Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

181–190 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#182

Earlier quoted context omitted.

The yuppy nuremberg defense. From the excellent movie "thank you for smoking"

You guys sound like you're 20. You think things in the world are so "obviously" black and white. Comcast making shitty business decisions is not burning Jews in ovens. And the fact your not immediately laughed out of the room when you make such comparisons is the real sad reflection of society in this thread.

There are other companies doing much more evil things.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#183

TFA mentions a Comcast tech referencing RFC 6108: "[JL] This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108 , which has been in place for many years now." However, RFC 6108 requirement for use R3.1.1 states: R3.1.1. Must Only Be Used for Critical Service Notifications Additional Background: The system must only provide critical notifications, rather than trivial notificatio…

Yea they don't really follow that RFC, they just use that RFC as an all-justification for their action.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#184

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

Thank you so much for participating in this discussion! Frequently having people like you who actually involved in what's being discussed is part of what makes HN special to me and many others. As another comment points out though, I'd also like to understand why it was decided to comminate by injecting JS into pages people are visiting rather than following a more traditional communication channel like snail mail. I…

Yup, you may get a better attach rate at the cost of absolutely destroying any customer trust.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#185
post #123

Earlier quoted context omitted.

If only there were some way to notify your users that wasn't so scummy... like via email or regular mail

In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?

I don't know what's worse: the straw man attempt at arguing efficacy while focusing on the weaker of two suggested options, or the (presumably) unscalable slippery slope of dispatching personnel to a customer's front door.

In either case, the argument does not address the fact that customers recognize unsolicited packet injection as unacceptable ISP behavior. Without support metrics, we can argue all day about the efficacy of one method of delivery over another, but the fact remains that no sensible user would perceive e-mail and/or post of official notice from their ISP as overtly intrusive. With as much internal advertising as Comcast distributes amongst its existing customers, it blows my mind that official notice generated from boilerplate and delivered via snail mail would fail to achieve the intended goal.

To be sure, your pre-edited comment: > Surely showing up in-person at their door must be an even more effective "reminder" than the browser injection! Is that next?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#186

I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…

I'm curious if there's a way to hash your code, so... I guess this can be overwritten as well. But like a check sum to make sure your client code is the same as you made it.

HTTPs is good, got it.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#187

TFA mentions a Comcast tech referencing RFC 6108: "[JL] This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108 , which has been in place for many years now." However, RFC 6108 requirement for use R3.1.1 states: R3.1.1. Must Only Be Used for Critical Service Notifications Additional Background: The system must only provide critical notifications, rather than trivial notificatio…

I'm sure the comcast "tech" knows what's in the RFC. Look in the top-right corner; he's one of its authors. He's also replying in this thread.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#188

I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…

I'm curious if there's a way to hash your code, so... I guess this can be overwritten as well. But like a check sum to make sure your client code is the same as you made it. HTTPs is good, got it.

Subresource integrity checking. Most CDNs provide tags with these hashes.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#189
post #178

Earlier quoted context omitted.

Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. And if Comcast can afford to send that much junk mail, I should tend to think Comcast can afford to send one or two, or five, mail pieces that carry a warning like ACTION REQUIRED TO MAINTAIN SERVICE on the envelope, to those of who…

because traffic injection is free, postal mail costs money.

They have no problem snail mailing other adverts. There is also e-mail, so no excuse.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#190

Why don't they use the Chrome Extension - uBlock origin?

Ads from website owners are not new, what is new is ISPs injecting into other people's pages, this sets a new precedent. Its a fundamental principle that was violated, so saying "just block it" is like saying people in China should just use a VPN... while a valid point, its still an outrage to some people that a government/ISP would tamper/block your traffic. Not trying to equate Comcast to China by the way, just using a metaphor
Post reply on HN