3 ms·
You’re seemingly pushing you own agenda here? As the article itself says: > Are other approaches feasible? For example, Firefox’s captive portal test uses del
by stuartd 6y ago
You’re seemingly pushing you own agenda here?
As the article itself says:
> Are other approaches feasible? For example, Firefox’s captive portal test uses delegated namespace probe queries, directing them away from the root servers towards the browser’s infrastructure.
- stefan_ 6y agoIn your agenda to expose my agenda in linking a Firefox blog post, you have missed that this isn't even about captive portal detection. Captive portals are easily detected by trying to load a known response page; captive portals don't fake that because they want to be detected so that the browser redirects you to their portal. This is about malicious DNS resolvers that don't return NXDOMAIN for non-existent domains but instead send you to an ISP advertisement page. This messes with the omnibox. For all other domains, they resolve just fine. These resolvers are inclined to evade detection, e.g. if browsers checked a static list of domains, they would just return NXDOMAIN for only those.
- carlhjerpe 6y agoI can't even remember last i got an advertisement page. Must've been about 10 years ago, though the last 5 I've been using third party DNS. I don't know any Swedish ISP that does this. I'm using ISP DNS on my phone.
- floatingatoll 6y agoSounds like your country isn't as commonly affected. Lucky you :)
- stefan_ 6y agoI assume at some point the calculus flipped for ISPs to not annoy you with low-quality ads and make customers cut them out, but instead operate a real DNS resolver so you can still sell their real-time browsing history to advertisers. Part of that is the Google and Cloudflare marketing campaigns for their public resolvers, so people had a ready alternative.
- GauntletWizard 6y agoGee, 10 years ago - About when Chrome implemented this feature and started to gain worldwide traction.
- stuartd 6y agoOk sorry, please forgive my misunderstanding, it sounds like you’re saying Cloudflare is a ‘malicious DNS resolver’, but I guess I’m wrong there as well? I opted into DoH when it became available in Nightly (though not in the US), am I being a mug here?
- eat_veggies 6y agothey're saying that ISPs run malicious DNS resolvers (which is correct), not Cloudflare.
- stuartd 6y agoI don’t see that in the parent comment, though, to which my misguided reply has been heavily downvoted? I guess I need to learn more about this. Edit: or just stay out of it.
- iancarroll 6y ago> captive portals don't fake that because they want to be detected so that the browser redirects you to their portal This is not always true; several systems try to get you out of the iOS/macOS captive portal detection because it boxes the user into a restrictive frame, and either always impersonate captive.apple.com or begin to impersonate it when they want the user to believe they're "online".