Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

131–140 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#131

When reading about Comcast I was always wondering why they have no competition when everyone who comments is complaining. I live in France and use Orange as my fibre provider. 1 Gbps/250 Mbps without constraints. I used to have Free which was great but did not offer fibre when fiber was installed. I switched to Orange in 5 min via a web page. I have another possibility (SFR) but they are despicable liars and for this…

Not to disagree with any of the other points, but it's always worth remembering that any physical utility in the US has approximately 16x more land to cover than France. Not to mention the greater variety in climates (which do impact utilities).

Some cities only have one existing fiber line even coming into them, usually owned by one of the local duopolies (typically phone, since they originally were required to offer phone service to everybody).

This gives incumbents an immediate advantage in terms of reaching customers with physical infrastructure, before counting any of the (admittedly fucked) politics involved.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#132

When reading about Comcast I was always wondering why they have no competition when everyone who comments is complaining. I live in France and use Orange as my fibre provider. 1 Gbps/250 Mbps without constraints. I used to have Free which was great but did not offer fibre when fiber was installed. I switched to Orange in 5 min via a web page. I have another possibility (SFR) but they are despicable liars and for this…

You were able to switch in 5 minutes because nothing actually changed except who sent you the bill. In the US this isn't possible because whoever owns the physical wire/fiber into your place gets to bill you, exclusively.

Yes, there is one cable and everyone has to share it, by law.

I thought that AT&T was split once in the past to differentiate backbone and service providers - why not in the case of fiber?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#134
post #4

The gigantic image: https://i.imgur.com/kN2rMhK.jpg (source: http://comcastsupport.i.lithium.com/t5/image/serverpage/imag... - URL manually edited to display largest possible size) I paged through the JS curiously, and found the URL bnpsa.g.comcast.net/images/mydevicealert/browser/. I wondered what would happen if I hit that from my ISP in Australia. I was surprised: I got an NXDOMAIN back. But I discovered that goog…

Here it is in code: https://gist.github.com/thoroc/f4d043ead762392561256e20dea81...

Doesn’t look like much has changed over the last 5 years.

https://gist.github.com/ryankearney/4146814/42d9ca5ec42fe43c...

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#135

Earlier quoted context omitted.

> Comcast can just start demanding that their customers install their root cert and that's that. Comcast can demand all they want but they are going to have to hand hold a lot of people though the process. Sure Windows/Mac could offer a nice executable to install it for you but you still have to get people to install it and that’s not something there while customer base will be able to do. The process of installing C…

I remember Kazakhstan announcing that policy, but I never saw the fallout. Did anyone write it up in English?

They tried a couple of times (not been keeping tabs on them too closely) to get a root cert into Mozilla - https://bugzilla.mozilla.org/show_bug.cgi?id=1232689 but were denied until they get a valid BR audit, https://bugzilla.mozilla.org/show_bug.cgi?id=1331364 But has yet to answer the follow up questions so the request hasn't progressed.

They published a response to the backlash - http://mic.gov.kz/en/news/matters-using-registration-certifi... saying that it would only be used to improve the security when accessing foreign resources, battle porn terrorism and transnational crime.

Dunno what the adoption rate of the cert was or if they do force the use of the cert when accessing foreign https sites

They quietly removed the notice off the telecom's websites saying that people will need to install the cert or may lose access to foreign https sites (not from kazakhstan) but I would expect someone would of gotten word out if they had (Maybe they did and i've just not come across it).

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#136
TFA mentions a Comcast tech referencing RFC 6108:

"[JL] This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108, which has been in place for many years now."

However, RFC 6108 requirement for use R3.1.1 states:

   R3.1.1.   Must Only Be Used for Critical Service Notifications
             Additional Background: The system must only provide
             critical notifications, rather than trivial notifications.
             An example of a critical, non-trivial notification, which
             is also the primary motivation of this system, is to advise
             the user that their computer is infected with malware, that
             their security is at severe risk and/or has already been
             compromised, and that it is recommended that they take
             immediate, corrective action NOW.
RFC 6108:

https://tools.ietf.org/html/rfc6108

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#137

Let me just drop Comcast like a bad habit. Oh wait. I can’t. There’s not another provider in my area with similar speeds. So I’m screwed.

I know and 90% of the web wants to give Comcast even more power to keep out competition by turning the Internet over to lobbyists.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#138
post #123

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

If only there were some way to notify your users that wasn't so scummy... like via email or regular mail

In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective.

Is that the idea here?

Or does this efficacy come at some cost (namely, the sentiment behind this thread)?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#139

You have really pathetic law in the US. After something like that in Europe, the company managers would have really huge problems. And in US people seem to be happy about that. If they wouldn't, it would be changed.

No one is happy, but we have almost zero opportunity to affect change. Look at the FCC's deliberately crappy email campaign for responses on eliminating net neutrality. They won't even release the data to a state DA. Between gerrymandered districts and lock step Republicans controlling everything currently, not to mention local monopolies by the biggest ISPs, our ability to affect change is virtually zero.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#140
post #94

Earlier quoted context omitted.

A mortgage and tuition for kids is a powerful motivator.

A good person doesnt blindly follow orders period. You dont get to call yourself a good person just because you signed a mortgauge or had a kid. If your actions are bad, then you are bad.

Reality forces a choice between lesser evils at times.
Post reply on HN