Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

241–250 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#241

The thing that's so irritating about large telco's is not just that they're evil, but the casual stupidity of their actions, including their evil actions. I mean, look at the code. Look at the function of this code. Look at the business purpose of this code. Look at the security aspects of using this code. Look at the legal ramifications (why the hell is that LGPL thing up top there ?). Look at their internal communi…

>obviously this has not passed legal review //

What makes that obvious to you - appears to pass the "we're unlikely to be fined and any fine will be too small to bother us" legal review.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#242

Earlier quoted context omitted.

downvoting because of snarkyness. Your suggestion of alt cmu channel is good however.

Downvoting because they weren't that snarky and because of your smugness. Your willingness to tell some one straight up why you downvoted them was good however.

why am I smug? I totally agree with the premise and personally hate comcast, but if _jal wants to be taken seriously by jlivingood, snarkyness isn't the way to go.

I don't mind the anon downvotes though, it's par for the course anywhere.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#243
post #210

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

As a web developer this feels like an absolutely terrible practice. I have to support contracts for website performance, quality and behavior with clients and you could be putting us in breach. If I got a bug report of unexpected ads popping up, we'd probably waste thousands trying to figure this out.

You can avoid this by using HTTPS.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#244
post #198

Earlier quoted context omitted.

So they print Important Plan Information on the envelope.

Time-Sensitive, Open Immediately You know it's actually an important piece of mail when the envelope isn't imploring you to open it.

The most serious snail mail correspondence is utterly and completely plain.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#245
post #109

Earlier quoted context omitted.

I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. It was an automated advertisement done in a very not good way; Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this? The reason everyone is freaking out is because they feel p…

> I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. I am skeptical of this - maybe we made a mistake in telling the customer that. The people that are sent notifications are carefully checked to match the EOL/EOS modem criteria or speed mismatch criteria and would not be sent otherwise. It is sometimes the case that a customer has recently…

Just a small note that as a customer I would prefer to be redirected to a notice hosted on your website so there is no confusion about the source of the notification. If I saw this pop up on a website I visited daily I would probably think it was spam and ignore it.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#246

Earlier quoted context omitted.

I'm curious if there's a way to hash your code, so... I guess this can be overwritten as well. But like a check sum to make sure your client code is the same as you made it. HTTPs is good, got it.

Subresource integrity checking. Most CDNs provide tags with these hashes.

But the MITM can just remove/change those hashes.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#247

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

Can you discuss why DOCSIS 3.0 users get this notice? I have a 3.0 modem, and received the notice, but it looks like my modem will still support my speed tier (75mbps in Chicago)

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#248

Earlier quoted context omitted.

All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.

There is no ethical excuse to ever inject code into a webpage. ...unless it's for adblocking... Although I do that with a MITM proxy locally (and thus filters everything on my LAN), it would certainly lead to a very interesting situation if an ISP decided to do it...

I mean, the end-user who requested the page certainly has a right to voluntarily inject script into the page they requested as it is rendered in their own browser running on a machine they own connected to an upstream internet provider they pay for access? Nice try at false equivalence however.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#249
post #231

Comcast is not alone in this. Cox Communications has been injecting code into HTTP traffic for years. I think sometime around 2008 I first saw them do it (I noticed NoScript blocking a script on a page that it wouldn't normally). If I remember correctly, following it to its source hinted that it was a test for some alert system. In 2012 I saw them injecting a script to notify people that their email servers were down…

> As far as I know they haven't injected anything into my SSL/TLS traffic... yet.

You say that as if it were even possible. Or are you referring to the use of SSL stripping?

HSTS preloading (or visiting a site with HSTS headers that you've previously visit) will protect you from even that.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#250

This is the bit I find amazing: > Comcast has my phone office number, my cell for texts, my email, and my home address, yet they choose to molest my requested web pages by injecting hundreds of lines of code. [JL] The notice is typically sent after a customer ignores several emails. Perhaps some of those ended up in your spam folder? So ignoring spam entitles you to this behaviour?

What he is saying is that they exhausted all other contact methods. If they stopped after the email and let the persons modem stop working, they would have likely been livid about that as well. Look, I don’t like Comcast any more than you do. But at some point, you need to recognize your biases when evaluating your enemy. I thought this was some nefarious attack based on the headline, but it’s just a critical system…

I hate to be too cynical, but in today's 'regulatory framework' it's easy to interpret this method of "notification" as merely a test to use for future notifications.

Not getting fast enough Netflix? Here's your message, injected every time you go to their site. Not getting the best search results? Try the new Xfinity search, it's faster and won't cost you the $.002 that Google search will cost.

This is a very slippery slope, and one that we're already sliding down thanks to Ajit Pai's FCC.

Expect to see more of this behavior from Comcast, as no amount of customer outcry can now prevent it.

Post reply on HN