AT&T Wifi hotspots inject unwanted advertisements to websites

Wifi hot spots of the American telecom provider AT&T automatically inject advertisements in websites which allows third parties to track the user's surfing behavior. Researcher Jonathan Mayer discovered this when he connected to a free AT&T hotspot on an airport.

fcc

When he was browsing he noticed that the websites he visited showed advertisements on unexpected positions. Even the site of government organisation FCC, which is normally ad-free, contained advertisements when connected to the AT&T hotspot. Mayer discovered that the telecom provider tampers with the HTTP traffic and injects advertisements through a startup called RaGaPa.

This startup advertises their service with the slogan, "monetize your network" and allows hotspot providers to add additional information to websites, including the content of advertising networks. In the case of AT&T the startup adds code that makes it possible to show ads on browsers that have javascript either enabled or disabled. The code then loads advertisements from third-party advertising networks.

Besides the drawback of getting cluttered pages with additional advertisements, there's another. "It exposes much of the user’s browsing activity to an undisclosed and untrusted business", Mayer writes. "It tarnishes carefully crafted online brands and content, especially because the ads are not clearly marked as part of the hotspot service", he continues.

The researcher calls for AT&T to stop with injecting advertisements in their Wifi hotspot traffic and underlines the importance of HTTPS for websites.  ecause HTTPS traffic is encrypted it's impossible for third parties to inject content. Unfortunately HTTPS is still rather costly and complicated for most website owners which is why not all websites support it (yet).

No posts to display