8 ms·
Am I hacked? Oh, it's just Vodafone
- Klathmon 11y agoAnd people still fight "HTTPS everywhere"... Secure should be the default with insecure being left for special cases that need it.
- r3bl 11y agoIf by "HTTPS everywhere" you mean the browser extension, that isn't very helpful since a huge chunk of websites that have properly implemented HTTPS turn it on by default. If by "HTTPS everywhere" you mean enabling HTTPS on all websites, I could not agree more. In any case, I haven't heard of a single source fighting against this switch. Some sources please?
- Klathmon 11y agoI mean the latter. And it's generally random web developers who are against HTTPS on everything. Generally the reasons are: * Cost (this one is going away hopefully) * Performance (tls is too slow!) * CPU/Memory overhead on the server * What they are showing doesn't need to be secured anyway. I don't really agree with any of those points, but that is what I hear when I bring it up.
- rdancer 11y agoShould have [2012] somewhere in the title. This is older than dirt, in Internet years.
- lorenzhs 11y agoI noticed this as far back as 2009 on Vodafone Germany
- rnhmjoj 11y agoI use H3G on a tablet: every time I reconnect (after the connection drops, when I reboot or switch from wifi to cellular network) the first http request is somehow redirected to a shitty H3G website full of ads. This is not only annoying but also manages to break everything using an internet connect. For example it overwrites bookmarks, reading list entries, applications fail to load. Anyway injecting scripts is crazy. Are they still doing it?
- pavel_lishin 11y agoHow does it overwrite bookmarks?
- jackweirdy 11y agoIf a user has a bookmark for http://a.com/ http://a.com/, and the ISP redirects with a 301 Permanent Redirect to http://isp.net/ http://isp.net/, the browser will rewrite a.com to isp.net.
- pavel_lishin 11y agoHuh, interesting - what browser is that?
- ryanlol 11y agoLike, all of them?
- pmontra 11y agoMmm, that's a browser that attempts to be smart at bookmarks management. I have a tablet with a SIM of that company. I'm using Dolphin on that tablet and I get redirected. However Dolphin doesn't rewrite my bookmarks. Maybe it's not a 301 redirect or maybe Dolphin is (luckily) not so smart.
- 11y ago
- ubercow13 11y agoYes this is why I left Vodafone. They aggressively recompress images so that they look noticably awful, including in phone apps where resources are loaded on demand, and there's nothing you can do about it bar using a VPN. O2 are exactly the same and all the virtual network operators using either network are the same.
- kuschku 11y agoT-Mobile is known in Germany for having done the exact same.
- patates 11y agoThey also remove comments from your markup. That removes the possibility of progressive enhancements with, say, knockout.js which would most easily rely on comments (unless you're using https, which you should).
- huuu 11y agoUsing comments for programming is very bad practice. I don't know knockout but that just sounds bad.
- petemc_ 11y agoI'm not sure this is still the case. I can recall it happening a long time ago but have not noticed it recently, at least since I started using their 4g service.
- akerro 11y agoMore reasons to encrypt everything and start HSs.
- codezero 11y agoSprint shows very compressed images on mobile as well. I had assumed they compress the images on the wire rather than injecting JavaScript but I didn't check. Maybe I should.
- compbio 11y agoVisit http://1.2.3.50 http://1.2.3.50 to disable this image compression for your device. Add "Cache-Control: no-transform" to your headers to disable image compression for all your site's visitors. Web devs should make sites that work without javascript, so that turning on NoScript is also a solution. The bmi.js injection may look a bit nasty, but it is there to save bandwidth for users who are on a bandwidth budget. Vodafone would profit from higher bandwidth usage.
- voltagex_ 11y ago1.2.3.50 is within the "APNIC Debogon Project" range. I don't understand using these kinds of ranges as internal IPs - Vodafone controls the DNS servers for these devices so just make it optout.voda and resolve that somewhere that you actually own.
- iofj 11y agoWell it's pretty much the addresses you start using when you've run out of IPv4 addresses everywhere else. A very popular example of this is 100.64/10, but one can find little bits here and there. Plenty of providers don't just use that range but 1/8 is pretty safe to use. There are even posts on networking mailinglists about tests for using the multicast ranges (multicast doesn't work* anyway and is now widely considered a "never gonna happen" design). Leave 224.0.0.0/24 alone and you can pretty much use the rest of 224.0.0.0/4. Also, most of broadcast is fine to use on most networking equipment. * of course, locally within a network it does work for a very small number of multicast streams (certainly doesn't work for 2^28 multicast streams as designed, so in ipv6 they upped the number of available multicast channels to 2^120)
- pravj 11y agoI remember 'Airtel' doing something similar in India, in May-June. Here is a story about the expose published in Hindustan Times, http://goo.gl/FX31Of http://goo.gl/FX31Of
- junktest 11y agohttp://www.medianama.com/2015/06/223-airtel-says-it-had-nothing-to-do-with-the-legal-notice-sent-to-thejesh-gn/ http://www.medianama.com/2015/06/223-airtel-says-it-had-noth...
- binwiederhier 11y agoThis is why I switched carriers, too. I had the same "Am I hacked?" moment a while back. Thanks for posting details!
- mosselman 11y agoDeep packet inspection is forbidden in the Netherlands as far as I know. Is there anyone who can confirm both this and if Vodafone is doing this in the Netherlands regardless of this, alleged, legal restriction?
- mosselman 11y agoAs rdancer pointed out this article is older than the internet and I, and probably some others, hadn't noticed. Still interesting, but not very.
- TrevorJ 11y ago4 years ago is hardly 'older than the internet'.
- tempestn 11y agoSince it's an article about the internet, I'm guessing parent realizes that and was exaggerating for emphasis.
- TrevorJ 11y agoI think that's accurate. I just get tired of the culture of newness. Knowledge who's age could best be described in months gets derided for be old and irrelevant.
- 0898 11y agoO2 does the same thing – with almost the same messaging ("Shift+R improves the quality of this image").
- batuhanicoz 11y agoLast time I've saw this behaviour (using Vodafone Turkey network) was not more than 6 months ago. Haven't checked since, they could still be doing this. So it's not "older than the internet".
- asztal 11y agoThe company I work for had problems with users who couldn't install our ClickOnce-deployed application. It turned out that they were using a 3G dongle which modified one of the JPEG files in-flight such that it didn't match the hash in the application manifest. We moved to HTTPS anyway so thankfully this stuff is more or less history.
- Buge 11y agoGreat, the blog post is not served over https. Do we actually want to fix the problem?
- alister 11y agoAs of 2 months ago Bell Canada has begun intercepting and modifying web traffic as well. Back in October, I started receiving notifications that said, “You've reached 50% of your Internet usage”. In the past these notifications would arrive by email or I could check my usage by logging into the Bell site, either of which is entirely acceptable. However, in October, these notifications began to appear embedded into web pages that I was browsing, specifically in web pages that don't belong to Bell and have nothing to do with Bell. I don't care that they provide a way to disable this, or that somewhere in Bell’s terms and conditions I may have ostensibly agreed to this action. They shouldn't be doing this any more than the post office should be tearing open my letters to insert notices that they want me to see. I wrote a complaint to Bell (and canceled my phone and Internet with them!) but they didn't reply. I also wrote to the CRTC and the Privacy Commissioner. The Privacy Commissioner said it's not in their jurisdiction. I'm still waiting to hear from the CRTC.
- Vexs 11y agoSuddenlink does the same thing-ish. Sometimes I get a popup that says "service outage incoming at XXX" at the top of the page- I ended up figuring out there was a checkbox for that sorta stuff in the account options tab. Similarly, it redirects non-websites to their own search engine that never seems to go away. (ex: igrj.43 redirects to http://search.suddenlink.net/index.php?origURL=http%3A//igrj.43/&r=&bc= http://search.suddenlink.net/index.php?origURL=http%3A//igrj...) Again, not terrible, but really invasive to my mind. As it stands, they're basically the only supplier near us (sub-rural texas), so I just got a VPN.
- gdwatson 11y agoIt's not unheard of for ISPs that typosquat the whole Internet like that to provide a second set of DNS servers that perform correctly for those who know how to use them. Mine does.
- hellbanner 11y agoWho's your ISP?
- sharjeel 11y agoSomeone recently noticed it on UFone (Pakistan) too: https://www.i.com.pk/ufone-3g-is-injecting-popup-ads-into-your-normal-browsing/ https://www.i.com.pk/ufone-3g-is-injecting-popup-ads-into-yo...
- markdown 11y agoVodafone Fiji used to do this over their 3G network, but that changed when they started serving over 4G 2 years or so ago. What's worse is that the script changes the content of the alt attribute for all images to something like (off the top of my head) "Press CTRL+A to load full-sized images". They did respect no-transform though, so I made sure all my sites had that.
- deleted 11y ago[deleted]
- ozim 11y agoSo https and content security policy should be enough to mitigate this kind of stuff or am I wrong? If they would amend csp headers and inject stuff I would be worried but still there would be https for the rescue.
- profmonocle 11y agoYep, ISPs can't do stuff like this to HTTPS traffic. This is one reason some people are advocating HTTPS for all sites, not just sites containing sensitive data.
- venomsnake 11y agoAren't they violating CFAA? Committing wire fraud by substituting the traffic?
- onslauth 11y agoThe system in question is developed by a company called Byte Mobile, which was bought by Citrix. Normally all port 80, and 8080 traffic are redirected to the system, and then rules are run to determine what happens to the traffic, and or code to be injected into the page.
- onslauth 11y agoSo let me add some more detail. The system is used to help reduce bandwidth, as well as including a better TCP algorithm for use over the radio links, to help cut down lag and retransmissions, because the radio links are notoriously bad, and the standard algorithm doesn't quite cut it. The system will actively try to down sample both images and video to help reduce bandwidth usage. In the case of video, it also tries to limit the buffered video to no more than X seconds ahead. And finally, it is also big cache, and it tries to keep the most requested content locally. One of the new features is the ability to 'guess' what video is being viewed inside a HTTPS stream and try to cache it too. As mentioned above with regards to the Canada telcos inserting iframes or content regarding their data usage and caps, the system can inject any content into the HTML page if it is provided over HTTP. They do this because normally they have no way to contact customers that have tablets, or 3G modems / dongles, to alert them of limits or just to be able to contact them.
- tempestn 11y agoHow could they not have any way to contact their customers? You need to provide contact information when you sign up for a data plan, don't you? Even if you accept that the only way for them to contact their users is via their data connection (which, again, doesn't make sense,) there are far less intrusive methods than injecting content into existing pages. For instance, they could send the user to a separate notification page, perhaps with a helpful link to the resource that the user was intending to browse to. No need to mess with (or see) the contents of any pages.
- onslauth 11y agoThey very possibly can do all of the above. However you have to understand how a lot of the cellular operators function. They don't build much of the systems in house, but buy from large companies like Ericsson, Huawei and so forth. Therefore all their functionality is controlled by those companies. That being said, the cellular operators don't like to hand out contact information about their customers. All billing is normally done via a MSISDN to a single system that stores a customers credit, and records all billing information. It does not contain any customer details. I have actually seen a different approach, wherein any messages going to a MSISDN that has been identified as a tablet or modem / dongle, will be redirected to another MSISDN as a SMS or an email address, depending on the customers preferences. All these details were stored in another database.
- joenathan 11y agoJust left my host for a similar issue, Arvixe shared Linux server. One of the shared users apparently installed some utility called siteapps, which some how effected my side of the server, not certain what it all does but it started showing 'badges' on all my pages saying 'this site has been optimized by siteapps'. I found a way to turn that off in cpanel but the siteapps was still injecting JavaScript code into all of my pages. I could not see any visual changes to the pages but found this unacceptable. I tried to contact support only to find out the company had been sold recently and the new owners saw fit to fire all the support staff and do away completely with telephone support for technical issues. Tried chat and after waiting, no joke, three hours for someone to show up in the chat was told that the problem was with my code. Even after telling the agent I could upload a blank page and the code would be injected into the page. Long story short, I am now hosting on my own server. Now looking for a good host I can point my customers to, one that won't try to nickle and dime them like godaddy.
- babuskov 11y agoI had great experience with Hurricane Electric. SSH access, servers without I/O bottlenecks. There's no cPanel or other crap pre-installed, so it turns away beginners and inexperienced developers who would write crappy unoptimized code that would take too much system resources. And their backbone connectivity is amazing. https://www.he.net/web_hosting.html https://www.he.net/web_hosting.html Isn't cheap, but this is the best shared host I used until I got a bunch of my own dedicated servers.
- bearbin 11y agoI've used NearlyFreeSpeech.NET for quite a few years now. It's not a cPanel host, but it's actually very easy for beginners to get started with. It's also very flexible and they have some really cool features. If you're going to use a shared host, you should use NFSN IMO.
- mort96 11y agoFor $5/month, you can get a pretty great VPS at digital ocean; 512MB RAM, 20GB SSD, 1Gbit/s bandwidth with 1TB/month trabsfer, giving you root access to your own server. You also get your own IP address, instead of sharing IPs and using virtualhost hacks like those web hosts do. Been using them for a while now, works really well.
- sdoering 11y agoHow can this even be legal. How can a ISP decide on the content quality, I would like to receive. Do they next deem words like 'anti-government', 'Democrats' or sites critical of the government too traffic-heavy to deliver but instead show a "cleaner" version of the world? I as a hobby web-dev and photographer like my images to be delivered in the exact quality, I put them on the server. So the Vodafones or O2s of this world mess with my intended design. As a user I want to experience the web with best image quality, not censored (right now in terms of quality) crappy versions of these images. This paternalism sadly is not felt by the majority of people out there and will never lead to 'uprising' (in loss for a better word). Be it done by cooperations or be it done by governments. We will see more of that in the future and I have lost believe in being able to tell others, not that tech-savvy why this is not good. They nod their heads, but it does not register. Sadly so.
- hartator 11y agoI wonder what country this is? France, Germany?
- lis 11y agoBased on the other content: Netherlands.
- thomseddon 11y agoSSL. That is all.
- tikums 11y agoVodafone's also actively pushing for "network management" (read, MITM) for HTTP/2. Previous discussion here: https://news.ycombinator.com/item?id=9422311 https://news.ycombinator.com/item?id=9422311
- golergka 11y agoThis is awful. But to understand why and how awful that is, you need to think of HTTP traffic as private letters. Unfortunately, because HTTP traffic is usually associated with access to public websites, a lot of laypeople think of it as _public_, instead of _private_ communication. Opening NYT website is more like browsing TV that having a correspondence with a trusted friend for them. This is the real reason shit like this happens. Would you expect Vodafone to modify contents of your private facebook messages or emails, if they had the chance? Of course not; the same suits that authorized this system would scream about user's privacy and never greenlight it. However, _this_ system, to an average user, and average manager, doesn't seem the same. If you imagine a high-level user story description for it, it won't read "new code is injected in private HTTP traffic", it likely was "make pictures download faster in 3G". Yes, they describe the same awful shit that shouldn't be happening — but the first description screams PRIVACY VIOLATION, while the second seems like a very good thing to do for the sake of the customers. Never attribute to malice that which is adequately explained by stupidity. And if you want to fight this, don't fight it as you would fight malice. Fight as you would actually fight stupidity.
- darkhorn 11y agoWhen you reach your download quote TTnet, biggest in Turkey, shows a notification in your first HTTP visit. It completely removes the original content. So you lost your POST for example. They even had a user tracking for advertisment. It constantly asked in StackOverflow (since most of the time I'm there) whether I want to join "track my online activities". Well, here exist laws too, and they are in sction but it lacks a good philosophy. No wonder they (Turkey) are between Europe and Middle East, both phisicall and mentally. Edit: I should note that TTnet's big part is now owned by Arabs. That's why they don't care much.
- WrofNiraid5 11y ago> In a little while we'll all be on TOR. Tried that. Can't get past the impossible Cloudflare captcha.