Slashdot Mirror


ISP Is Bypassing Firefox's Location Bar Search

It was only a matter of time before ISPs began doing more than just redirecting failed DNS requests to their own pages. An anonymous reader writes "It looks like the largest ISP in Hong Kong has started bypassing search results from Firefox's location bar (which typically uses Google), forcing their own search provider (yp.com.hk) onto their users. ... Can an ISP just start re-directing search traffic at will?"

24 of 385 comments (clear)

  1. Re:Sure they can by NervousNerd · · Score: 4, Insightful

    It looks like the largest ISP in Hong Kong

    I never knew that Hong Kong was in the United States.

  2. Nope by ffreeloader · · Score: 4, Funny

    Can an ISP just start re-directing search traffic at will?

    Not in my book. My ISP started doing some redirection and they got an immediate complaint from me. In person, at their local office. If there was an alternative to their service I would have switched ISP's immediately.

    --
    "while democracy seeks equality in liberty, socialism seeks equality in restraint and servitude." de Tocqueville
    1. Re:Nope by ffreeloader · · Score: 4, Insightful

      Who knows? They have been quite responsive to complaints about services in the past. Even if I don't get an immediate response my voice was heard. They do know at least one of their customers was angry about their conduct. Should I just silently accept them screwing with me and not voice my concerns? That seems to me a guarantee that they won't change their ways.

      From your post it seems that you think not standing up for yourself is the way to change things. Don't vote. Don't express your opinion. Be a martyr. How's that working for you? Effecting a lot of change in society are you?

      --
      "while democracy seeks equality in liberty, socialism seeks equality in restraint and servitude." de Tocqueville
  3. Encryption by dmbasso · · Score: 5, Insightful

    And that's why we should start using encryption for everything...

    --
    `echo $[0x853204FA81]|tr 0-9 ionbsdeaml`@gmail.com
    1. Re:Encryption by JesseMcDonald · · Score: 4, Insightful

      Remember that encryption won't help without authentication; your ISP will just MITM all your encrypted traffic. You need to know who you're really talking to.

      --
      "The state is that great fiction by which everyone tries to live at the expense of everyone else." - Bastiat
  4. Not much evidence yet... by Interoperable · · Score: 5, Insightful

    The article is a single post on a forum from one user with no follow-up. Can anyone else confirm the allegation?

    --
    So if this is the future...where's my jet pack?
    1. Re:Not much evidence yet... by jimicus · · Score: 4, Informative

      Indeed, the poster only discusses what happens when he puts the name of a website into Firefox's address bar. By default, that will carry out a DNS lookup and if that lookup fails, Firefox will redirect to a Google "I'm feeling lucky" result.

      Lots of ISPs are intercepting failed DNS requests and injecting their own ad page, there's usually a way to bypass this.

  5. Re:Sure they can by eldavojohn · · Score: 4, Insightful

    As shown by the recent Comcast - FCC ruling, ISPs can barely be regulated at all (and therefore can do anything they want).

    Well, as someone else pointed out, this is an ISP in Honk Kong, not the US. While most of the "harmonizing" efforts of the Chinese government have been passive toward the consumer of the "non-harmonious" content, I would fear that this is a sort of precursor towards ISPs in China being required to pass search terms linked to individuals/accounts/addresses to the government for non-harmonious search terms indicating a level of dissent associated with that individual. Call me a tin foil hat but I haven't been too impressed with what's going on out in China. While you might claim it's overhead and too expensive, I guess we might start talking about https (port 443 secure) traffic even for search terms to avoid this inspection? Even that's naive though as the government could just ask the inside search provider for the data ... or failing that block the that port on that provider.

    --
    My work here is dung.
  6. Sleezy by nicolas.kassis · · Score: 4, Interesting

    This is as sleezy as it gets for an ISP. I hope firefox and google setup some sort of trusted cert and use HTTPS for the traffic from that bar. That might make it much harder for them to do men in the middle attacks of the sort. Google could sue the ISP for impersonation or something similar.

  7. Making their own argument for net neutrality... by MikeRT · · Score: 4, Insightful

    Most people still believe that just because you can legally do something, doesn't mean you should. When businesses do every sneaky, duplitious thing they can to make a buck, they push that natural tendency toward expecting civility and something resembling high-mindedness in civilized people straight into the Socialist camp.

    As a Capitalist, that really offends me. If businesses want to be treated laissez faire then they damn well better learn to make society not feel like they're a bunch of crooks who care so little about the common good that if regulators aren't going Big Brother on them every nanosecond they'll steal everything that isn't nailed down and cheat everyone who isn't paying 110% attention to every detail of their lives.

  8. Re:Sure they can by Jurily · · Score: 4, Funny

    I never knew that Hong Kong was in the United States.

    It's rude to derail a rant with logic.

  9. This is why we need net neutrality by Fallen+Kell · · Score: 4, Insightful

    A perfect example of why we need net neutrality rules in place. An ISP should not be allowed to modify packets or redirect packets to/from known destinations.

    --
    We were all warned a long time ago that MS products sucked, remember the Magic 8 Ball said, "Outlook not so good"
  10. Re:Sure they can by Bryansix · · Score: 4, Informative

    This IS Slashdot right? Let's look at the technical limitations here. As long as your ISP does not block DNS requests then you can use any DNS provider you want and therefore bypass any redirection. If an ISP started blocking the use of other DNS server then I'd say it's time to jump ship.

  11. Re:Sure they can by Cryonix · · Score: 5, Informative

    My US ISP recently started doing this (windstream.com). This was done without any real notice and turned on by default. Granted, there is a link in the redirected search results to turn it off.

  12. Re:Why? by koreaman · · Score: 4, Insightful

    Do you really believe the average firefox user has the technical know-how to even understand what a DNS server is, let alone how to setup and configure one, even if it is "trivially easy" for you? Please...

  13. Re:More profit! by Yvan256 · · Score: 4, Funny

    They could even be sleazy and open up shops that almost look like the same name depending on the font used.

    Shop at Arnazon.com!

  14. Re:Sure they can by Eponymous+Coward · · Score: 5, Informative

    They don't block DNS requests, they just send all port 53 traffic to their DNS server.

    There are a lot of areas with a single good internet option (where 'good' means decent bandwidth and latency). Jumping ship may not be a realistic option.

  15. Re:In China? by Nadaka · · Score: 5, Funny

    If any high tech company is going to come out of the closet, it would be apple.

  16. Probably NXDOMAIN wildcarding.... by nweaver · · Score: 5, Informative

    What firefox does is first try to do DNS lookups for:
    foo
    foo.com
    www.foo.com

    before launching the google search.

    Thus NXDOMAIN wildcarding (which is unfortunately growing very common, distressingly so in our data) will mess up the firefox behavior by causing one of the three names to resolve to the "helpful" search page belonging to the ISP.

    --
    Test your net with Netalyzr
  17. China? by PatDev · · Score: 4, Informative

    Heck, it happens here in the USA. I'll name names too - Windstream Communications. As of a couple months ago they started redirecting our google search bars to their custom search portal. Annoyed the hell out me. Emailed, but apparently got dumped into the bucket of spam/"unhappy customer, please ignore".

  18. Windstream, DSL US ISP is already doing this by Anonymous Coward · · Score: 5, Informative

    This isn't new, and this isn't NXDOMAIN hijacking. Windstream, a US DSL provider, was already caught red-handed doing this. Not only this but they also refuse to answer very specific questions asked (see http://www.dslreports.com/forum/r24059591-DPILayer7NXDOMAIN-Privacy-questions-re-Windstream-DSL) and provide a paper-thin excuse as to why it's happening (see http://www.dslreports.com/forum/r24074065-Our-Response-to-Redirect-Service-Concerns).

    Affected users are not using the ISP's DNS servers, this is not NXDOMAIN hijacking. This is layer 7 inspection, the sheer fact the URL was transformed, being carefully re-written, from the URI passed to 'www.google.com' discredits what Windsteam has said entirely.

    When a user performs a search using the Firefox search bar against Google HTTP/1.1 is used with an HTTP method of GET against Google. The following URI is constructed:

    q=[search critera]
    ie=[encoding]
    oe=[encoding]
    aq=
    rls=[browser]

    So, when I search against Google I pass ?q= for my search term.

    When this is redirected to searchredirect.windstream.net the URI is transformed, with the ?q= parameter being extracted. Windstream's site uses this URI structure:

    search=[search criteria]
    src=[interger value, likely points to an RDBMS based on HTTP_REFERER]

    Windstream is not disclosing the truth. For this behavior to occur you would have to be using an MITM proxy or DPI; either way they are inspecting layer 7 traffic, extracting the ?q= URI string passed to Google, and either transparently or via HTTP 302 redirecting customers to searchredirect.windstream.net

    They got caught, red handed, and have been fabricated mis-truths from the start.

    How HTTP/1.1 GET against /search?q=my_search_term becomes /search.php?search=my_search_term without some form of Layer 7 is impossible. This CANNOT be NXDOMAIN.

    Clearly they're not disclosing the full details or hiding behind careful sentence structure and semantics. This appears that there is now an industry initiative and a company behind this search harvesting and privacy invasive technology which is being sold to ISPs. Expect more to come, this isn't isolated to over-seas, it's already happening right here in the US.

    -SirMeowmix_I

    1. Re:Windstream, DSL US ISP is already doing this by nweaver · · Score: 5, Interesting

      If you are a windstream customer, could you please run netalyzr (http://netalyzr.icsi.berkeley.edu) and send teh results URL to netalyzr-help@icsi.berkeley.edu?

      I'd like to investigate this in further detail.

      --
      Test your net with Netalyzr
  19. Re:Sure they can by wvmarle · · Score: 4, Informative

    Like another poster also pointed out: Hong Kong is not China. It is politically part of China, but for all practical reasons it acts as a different country (and you as not being involved in the world political stage should simply consider it as such, much closer to the everyday reality):

    Separate currency, the Hong Kong dollar, linked at 7.8 to the US dollar and fully convertible (can't say that of the yuan).

    Borders with China. I am Hong Kong resident, and still need to buy a visa to enter China.

    Hong Kong is a free port for import and export of goods and services. China is pretty thoroughly locked down, import duties of goods to China are huge. Really.

    Hong Kong has an open, accountable judiciary, with a strong respect for the rule of law. The exact opposite of the other side of the border.

    Hong Kong has press freedom, and not just official.

    Hong Kong people have the right to demonstrate, and do so. In 2003, half a million people took to the streets - or about 7% of the total population. It sent shock waves throughout the country, all the way to Beijing. Something like that would never be allowed in China.

    And last but not least Hong Kong has the permission from Beijing's overlords to move towards full democracy.

  20. Re:Sure they can by icebraining · · Score: 4, Informative

    DNSSEC prevents tampering, if I understand it right. If you request an answer from server X, the client won't accept a server from any other server, thus prevent man-in-the-middle attacks like this.

    Alternatively, you can redirect all or part of the traffic through a VPN or secure proxy. Even Tor, if you compensate the long delays with some DNS caching, as provided by pdns or other caching server (even if you don't need it, it's awesome, I tell you! Every request after the first takes 0ms).