5 ms·
Does changing your DNS modify this behavior? I had some similar issues with Cox in DC, and switching to run everything through 8.8.8.8 resolved the issues. It a
by RickS 7y ago
Does changing your DNS modify this behavior? I had some similar issues with Cox in DC, and switching to run everything through 8.8.8.8 resolved the issues. It also resolved a problem with CenturyLink in Seattle where for whatever reason I couldn't speedtest through fast.com.
- irq 7y agoCurrent Comcast user here, I can confirm that it does not.
- BonoboIO 7y agoDoes an allways on VPN help?
- grepsedawk 7y agoyes
- grepsedawk 7y agoNope, they physically open your packets, change the content of the HTML, and send the packets along the way. Even if you access the IP directly, it still injects code via MITM attack.
- bloody-crow 7y agoI saw the MITM injection from Comcast exactly once and it served as a reminder to go and change the DNS settings on my routers. Never seen the injection since, and I've been on Comcast for years.
- AtomicHyper 7y agoThat is odd, I recently got a MITM injection even while running everything on openDNS.
- bloody-crow 7y agoMaybe you're right and me not seeing injections could be explained that a lot more traffic goes through SSL/TLS by default, or I'm just not getting close to my monthly quotas any more.
- basch 7y agoI still get it with Cloudflare, Quad9, and Google as dns.
- elliekelly 7y agoIf you're using a Comcast router they don't even let you change your DNS on the router and any client DNS settings will be completely ignored. It's kind of insane that they get away with charging customers $10-15/month for the privilege of a router without any privileges.
- indigodaddy 7y ago"any client DNS settings will be completely ignored" - how are they accomplishing this? I wouldn't think this would be possible...
- kevin_b_er 7y agoThey perform a MITM attack on your DNS packets, since DNS protocol is unsecured. It is another reason they're flagrantly against encrypting DNS and attempting to get laws passed against it.
- bifrost 7y agoGiving google your DNS requests isn't really better either...