I wonder if a website could sue Comcast for copyright violation.
Unfortunately if this were to happen and it succeeded, the precedent would kill the Web Archive. :(
Comcast is injecting 400+ lines of JavaScript into web pages
161–170 of 498 posts
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#162Most interesting part was the reply from the Comcast employee.
Yes, indeed it was. It's a fairly standard, unsurprising response for this situation; doesn't try to be defensive, doesn't try to provoke. [Edit: I'm horribly under-perceptive, after reading other comments I see I'm a bit off.] But... this bit. > ... [JL] This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108 , which has been in place for many years now. ... Oh, interesting, w…
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#163Earlier quoted context omitted.
I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. It was an automated advertisement done in a very not good way; Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this? The reason everyone is freaking out is because they feel p…
> I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. I am skeptical of this - maybe we made a mistake in telling the customer that. The people that are sent notifications are carefully checked to match the EOL/EOS modem criteria or speed mismatch criteria and would not be sent otherwise. It is sometimes the case that a customer has recently…
As a Comcast customer, I request you discontinue this injecting of javascript into webpages for ANY reason, unreasonably limiting an INFINITE RESOURCE and monopolizing localities so you are the only viable choice. This should not be the behavior of the largest telecom provider in the continental US. We deserve better.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#164I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…
> Do we, as a community, have any mechanism to detect if these sorts of attacks are occurring?
Yes, Caddy can detect whether a connection is being MITM'ed: https://caddyserver.com/docs/mitm-detection
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#165Earlier quoted context omitted.
>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.
> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…
And mail pieces don't produce the potentially rather widespread indignation that traffic injection does. Granted, I don't see the harm in it that a lot of people here do. Unencrypted traffic is unencrypted traffic - open to tampering by anyone, not just Comcast, and for many less innocuous reasons than the one for which you've chosen to do so. But with Let's Encrypt, browser manufacturers, and friends leading the charge toward TLS everywhere or as nearly so as is practical, and with most sites that most people use already employing TLS, the attack surface is closing for even an other-than-innocuous variant of your notification methodology. Of course, that also means that that methodology itself is reaching a natural end-of-life, as it cannot work anywhere that TLS exists, and the majority of the web where it does exist continues to grow. If this low-latency notification scheme is of unique value to your business, then now is the time to consider replacing the outdated technology that underpins it with something which will continue to work reliably over the next decade or two.
All that said, I appreciate your decision to engage in this forum. That's unprecedented in my experience from someone in a position like yours, and I wouldn't mind seeing more of it.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#166Earlier quoted context omitted.
In a natural monopoly regulation /increases/ competition and freedom for the consumer. The BBC had an article about this a few years ago [0]. Basically the highly regulated countries had cheaper and faster internet. > Rick Karr, who made a PBS documentary in which he travelled to the UK to find out why prices were lower, says that the critical moment came when the British regulator Ofcom forced British Telecom to all…
It might be easier to convince me ISPs were a natural monopoly if they weren't also a legally protected monopoly where they are, and generally have plenty of competition where they aren't.
I’m prone to suspicion of their business practices too, but every one of the Comcast technical staff I’ve met, from Jason down, has been an excellent person deeply committed to the best mission of a telecoms company, enabling human communication. Is that a marketing campaign? Yes, but as far as I can tell it’s an honest campaign of showing the world who they are and what they care about.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#167Earlier quoted context omitted.
> I mean, I know the answer is "government" and government making them a monopoly, but still. WTF. Eh, telco infrastructure is a natural monopoly. No government needed for that.
Bs. Heard about the 1996 telecommunicatins act? The government payed for their monopoly, and now it lets them keep it and not share it.
The problem with anti-government rhetoric in the US is it creates a self-fulfilling prophecy. Government is not inherently as incompetent and weak as yours often is.
There is no reason why a regulatory solution cannot work in the US when they work well in many other countries of greatly varying size and population density.
If your government fails you, that is not a failure of government: it is a failure of your government.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#168Earlier quoted context omitted.
If only there were some way to notify your users that wasn't so scummy... like via email or regular mail
In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#169Earlier quoted context omitted.
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…
All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.