Comment by abtinf

7 years ago

That link was useful, thank you. I don't find it hard to believe technically, but it strikes me as a fundamentally different practice than what I'd head of before. If I request for traffic to go to a certain IP, I expect it to be sent to that IP. MITMing and manipulating that traffic is bad, but not delivering it at all is qualitatively different. I suspect it could be grounds for a serious civil or criminal action.

I can confirm we run across transparent dns proxying with customers at DNSFilter all the time. Mobile carriers are the worst for doing this.

A few days ago it was a customers compromised router doing it.