Small ISPs use "malicious" DNS servers to watch Web searches, earn cash
arstechnica.com
arstechnica.com
A working DNS server is a good thing.
I was surprised by this rather recently, when my girlfriend and I moved in with her brother to conserve finances (both his and ours, since their other brother had just moved out leaving him with larger-than-payable bills). I mistyped a URL and it came back with an ISP-provided search page, which infuriated/surprised me. As it turns out, I only had the wireless connection set to use GDNS, but I was temporarily using a wired connection until I could buy a new wireless router (the previous one was a modem/router combo from the ISP, despite the fact that when I returned it the woman at the desk "corrected" me when I told her I was returning the router, saying that they don't deal with routers. I just smiled, did my business, and left.)
75.75.75.75 and 75.75.76.76
I prefer to use OpenDNS. They do show a search page, or a "not responding" page, but they don't bug or track me that I'm aware of.
It's frightfully annoying (but easily disabled for the technically-aware), because it actually redirects - this means fixing newss.ycombinator.com requires retyping the URL in its entirety.
The statement of "DNS server in question not passing the query directly to the search engine but through a host of other URLs" is factually nonsense - DNS server only is supposed to pass the query (that being a query for an A/AAAA records in the browser case, not the search query as they imply) to the authoritative servers within the hierarchy.
I think what this article means is as follows:
- the browsers try the name lookup on the DNS before treating the contents in the address bar as a search query.
- this treatment happens if the DNS replies NXDOMAIN
- if the domain exists (the browser gets A/AAAA record), the browser contacts the server in the reply.
- so the malicious DNS servers take the queries for which they are supposed to return the NXDOMAIN and instead interpret them and return the A/AAAA answers pointing to the servers filled with ads related to the keyword which was present in the DNS query.
- this is bad.
Of course this kind of "setup" breaks other applications besides the web - but, HTTP being north of 90% traffic volume, no-one cares too much, probably.
Thankfully VeriSign did this to .com once with their SiteFinder service, so FOSS DNS servers generally have good support for assigning a particular IP address as "this is really NXDOMAIN". (Nowadays, I'm running Unbound locally anyway for DNSSEC.)
EDIT: the opening paragraph used to read "My ISP started doing this," but a closer look at TFA indicates this issue is about intercepting DNS queries to existing, legitimate search providers in order to substitute paid results.
(That is, setting aside the obviously evil practice also alleged in this article of sometimes using these redirects for click fraud.)
Sadly, in many places in the US, especially those places served by the ISPs mentioned, that is not the case. In the absence of reasonable choice (roughly the same speed of service) this becomes something that should be regulated.
Again, these kind of things would all go away if we had public last-mile fiber that ISPs could lease. Regulation is a poor substitute for true competition.
https://www.eff.org/deeplinks/2011/07/widespread-search-hija...
...makes it clearer the affiliate-payments scam, making these redirected searches look like paid clickthroughs, is central to the Paxfire approach. That's clearly fraudulent, and not equivalent to the Google tracking. (If they were just collecting interest/trsffic/targeting info, then the equivalence I suggested above would apply.)
When I first saw the headline, I thought the DNS server was reading my URLs, which would have been really interesting because it's impossible :)
Geolocation isn't an exact science though, as anyone who has ever seen an ad saying that beautiful people in <reasonably close, yet still hilariously wrong city> want to meet you can attest, and the more disparate the ISP, the more wrong it becomes, since in most cases you only really have "this IP block belongs to this ISP" to go on.
You can get a court order to use this information to force Google to give you information that can be used to identify you with your ISP, but your ISP already has a lot more information on you anyway.
If you're really paranoid that Big Brother Google is keeping an eye on your internet habits, then you should fire up Tor and put the IP address for howtooverthrowtheusgovernment.com in your hosts file.
My ISP (Virgin Media) does this, but you can opt out. In fact, their opt-out page gives a much better explanation than the article: http://www.virginmedia.com/myvirginmedia/advancederror/feedb...
Vote Rigging or just brand brainwashing or maybe groupthink?