5 ms·
The EFF explains how this was done here: Back in 2011, several ISPs were caught red-handed working with a company called Paxfire to hijack their customers’ se
by quincyla 10y ago
The EFF explains how this was done here:
Back in 2011, several ISPs were caught red-handed working with a company called Paxfire to hijack their customers’ search queries to Bing, Yahoo!, and Google. Here’s how it worked.
When you entered a search term in your browser’s search box or URL bar, your ISP directed that query to Paxfire instead of to an actual search engine. Paxfire then checked what you were searching for to see if it matched a list of companies that had paid them for more traffic. If your query matched one of these brands (e.g. you had typed in “apple”, “dell”, or “wsj”, to name a few) then Paxfire would send you directly to that company’s website instead of sending you to a search engine and showing you all the search results (which is what you’d normally expect). The company would then presumably give Paxfire some money, and Paxfire would presumably give your ISP some money.
In other words, ISPs were hijacking their customers’ search queries and redirecting them to a place customers hadn’t asked for, all while pocketing a little cash on the side. Oh, and the ISPs in question hadn’t bothered to tell their customers they’d be sending their search traffic to a third party that might record some of it.
Source: https://www.eff.org/deeplinks/2017/03/five-creepy-things-your-isp-could-do-if-congress-repeals-fccs-privacy-protections https://www.eff.org/deeplinks/2017/03/five-creepy-things-you...
- koolba 10y agoOkay that sounds completely illegal and the exact definition of digital hijacking. Any type of modification of the packets themselves outside of dropping them for network control is a clear violation in my book. I don't see that working for connections over SSL. I wonder how the companies that operate these questionable "services" deal with the rapid rise of SSL the past few years.
- yebyen 10y agoI think this type of attack being described was (is) actually done by hijacking requests that should have returned DNS NXDOMAIN. You tried to visit a URL that did not exist, but your DNS server failed to make that clear in the standard way to your browser, and now your traffic is sent somewhere else, instead of sending you to the familiar (or ugly, they might argue) NXDOMAIN browser error page. So there aren't really any packets being modified, since you already get your DNS from your ISP. They're just returning bad information to requests that your browser naturally had directed at them.
- koolba 10y agoThe NXDOMAIN hijack isn't as bad as this. It involves replacing the response from the resource you requested with the ISPs preferred response. It can happen either through DNS hijacking (nslookup for google.com goes to isp-fake-google.com) or they can just sniff all the traffic and MITM HTTP traffic for "GET /q=?" with a "Host: google.com". In either case they send you to whatever they'd like rather than the original request (and of course sell the data that User X searched for Y).
- resfirestar 10y agoNXDOMAIN hijacking is closely related, but Paxfire had another service (at least in 2011, when fewer searches were done over SSL) that was sending all traffic directed to the major search engines through its proxy servers. https://www.eff.org/deeplinks/2011/07/widespread-search-hijacking-in-the-us https://www.eff.org/deeplinks/2011/07/widespread-search-hija...