16 ms·
I fought my ISP's bad behavior and won
- JoshTriplett 13y agoVery nicely done: reporting this as abuse to the companies offering these affiliate programs seems quite appropriate, and it sounds like they reacted appropriately. One person complaining to an ISP is noise; one person making an abuse report is all it takes to get that ISP banned from the affiliate program.
- helfire 13y agoThanks! I was in a state of hopelessness for a week or so till I had that idea.
- webmonkeyuk 13y agoIf the ISP was being transparent about where they were going to source traffic I'm surprised that they ever got onto the affiliate program in the first place.
- tdumitrescu 13y ago"I will continue to monitor periodically their DNS entries and compare them with other public DNS servers." This would make for a great watchdog site to provide visibility across different ISPs (and could also discourage other ISPs from pulling this crap).
- helfire 13y agoI think so too, though CDN's will mess with the results a bit. It would be nice if DNS had a way to sign/validate/somehow know the record you got was correct. Especially on the apex record as it can happen before ssl.
- Procrastes 13y agoIt's interesting no one brought up DNSSEC[1]. Has anything happened there since 2010? 1. http://en.wikipedia.org/wiki/Domain_Name_System_Security_Extensions http://en.wikipedia.org/wiki/Domain_Name_System_Security_Ext...
- helfire 13y agoI was going to mention it, but I haven't found anyone using it or a usable implementation.
- dingaling 13y agoDNSSEC is great in theory, but after three years I still haven't deployed a live instance. It is cumbersome to implement and maintain, requiring co-operation of registrars and frequent key regeneration. It is also very, very chatty and imposes a considerable processing burden on the first-hop DNS resolver. We need a signed DNS solution that isn't DNSSEC.
- JoshTriplett 13y agoCDNs will indeed mess with the results, but it would still likely be possible to tell the difference between a legitimate result and a forged one, especially if you know something about the CDN structures used by major site. And the more people run it, the more likely you can detect anomalies, much like Perspectives does for SSL. SSL, incidentally, seems like a major help here: you could detect common DNS hijackings by accessing the site via SSL. If you access https://amazon.com/ https://amazon.com/ , an ISP hijacking the site would produce either a certificate error or a connection failure (depending on whether they even attempt to listen for SSL traffic).
- _RPM 13y agoGaming the system seems to be the secret to winning.
- gesman 13y agoGaming the system is as sustainable as winning at casino. It's fun while it lasts.
- philip1209 13y agoThis is why you should encrypt your DNS.
- helfire 13y agoDo you have a link to a usable encrypted DNS solution? I searched but didn't find anything actively used, but a lot of proposals.
- IvyMike 13y agoDNSCrypt http://www.opendns.com/technology/dnscrypt/ http://www.opendns.com/technology/dnscrypt/ This works well for me. But I have found that this is the kind of thing where an expert can pop in and say "have you considered risk X with solution Y?" and leave me dumbfounded. So use at your own risk.
- phySi0 13y agoBetter page: http://dnscrypt.org http://dnscrypt.org
- dmourati 13y agoYou can easily setup a VPN and use the DNS servers on the other side. Connecting to the VPN can be done via IP.
- deleted 13y ago[deleted]
- rcfox 13y agoCould you elaborate on this? How would encryption help? The DNS server would need to decrypt the request in order to service it.
- lambda 13y agoThis also shows a weakness in DNS. There is currently no way to validate the DNS record you’re being served is what the person hosting the website intended. That's what DNSSEC is for, but it hasn't become pervasive enough yet to be able to depend on it.
- rwg 13y agoStrangely enough, the largest deployment of DNSSEC-enabled, customer-facing, recursive/caching nameservers in the United States is... Comcast. That's right, the same Comcast that, back in 2009, hijacked NXDOMAIN responses by default and returned A records pointing to servers that served up advertisement-laden search pages over http.
- jasoncartwright 13y agoI was also impressed to see that my Comcast connection uses IPv6. Turns out they have (or will have) one of the the largest IPv6 network in the world - http://gigaom.com/2013/11/27/comcast-xfinity-broadband-is-now-one-the-largest-ipv6-network/ http://gigaom.com/2013/11/27/comcast-xfinity-broadband-is-no...
- X-Istence 13y agoComcast's IPv6 network for content from Netflix or YouTube is actually better than using IPv4. A while back I set up an IPv6 only machine just to see the difference, and it is night and day. That being said, their network still leaves something to be desired, the IPv6 routes taken to get to the same IPv6/IPv4 host can sometimes be circuitous and I have noticed that they have a higher latency too. So there are upsides and downsides, but I hope it can only get better with time!
- IvyMike 13y agoSadly DNSSEC kinda sucks. Here's some earlier discussion on HN, with a lot of links. (Namedrop: tptacek is against DNSSEC and talks about it in the link.) https://news.ycombinator.com/item?id=5937004 https://news.ycombinator.com/item?id=5937004 TLDR: DNSSEC is kinda complex and hacko, doesn't protect you as much as you might think, and introduces a whole new PKI that you should probably trust even less than the current ones. But read the links above for the real story. I'm using DNSCrypt right now, which (correct me if I'm wrong) protects against DNS interception by my ISP, and seems like a whole lot less trouble than DNSSEC.
- rcfox 13y agoOne a slightly related note, in Chrome extensions, it's possible to redirect DNS requests on a per-URL basis. This is how Media Hint works to allow non-US Netflix users access the US version of the site. I'm surprised we haven't seen similar behaviour from Chrome extensions. I'm sure it would be caught eventually, but this isn't exactly something that people tend to look for, so it would take a while for people to catch it.
- dangrossman 13y ago> I'm surprised we haven't seen similar behaviour from Chrome extensions The "Window Resizer" Chrome extension got a silent update a few weeks ago. It rewrote all the links on Google search result pages to point to a proxy that added affiliate links where possible.
- peregrine 13y agoOver the holiday I did usual, fix/clean my grandmother's computer. She's been using chrome because I explained to her how much safer it is. I did a google search and realized something wasn't right. Uninstalled all the crapware apps that wormed their way in. And then I looked at the chrome extensions and low and behold there it was, more crapware. I removed them and they re-added themselves. I had to run spybox s&d to remove it completely. Moral of the story: chrome extensions are in some ways worse than toolbars.
- dminor 13y agoI had an extension that did that as well. I reported it to Amazon and left a 1 star review warning other users.
- ozh 13y ago+1 to OP, and +2 to companies who responded positively (and -3 to ISP, obviously)
- dmourati 13y agoSuper shady stuff. I never rely on any ISP provided DNS servers. I'm glad you talked to the the etailers to let them know what was going on. These business practices do introduce latency, regardless of what he told you. Not to mention, they are highly unethical and dishonest.
- helfire 13y agoA really shady ISP could intercept and redirect any outgoing port 53 traffic to their servers.
- dmourati 13y agoIf that were the case, I would immediately terminate any relationship with them and out them in public. While technically possible, you're now talking about a whole other form of dishonest behavior. Some would say criminal.
- anonymoushn 13y agoThis has been done. I'm not sure how prevalent it is now. http://comcastisfuckingwithyourport53traffic.wordpress.com/ http://comcastisfuckingwithyourport53traffic.wordpress.com/
- cdjk 13y agoThat's what my ISP does. What's worse is that sometimes their dns servers fail intermittently (something to do with fragmented packets and retrying DNS queries in TCP mode). It did take a while to figure out what was causing the intermittent DNS failures. "My ISP is hijacking all port 53 traffic" was fairly low on my list of possibilities, I must admit. Fortunately it's not that hard to run a local resolver that forwards queries to an external resolver on a vps on an alternate port. I'd switch ISPs, but I live in a remote area and my only other choices would be satellite or cellular, so I'm stuck with them.
- aendruk 13y agoMy ISP [1] actually does this. They offer an opt-out of NXDOMAIN hijacking, but silently proxy all port 53 traffic regardless. This experience has taught me simply to distrust the DNS protocol in its current form and use DNSCrypt in all situations. [1]: Shaw Communications, chosen by the landlord. [2]: http://dnscrypt.org/
- sloop 13y agoIf your ISP and/or Aspira were making any significant amount of affiliate commissions, I would be surprised if the merchants do not take action against them for fraud. This sounds like the same behaviour that Shawn Hogan got in trouble for with cookie stuffing http://en.wikipedia.org/wiki/Shawn_Hogan http://en.wikipedia.org/wiki/Shawn_Hogan
- helfire 13y agoI chatted with a company that investigates affiliate fraud, they may have a blog post up after the new year about this. Will submit it if/when they do.
- dmak 13y agoAhh... DigitalPoint, those were the days.
- jauer 13y agoThe ISPs that I've heard of using this claim to be getting low to mid thousands per month in revenue from it. I'm not sure if that counts as a significant amount of commission, but...
- gpcz 13y agoThe cynical side of me says that the ISP is just going to redirect the author's traffic to the "pure" DNS server in the future (even when he or she directs traffic to the main one) unless they get in serious enough trouble with one of the companies this first time. If anyone wants to do this in the future, I'd recommend just sending affiliate abuse emails with no notice to the ISP. Also, the future person may want to revise the [2] script to scan in a more surreptitious manner (change the order, add delays, simulate legit web traffic, etc).
- neil_s 13y agoInterestingly, you might have benefitted more from keeping quiet about this. While the original retailers are losing money through this, you aren't really affected negatively by them doing it. In fact, with this additional revenue source, they might be able to support thinner margins on their broadband charges, saving you some money. You did the morally correct thing, but perhaps at a potential personal cost.
- goldenkey 13y agoThe affiliates are getting hurt hugely though. Affiliate profits are supposed to be for helping the purchase - through marketing efficiency. The ISP is doing none of that, they are simply mafiosoing affiliate dollars through hijack. Amazon would not like this, the ISP gives exactly 0% efficiency boost to the e-commerce process, they're just a gypsie snake.
- emilv 13y agoWhy did you have to end an otherwise good answer with a racist slur?
- goldenkey 13y agoWhy have you failed to visit an abortion clinic yet? You're not fit for children. Gypsy: "An itinerant person or any person suspected of making a living from dishonest practices or theft; a member of a nomadic people, not necessarily Romani; a carny."
- ars_technician 13y ago>you aren't really affected negatively by them doing it. Even if you are fine with your ISP committing fraud, you are negatively effected by the complexity (points of failure) and latency this adds to the network.
- jauer 13y agoAs a ISP when we were considering using Aspira they claimed that no referral tokens would be replaced and that the only behavior was injecting a popup coupon window. I decided not to proceed with it because it seemed like a support nightmare and tampering with non-malicious subscriber traffic crosses a line. Their marketing affiliates (such as Cash4Trafik) are always reaching out to CEO types at small ISPs and the money they bring (particularly when you are small) can be hard to pass up.
- erichurkman 13y ago> Cash4Trafik It may be the cynic in me after seeing abuses for companies like Cash4Gold, but "Cash4" anything does not instill any amount of trust in a brand, at least to me.
- helfire 13y agoYes, and conditioning your users to click on popups. Glad you chose not to!
- click170 13y agoMay I ask which ISP you work for? Knowing that you consider tampering with nonmalicious subscriber traffic to be crossing a line is something I would pay a premium for.
- jauer 13y agoJust a little Rural Wireless/Fiber+Metro Datacenter/whatever provider in Southeastern Wisconsin. I try to keep my personal opinion at least one step removed from their name just in case :-) My email is in my profile. If you need a connection in that geographic area hit me up and I'll see what we can do.
- gnu8 13y agoIs there a way we can choke companies like Apira by making a concerted distributed effort to disrupt the referral programs they exploit (either by reporting them or by feeding them false referrals somehow)?
- gregcohn 13y agoAgree with this sentiment, but I think the effort would be better spent taking steps to switch to trusted DNS providers, as well as building layperson tools to monitor them.
- natch 13y agoI'd like to try out this curl command. I'm not using macports, though. Like many people, I've switched to brew since some time. Is there a quick way to see if my curl install is compiled with 'ares' whatever that is?
- helfire 13y agoports > brew! But seriously I don't know how brew works, though looks like the code supports the option: https://github.com/Homebrew/homebrew/blob/master/Library/Formula/curl.rb#L12 https://github.com/Homebrew/homebrew/blob/master/Library/For...
- sikhnerd 13y agobrew install curl --with-ares
- helfire 13y agoAlso looks like MacOS 10.9 has ares by default.
- afhof 13y agoCox does something similar but bypasses the the DNS records and just slipstreams in a response. I noticed Cox would redirect javascript requests to their own HTTP server and put in their own snippets, effectively doing mass javascript injection. The snippet ended up being some sort of alert about upcoming maintenance, but using a malicious technique for a benign purpose is the path to the dark side. Use HTTPS! (I use 8.8.8.8, it didn't help)
- jamesbritt 13y agoI had this happen to me and it pushed me to use a vpn for all personal Web traffic.
- RKearney 13y agoComcast also injects JavaScript into HTML responses if they feel the need to send you a message. Here's the code they use: https://gist.github.com/ryankearney/4146814 https://gist.github.com/ryankearney/4146814 And here's my (extremely short) writeup on it: http://blog.ryankearney.com/2013/01/comcast-caught-intercepting-and-altering-your-web-traffic/ http://blog.ryankearney.com/2013/01/comcast-caught-intercept...
- venomsnake 13y agoIsn't that CFAA abuse on their side?
- ihsw 13y agoRogers (Canada's Comcast) does the same thing, but for warning you about your bandwidth usage.
- squintychino 13y agoVPN + HTTPS for good measure
- squintychino 13y agoVPN + HTTPS just for good measure
- zquestz 13y agoEric, I am very sorry to see this happen to you. Unfortunately more and more companies are using our data for marketing purposes. All is not lost though. There are several ways you can protect yourself from these practices. The first thing I would do is get a router capable of using dnscrypt-proxy (http://www.opendns.com/technol... http://www.opendns.com/technol.... Then you can be confident that your DNS traffic is not being modified by your ISP. It does require that you have trust in a 3rd party DNS provider like OpenDNS, but at the end of the day you have to trust someone to provide DNS lookups. The second option is to setup DNSSEC so that you can verify where your DNS responses are coming from. While people will still be able to intercept what sites you're looking up, at least you know you're getting valid responses which is better than your situation is currently. Third is to use both. =) Anyhow, really awesome to see people standing against these practices. It takes users complaining to make change. The sad truth of the matter.
- jlgaddis 13y ago> It does require that you have trust in a 3rd party DNS provider like OpenDNS ... The same OpenDNS that hijacks NXDOMAIN responses?
- webmonkeyuk 13y agoOnly for the unregistered accounts IIRC. Can't you disable it after going thought the simple registration and claiming of IP address?
- reginaldjcooper 13y agoSo only if you help them associate all of your internet traffic with a registration. Hm, sounds privacy-conscious.
- zquestz 13y agoI only said OpenDNS was one of the options. There are many DNSCrypt enabled servers not run by OpenDNS. Seems anytime someone event mentions OpenDNS the same arguments get brought back up. If you don't like OpenDNS, then use DNSCrypt with another server. Simple solution.
- GigabyteCoin 13y agoCongratulations. What they were doing was absolutely evil in my opinion.
- AlonsoGL 13y agoHere it goes: Behind a ISP-wide cache. Any 'traceroute' passes by transtelco.net (ISP used to have their own infraestructure for voip services Megafon) now i have 5/6? DNS jumps! and all my traffic going to Transtelco. traceroute to news.ycombinator.com (198.41.191.47), 30 hops max, 60 byte packets 1 customer-GDL-**-***.megared.net.mx << 177.230.**.*** Dynamic IP, GDL is the city of the company 2 10.0.28.62 (10.0.28.62) 8.939 ms 8.941 ms 8.935 ms 3 10.2.28.195 (10.2.28.195) 8.912 ms 8.903 ms 8.891 ms 4 pe-cob.megared.net.mx (189.199.117.***) 8.878 ms 8.866 ms 14.201 ms << COB is the user city 5 10.3.0.29 (10.3.0.29) 23.494 ms 23.483 ms 23.408 ms 6 10.3.0.13 (10.3.0.13) 22.842 ms 19.609 ms 19.596 ms 7 10.3.0.10 (10.3.0.10) 19.560 ms 19.555 ms 19.536 ms 8 201-174-24-233.transtelco.net (201.174.24.233) 19.527 ms 20.650 ms 19.468 ms 9 201-174-254-105.transtelco.net (201.174.254.105) 34.239 ms 31.793 ms 31.268 ms 10 fe3-5.br01.lax05.pccwbtn.net (63.218.73.25) 31.792 ms 31.736 ms 33.533 ms 11 any2ix.coresite.com (206.223.143.150) 32.834 ms 33.221 ms 33.429 ms 12 ae3-50g.cr1.lax1.us.nlayer.net (69.31.124.113) 41.288 ms 41.228 ms 41.231 ms 13 ae2-50g.ar1.lax1.us.nlayer.net (69.31.127.142) 42.632 ms ae1-50g.ar1.lax1.us.nlayer.net (69.31.127.138) 35.192 ms 33.860 ms 14 as13335.xe-11-0-6.ar1.lax1.us.nlayer.net (69.31.125.106) 35.143 ms 44.714 ms 44.666 ms 15 198.41.191.47 (198.41.191.47) 37.638 ms 37.239 ms 36.997 ms I don't know how normal or ethic is this type of cache. No download limits, I have the 10mb and get 20mb(2000-2300kbps) downloads, for uploads is limited to 1mb.
- emilv 13y agoAs long as they don't tamper with the data I think an HTTP cache is perfectly OK. HTTP has loads of built-in mechanism for that kind of caching. It saves bandwidth upstream, not least for website owners, and may make your web browsing speed faster if the proxy is good. Tampering with the data, however, is not OK at all. In the U.S. I believe it may make the ISP exempt from for example the safe harbor clauses in the DMCA.
- ceejayoz 13y agoSome of the big content providers like Netflix are even reportedly making caching deals for their content. Both the content provider and the ISP get better performance and less exterior bandwidth.
- samweinberg 13y agoAnyone know if Time Warner Cable does this?