4 ms·
It is actually really easy to ignore user's selected DNS server. Basically ISP can just inject responses, given that DNS is unauthenticated. I don't know if US
by vasachi 4y ago
It is actually really easy to ignore user's selected DNS server. Basically ISP can just inject responses, given that DNS is unauthenticated.
I don't know if US ISPs do that, but it can be done.
- ev1 4y agoI know that both T-Mobile and Comcast have both ignored user selected non-DoH DNS settings by force in the past, either by DPIing port 53 traffic or static routing major public DNS servers toward their own resolvers.
- gsich 4y agoSo, do they still do it? This fearmongering about DNS selling pops up in every DNS thread here.
- 542458 4y agoI don’t really understand this perspective. “Sure, I’m using vulnerable technology, but nobody has exploited me lately that I know of” isn’t a statement that would get positive reception in any other netsec discussion.
- autoexec 4y agoyeah... it's not fear mongering when it's a thing that actually happens. Some ISPs collect and sell your data. I mean, they even paid congress to make it okay for them to do it. They sure can't be expected to keep their word https://arstechnica.com/tech-policy/2019/01/t-mobile-sprint-and-att-still-selling-your-location-data-report-says/ https://arstechnica.com/tech-policy/2019/01/t-mobile-sprint-...
- hulitu 4y agoAnd you really believe that "every ISP" sells your data, only Cloudfare is not doing it ? You know, Apple was a "privacy oriented company" until some years ago.
- eli 4y agoCloudflare promises that they don't in a legally binding document. Does your ISP do the same?
- autoexec 4y agoWell... I said "some ISPs" sell your data, not "every ISP", but I wouldn't put it past any of them. Personally, I don't trust cloudflare, I don't like efforts to kill ad-blocking, and I don't like further consolidating people's DNS traffic into the hands of a smaller and smaller number of providers. I've got the feature disabled for now. I wish someone like EFF would set up a DNS server supporting DoT. I'd pay for the service!
- sbarre 4y agoISPs don't have the best profit margins, especially ones in competitive markets.. If the big players are selling DNS data, I guarantee you there are companies out there approaching every other smaller ISP with a turnkey solution that makes it as easy as possible to do the same thing with some kind of revenue share model. Not a lot of businesses would turn down extra money like that, when they know their big competitors are doing the same thing. Unlike most ISPs, privacy and security are a core part of Cloudflare's brand and business model - at least at the moment - so it's in their own interest to actually not do this stuff. Only time will tell whether or not they pull a "don't don't be evil" on us, but that's a different conversation. :-)
- joveian 4y agoCloudbleed and particularly Cloudflare's response to it (the way they publicly blamed Google) tells you everything you need to know about how trustworthy Cloudflare is. I personally use Google via DNS over TLS, not that it is a good option but I personally prefer that to the alternatives available near me. CenturyLink was intercepting DNS last I checked a few years ago.
- TheCoelacanth 4y agoIt is much easier to replace Cloudflare if they violate your privacy than to replace your ISP if they violate it. That helps to keep Cloudflare honest.
- gsich 4y agoThe article is not about DNS?
- eli 4y agoI can confirm T-Mobile currently still does it.
- clsec 4y agoComcast does it to this day.
- ciupicri 4y agoHow can this be legal, interfering with someone's Internet traffic?
- sbarre 4y agoI guarantee the ToS you agree to with your ISP gives them to right to do this kind of stuff, for "network stability and performance" reasons or some other reason.
- leguminous 4y agoI used to have Spectrum "community wifi" (their service for apartment buildings). They were doing this as of last year. They even spoofed responses from root servers, which utterly broke things like `dig +trace`.