Friday, February 6, 2015

2015-005- Is your ISP doing a 'man-in-the-middle' on you?

During our research with Lee Brotherston, who we had on last week for our podcast on threat modeling, we got to listen to one of his talks about how his ISP in Canada was actively doing a Man-in-Middle injection of a banner into sites that he visited.  


We were intrigued, and also gobsmacked (I can say that, right?) about the brashness of an ISP not apparently understanding the security implications of this, so we had him back on totalk about the finer points of his research.  The bad news? Other ISPs, including American ISPs are using this technology.


This is one of those podcasts that you need to tell your friends about, cause it's truly surprising the lengths ISPs go to injecting content into your pages.

 We also have a short message about the Bsides Las Vegas Proving Grounds this year... If you've wanted to present a paper at a conference, and have a mentor guide you through the process, hit them up on the Proving Grounds page at

Show notes (lots of info): 









"Dirty Rhodes" created by Kevin MacLeod ( 
Licensed under Creative Commons: By Attribution 3.0

Here is a new episode of Brakeing Down Security!

No comments: