Slashdot Mirror


How One Man Fought His ISP's Bad Behavior and Won

An anonymous reader writes "Eric Helgeson documents his experience with an unscrupulous ISP that was injecting affiliate IDs into the URLs for online retailers. 'It appears that the method they were using was to poison the A record of retailers and do a 301 redirect back to the www cname. This is due to the way apex, or 'naked' domain names work.' Upon contacting the ISP, they offered him access to two DNS servers that don't perform the injection, but they showed no indication that they would stop, or opt-out any other subscribers. (It was also the only wireless provider in his area, so he couldn't just switch to a competitor.) Helgeson then sent the data he gathered to the affiliate programs of major retailers on the assumption that they'd be upset by this as well. He was right, and they put a stop to it. He says, 'ISP's ask you to not do crummy things on their networks, so how about they don't do the same to their customers?'"

8 of 181 comments (clear)

  1. Use public DNS by DigiShaman · · Score: 5, Informative

    Google DNS is 8.8.8.8. and 8.8.4.4
    Open DNS is 208.67.222.222 and 208.67.220.220

    Norton Safe Connect (personal use, not for business) is 199.85.126.10 and 199.85.127.10. Supposed to protect against malware, phishing sites, and scams.
    https://dns.norton.com/dnsweb/homePage.do

    --
    Life is not for the lazy.
    1. Re:Use public DNS by Nerdfest · · Score: 5, Informative

      You can try this tool to check your existing DNS for performance and behaviour. Google's is very well behaved by the way, so please don't spread FUD.

    2. Re:Use public DNS by Nerdfest · · Score: 5, Informative

      I should add that both Google DNS and OpenDNS support DNS-SEC which is nice as well. OpenDNS also supports a form of DNS request encryption which hides even the sites you go to.

    3. Re:Use public DNS by Anonymous Coward · · Score: 5, Insightful

      I think the point is that Google pwns every bit of information about you.

      It's not good enough that they track you at every site that uses Analytics, every site that uses AdWords, every site you go to from their search engine, every site you visit with their Toolbar in play. (I'm forgetting a hundred other ways they suck your data.)

      Nah, not good enough. Why not tell google every single DNS lookup you ever make??

      Why do people mistrust the NSA so much and yet think Google is some kind of sparkly-super-shiny white hat? They work very hard to provide you with tons of free services that give them this wealth of information about you. WHY do they give you these????

  2. Not wireless by Anonymous Coward · · Score: 5, Informative

    (It was also the only wireless provider in his area, so he couldn't just switch to a competitor.)

    No, the blog says:

    You may be asking why don’t I switch ISPs? Well they are the only one besides a wireless provider in my area.

    Which means there are 2 ISPs. The one he's using is not wireless, and the other one is wireless.

  3. Re:Public DNS considered harmful by drmofe · · Score: 5, Interesting

    I commented on the reddit thread in the same vein as you and got downvoted. So I did some research. Several contributors to that thread suggest that Google DNS has solved the CDN problem by adding and original IP field that the CDN can use to geolocate the subscriber. This is due to Google implementing edns-client-subnet EDNS0 extensions as of late-2011.

  4. Re:Repost! by 228e2 · · Score: 5, Funny

    I think I read 75% of the things here elsewhere around a day in advance.
    Slashdot isn't (well, in its prime) where you come for breaking news, it's where you go (again, back in its prime) for great intellectual technological discussions.

    --
    Since when does being a Socialist mean 'someone who has a different opinion than me'?
  5. Re:What exactly happened? by hey! · · Score: 5, Informative

    Short, simplistic answer: the ISP found a way to fraudulently skim a percentage from online retailers for every purchase made by the ISP customers.

    Slightly more detailed answer: the ISP directed users looking for online merchants like "amazon.com" to it's own bogus server. That bogus server then re-directs the user's browser to the merchant's server in such a way the consumer doesn't notice and the merchant thinks the customer is following a product referral from an advertising partner. Thus the ISP collects a kickback intended for people who make product recommendations and referrals, without actually having made any recommendation or referral.

    --
    Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.