Live data from Hacker News

ISP Advertisement Injection - CMA Communications

zmhenkel.blogspot.com

11–20 of 81 posts

Re: ISP Advertisement Injection - CMA Communications

#11
Immediately cancel your account and switch. If you are forced to use them as an ISP due to municipal/geographical regions complain to your city manager.

The only way to slap these companies back into line is with your wallet. If you can't do that then a couple complaints to the city manager can go a lot farther than you think, especially in smaller areas where there isn't a lot of support staff in city hall.

Re: ISP Advertisement Injection - CMA Communications

#12
This was inevitable.

That's why I bought Google stock after they got into Android, as Android makes it possible for Google to now step in & protect against the MITTM attacks by ISP's blocking their ads. The OS gets the final word before it displays content to the user & it can detect & block these.

Now, they just have to deploy the fix to Android...

Re: ISP Advertisement Injection - CMA Communications

#13

Immediately cancel your account and switch. If you are forced to use them as an ISP due to municipal/geographical regions complain to your city manager. The only way to slap these companies back into line is with your wallet. If you can't do that then a couple complaints to the city manager can go a lot farther than you think, especially in smaller areas where there isn't a lot of support staff in city hall.

Considering just how big the outcry was over ISPs delivering advertisements instead of an NXDOMAIN response, and how many ISPs are continuing to mess with DNS over ten years after the execrable practice started, I haven't got much faith in the power of the market. Has there been just one ISP that stopped hijacking DNS over customer complaints?

Re: ISP Advertisement Injection - CMA Communications

#14

This was inevitable. That's why I bought Google stock after they got into Android, as Android makes it possible for Google to now step in & protect against the MITTM attacks by ISP's blocking their ads. The OS gets the final word before it displays content to the user & it can detect & block these. Now, they just have to deploy the fix to Android...

And what happens when Google are the one doing the MITTM attack?

It all comes down to who do you trust.

Re: ISP Advertisement Injection - CMA Communications

#15

Immediately cancel your account and switch. If you are forced to use them as an ISP due to municipal/geographical regions complain to your city manager. The only way to slap these companies back into line is with your wallet. If you can't do that then a couple complaints to the city manager can go a lot farther than you think, especially in smaller areas where there isn't a lot of support staff in city hall.

Considering just how big the outcry was over ISPs delivering advertisements instead of an NXDOMAIN response, and how many ISPs are continuing to mess with DNS over ten years after the execrable practice started, I haven't got much faith in the power of the market. Has there been just one ISP that stopped hijacking DNS over customer complaints?

Sonic.net ftw! Not available everywhere but great ISP who stands up for a free and open Internet.

Re: ISP Advertisement Injection - CMA Communications

#16

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

We hope ads/no-ads arms race would end there. But I could easily see some unscrupulous/greedy ISPs then resorting to setting up SSL proxies to MITM your ostensibly secure traffic, as some private organizations (schools, corporations) already do.

That's a good way to get yourself the CA death penalty.

Re: ISP Advertisement Injection - CMA Communications

#17
Technically, isn't this copyright violation? People who inject ads into a page are creating a derived work without permission of the rights holders. I'm sure Apple didn't okay that addition to their HTML.

It would be interesting to see a lawsuit along those lines.

Re: ISP Advertisement Injection - CMA Communications

#18

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

We hope ads/no-ads arms race would end there. But I could easily see some unscrupulous/greedy ISPs then resorting to setting up SSL proxies to MITM your ostensibly secure traffic, as some private organizations (schools, corporations) already do.

They'd have to have their certs installed on your computer, or be an existing CA. Schools and corps (including the one I work for) can do this because they have admin control over destination machines.

Re: ISP Advertisement Injection - CMA Communications

#19

Earlier quoted context omitted.

Considering just how big the outcry was over ISPs delivering advertisements instead of an NXDOMAIN response, and how many ISPs are continuing to mess with DNS over ten years after the execrable practice started, I haven't got much faith in the power of the market. Has there been just one ISP that stopped hijacking DNS over customer complaints?

Sonic.net ftw! Not available everywhere but great ISP who stands up for a free and open Internet.

Looks like Sonic only provides service in CA.
Post reply on HN