The thing that's so irritating about large telco's is not just that they're evil, but the casual stupidity of their actions, including their evil actions. I mean, look at the code. Look at the function of this code. Look at the business purpose of this code. Look at the security aspects of using this code. Look at the legal ramifications (why the hell is that LGPL thing up top there ?). Look at their internal communi…
> I mean, I know the answer is "government" and government making them a monopoly, but still. WTF. Eh, telco infrastructure is a natural monopoly. No government needed for that.
Comcast is injecting 400+ lines of JavaScript into web pages
41–50 of 498 posts
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#42I wonder if a website could sue Comcast for copyright violation.
How is it copyright violation? If this is copyright violation, is it copyright violation of Comcast allowing you to download a file off the internet?
Comcast are playing into this interpretation by adding their own license to the code they're adding.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#43Earlier quoted context omitted.
"Must Only Be Used for Critical Service Notifications." [0] https://tools.ietf.org/html/rfc6108#section-3.1
> and is instead based in open IETF standards and open source applications. Why did the IETF ever agree to standardize this? It reminds me of their standardization of Cisco's "lawful intercept" router backdoor protocol. https://tools.ietf.org/html/rfc3924 https://www.blackhat.com/presentations/bh-dc-10/Cross_Tom/Bl... I guess this is what you get when the IETF literally has NSA agents as chairs of its groups. https:/…
>This RFC is not a candidate for any level of Internet Standard. The IETF disclaims any knowledge of the fitness of this RFC for any purpose
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#44Re: Comcast is injecting 400+ lines of JavaScript into web pages
#45https://github.com/jawj/IKEv2-setup https://github.com/trailofbits/algo etc.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#46The thing that's so irritating about large telco's is not just that they're evil, but the casual stupidity of their actions, including their evil actions. I mean, look at the code. Look at the function of this code. Look at the business purpose of this code. Look at the security aspects of using this code. Look at the legal ramifications (why the hell is that LGPL thing up top there ?). Look at their internal communi…
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#47Re: Comcast is injecting 400+ lines of JavaScript into web pages
#48Earlier quoted context omitted.
Yes. You can’t inject code in a TLS-secured connection unless you can MITM TLS and if they can do that, all is lost anyways.
There are several corporate firewall products that can do just that. Comcast can just start demanding that their customers install their root cert and that's that. Remember they are the only venue to access the internet for a lot of people, what are they going to do? Stop using the pretty much mandatory communication and information platform? I'm always surprised just how many people here on this site think you can f…
Regardless of what an ISP might do, HTTPS everywhere is excellent advice.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#49Oh and of course he's also retweeting a lovely Net Neutrality tweet... https://twitter.com/feamster/status/938236691126636546
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#50The gigantic image: https://i.imgur.com/kN2rMhK.jpg (source: http://comcastsupport.i.lithium.com/t5/image/serverpage/imag... - URL manually edited to display largest possible size) I paged through the JS curiously, and found the URL bnpsa.g.comcast.net/images/mydevicealert/browser/. I wondered what would happen if I hit that from my ISP in Australia. I was surprised: I got an NXDOMAIN back. But I discovered that goog…
https://gist.github.com/thoroc/f4d043ead762392561256e20dea81...