Live data from Hacker News

ISP Advertisement Injection - CMA Communications

zmhenkel.blogspot.com

1–10 of 81 posts

Re: ISP Advertisement Injection - CMA Communications

#3
A picture speaks a thousand words here; the author did a great job supplying plentiful screenshots to emphasize how wrong this practice is. I read about this in the past but wasn't too moved until I scrolled through all those screenshots and thought, wow, this is not good for ad publishers OR brands OR anybody. This is only good for the greedy ISP.

Re: ISP Advertisement Injection - CMA Communications

#5
I posted about this on reddit a few weeks ago[0]. Someone in the thread said they had contacted the Better Business Bureau, but I'm not sure what their process is or how far it's gotten.

There has also been a short email thread in which their official response is this:

> Mr. [redacted],

> CMA is in the process of trying to find ways to drive income from our internet service in new ways. These new ways would allow us to expand our service offering and maintain the cost of the current residential and business internet services.

> We’ve been testing a new service which allows us to overlay / insert some local advertisement on certain web pages. A company called Route 66 is our partner. Right now, you’re barraged with a lot of internet advertising, popups, etc… This has become part of the internet experience. At the core, we’re simply trying to better customize some of this experience. And possibly give you access to highly relevant local advertising.

> Having said that, I’ve recently become a little more familiar with what some of these ads look like and how they operate. I will concede that I’m not sure they strike the perfect balance between being information and non-invasive. Like I mentioned, we’re involved in a test and the feedback we’re getting from the test is helping us to refine and improve how (or if) we’ll continue here. So I’m stopping short of saying that we’ll be ceasing this type of internet advertising experiment. But I do want you to know that your feedback has resulted in the beginning of a pretty intense internal dialogue.

> Thanks for your feedback.

> [redacted]

> CMA Communications

It's absolute insanity and a major breach of trust that they'd inject their own content into webpages I visit. I'm permanently using a remote VPN for all outgoing traffic through CMA.

[0]: Didn't know exactly where the post belonged, so I put it in /r/self: http://www.reddit.com/r/self/comments/19zhl6/my_isp_is_injec...

Re: ISP Advertisement Injection - CMA Communications

#6

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

You shouldn't have to encrypt your data to stop your ISP from actively 1) scanning and 2) corrupting it.

What is the FCC good for?

Re: ISP Advertisement Injection - CMA Communications

#7

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

We hope ads/no-ads arms race would end there. But I could easily see some unscrupulous/greedy ISPs then resorting to setting up SSL proxies to MITM your ostensibly secure traffic, as some private organizations (schools, corporations) already do.

Re: ISP Advertisement Injection - CMA Communications

#8

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

Actually, the "HTTPS Everywhere" plugin [1] for firefox and chrome is an incomplete solution. The reason is simple; not all sites support HTTPS, so the plain HTTP-only sites are still vulnerable.

Injecting a script into insecure HTTP is just one of many abuses possible by ISP's. Replacing images on the fly is another. Recompressing (degrading) images/video is another. Messing with DNS responses is another, and so on...

A far better working solution is to use a VPN service since when it's configured correctly, it will encrypt all traffic passing through your ISP. Of course, this is really just moving the trust problem, rather than solving it, but at least using a VPN service makes it your decision who to trust. I use Tunnelr.com [2] since by reputation, similar interests, and years of traded emails, I know the people who run it.

[1] https://www.eff.org/https-everywhere

[2] http://tunnelr.com

Re: ISP Advertisement Injection - CMA Communications

#9

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

You shouldn't have to encrypt your data to stop your ISP from actively 1) scanning and 2) corrupting it. What is the FCC good for?

Indeed. What's with the Internet being a set of tubes?

Re: ISP Advertisement Injection - CMA Communications

#10

HTTPS everywhere would solve this, and the Comcast Javascript injection - I wonder how many more people will deploy things like this before that happens?

It would solve it for many sites, but there are plenty that don't have full https support (and some that have none at all)
Post reply on HN