5 ms·
How would encrypting DNS help me avoid Comcast MITMing my HTTP traffic to inject bandwidth cap notifications? Doesn't the system just inject a script tag into t
by sprayk 6y ago
How would encrypting DNS help me avoid Comcast MITMing my HTTP traffic to inject bandwidth cap notifications? Doesn't the system just inject a script tag into the appropriate place in the HTTP response?
- entropicdrifter 6y agoHTTPS Everywhere + encrypted DNS blocks a huge chunk of what they can see without expending effort on you in particular
- sprayk 6y agothat is not what I was asking. GP claimed that encrypted DNS would stop comcast from injecting notifications into HTTP traffic, I want to know how that would work, in the hopes that my assumptions about the system are wrong.
- proverbialbunny 6y agoYou make a good point. I worked on the code before encrypted DNS was a thing (or anything I knew about) so I'm going off of theory, not first hand experience. When a request is sent for a http web page it is ran through the layer 4 proxy. In there is a user profile where http injection can occur. It works by injecting JavaScript into the end of the web page. If the dns request is encrypted all of the handshaking goes through tls bypassing the proxy's view of this data for everything except disconnected http body data. However, it could be that as years have gone by it's been updated to take in http data without any sort of head and then it would work again. It's probably as simple as running some regex looking for </html>. So, me in my half awake state this morning didn't really think it through. In previous versions of the software this wouldn't be supported, but in hindsight it's not a terribly difficult problem to fix, so Comcast probably does support HTTP injection even when using encrypted DNS by now. My apologies.
- dylz 6y agoFYI if you block this notification (it requires the script tag to load and you to click an I AGREE TO PAY PER GB bullshit thing), you can no longer do UDP traffic and your TCP connections start getting reset. I found this out the hard way, because I browse nearly all HTTPS sites, and uBlock blocks the injected malware script on the few plaintext sites and never really noticed. Your IP changes into a shared Comcast-run squid proxy one, all TCP ports are no longer available other than 80/443 filtered through squid, all UDP is no longer available.