesman gets reported as a good salesman, wins the trip or the bonus or whatever the boss is giving out, and takes more commission from the boss — the boss who should have had a certain number of transactions that aren't credited to any salesman.
This store has a good reputation. Customers come in and buy stuff. And it really is true for e-commerce retailers: we already advertised on TV, on the sides of buses, we have such a great product that there's word of mouth. Stores are counting on those things. That's part of how they make the numbers work. Not every transaction should be commissionable to an affiliate — but forced clicks takes those commissions even when they're not fairly earned.
Rob: Phia's response was to say, oh, it's a bug. I remember cases I can't talk about, but in my experience — one case where we met with a company that had done something when I was at Facebook, and my colleague said, "Watch, I bet within the first three minutes they'll throw some internal team under the bus and say it was a bug." And honest to goodness, that is exactly what happened. So what do you think of the company's response, and the credibility of claiming this was a bug they've now fixed?
Ben: There are multiple levels of their response that don't convince me. Maybe the easiest to debunk was their claim that this was very recent. They said it was in a recent build, suggesting the problem was in effect for a matter of days or weeks.
Now, every old version of an app in the Chrome plugin store is preserved. You can go back and download the CRX of a historic version. A CRX is a zip file, so you can unzip it and read the code. It's minified, but if you're smart — or you know an AI that can read minified code, or you have some other strategy — you can just find the first version that had it. This is not a good thing to lie about, because we're just going to go get the old versions and see how recent it is. And by doing that, you quickly find it's December 2025.
Rob: So that's right in the peak of the holiday season.
Ben: Not particularly recent. I mean, compared to Windows 3.1 or Tyrannosaurus Rex, it's all recent. But relative to e-commerce, relative to Chrome plugins, relative to Safari mobile plugins — it's not that recent.
Then, as to intentionality: bugs have a way of looking a certain way, and intentional misconduct has a different way of looking. When you see someone make a quote-unquote mistake, and it's totally self-serving, you don't tend to think it's a bug. You tend to think it was an intentional decision for their benefit.
If I see United Airlines sell a plane ticket for a dollar, I say, okay, that's got to be a mistake — this ticket is usually $100 or $1,000, maybe they missed two zeros. And if you see them try to sell a ticket for $10 million, you say, that can't be right; nobody pays $10 million for a plane ticket, you'd just buy your own plane and fly where you want to go. It's got to be a mistake. Those are two bugs that redound very much to their detriment. The price being too low leads to a bunch of fighting — probably you don't actually honor it, but you've got lots of angry customers to deal with. The price being too high, you don't sell anything, and eventually you're going to notice why no one is buying seats on this plane.
Versus this bug — it's a very convenient bug. It's only in the version of the software that no one looks at. No one really tests the Safari extension all that carefully compared to the Chrome extension. It's invisible; it has no on-screen manifestation. And it makes them a bunch of money — it probably 10x's their revenue on users who are on Safari mobile. So that doesn't look like a bug to me.
Eventually, I guess we'll find out. It only takes one company suing them, one network demanding the documents, for the intentionality to be revealed.
Rob: And this wasn't the first incident they'd had. Looking online, there was a bunch of stuff that came out late last year around them taking screenshots from within the app. Can you explain your understanding of what occurred there?
Ben: It's weirdly simple. Screenshots are screenshots. They were taking screenshots of sensitive information that people wouldn't want screenshotted. Maybe that could be understood as sort of unintentional — we just take screenshots of everything, sensitive or not.
Was it in the privacy policy? Was it disclosed? I haven't checked that; I don't have a good feeling about it. But even if it was, it seems so totally unnecessary. For a shopping app, classically you'd need to know what products I bought and what products I looked at but didn't buy, and from that you make your recommendations. You do not need a screenshot of what's on my screen — what YouTube I'm watching, what emails I'm sending, what my insurance company says about my recent doctor's visit. Those are all things that are going to be on my screen. They're all not important for a shopping plugin. They're sort of radioactive: you go and collect that, and everyone's going to be angry at you when they find out. It looked like a dumb product decision to me. A sophisticated, experienced team just wouldn't do that.
Rob: I feel like we're at a very dumb part of the tech cycle right now. There are a bunch of apps that take screenshots. Even the way some of the foundational models operate is they'll take screenshots of the screen and then analyze them to see if they did the right thing, or figure out what's on the screen so they can manipulate it — instead of the harder work of looking at the actual files and figuring out what's on the page. JavaScript is tricky, and all these things.
So I feel like we're at this lazy part, where not only are we offloading our brains to AI in many ways, but we're offloading a lot of these things and then not worrying about the sensitivity of what might be on the screen — or frankly, the fact that these are highly inefficient ways to do some of these learnings, or to train these models. I was looking at Wispr Flow, one of these voice apps, and they disclose it — but a lot of people I spoke to using it didn't realize it takes screenshots of your device in order to figure out if it's doing the right things. I just think some of the trade-offs we're making with respect to efficacy versus privacy are way off right now.
Ben: Certainly. I was going to go right to efficiency, where you went in the second half of your remarks. The efficiency aspect of it — reliability too, accuracy. When you build a robust data pipeline, it works. Maybe something could get messed up; someone could change a field name, change the structure of the payload. But short of that, it's efficient, it's reliable. There's so much to be said for the goodness of building something right.
Versus when you work on screenshots and the hackiest of hacks — you're consuming compute time, you're inflating your payloads, and their reliability drops too. I'm just not a fan. I guess I feel like an old guy sometimes: in my day we built things right, we built our buildings out of bricks. But you try to build it right so that it actually lasts and is reliable and efficient to use.
Rob: There's a recurring theme here. You talked about how you started your work around Gator — essentially client-side software sitting there looking at what you're doing and then deciding the right time to insert an ad or pop up a message. Now we're talking about 2025, 2026, companies doing essentially the same thing by other means. How do you see this category of "shopping help"? Is this an area where we're just going to have to always be watchful?
Ben: I've not been a fan of shopping plugins going back to, I guess, IE6, when there were EXEs that would hook into Internet Explorer and manipulate the DOM in order to do much the same thing Phia is doing. I was not a fan then; I'm not a fan now. First and foremost, because I don't think it adds value for merchants.
It's one thing for a merchant to say to a shopping website: look, if you want to pay the affiliate commission out to the user — as, say, FatWallet did 20 years ago — you go to fatwallet.com, you click their link to Dell, Dell pays a commission to FatWallet, FatWallet rebates most of that to you, the user, maybe even all of it, and makes its money some other way: advertising, or float, or breakage. I like that. I was a satisfied FatWallet user; I was sad when they shut it down. These days there are some other companies doing much the same thing.
When it's done on the web, such that the user has to remember to go to that site and click the button, there's a reasonable inference that the user actually is influenced by it. The user wants the cash back enough to remember. And so is it incremental to the merchant anyway? The merchant is able to separate the price-sensitive customers from the non-price-sensitive customers, and encourage users not to go through expensive paid search. Okay, fine, that works.
But make it automatic. Put a shopping plugin on the user's computer so that they always go through. Suddenly it's not that good a deal for the merchant. It's turning every transaction into a commissionable transaction. That's good for the affiliate manager trying to make his or her numbers — "Boss, my numbers are up 50% year over year, can I have a bonus?" And it might be good for the head of interactive marketing, who looks even more important: our marketing budget has gone up, I should get more headcount to manage the higher budget, and I should get a bonus too, no doubt.
But is it actually good for the shareholders? On that one, I was sour on it 20 years ago and I'm still sour on it today. There are all kinds of people who want to say that it works — the affiliate managers, the head of interactive marketing, the agencies. And the networks have mixed incentives on this too; they're marking up everyone's commissions. If I owned a company that had an affiliate program, I would not be in any great hurry to allow the shopping plugins in.
Rob: The incrementality is so hard to measure. And part of this problem is that I've been conditioned — whenever I'm about to check out and I see something that says "coupon code" on the checkout page, I'm like, oh wait, am I a sucker? Should I be getting 20% off here? Should I have signed up for the 15% off your first purchase? I just want to buy the thing, but now I'm wondering if I've missed something. We've been conditioned as consumers to be looking for deals all the time, and sometimes that leads to bad places.
Ben: The coupon code box is paradoxical. I'm not exactly a fan of it, though I don't have an alternative to suggest.
Rob: One of the other things about online shopping is that it's tricky to figure out who a good merchant is, if it's someone you've never bought from before. There are a lot of challenges. For example, someone brought to my attention recently these AI-generated images of products that don't exist — you order it, it takes a few weeks, and you get something that is nothing like what was described in the AI-generated imagery. The time delay of shipping stuff to people also allows a lot of shenanigans to slip in.
Ben: I haven't worked on that, but I can imagine, and it doesn't sound great. We are so spoiled by the marketplaces that make it easy to get goods at ridiculous prices. You look at some of the prices from — maybe I don't need to say the name — marketplaces that give much cheaper stuff than you're accustomed to from an Amazon. And is the quality there? What is your recourse if it isn't? It can be kind of messy.
Rob: This investigation got a lot of attention, partly because of the fame of the founders in this case. It's also this Silicon Valley truism, "fake it till you make it," which I think is an unfortunate but real thing with startups. The Honey case was more surprising to me in many ways, because this is a publicly traded company and the dynamics feel a little different. Is it the case that publicly traded companies are better behaved? Do you think startups are the ones playing fast and loose with the rules, or is there plenty of bad behavior to go around either way?
Ben: I haven't been shy in criticizing the very largest companies, including publicly traded companies valued now in the trillions — they weren't, at the time when I was most intensely looking at them.
In general, you see a slightly different kind of misconduct from big companies versus small companies. When I was criticizing Google, for example, it was clear that lawyers had had their way with all of the areas I was thinking about. Lawyers were the perpetrators of some of it — some contract that seems intended to obstruct competition and prevent competitors from getting a toehold. With the benefit of discovery and further litigation, we know that's exactly right: the lawyers designed a bunch of these contracts thinking they were at the edge of what was legal, but legal enough. And anyway, if we have to pay a billion-dollar fine someday, it's still a small fraction of the benefit we get. So that's big-company shenanigans.
Honey was paradoxical in that it's sort of using small-company tactics despite, as you say, having grown into a big company. We got the source code that implemented Honey's shenanigans, and presented it in detail with color-coded highlighting — the kind of article I love to write, and that I hope readers expect from me at this point.
It's nasty stuff. They're saying, okay, we really want to ignore the stand-down rules. We want to say that we referred the user even though someone else has already referred the user — but we can't get caught. So let's look at this user. Who is the user? Is the user's account more than 30 days old? We don't want to break this rule on anyone in their first 30 days; it could be a network quality tester looking for violations. Does the user have at least 5,000 points? Later they raised it to 65,000 points. These are pretty big numbers — that's hundreds of dollars of commission earned, of rebate value, through the Honey platform. What tester would ever spend $5,000 in order to earn $600 of commission? You'd have to be crazy as a tester. Where are you going to get the budget to buy $5,000 of stuff just to test Honey? Fortunately, it's possible to fake your points and then see what it would do if you had such-and-such many points.
These are the tactics of a small company that wants to break the rules, doesn't want to get caught, and wants to hide from the testers. It wasn't smart for Honey, and now they're going to pay a price for it. Already in litigation they take the position that this is legacy code — they didn't exactly do it, the old people did it. That isn't quite convincing, based on the facts we can prove as to the code being modified, and certainly the parameters for the code being modified.
Rob: Sure. And there's due diligence. If you're acquiring someone, aren't you supposed to look at the code and figure out what the people do and how everything works?
Ben: That too — certainly in a diligence process. But separate and apart from that, during the period in which PayPal owned Honey, the configurations were changed. So who changed them, and why? They're raised as if the code was getting more compliant — they were tightening the requirements, rather than being willing to violate stand-down if a user had just 5,000 points. As I mentioned, they raised it to 65,000. That's a big change. Whose decision was it? It must have been a PayPal employee's decision, because it happened really years after the transaction.
Rob: The other super interesting thing about Honey — I'd love your comments on this — is that the MegaLag YouTube videos were super engaging, really interesting. Folks like Bloomberg and others do great work, but I feel like you have a much more creative space there to explain what's going on to people, and to get some combination of distribution, viral sharing and outrage going online. So how do you feel that's evolving for this type of work? Would people have cared about Honey if it was just an article in some publication? A lot of great work gets done, but the falloff of people actually caring or paying attention seems very steep.
Ben: I certainly have work that I did that I felt didn't get as much attention as it deserved based on its technical or substantive merit, and other work that seemed to get a lot of attention relative to the ultimate importance of what it was all about. So media can be a rough justice.
MegaLag is a beast. The quality of his production, the amount of time and care he puts into it — he deserves every bit of recognition he's gotten, and every good thing that comes down the pike for him. He made the first video not as an expert in affiliate marketing. He gets a lot of credit from me for bravery, putting himself out there. The video wasn't totally perfect. There were parts of it that were kind of messed up, actually. And that's okay — perfection is not the standard. By the third video, the guy really knows what he's talking about. He knows the affiliate marketing business. And just imagine all the things he has that he hasn't put into a video yet. So: big admirer, much respect.
I like to see this work done by everyone who has an angle on it, who has any economic incentive to keep doing it. There's certainly plenty of work to be done and no shortage of it. If Bloomberg can somehow find technical people to do it in-house — and note the byline on the recent Phia article: three people, two of whom are quite technical. That's amazing. More credit to Bloomberg for finding and managing and retaining and paying those people. Otherwise it'll be people like me and MegaLag doing it as a hobby, maybe scavenging together what revenue we can from it.
Rob: I feel like this area is really interesting. A lot of people I know who are on the fringes of privacy, security, trust and safety teams also want more independence, but have a lot of technical competency. So I feel like there's a combination — folks who have a platform, whether that's old media, new media, whatever it is, along with technical folks who can help do investigations or complement that. There's got to be some model there that's durable and sustainable in the future. What it is exactly, maybe it's affiliate revenue that sustains it. I'm just kidding — it's probably not.
Ben: That wouldn't be my first choice anyway. It's interesting to think: if I made a shopping plugin or a shopping site, how would it be different from the others? Anyway, that's not a plan I've been thinking about.
Rob: Speaking of other investigations — it sounds like some go well and get a lot of attention, and you never really know what's going to catch people's attention in the public sphere. What are some that you think are still important, have been frustrating, or where you feel like there's more to be uncovered? I know some of these are in litigation, but what have you been frustrated hasn't gotten the purchase you expected?
Ben: I wrote up a quick piece on stand-down violations by Microsoft Edge in fall 2025, before MegaLag 3 broke. Really, no one noticed the piece. It was slightly pathetic that I write about violations by what was then, I think, maybe the second most valuable company in the world — in a browser that is shipped on your computer whether you asked for it or not, in a shopping app that sort of gets turned on whether you wanted it or not — and then it doesn't even follow the stand-down rules. Microsoft said it was an accident, or a mistake-ish. They sort of said it. It's not like there was a ton of media coverage requiring them to respond. Anyway, I know someone who had recently worked at Microsoft. I was kind of unimpressed by the whole thing, and wondering who's even running that, having seen it turn over a couple of times even in the period when I was there.
More generally: typosquatting. I've always been a big skeptic of typosquatting. I was co-counsel in class action litigation against Google as to Google's role in funding typosquatting. Google was paying the typosquatters. We said that Google was "using" the typosquatting domains. The language under the ACPA is that you can't register, traffic in, or use the infringing domains. We said, okay, Google didn't register them, but they seemed to be trafficking in them when they bought the traffic. What does trafficking in it mean other than buying the traffic? Do you have to buy the thing rather than the traffic from the thing? But anyway, they certainly used it when they bought the traffic from the thing. We said Google should be liable.
The court said each trademark holder would have to sue Google separately and independently — which obviously is never going to happen. Either they get one set of lawyers and do it all together, or it doesn't get done at all. So that judge basically chose "doesn't get done at all." That was heartbreaking. That was also more than a decade ago, so I've had my time to get over it.
Rob: I was at an ad tech conference recently, and a founder I know there was sharing his frustration that the good work they're doing at his company is getting undermined by other companies. The whole ads ecosystem is very poorly understood, especially by media — because media also has an interest in ads, so they've tended to shy away from covering it well. Do we just need more understanding of ad tech and marketing-related technologies? Is that realistic? One of the things that bugs me is that there are hundreds of billions of dollars flowing through these companies, but the attention paid relative to what share of the economy they occupy seems really low. Am I off on that?
Ben: There's been greater attention on Google and Meta and Amazon and Apple from antitrust folks over the past 10 years. I feel like I was right on that. I was very early to the party of saying Google was an antitrust villain, and I was booed out of classrooms and off of stages — maybe not literally, but if they could do it to me through teaching evaluations, or "invite this guy back to the next iteration of this conference," I certainly made myself an unpopular fellow in a bunch of audiences. And didn't really care. I wanted to say what I thought was true, and figured eventually the world would come around to see it the way I did. Which was right.
It's amazing — the ultimate "I told you so" moment is when the United States copies something off my blog, which literally happens. I blog about something, and then antitrust regulators on a couple of continents sue Google years later over exactly that. Very satisfying in an ultimate I-told-you-so kind of way, and also totally worthless in terms of money in the bank.
There are specific instances where things really don't get the attention they deserve. Most on my mind in that regard is AppLovin. Because AppLovin isn't a household name — they don't have a B2C personality, they're just in a B2B context. I pitched the Wall Street Journal on an AppLovin story, and the Journal said, no, we don't cover those guys because they don't market to consumers. I said, I'm sorry, don't you cover finance? Companies that are traded on stock exchanges, and your readers as sophisticated investors want to know whether the stuff is what it's supposed to be.
Fortunately, Bloomberg — actually the same journalist who had the Phia story, Olivia Solon — had written a couple of things about AppLovin. So I pitched her, and she covered some serious AppLovin misconduct that I stumbled into last year. But no one else wanted to. It blew my mind that the Wall Street Journal not only wouldn't do it, but wouldn't do it for that reason, and would state the reason. They should have just told me "sorry, too busy," and I would have thought the better of them, versus what they actually told me.
Rob: I want you to talk a bit more about AppLovin. When I read some of the material, it reminded me of Cheetah Mobile — I was at Facebook at the time when they were removed from Facebook, and then later Google. Obviously I can't talk about the specifics directly, but what I can say is they disclosed that in their public filings. The initiation point for that was a report by a company about them allegedly stealing attribution credit from other companies, and then an article in BuzzFeed and so on that also talked about that.
So I do feel like the culmination works: deep research by folks who have an interest in this area, journalists who are very competent and have a good technical understanding, and companies then looking at the data, doing their own investigations, and holding companies accountable. We presume that's what happened in all of these cases. Can you talk about AppLovin and what you've seen, at least at a high level?
Ben: There are multiple aspects of AppLovin's business that are of concern. I have hypotheses about multiple parts of their business that I'm skeptical about, including attribution — maybe lead stealing, taking credit for other people's leads. But I couldn't prove any of that to my satisfaction, and haven't in the subsequent six or eight months made any progress on it.
Where I did make a lot of progress, and proved very much to my satisfaction, was looking at what's called an install helper: a relationship between the AppLovin code in the SDK of an app, typically a game, and some other piece of code that's preloaded on a phone or tablet or other device, typically by the carrier or the manufacturer. What happens is that AppLovin is able to use that preloaded, super-privileged piece of code to install stuff onto the user's device without the user agreeing to it.
So you're playing game A, up comes an AppLovin ad for game B, and next thing you know, game B is installed on your device — without you tapping, without you seeing anything in the Play Store. In some implementations they'll have a countdown: 5, 4, 3, 2, 1, we're installing it. And you say, wait, wait, wait, that's not how it's supposed to be. This is Android. It's super secure. I have to press the magic button, and only Play Store can show me the button. But they found a way around all of that.
So I went through their source code, which was a real heavy lift for me anyway — someone smarter than me could do it more easily. It was 600,000 lines of code, heavily obfuscated. This was compiled Java code — except Java is never really compiled, it's sort of pseudo-compiled. All the string identifiers got messed up, so the function names were turned to gibberish, and the variable names. But still, when they call an Android core function, I can see that. I had some AI that helped me; I had to check every step of the work to make sure it was right. Bottom line is I traced the execution stack from showing the ad through to installing the app, and put all the work on my website.
Bloomberg published it, but published it as a he-said-she-said. Edelman says they're doing this, and AppLovin says they always get user consent. I don't know what they meant by consent. If 5-4-3-2-1 is consent, there's going to be a whole lot of consenting going on once people find out that'll do.
And no one piled on. There's litigation about it that I'm not part of; they cite my website, which is nice, I guess. No other media publication jumped in to get to the bottom of it, to ask AppLovin: what do you mean, consent? Are you saying 5-4-3-2-1 is consent? Did you always do 5-4-3-2-1? Did you sometimes not do 5-4-3-2-1, and just install it in the background? I went through the code, so I can see all the forks and the different things it's capable of. Anyway, no one was interested. Maybe this podcast will be the thing that gets some ambitious journalist to want to get to the bottom of what happened. It was only last year. It's not time-barred. It's still very much in scope. Still very current.
Rob: Who would allow something like that? The handset makers would have some deal with the company to allow those pre-installs to happen? Is that like the old junkware on your PC, or is it something different?
Ben: I think it's kind of like that. Samsung and T-Mobile were the two big US names — Samsung obviously not based in the US, but widely known by American customers. They both had preloads on devices they were marketing to American consumers. In other countries, there are carriers pre-installing AppLovin software. It only takes that little preload for AppLovin to then be able to flip on all of this capability.
I never really was certain to what extent the carriers and manufacturers were victims here — that AppLovin had told them one thing and was doing something quite different — versus participants, happy to throw AppLovin under the bus but also happy to collect their rev share for as long as possible. I still don't know. Again, a good opportunity for a journalist to get to the bottom of it: call the people in T-Mobile business development and run it down. And so too for Samsung, and Oppo, and down the list. I gave the names, which I extracted from the code, because the code separately lists each of the companies AppLovin had a partnership with. So it's quite the source for journalists.
Rob: Speaking historically, carriers have been very happy to take large rev shares from very questionable business practices. I'm reminded of direct billing 10, 15 years ago, where people were being told "get 10 free ringtones," "get 10 free crushes," or whatever the social media dating nonsense was, and then it starts billing them $10, $15, $20 a month. Some of those practices are worse now, but in some cases they've been curtailed via various lawsuits. The whole direct billing space was always a nightmare, and kind of showed the willingness of some of these companies to just take the money.
Ben: Right. Carrier billing, where customers typically didn't understand that they could dispute those transactions — maybe even more easily than their Fair Credit Billing Act disputes with credit card charges. You could dispute a carrier direct billing charge pretty easily and it would just go away. But some people didn't know that. They thought, oh my goodness, if I don't pay my T-Mobile bill, I'm not going to have T-Mobile service and my phone number won't work anymore. So I guess I have to pay. They swindled me fair and square.
There was amazing litigation. And I guess I immediately jump to Google. I wrote about this a decade-plus ago, but Google was deep in bed with some of these companies, for whom the main expense was paying Google for the ads to sucker the users in. So Google was sort of a majority partner in some of these companies, extending credit to them as an AdWords advertiser. They could be trusted to pay their bill — but why not extend the guy some credit so we can ramp up even faster? It was just insanity to me. Not a fan.
Rob: That's frustrating. Are there things you'd recommend from a policy perspective to create more accountability for these practices? Often there isn't a private right of action; some of these companies have click-wrap terms that require arbitration. There's a lot of nonsense on that side of it too — more than we have time to get into in depth. But what would a series of accountability steps look like that could help consumers in these cases?
Ben: First, the click-wrap stuff — the class waiver and arbitration clauses — those are a disaster and an embarrassment to the American legal system. What would Ben Franklin say? I love that guy. I love his writings, and it's a good guidepost to ask yourself what he would say. He would not recognize this as any judicial system he wanted to be a part of.
But separately, it's interesting to think about who that doesn't bind. It doesn't bind the attorney general of New York, or California, or Oklahoma. All of those states have serious, ambitious attorneys general who want to do good work, want to see their name in headlines, want to do right by the citizen taxpayers of their respective jurisdictions.
I would like to see one of those attorneys general pursue AppLovin. Why the heck not? You're putting junk onto my constituents' phones with 5-4-3-2-1, or maybe not even that, and you are profiting from it. We want the money back. Why don't you give each user the money you got — 100 cents on the dollar, plus interest at the prevailing rate? If you charge someone $6 to put something on Rob's phone without Rob agreeing to it, give me, the attorney general of Oklahoma, the $6, and I'll find Rob and give it to him. That would be amazing. And it seems like a great opportunity. It's not that any particular attorney general wants to do it, but with 51 of them in the country, someone should want to do it. And the lead is right there on my website, ready for them.
Many years ago I used to get invited to conferences of attorneys general to give them leads. And I really would be giving them leads, and they'd bring some of the cases. We had some good cases and some good times there. I'd love to be back in the thick of that. Maybe I'm starting to get back into the leagues where my ideas and my leads are worth people listening to.
Rob: We're definitely going to include that link to your website in the show notes. Hopefully folks are listening and reading — or having their AI read our AI-generated transcript. That's okay too; we'll take that.
I guess I'll end with: any advice to founders or people building technology in this space, to stay clear of your investigations and do things the right way?
Ben: It is really tough. When I was teaching MBAs, I was teaching during a period of just massive law-breaking — sort of the rise of Uber and Airbnb, which was nuts. To see Uber, which was so totally illegal, coaching the drivers: why don't you have your passenger sit in the front seat, so it looks like a friend rather than a paying customer? That was an actual paid message from an Uber city manager to all of the drivers in his jurisdiction. I have a copy of the message preserved on my site to this day.
It was hard for me to teach MBAs, because a lot of them were starting to have ideas that were totally illegal. I vividly remember one student who came into my office — an Indian American student — who said, you know, the Indian American food you get from a restaurant is just not the same. I know a bunch of Indian grandmas who are here. They could cook. You just go to their kitchen and they hand you the food in a bag from the front door. And I say, wait, wait, wait. They're here on tourist visas. They're cooking in a house — it's not a commercial kitchen. Do they have training on food safety? Are you going to pay sales tax? There's a bunch of stuff.
And the kid looks at me like: why would I possibly follow any of those laws? I'm just going to do an Uber and Airbnb and do whatever the heck I want, and no regulator will chase me fast enough to stop me. And it was hard to tell him he was wrong, because he wasn't exactly wrong. He was sort of wrong, at least — but not 100% wrong. So it was very frustrating for me.
I would love to tell founders that the only path is the straight and narrow. Actually, I think there's a certain amount of cheating that a certain set of companies can get away with. And for better or worse, if I was advising a friend or a student, I'd probably tell them: you can cheat some companies some of the time, and you'll probably get away with it. Doesn't mean you'll be proud of it. Doesn't mean you'll want to tell your grandchildren about it.
And the risk is extraordinary. The risk can explode in your face in ways that are kind of hard to anticipate. I don't think the Phia founders anticipated that this particular set of violations would explode on them in the way it has. With the benefit of hindsight, obviously everyone can see where they were vulnerable. God knows I've made some mistakes too. I don't really like monsters in my closet. I don't see why any founder should want to have monsters in their closet. The straight and narrow is awfully tempting, if you ask me.
Rob: I enjoyed talking to Tom Wright a few episodes ago. He's a great journalist and he sees a lot of this stuff up close, and he's very frustrated by the "you can just do things" mentality, where people are pointing to possibly criminal, illegal behavior as something to be celebrated. I do not celebrate it either. And I agree — the risk is much higher than people realize.
But I think that's a great place to leave it. I have a feeling, Ben, that we'll be talking again on this podcast. It may take a while for the long arm of the law to move, but I'm really glad you spent the time to chat and catch up about this stuff with me.
Ben: Well, thank you. Thanks for your interest. Great to be back in touch. It's been too long.
Rob: It has. Thanks, Ben.