AT&T Hotspots: Now with Advertising Injection
webpolicy.org
webpolicy.org
The requirement for arbitration in the AT&T terms does not apply, because the Computer Fraud and Abuse Act is a criminal law. [2]
[1] http://www.att.com/legal/terms.wiFiServices.html [2] http://apps.americanbar.org/litigation/committees/criminal/a...
The users probably agree to it in a terms of service, but the served websites do not, and AT&T is creating what logically seems like a highly derivative (but altered) copy of their content with their own content inserted without permission of the original copyright owners.
While some amount of data rewriting is inherent in the nature of how the Internet works, modifying the content of web page bodies to insert advertisements just feels like it steps way, way over the lines of that, especially when it can easily present situations where you have ads selling products that would be vehemently opposed by the people whose site it seems to be appearing on to the average user.
This is as though AT&T printed magazines written by others and advertised in by others, and inserted their own extra advertisements in addition. So they take a 90 page magazine and add an extra 10 pages of ads. Clearly not kosher as they don't have the rights to the articles, ads, or anything. But they're trying to sell it at the AT&T newsstand as though it's the original.
Now suppose that I buy a magazine, and the first thing I do is page through it quickly and rip out all the ads. That's legit right? Once I own it, I can do whatever I want with it. Now suppose I -- after purchasing the magazine -- convince my friend to rip out all the ads for me, before I ever see any of them. Still OK isn't it?
I hope the parallels make it easy to see that what you do with the content once it reaches your computer are very different than what other 3rd parties do to content while it's in transit.
As far as the publisher is concerned, your friend and AT&T might as well be the same person. Both are taking a copyrighted work from the publisher, altering it materially, and presenting it to you.
AT&T is not selling the work, they are delivering it.
If one is a copyright violation, both are.
As the Supreme Court made clear in the aero case, intent and impact is far more important than technical details about transmission.
https://en.wikipedia.org/wiki/Family_Entertainment_and_Copyr...
Copyright protects publishers from unauthorized reproductions. AT&T are making an unauthorized reproduction when they insert extra things into something that isn't theirs.
If this got to court, a tech illiterate judge wouldn't see the difference.
The broadcaster pays the movie's rights owner for the right to rebroadcast whereas AT&T has no such deal with the website owners and is supposed to be acting as a simple common carrier.
No, they didn't. See the link above to the terms of service.
The reality is AT&T probably has no idea how bad this is, and likely would not care. Somewhere, someone sees the potential dollars on the upside and that's the only factor that matters.
There are better ways to monetize free WiFi today. Advertising is a piece of that puzzle, but there are others too.
Most likely, the WiFi provided by carriers like AT&T is meant for offloading. The phones will do EAP-SIM or some other authentication the customer has no idea of. That will get the voice and SMS traffic passing via WiFi and associated backhaul to the Mobile Core, instead of the mobile network.
Assuming that scenario, where WiFi is really a low-cost extension of the mobile network, the carrier has very little incentive to do the "right thing" when it comes to injecting ads and/or content filtering. They are already improving the services their customers pay for. Offsetting that (relatively low cost) with some "bad form" advertising probably won't get a second thought.
- Using HTTPS directly, in particular with HSTS set (optimal).
- Use a third party like CloudFlare to add HTTPS via their proxy.
- Alternatively: HTTP with Content Security Policy set (since it will reject their scripts and CSS running as it isn't in the whitelist). This is only a short term solution since they can alter the CSP header, but it will work if you're stuck on HTTP for now. We bounce a lot of advertisers and malware off of our site this way.
Ultimately this is yet another "Use HTTPS!" broken record. But the CSP solution works until they get wise to it.
The good thing is that at least most browsers these days are good at blocking mixed content so you won't have HTTP adds growing tumors due to injections anyhow.
What i don't understand is why AT&T has to do injection in the 1st place they can easily setup their own AdNetwork and partner with the large AdNetworks to route through AT&T's own internal servers.
Adnetworks are saving bandwidth, AT&T doesn't have to fight with HTML injection which can break on many sites, AdNetworks get better targeted advertisement win for everyone...
Wonder how it handles apps that expect json, or jquery/ajax calls that works with html fragments. Or even someone authoring a wordpress blog post?
Nowadays I mostly avoid tethering unless I really have to use it, since it's always rolling the dice whether it's going to eat hundreds of megabytes of my data quota without asking. Fortunately, there are so many wifi hotspots around that I'm finding tethering at all increasingly unnecessary. And a VPN takes care of the security issues well enough.
I would expect OSX has a similar setting somewhere, with the increase in metered networks.
The only time you "can't" do it is if you are using a Wifi Hotspot method in which case you'll have to set the Wireless connection to a metered one so it will keep track of the cap no matter to which HotSpot you connect too.
That said Windows doesn't block applications from accessing metered connections it moderates it self(Windows Update, Windows Mail etc...), has a separate setting for what ever MSFT calls "Metro" apps these days (so "Store" apps can be toggled individually with metered access policies), and for windows services so if Spotify decides to download a playlist you might get a surprise bill in the mail.
Everything I've seen on Win 10 metered connections -- including from Microsoft -- indicates that only WiFi (not-metered by default) and cellular (metered by default) connections can be set as metered, and that other network interfaces are always treated as non-metered and cannot be set as metered.
Take a look at this for OS X: https://www.tripmode.ch/
> TripMode is turned ON automatically when your Mac is connected to a mobile hotspot.
> TripMode only allows Internet access to apps important to you. Allow more apps when you need to.
Even people in ATT's forums are having same question:
https://forums.att.com/t5/Data-Messaging-Features-Internet/W...
In general however, I rely heavily on hotel wifi, as weak data signal is a real thing and drains battery. Tethering is a great backup, but not my daily driver even if I had unlimited.
For many activity categories- email, light browsing, etc- a few GB per month is more than sufficient.
If you want to torrent terabytes per month or run multiple Netflix streams all day long, you are a three or even six sigma user, and carriers realize that subsidizing your unusual usage with other subscriber's fees increases costs for the average user, making the carrier less cost-competitive. So you are either going to get pushed to hard lines, or you are going to have to pay for those terabytes of data.
My phone (Verizon prepaid) freely allows me to tether, although this relaxation is a recent development so there are probably many older phones that simply have not been updated to allow tethering. My 1GB is definitely a snug limit but not unworkable.
I agree that LTE is usually orders more reliable than 95% of wifi hotspots, unfortunately.
Ads that immediately broke all of our javascript that we were testing on QA sites.
It took us an hour to realize what was going on, and that it wasn't our code that was breaking, and another 30 minutes of angry phone yelling before they backed down and turned that shit off.
The infuriating part is that these ads are typically folded into original content as if the original page had the extra garbage in it. When you see an obnoxious ad, you're not thinking "well I guess I won't use this wifi again"; you think "well I guess I'm not going to this site ever again".
We desperately need a way to strongly sign each part of a page so that it is impossible to display a web site with any third-party content that wasn't explicitly added by the site owner (e.g. such as an authorized "Like" button). This naturally means removing i-frames and all other similar mechanisms from browsers, or at least making them a hell of a lot more obvious.
Not that I begrudge them trying to get some money out of their "free" service, and I choose not to use such services.
Of course you will then get MITM routers which link to the free WiFi, offer their own free WiFi on a different channel, and then swap the 'customer id' on the ads going through to send them the money. Or something like that. I'm sure there is a RasPi build to do something like this.
Things like this are the reason I strongly feel we should have admin privs on our phones without having to root it.
I reset my iPhone the other day without restoring any backup. Later that day I found my phone connected to attwifi without any instructions from me.
They log pretty much ALL of the traffic too. Not just CAN LOG. They DO LOG.
-
See http://www.ragapa.com "analytics" tab:
Here are some of the analytics RaGaPa device collect:
Geographical Location
Mac Address/Cookie Tracking
User Agent
User Browser
Destination URL
Ad/Message Impressions
Ad/Message Clicks
User Activity with Time
But even websites which support HTTPS won't mark cookies secure, so the browser will happily upload it to the HTTP version for the world to see.
Ultimately open WiFi hotspots are a security nightmare, it is quite incredible that nothing has been done about it. There's no reason we couldn't utilise something akin to SSL to secure the WiFi connection itself (since the scenario is identical, two previously unknown parties wanting to communicate securely, and utilising an already trusted CA to facilitate that).
I guess as an industry we're just too lazy to make anything except PSK work.
Weak Wifi signal is also a killer - you're using maps and driving near a Starbucks? Data crawls to a halt as your phone tries to connect to a wifi point 30+m away.
Eventually I just gave up on them.
I would prefer that carriers didn't do this kind of nonsense, but I'd also prefer that companies like Facebook & Google didn't have the core of their business built around the same function. We live in a world where people expect miraculous technology for "free."
It's trivial to get around this.
There are ways around the DPI with SSL wrapping and such, but it's not always "trivial".
Point in case, I'm living in a town with a population under 40k, and I know of at least 3 places so far which block OpenVPN traffic over both UDP and TCP.
Are they really doing flow inspection & identifying protocols? Or is it just that they're watching for standard ports?
feature technical information about the technology used to block VPNs.
SSH also works properly, and I can use a SOCKS proxy over that.
This is either a failure on our part to educate, or a failure to build secure systems, or a failure to regulate the people who would do these things. But either way, it's our failure -- not a failure of the users.
At least in this situation, you have a mechanism to opt out if you pick up a VPN and disrupt traffic injection.
Your only solution with companies like google & facebook is not to play.
I agree that it is disappointing that the laymen isn't going to be able to disrupt this traffic injection. We are already so deeply into a privacy dystopia that I think think you're focusing on the wrong fight. Some of the most successful companies have more users than customers. They are using TLS to avoid MITM attacks between the client & their infrastructure, but then harvesting data & injecting traffic till the cows come home.
Arguing for other mechanisms to disrupt carrier traffic injection is in essence an argument for defending the privacy invasive business cases of google & facebook.
The funny thing is, this network requires you to log in with your Bright House username and password, so anyone seeing that little "provided by" intrusion is already a paying customer.
What am I missing?
Ha! They do a better job of degradation than most web sites!
I wonder whose bright idea it was to roll this out now.
Well, I guess if websites don't want ads crapping all over their stuff, they'd better get on the stick.