Live data from Hacker News

I fought my ISP's bad behavior and won

erichelgeson.github.io

31–40 of 115 posts

Re: I fought my ISP's bad behavior and won

#31
post #19

If your ISP and/or Aspira were making any significant amount of affiliate commissions, I would be surprised if the merchants do not take action against them for fraud. This sounds like the same behaviour that Shawn Hogan got in trouble for with cookie stuffing http://en.wikipedia.org/wiki/Shawn_Hogan

I chatted with a company that investigates affiliate fraud, they may have a blog post up after the new year about this. Will submit it if/when they do.

Re: I fought my ISP's bad behavior and won

#32
post #19

If your ISP and/or Aspira were making any significant amount of affiliate commissions, I would be surprised if the merchants do not take action against them for fraud. This sounds like the same behaviour that Shawn Hogan got in trouble for with cookie stuffing http://en.wikipedia.org/wiki/Shawn_Hogan

Ahh... DigitalPoint, those were the days.

Re: I fought my ISP's bad behavior and won

#33
post #3

Very nicely done: reporting this as abuse to the companies offering these affiliate programs seems quite appropriate, and it sounds like they reacted appropriately. One person complaining to an ISP is noise; one person making an abuse report is all it takes to get that ISP banned from the affiliate program.

Thanks! I was in a state of hopelessness for a week or so till I had that idea.

I was very impressed with your firm but polite tone! We'll done.

Re: I fought my ISP's bad behavior and won

#34
The cynical side of me says that the ISP is just going to redirect the author's traffic to the "pure" DNS server in the future (even when he or she directs traffic to the main one) unless they get in serious enough trouble with one of the companies this first time.

If anyone wants to do this in the future, I'd recommend just sending affiliate abuse emails with no notice to the ISP. Also, the future person may want to revise the [2] script to scan in a more surreptitious manner (change the order, add delays, simulate legit web traffic, etc).

Re: I fought my ISP's bad behavior and won

#35
post #13

One a slightly related note, in Chrome extensions, it's possible to redirect DNS requests on a per-URL basis. This is how Media Hint works to allow non-US Netflix users access the US version of the site. I'm surprised we haven't seen similar behaviour from Chrome extensions. I'm sure it would be caught eventually, but this isn't exactly something that people tend to look for, so it would take a while for people to ca…

> I'm surprised we haven't seen similar behaviour from Chrome extensions The "Window Resizer" Chrome extension got a silent update a few weeks ago. It rewrote all the links on Google search result pages to point to a proxy that added affiliate links where possible.

Over the holiday I did usual, fix/clean my grandmother's computer. She's been using chrome because I explained to her how much safer it is.

I did a google search and realized something wasn't right. Uninstalled all the crapware apps that wormed their way in. And then I looked at the chrome extensions and low and behold there it was, more crapware.

I removed them and they re-added themselves. I had to run spybox s&d to remove it completely.

Moral of the story: chrome extensions are in some ways worse than toolbars.

Re: I fought my ISP's bad behavior and won

#36
Interestingly, you might have benefitted more from keeping quiet about this. While the original retailers are losing money through this, you aren't really affected negatively by them doing it. In fact, with this additional revenue source, they might be able to support thinner margins on their broadband charges, saving you some money. You did the morally correct thing, but perhaps at a potential personal cost.

Re: I fought my ISP's bad behavior and won

#37
post #6

Earlier quoted context omitted.

I think so too, though CDN's will mess with the results a bit. It would be nice if DNS had a way to sign/validate/somehow know the record you got was correct. Especially on the apex record as it can happen before ssl.

It's interesting no one brought up DNSSEC[1]. Has anything happened there since 2010? 1. http://en.wikipedia.org/wiki/Domain_Name_System_Security_Ext...

DNSSEC is great in theory, but after three years I still haven't deployed a live instance.

It is cumbersome to implement and maintain, requiring co-operation of registrars and frequent key regeneration.

It is also very, very chatty and imposes a considerable processing burden on the first-hop DNS resolver.

We need a signed DNS solution that isn't DNSSEC.

Re: I fought my ISP's bad behavior and won

#39
post #28
post #12

Earlier quoted context omitted.

Do you have a link to a usable encrypted DNS solution? I searched but didn't find anything actively used, but a lot of proposals.

DNSCrypt http://www.opendns.com/technology/dnscrypt/ This works well for me. But I have found that this is the kind of thing where an expert can pop in and say "have you considered risk X with solution Y?" and leave me dumbfounded. So use at your own risk.

Better page: http://dnscrypt.org

Re: I fought my ISP's bad behavior and won

#40
As a ISP when we were considering using Aspira they claimed that no referral tokens would be replaced and that the only behavior was injecting a popup coupon window.

I decided not to proceed with it because it seemed like a support nightmare and tampering with non-malicious subscriber traffic crosses a line.

Their marketing affiliates (such as Cash4Trafik) are always reaching out to CEO types at small ISPs and the money they bring (particularly when you are small) can be hard to pass up.

Post reply on HN