Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

251–260 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#251
post #246

Earlier quoted context omitted.

Subresource integrity checking. Most CDNs provide tags with these hashes.

But the MITM can just remove/change those hashes.

Yes, if the index.html is not HTTPS or otherwise compromised.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#252
Comcast forced me to upgrade a perfectly acceptable modem so I would have to option to have higher speed service (which I do not want)! Here's what they did: 1. asked me to upgrade the modem (emails and letters) 2. Inserted a filter on my line so I lost my connection 3. I bought a new modem (not realizing they stuck a filter there) 4. They removed the filter

I guess this approach does not scale as well as the 400 lines of Javascript!

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#253

Earlier quoted context omitted.

Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. And if Comcast can afford to send that much junk mail, I should tend to think Comcast can afford to send one or two, or five, mail pieces that carry a warning like ACTION REQUIRED TO MAINTAIN SERVICE on the envelope, to those of who…

As was mentioned in the original thread, other means of attempting to contact the individual occurred. This was apparently not the first attempt or method used to contact individuals.

Perhaps the user read those emails and simply doesn't care to upgrade the modem. Unless those emails created an opportunity for the user to acknowledge receipt, then there will probably be numerous people who receive these popups despite receiving the emails, deliberating, and choosing to take no action.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#254

Earlier quoted context omitted.

I think it's amazing Comcast documented their MITM attack as an RFC. Are those still literally Requests for Comments? Are the comments collected anywhere?

You're wildly OT, I suggest Wikipedia.

Huh? Not even close to wildly OT. The RFC was mentioned above.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#255

Earlier quoted context omitted.

HTTPS does prevent this. This can only be injected on non-secure connections.

Use HTTPSEverywhere on your browsers, and then enjoy the "You're close to your monthly limit!" pop-up on the Steam Store!

Um, I assume the code for that pop-up is rendered into the page on the web server that produced the page, before being returned to the browser.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#257
post #195

Earlier quoted context omitted.

First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…

> Snailmail is fine; you try to upsell me constantly through that channel already. Implying you’d probably miss it and, if not you, the customers they’re trying to reach.

Then they ought to stop abusing the communication channels they have. If they send so much email and snail mail spam that the customer automatically ignores it, that's the choice they have made.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#258
post #237
post #195

Earlier quoted context omitted.

First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…

They do say they try to email you a bunch of times first... Email seems like a decent enough alternate channel.

They emailed my Comcast.net address, which I didn't even know I had.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#260
As a big ISP that stands to profit from the current FCC standpoint, Comcast is in the crosshairs of the internet community.

But if what has been said by all parties is true, I can't find significant fault with Comcast.

Here is the text of the "ad" (typed from viewing the attached image in the OP):

  Get ready, we're increasing Internet speeds in your area.

  Our records show that the modem you currently have connected to our network won't be able to handle these faster speeds, so we recommend updating your equipment.

  Buy from a Retailer

  Before you make your purchase, visit https://mydeviceinfo.xfinity.com to view a list of modems certified to work on our network with your speed tier.

  Lease and XFINITY Modem

  Call 1-855-242-2876 and we will send you a Self Install Kit

  Equipment Update
Seems appropriate and to the point. They tell the customer they can either go buy a modem from a retail store, or lease one from XFINITY. Hardly a high-pressure ad.

Injecting anything into a website makes me feel a bit dirty, but nobody has refuted Comcast's claim that other communication methods were tried first and that this was more of a last resort.

Speaking in general terms because I'm not involved deeply with DOCSIS, older devices are less efficient and generally use more spectrum(even in a cable, there are RF spectrum limitations) to deliver the same speeds. Customers using old devices that don't support the newer and faster standards reduce the total bandwidth available to all customers, increasing costs for both Comcast and its customers.

edit: fix formatting. HN needs a preview button.

Post reply on HN