The Electronic Frontier Foundation worked with UC Berkeley's International Computer Science Institute to uncover a widespread program of search-hijacking by American ISPs. Many US ISPs run covert proxies that redirect certain lucrative search queries (made by customers who believe that they are searching Google or another search engine) to their preferred suppliers, pocketing an affiliate fee for delivering their customers. Participating ISPs, which include Cavalier, Cogent, Frontier, Fuse, DirecPC, RCN, and Wide Open West (Charter used to do this, but appear to have stopped), did not disclose the practice to their customers, who were meant to believe that they were getting the search results that their preferred search-engines had presented.
EFF and ICSI uncovered the vendor that supplied the hijacking software, a company called Paxfire.
Using EFF's HTTPS Everywhere Firefox extension and a search-engine that permits HTTPS logins (such as Google or DuckDuckGo) will prevent this sort of hijacking.
Widespread Hijacking of Search Traffic in the United States
The proxies in question are operated either directly by Paxfire, or by the ISPs using web proxies provided by Paxfire. Major users of the Paxfire system include Cavalier, Cogent, Frontier, Fuse, DirecPC, RCN, and Wide Open West. Charter also used Paxfire in the past, but appears to have discontinued this practice.
Why do they do this?
In short, the purpose appears to be monetization of users' searches. ICSI Networking's investigation has revealed that Paxfire's HTTP proxies selectively siphon search requests out of the proxied traffic flows and redirect them through one or more affiliate marketing programs, presumably resulting in commission payments to Paxfire and the ISPs involved. The affiliate programs involved include Commission Junction, the Google Affiliate Network, LinkShare, and Ask.com. When looking up brand names such as "apple", "dell", "groupon", and "wsj", the affiliate programs direct the queries to the corresponding brands' websites or to search assistance pages instead of providing the intended search engine results page.
(Image: 2005_South Africa_Centurion_DSCF0242, a Creative Commons Attribution Share-Alike (2.0) image from hmvh's photostream)
“Bentonite Me Baby” is a brand of “detox clay” that you spread on your face, or eat, to rid your body of mysterious, nonspecific “toxins.” It is full of lead.
Last December, Vtech, a crapgadget/toy company, suffered a breach that implicated the data of 6.3 million children, caused by its negligence toward the most basic of security measures.
Virtually all the climate scientists working at Commonwealth Scientific and Industrial Research Organisation — Australia’s answer to NASA — have been fired or moved out of climate research.
You travel around a lot. It might be that jet set life from New York to LA to London to Tokyo, or it might be back and forth from the coffee shop to the office, or from the kitchen to the couch. Any which way, you’re mobile and that’s the way to live. When you […]
It’s 2016 and we like our technology really small. Our phones fit in our pockets, our remotes are lighter than ever, and even our cars seem to be shrinking. So your new drone shouldn’t be an exception. This Axis VIDIUS Drone is 21% off right now and it’s so little, your biggest problem won’t be […]
You’ve heard the news: cyber security is the new and very scary frontier. Hackers are out there just waiting for you to relax for a second and let them in. But that’s not going to happen to you. With a lifetime premium subscription to ZenMate VPN, you’re completely protected from anyone out there who wants […]