Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

DNS from ISPs used to do this too, right?


Right. Telekom (germany) had this around 2010. It was called "Navigationshilfe" ("navigation aid"). At least there was an opt-out option.

Edit: seems to have been there from 2009 till 2019 (!) after users took legal actions. See https://www.golem.de/news/t-online-navigationshilfe-telekom-... (german)


This reminds me of another ISP scam. Around 2010, my ISP would occasionally inject pop-up ads into clear text HTTP pages. Apparently the solution was to call in a complaint. The customer support agent would act surprised (lol) and promise to investigate, and no ad would be delivered to the complaining customer afterwards.


This was one of the main reasons HTTPS took off. The other was Firesheep.


Yea, everyone gets mad at Google for requiring https nearly everywhere, but outside of actual hackers, the ISPs were the cause of this.

Redirecting you to an add page is terrible enough, ensuring that the ads on that page eventually served malware was the icing on the cake.


AT&T was doing this in 2021. They called it "DNS Error Assist."

I imagine they're still doing it.


They implement this at the edge, so bypassing the nameservers bypasses the silly search page and doesn't change the authoritative domain name. Verisign was changing it at the root, for everyone.


A difference of degree, not kind. This technique is the predator of the attention ecosystem, singling out the "old and weak" if typos imply weakness!

An angle no one has mentioned it how this played into googles dominance. These predators made it legitimately safer to type into a search box than a URL bar. At least for a little while.


> singling out the "old and weak" if typos imply weakness!

They don't.


Do you have an actual disagreement to communicate, or just thought-terminating dismissal, because it seems that typos would be more frequent for users with poorer attention to detail, which sounds to me like the kind of user that is more likely to fall for a scam.

So yeah, preying on users who make frequent typos would also serve to target less observant users, who have the potential be exploited more easily than the general population. AKA: typos imply an exploitable weakness

Case in point: Verisign and Telekom squatting on typo'd domains to extract revenue from exploitable users.


Having a weakness in typing isn't what "the weak" means. There's no need to be overly emotive. We can define its badness objectively.


Arcor had this around 2004 iirc.



In Romania, one of the top 5 ISPs, telekom.ro, is still doing it in present days.


One extra reason to never use the ISP DNS services. Just switch to Cloudflare and never look back.


Cloudflare has control over too much of the modern web infrastructure. 5/10 sites I visit use it and its captchas are annoying as hell.

Better use OpenDNS, etc just to have more diversity


That was what initially spurred many people to stop using their ISP's DNS resolvers.


It is the norm here in Texas. All the ISPs available to me do this.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: