I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…
Comcast is injecting 400+ lines of JavaScript into web pages
191–200 of 498 posts
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#192Earlier quoted context omitted.
>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.
> And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" Making up quotes like this is against HN guidelines (and common decency).
Moreover there's nothing in the guidelines about "making up quotes" (which again isn't a reasonable interpretation of what that is), whereas there are actual, explicit guidelines against addressing yourself to unreasonably interpreted versions of other people's comments.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#193Earlier quoted context omitted.
I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. It was an automated advertisement done in a very not good way; Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this? The reason everyone is freaking out is because they feel p…
> I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. I am skeptical of this - maybe we made a mistake in telling the customer that. The people that are sent notifications are carefully checked to match the EOL/EOS modem criteria or speed mismatch criteria and would not be sent otherwise. It is sometimes the case that a customer has recently…
You admit alternatives exist, but decided to modify webpages anyway? Adding your own modifications to a copyright protected work (e.g. any web page) creates a derivative work. Generally only the copyright holder of the original work can create or authorize derivative works. Unless you have a license the copyright holder for each webpage you are modifying, this is copyright infringement. Why did your legal department approve a plant that might make the company liable for up to $150,000 per work infringed?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#194Earlier quoted context omitted.
I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. It was an automated advertisement done in a very not good way; Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this? The reason everyone is freaking out is because they feel p…
> I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. I am skeptical of this - maybe we made a mistake in telling the customer that. The people that are sent notifications are carefully checked to match the EOL/EOS modem criteria or speed mismatch criteria and would not be sent otherwise. It is sometimes the case that a customer has recently…
This is a perfect example of the culture problem at Comcast. You seem to have worked yourselves into believing that you're something other than a dumb pipeline. Now you feel entitled to stick your fingers into the content.
I suspect this mass-psychosis is coming from the top, and the need to move into higher-margin businesses. Keep your messages on xfinity.com.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#195J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…
Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled.
So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don't permit this one. Snailmail is fine; you try to upsell me constantly through that channel already.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#196Earlier quoted context omitted.
In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?
With all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#197I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…
As the other comment said, HTTPS does prevent this, and this only happens on HTTP pages. > Do we, as a community, have any mechanism to detect if these sorts of attacks are occurring? Yes, Caddy can detect whether a connection is being MITM'ed: https://caddyserver.com/docs/mitm-detection
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#198Earlier quoted context omitted.
In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?
With all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#199Earlier quoted context omitted.
Yes. You can’t inject code in a TLS-secured connection unless you can MITM TLS and if they can do that, all is lost anyways.
There are several corporate firewall products that can do just that. Comcast can just start demanding that their customers install their root cert and that's that. Remember they are the only venue to access the internet for a lot of people, what are they going to do? Stop using the pretty much mandatory communication and information platform? I'm always surprised just how many people here on this site think you can f…
I don't understand. Your second sentence seems to contradict your first; Comcast bribing legislators is a social/political attack. What did you mean?
I currently see more hope in tech solutions than political solutions to the problems of privacy, net neutrality, and script injection. We have the option to use content and routing encryption technology that looks something like TOR or I2P. Instead, we're asking politicians who don't understand the tech to protect us from ISPs who will never stop trying to leverage anything they can find in our traffic. Allowing Comcast to see the traffic at all is the problem, and politics will never prevent that.
If it's apparent to you that the political fight is more winnable, or that technical approaches to privacy are doomed, then what is the social/political solution to internet privacy? Because we don't have any right now, and it looks like we're losing the political war.