Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

141–150 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#141
post #67

Earlier quoted context omitted.

Not HTTPS Everywhere, the extension, which has ridiculous system demands.

Perhaps you might like to suggest a replacement and or reasons for your statement?

I stated the reason, and I don't have a replacement. It's a great idea, but for now I'll have to wait for websites to enforce https on their users. But of course it can work for you if you have the resources to spare.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#142

Earlier quoted context omitted.

>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.

> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…

If his modem is actively interfering with your network I could see that this is critical. If he has been hacked and is actively DDOSing sites, that’s critical. We can debate the correct response in those cases (getting on the phone and calling seems to work really well when you want people to pay you, as does turning off service).

Unless I’m misunderstanding, this was not causing such a problem. Casting it as a customer good is rhetorically amusing, and probably holds water with people who are predisposed to agree with you, but I can make any number of morally bankrupt decisions using exactly the same logic. You have simpler ways to deliver this message, that do not cause nearly as much harm to your customer and do not require you to intercept and modify their traffic.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#143

When reading about Comcast I was always wondering why they have no competition when everyone who comments is complaining. I live in France and use Orange as my fibre provider. 1 Gbps/250 Mbps without constraints. I used to have Free which was great but did not offer fibre when fiber was installed. I switched to Orange in 5 min via a web page. I have another possibility (SFR) but they are despicable liars and for this…

Not to disagree with any of the other points, but it's always worth remembering that any physical utility in the US has approximately 16x more land to cover than France. Not to mention the greater variety in climates (which do impact utilities). Some cities only have one existing fiber line even coming into them, usually owned by one of the local duopolies (typically phone, since they originally were required to offe…

Then why do Americans in large urban centers not have greater choice of ISPs? If it's all about physical distance, why is there still no competition in dense areas?

I live in Washington DC, in the city, and I only really have one choice where I live, Comcast.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#144
post #109

Earlier quoted context omitted.

What he is saying is that they exhausted all other contact methods. If they stopped after the email and let the persons modem stop working, they would have likely been livid about that as well. Look, I don’t like Comcast any more than you do. But at some point, you need to recognize your biases when evaluating your enemy. I thought this was some nefarious attack based on the headline, but it’s just a critical system…

I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. It was an automated advertisement done in a very not good way; Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this? The reason everyone is freaking out is because they feel p…

> I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem.

I am skeptical of this - maybe we made a mistake in telling the customer that. The people that are sent notifications are carefully checked to match the EOL/EOS modem criteria or speed mismatch criteria and would not be sent otherwise. It is sometimes the case that a customer has recently upgraded their device but their old device remains provisioned and on their account (and needs to be removed), which sometimes explains this.

> It was an automated advertisement done in a very not good way;

It was not an ad - it was a request that the customer replace/upgrade their device. They can buy that anywhere, whether used on eBay or new on Amazon, etc.

> Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this?

We've been working to greatly simplify billing, as customers have told us for some time that we were packing too much info into those statements and it was sort of information overload.

> The reason everyone is freaking out is because they feel pretty darn strongly that the ISP should not be injecting code into webpages delivered,

Available alternatives are not great, such as using DPI everywhere, DNS modification (we use DNSSEC), or a walled garden (all service disrupted while in walled garden). These methods tend to be more costly and cause more disruption for customers. As noted elsewhere, we're working on better methods and part of that might depend on Internet-wide standards rather than something Comcast-specific (which is always my personal preference).

> If this is to be a service, the bar for what is necessary for such information must be far higher than "an automated system decides it's time." We get into really scary territory just by doing this in the first place, but to use it for advertisements or basic maintenance? That is a misuse of such technology.

It's not basic maintenance - that should always be transparent to customers. This is about moving to new technology from outmoded technology. A good example of a key concern for modem upgrades is that the vendor does not support it any longer and the software/hardware is 8 - 10 years old.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#145

I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…

HTTPS does prevent this. This can only be injected on non-secure connections.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#146

Let me just drop Comcast like a bad habit. Oh wait. I can’t. There’s not another provider in my area with similar speeds. So I’m screwed.

I know and 90% of the web wants to give Comcast even more power to keep out competition by turning the Internet over to lobbyists.

90% of the web? Who specifically are you talking about? Is this big-startup-co or...?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#147

Earlier quoted context omitted.

>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.

> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…

Like most on this thread, I think that injecting code is a step too far, but I definitely appreciate that you took the time to explain the motivations behind this.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#148

Earlier quoted context omitted.

Good engineers don't do evil things, even if their bosses tell them to.

"Good" as in morally upright? (in which case true). or "Good" as in technically competent? (in which case untrue).

it's the engineer part that suggests the moral uprightness. without that, it's more "developer"

"good" as in having the qualities required for a particular role, as per Google.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#149

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

Thank you so much for participating in this discussion! Frequently having people like you who actually involved in what's being discussed is part of what makes HN special to me and many others.

As another comment points out though, I'd also like to understand why it was decided to comminate by injecting JS into pages people are visiting rather than following a more traditional communication channel like snail mail. I assume that this solution scales better and has get immediate $ attached. However, it also seems obvious to me that it reenforces brand image and political issues people have with your company.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#150

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

All that may be true.

There is no ethical excuse to ever inject code into a webpage.

Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it.

You should be embarrassed to attach your name to such an obviously poor decision.

Post reply on HN