Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Cox does this as well. I was recently staying a hotel and they were doing something similar prompting me to rate my experience. I started thinking about standards to make this kind of thing impossible... Ultimately TLS solves this issue. We should be bullish on making TLS standard.


TLS is pretty much standard. Unless you mean in some other way I am not paying attention to.


I agree it is "pretty much standard" but the ISPs and other network providers are not doing this with TLS traffic. They are only injecting the scripts in HTTP requests without TLS, at least in my experience.


Cox is absolutely MITM this too. HTTP/HTTPS it doesn’t matter. Terminate the tunnel, forge a cert and QED.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: