Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

61–70 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#61

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.

This is just about the worst possible way to notify a customer of any issue anyway, because it legitimizes those stupid ad-based malware popups that have become so prevalent.

As more Comcast customers receive JS-based notices like these injected into their normal web traffic, any enterprising jerk can clone the message, change the links to point to their own phishing site, change or omit the phone number, and snag a whole bunch of unsuspecting Comcast customers.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#62
post #58

Earlier quoted context omitted.

All of these products require that a corporate root certificate is installed on the devices initiating the connection. This would require that all users install the cert on all devices, some of which do not allow such an install. I don’t think you can install certs of your choice on a PlayStation, an Amazon Echo, an Apple TV or any of the home automation systems. This would break all of those devices. It would also b…

So they'll be whitelisted. They just need to make use of FB/Google/Amazon/etc. websites impossible without the root cert and they can continue injecting ads into any website content. It's not like they care about injecting ads into PS4 API calls (yet). Also how hard do you think it would be for American telcos to push for inclusion of their MITM certificates? Especially if other companies like Verizon come aboard the…

Browser vendors distrusted whole CAs for less than full interception. In the end, all of this would require control over the device and Comcast can’t achieve that (unless legislated, but that’s a whole different ballpark)

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#63
post #37

Earlier quoted context omitted.

> I mean, I know the answer is "government" and government making them a monopoly, but still. WTF. Eh, telco infrastructure is a natural monopoly. No government needed for that.

Bs. Heard about the 1996 telecommunicatins act? The government payed for their monopoly, and now it lets them keep it and not share it.

They have to share the last mile infrastructure with new entrants. And the FCC can preempt local and state level requirements to help new entrants.

The current problems are that a) since Trump the FCC is shit, b) local municipalities "vowing" to not enter the market (and others have no incentive).

See these for b: - https://arstechnica.com/tech-policy/2017/11/voters-reject-ca... - https://www.wired.com/2013/07/we-need-to-stop-focusing-on-ju...

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#64
Unfortunately, in the US and Europe at least most people will care about this and even get a response. I think 4-5 years back when I was in one of the cities in which MTNL is there in India, ads were being served in the same way on MTNL. They were injecting an ad serving pop-up on every page served on HTTP. The worst thing was it sometimes used to show some sketchy virus ads also. I complained about it multiple times, never even heard back from them.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#65

The thing that's so irritating about large telco's is not just that they're evil, but the casual stupidity of their actions, including their evil actions. I mean, look at the code. Look at the function of this code. Look at the business purpose of this code. Look at the security aspects of using this code. Look at the legal ramifications (why the hell is that LGPL thing up top there ?). Look at their internal communi…

Under Ajit Pai's reasoning, by doing this, Comcast is adding to the evidence that it is an "information service" rather than a "communication service."

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#66
When reading about Comcast I was always wondering why they have no competition when everyone who comments is complaining.

I live in France and use Orange as my fibre provider. 1 Gbps/250 Mbps without constraints. I used to have Free which was great but did not offer fibre when fiber was installed. I switched to Orange in 5 min via a web page. I have another possibility (SFR) but they are despicable liars and for this reason alone I scraped them.

This is France, where competition is not a national sport so I was expecting the US to have 5 other companies banging on the door.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#67
post #39

Earlier quoted context omitted.

There are several corporate firewall products that can do just that. Comcast can just start demanding that their customers install their root cert and that's that. Remember they are the only venue to access the internet for a lot of people, what are they going to do? Stop using the pretty much mandatory communication and information platform? I'm always surprised just how many people here on this site think you can f…

They could, but they don't. Until they do, or imply in any way that they might, let's stick to the facts and leave wild, flailing speculation to reddit. Regardless of what an ISP might do, HTTPS everywhere is excellent advice.

Not HTTPS Everywhere, the extension, which has ridiculous system demands.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#68
post #51

Earlier quoted context omitted.

After all the horrible consumer practices Comcast does regularly you'll still give them the benefit of the doubt? How many times do they have to prove themselves as untrustworthy and consumer hostile that you'll stop sitting there and just hoping that next magical tech will make them stop trying to extract maximum money and inject ads into your stream? Yes, HTTPS is great and should be deployed everywhere. But thinki…

The technical capability to MiTM TLS exists since the very moment TLS was designed. It all hinges on the ability to get a trusted certificate for the domain you want to MiTM. You can do TLS MiTM with Apache if you choose to. Acquiring the Cert has always been the problem and nothing changed in that regard. Strictly speaking, things on that front have become harder since browsers are becoming more and more strict abou…

Comcast and their telco friends just managed to lobby legislation away while completely ignoring complaints and good business. It doesn't look like Americans have any power to fight against these companies so trust into other for-profit companies which are reliant to Comcast & Co. for their profits seems a bit optimistic to me :/

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#69
post #44

So how exactly is this not criminal?

They are not blocking, throttling, or interfering (in any way that harms functionality) with legal applications; in a nutshell that is 2015 requirement.

Now, if that Javascript happens to interact badly with some particular web page, then you could complain to the FCC as long as the 2015 rules remain in effect (which is more than a week, for what that's worth).

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#70

When reading about Comcast I was always wondering why they have no competition when everyone who comments is complaining. I live in France and use Orange as my fibre provider. 1 Gbps/250 Mbps without constraints. I used to have Free which was great but did not offer fibre when fiber was installed. I switched to Orange in 5 min via a web page. I have another possibility (SFR) but they are despicable liars and for this…

In a natural monopoly regulation /increases/ competition and freedom for the consumer.

The BBC had an article about this a few years ago [0]. Basically the highly regulated countries had cheaper and faster internet.

> Rick Karr, who made a PBS documentary in which he travelled to the UK to find out why prices were lower, says that the critical moment came when the British regulator Ofcom forced British Telecom to allow other companies to use its copper telephone wires going to and from homes.

> But US regulators took a different approach. Rather than encouraging competition between operators using the same network, the US encouraged competition between different infrastructure owners - big companies that could afford to build their own networks.

> Some believe that UK-style regulation is bad for competition and innovation, however, and suggest that the US is already one of the world leaders in broadband.

[0] http://www.bbc.co.uk/news/magazine-24528383

Post reply on HN