{"id":5,"date":"2015-06-29T17:49:03","date_gmt":"2015-06-29T17:49:03","guid":{"rendered":"http:\/\/ipv.sx\/blog\/?p=5"},"modified":"2015-06-29T17:49:03","modified_gmt":"2015-06-29T17:49:03","slug":"attacks-on-non-secure-http","status":"publish","type":"post","link":"https:\/\/ipv.sx\/blog\/2015\/06\/29\/attacks-on-non-secure-http\/","title":{"rendered":"Attacks on non-secure HTTP"},"content":{"rendered":"<p>The last few months have been a bounty of attacks against non-secure HTTP &#8212; things that HTTPS would have prevented. \u00a0This post is just a collection of links for reference.<\/p>\n<ul>\n<li><a href=\"http:\/\/arstechnica.com\/tech-policy\/2014\/09\/why-comcasts-javascript-ad-injections-threaten-security-net-neutrality\/\">Comcast injecting ads into their customers\u2019 web traffic<\/a><\/li>\n<li><a href=\"https:\/\/gigaom.com\/2015\/02\/19\/dont-let-att-mislead-you-about-its-29-privacy-fee\/\">AT&amp;T tracking their users\u2019 browsing habits<\/a><\/li>\n<li><a href=\"https:\/\/www.eff.org\/deeplinks\/2014\/11\/verizon-x-uidh\">Verizon injecting tracking headers<\/a><\/li>\n<li><a href=\"http:\/\/www.zdnet.com\/article\/optus-hands-over-customers-numbers-to-websites\/\">Optus handing out customer phone numbers in HTTP headers<\/a> (a practice known euphemistically as &#8220;<a href=\"http:\/\/www.juniper.net\/techpubs\/en_US\/junos-mobility11.4\/topics\/concept\/httphe-mobility-overview.html\">HTTP<\/a> <a href=\"http:\/\/www.cisco.com\/en\/US\/prod\/collateral\/wireless\/ps11035\/ps11047\/ps11072\/solution_overview_c22-606224_ns973_Networking_Solution_Solution_Overview.html\">header<\/a> <a href=\"file:\/\/\/Users\/rbarnes\/Downloads\/Enabling%20Agile%20Service%20Chaining%20with%20Service%20Based%20Routing.pdf\">enrichment<\/a>&#8220;)<\/li>\n<li><a href=\"http:\/\/thejeshgn.com\/2015\/06\/15\/my-reply\/\">Bharti Airtel injecting JavaScript into web pages<\/a><\/li>\n<li><a href=\"https:\/\/citizenlab.org\/2015\/04\/chinas-great-cannon\/\">The \u201cGreat Cannon of China\u201d knocking Github offline<\/a><\/li>\n<li><a href=\"http:\/\/www.bgpmon.net\/the-canadian-bitcoin-hijack\/\">An unknown attacker hijacking BGP routes to steal bitcoin<\/a> [OK, I don&#8217;t know if the victims\u00a0were using HTTP or not, but they clearly weren&#8217;t using authentication &#8212; they would have been protected if they had used HTTPS.]<\/li>\n<li><a href=\"http:\/\/www.bgpmon.net\/turkey-hijacking-ip-addresses-for-popular-global-dns-providers\/\">Turk Telecom hijacking Google&#8217;s public DNS address space to provide bogus responses for YouTube\u00a0and Twitter<\/a><\/li>\n<\/ul>\n<p>Ping me at <a href=\"https:\/\/twitter.com\/rlbarnes\">@rlbarnes<\/a> if you&#8217;ve got others!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The last few months have been a bounty of attacks against non-secure HTTP &#8212; things that HTTPS would have prevented. \u00a0This post is just a collection of links for reference. Comcast injecting ads into their customers\u2019 web traffic AT&amp;T tracking their users\u2019 browsing habits Verizon injecting tracking headers Optus handing out customer phone numbers in &hellip; <a href=\"https:\/\/ipv.sx\/blog\/2015\/06\/29\/attacks-on-non-secure-http\/\" class=\"more-link\">Continue reading <span class=\"screen-reader-text\">Attacks on non-secure HTTP<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-5","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/posts\/5","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/comments?post=5"}],"version-history":[{"count":2,"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/posts\/5\/revisions"}],"predecessor-version":[{"id":7,"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/posts\/5\/revisions\/7"}],"wp:attachment":[{"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/media?parent=5"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/categories?post=5"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ipv.sx\/blog\/wp-json\/wp\/v2\/tags?post=5"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}