ISPs, Comcast in particular, inject ad-loading javascript into HTTP pages.
https://arstechnica.com/tech-policy/2014/09/why-comcasts-jav...
ISPs, Comcast in particular, inject ad-loading javascript into HTTP pages.
https://arstechnica.com/tech-policy/2014/09/why-comcasts-jav...
Your isp knows you visited a certain domain with https. That's a concern.
You just shift the trust around. Now I have to trust the hoster, e.g. OVH instead of my local ISP. Really the best thing you can do is end-to-end encryption, don't send plaintext over the internet.
> Your isp knows you visited a certain domain with https. That's a concern.
How about DNS over HTTPS?
Any ISP is allowed to sniff and manipulate packets, so this isn't just about my ISP -- it's the server's ISP as well as any entities in-between.
Even if I did (assuming that I reasonably could!) change my ISP, that's changing only one of the potentially many hostile actors.
>why wouldn't you use a vpn
That would require me to trust the connection between the VPN and the server.
Plus, then I would need to buy a VPN subscription :) Just serve HTTPS!
A vpn moves any legal situation into a country with different laws.