[143332] in North American Network Operators' Group
Re: US internet providers hijacking users' search queries
daemon@ATHENA.MIT.EDU (Owen DeLong)
Sat Aug 6 13:01:58 2011
From: Owen DeLong <owen@delong.com>
In-Reply-To: <4E3D5286.7080307@ispalliance.net>
Date: Sat, 6 Aug 2011 09:55:34 -0700
To: Scott Helms <khelms@ispalliance.net>
Cc: nanog@nanog.org
Errors-To: nanog-bounces+nanog.discuss=bloom-picayune.mit.edu@nanog.org
--Apple-Mail=_879DB017-C613-45B4-AA92-730DEFCE3A2E
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain;
charset=iso-8859-1
I prefer running my own resolver. It's pretty trivial to do on a Mac and =
I would tend to
think wouldn't be all that hard on Windows, though I have no idea.
A resolver doesn't get much more local than ::1/128.
Owen
On Aug 6, 2011, at 7:41 AM, Scott Helms wrote:
> Correct, I don't believe that any of the providers noted are actually =
hijacking HTTP sessions instead all of these are DNS based tricks. =
Since the service providers are also providing DNS (via Paxfire and =
others) users don't have a lot of choice. You can switch to using a =
known public name server (Google's 8.8.8.8 for example) but I hesitate =
to recommend that to most end users because in non-evil networks its =
better to have local name resolution (because of GSLB & other reasons).
>=20
> On 8/5/2011 9:14 PM, Joe Provo wrote:
>> On Fri, Aug 05, 2011 at 05:04:51PM -0700, Bino Gopal wrote:
>>> =
http://www.newscientist.com/article/dn20768-us-internet-providers-hijackin=
g-users-search-queries.html
>> It is more than slightly misleading to say "hijacking search
>> queries"; paxfire is evil as it hijacks dns and breaks NXDOMAIN
>> and they've been doing that for ages. The user behavior of
>> searching in the address bar has become more common place, and
>> browser behavior to try and resolve first, fallback to search
>> for the same input field has both trained the humans to keep
>> doing this and made it possible for DNS query interlopers to
>> appear to be generic-search interlopers.
>>=20
>>=20
>=20
>=20
> --=20
> Scott Helms
> Vice President of Technology
> ISP Alliance, Inc. DBA ZCorum
> (678) 507-5000
> --------------------------------
> http://twitter.com/kscotthelms
> --------------------------------
>=20
--Apple-Mail=_879DB017-C613-45B4-AA92-730DEFCE3A2E
Content-Disposition: attachment;
filename=smime.p7s
Content-Type: application/pkcs7-signature;
name=smime.p7s
Content-Transfer-Encoding: base64
MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEHAQAAoIIERDCCBEAw
ggOpoAMCAQICARQwDQYJKoZIhvcNAQEFBQAwgaYxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTER
MA8GA1UEBxMIU2FuIEpvc2UxGjAYBgNVBAoTEURlTG9uZyBDb25zdWx0aW5nMSUwIwYDVQQLExxE
ZUxvbmcgQ2VydGlmaWNhdGUgQXV0aG9yaXR5MRYwFAYDVQQDEw1jYS5kZWxvbmcuY29tMRwwGgYJ
KoZIhvcNAQkBFg1jYUBkZWxvbmcuY29tMB4XDTA2MTIxNjE2MzcxN1oXDTE2MTIxMzE2MzcxN1ow
fTELMAkGA1UEBhMCVVMxCzAJBgNVBAgTAkNBMRowGAYDVQQKExFEZUxvbmcgQ29uc3VsdGluZzEP
MA0GA1UECxMGUGVyc29uMRQwEgYDVQQDEwtPd2VuIERlTG9uZzEeMBwGCSqGSIb3DQEJARYPb3dl
bkBkZWxvbmcuY29tMIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEA7H7JBEUaAy56E6qY
0JoHKfI+6QT7hYjnc1JezeZOA5XxK7QERkx8rdcND47xeNXjw06ZMjfhrcGkxM+1PEatBxC1Aax1
V95fKtw0DkNMKRgH138E6mZhwuWsvcA1bhxJQQc++SumEX5Uyr5dX4jYy2WgmaLKc8TD/N5G+/zb
Rc1sLrznovNvv7daKfDFlufRkPnLpeG0gx/HIFa4csMNYH2rdLt2xUBAt4TSy3fjEbp0HFVRJI4G
QRHbMmb6tBMnT9vpUZrwMHydqHHTiGr2A8PgdQeQLNEknKynVFTjJIXhBUSINhCl2HtQA+TKv+gu
EF9HrIybZSDlhGym0JUgKwIDAQABo4IBIDCCARwwCQYDVR0TBAIwADAdBgNVHQ4EFgQUzaaV8BC8
UhxaWk6IQTpqK9mLnSgwgdMGA1UdIwSByzCByIAU15gTZIxt8E1K2l0KkjrRFpdc5eyhgaykgakw
gaYxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTERMA8GA1UEBxMIU2FuIEpvc2UxGjAYBgNVBAoT
EURlTG9uZyBDb25zdWx0aW5nMSUwIwYDVQQLExxEZUxvbmcgQ2VydGlmaWNhdGUgQXV0aG9yaXR5
MRYwFAYDVQQDEw1jYS5kZWxvbmcuY29tMRwwGgYJKoZIhvcNAQkBFg1jYUBkZWxvbmcuY29tggEA
MBoGA1UdEQQTMBGBD293ZW5AZGVsb25nLmNvbTANBgkqhkiG9w0BAQUFAAOBgQCWRsD48eQfaNKH
K2lohMTD9voszp/GuoWTyi6RckNxW0b0V0gv7ZGH1BUmgq2Jt7SjIis7vTY3FCZUDcR9e7fpBXJL
/euk2pPEBSHbCWAYO+uFeZ17UHz0WtInBB7Yo2EHUrkf4jeJDL7rHOG5YOVQzoV1+vdFkmQvPCPX
zPyYyzGCA7cwggOzAgEBMIGsMIGmMQswCQYDVQQGEwJVUzELMAkGA1UECBMCQ0ExETAPBgNVBAcT
CFNhbiBKb3NlMRowGAYDVQQKExFEZUxvbmcgQ29uc3VsdGluZzElMCMGA1UECxMcRGVMb25nIENl
cnRpZmljYXRlIEF1dGhvcml0eTEWMBQGA1UEAxMNY2EuZGVsb25nLmNvbTEcMBoGCSqGSIb3DQEJ
ARYNY2FAZGVsb25nLmNvbQIBFDAJBgUrDgMCGgUAoIIB3zAYBgkqhkiG9w0BCQMxCwYJKoZIhvcN
AQcBMBwGCSqGSIb3DQEJBTEPFw0xMTA4MDYxNjU1MzVaMCMGCSqGSIb3DQEJBDEWBBQMirRDxvkr
R04BpbSJqMYMFs+4IzCBvQYJKwYBBAGCNxAEMYGvMIGsMIGmMQswCQYDVQQGEwJVUzELMAkGA1UE
CBMCQ0ExETAPBgNVBAcTCFNhbiBKb3NlMRowGAYDVQQKExFEZUxvbmcgQ29uc3VsdGluZzElMCMG
A1UECxMcRGVMb25nIENlcnRpZmljYXRlIEF1dGhvcml0eTEWMBQGA1UEAxMNY2EuZGVsb25nLmNv
bTEcMBoGCSqGSIb3DQEJARYNY2FAZGVsb25nLmNvbQIBFDCBvwYLKoZIhvcNAQkQAgsxga+ggaww
gaYxCzAJBgNVBAYTAlVTMQswCQYDVQQIEwJDQTERMA8GA1UEBxMIU2FuIEpvc2UxGjAYBgNVBAoT
EURlTG9uZyBDb25zdWx0aW5nMSUwIwYDVQQLExxEZUxvbmcgQ2VydGlmaWNhdGUgQXV0aG9yaXR5
MRYwFAYDVQQDEw1jYS5kZWxvbmcuY29tMRwwGgYJKoZIhvcNAQkBFg1jYUBkZWxvbmcuY29tAgEU
MA0GCSqGSIb3DQEBAQUABIIBAKHLL4joIw9ZoD+gvSvpsJqZ+qJg5EGoKLn3jpfUPcalYSQ21hql
BNuI/Sp1LoiMlNrwrRMzDd0Ikbhla4+4EPNzJ1ARH0u4W7rjAd6DQqIeGrKPV+Wjx4CACwXA3fcn
sSAGfR24wC20EYcXi2vYYZnF3Newi/DKfJhMAcSXiQrBvBVjT1b+4Rhkqbn/TFC77ZXXTZukbfnX
1SH9Zd2Koq1J6wpazNk1ASizaUYE3cguO3BUcOkbD6TpLf6TWVbr6LOocdsa44McUsJs8co58oba
HFDdlULJGNfogR+2jwmvrspJivSTZF9LwBFKwuuDH1KWpcW/bNCNC8YgXbyUx/cAAAAAAAA=
--Apple-Mail=_879DB017-C613-45B4-AA92-730DEFCE3A2E--