Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

201–210 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#201
I am not fan of Comcast, but this is a bit of a tempest in a tea kettle. In over a decade of having their service, I have only seen them use this once, when my cable modem was nearing EOL and upgrading to a new modem that supported DOCSIS 3 (I think?) gave me a big speed boost. I probably wouldn't have looked at snail mail or email from them, so I appreciated it.

I guess their is a "slippery slope" argument to be made here, but in the current incarnation, this is innocuous.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#202

Earlier quoted context omitted.

In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?

I don't know what's worse: the straw man attempt at arguing efficacy while focusing on the weaker of two suggested options, or the (presumably) unscalable slippery slope of dispatching personnel to a customer's front door. In either case, the argument does not address the fact that customers recognize unsolicited packet injection as unacceptable ISP behavior. Without support metrics, we can argue all day about the ef…

Time Warner did show up at my door when they updated their speeds. I thought it was strange,and asked him to have Time Warner call and schedule a time, but it worked. He was going door to door.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#203

Earlier quoted context omitted.

I'm curious if there's a way to hash your code, so... I guess this can be overwritten as well. But like a check sum to make sure your client code is the same as you made it. HTTPs is good, got it.

Subresource integrity checking. Most CDNs provide tags with these hashes.

Thanks I will look into that.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#204

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

I think it's amazing Comcast documented their MITM attack as an RFC. Are those still literally Requests for Comments? Are the comments collected anywhere?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#205

Earlier quoted context omitted.

With all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.

But you probably wouldn't read it, because lots of people don't read their email (at least partially because of the junk).

Yes, but if you don’t get the speed Comcast promises you, and you paid attention to that, then you’d call them up, and find out that way.

More work, but way less scummy.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#206

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.

There is no ethical excuse to ever inject code into a webpage.

...unless it's for adblocking...

Although I do that with a MITM proxy locally (and thus filters everything on my LAN), it would certainly lead to a very interesting situation if an ISP decided to do it...

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#207

Earlier quoted context omitted.

>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.

> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…

>Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us.

This reminds me of the part in Romeo & Juliet where Sampson says "I do not bite my thumb at thee, but I do bite my thumb."

As other commenters have mentioned, these are such small distinctions to legitimize something as fundamentally troubling as javascript injections.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#208

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.

...unless the upgrade actually means loss of service due to incompatibility, in which case I would agree that is critical, but nonetheless "go buy a new modem" is something no customer wants to hear, especially if they're already paying $$$ every month for the service.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#209
post #198

Earlier quoted context omitted.

With all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.

So they print Important Plan Information on the envelope.

Time-Sensitive, Open Immediately

You know it's actually an important piece of mail when the envelope isn't imploring you to open it.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#210

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

As a web developer this feels like an absolutely terrible practice. I have to support contracts for website performance, quality and behavior with clients and you could be putting us in breach. If I got a bug report of unexpected ads popping up, we'd probably waste thousands trying to figure this out.
Post reply on HN