2 ms·
> Can they legally do this? You should ask lawyers in your country about that. > Isn't my browser sending each visited-domain's cookies to my ISP now? Yes, b
by selectnull 10y ago
> Can they legally do this?
You should ask lawyers in your country about that.
> Isn't my browser sending each visited-domain's cookies to my ISP now?
Yes, but that's not different even if they didn't hijack your sessions. Everything goes thru your ISP, so in any case, they see everything (not just cookies) that goes thru http.
> Doesn't this pose a security risk?
Yes.
> I have no idea whom to complain to.
As first measure, complain with those sites and ask them to implement and enforce TLS and move all traffic to https. That way your ISP doesn't see your traffic and can not MITM you. Then, complain to your ISP or even better find new one (after you complained to them, vote with your money).
Btw, TLS is really first solution (but not the only and last) to this (and many other) problems on the web.