J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…
I think it's amazing Comcast documented their MITM attack as an RFC. Are those still literally Requests for Comments? Are the comments collected anywhere?
Comcast is injecting 400+ lines of JavaScript into web pages
281–290 of 498 posts
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#282Re: Comcast is injecting 400+ lines of JavaScript into web pages
#283Or do modern browsers mitigate that?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#284The thing that's so irritating about large telco's is not just that they're evil, but the casual stupidity of their actions, including their evil actions. I mean, look at the code. Look at the function of this code. Look at the business purpose of this code. Look at the security aspects of using this code. Look at the legal ramifications (why the hell is that LGPL thing up top there ?). Look at their internal communi…
> How can an organisation that executes this badly become this big ? Lots of ads, undercut your competition by something like $1 and "new customer deals" and then shaft your customers after a while The average customer just go to the store with the flashier lights (or the one which is more convenient)
When there even is any competition. Where I live, it's literally Comcast or else tether my mobile phone. Satellite is technically an option, but realistically between the cost and my tree coverage there's no way to make it work.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#285Earlier quoted context omitted.
Use HTTPSEverywhere on your browsers, and then enjoy the "You're close to your monthly limit!" pop-up on the Steam Store!
What?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#286Does Comcast inject this code in https urls or just http urls? Since https transfer is encrypted I suspect the code injection can't be done. Can someone please tell if my reasoning is correct?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#287Comcast forced me to upgrade a perfectly acceptable modem so I would have to option to have higher speed service (which I do not want)! Here's what they did: 1. asked me to upgrade the modem (emails and letters) 2. Inserted a filter on my line so I lost my connection 3. I bought a new modem (not realizing they stuck a filter there) 4. They removed the filter I guess this approach does not scale as well as the 400 lin…
What spec of DOCSIS was your old modem? If it was 1.0, 1.1, or 2.0, sorry you lose all support, the older specs had hard bonded channels that HD TV on them after the swap that they informed people of for 2 years before it happened. And they put TV on them since they were degrading channels due to overuse across the entire network (as in across the country). The later specs allowed for floating channels based on chann…
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#288Earlier quoted context omitted.
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…
All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#289Could Comcast hijack DNS and redirect https requests to a page explaining the issue with a button that lets the user go back to the site they wanted to visit? Or do modern browsers mitigate that?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#290Earlier quoted context omitted.
What?
I think the intent was to comment that extensions don't protect programs with embedded web views, like the steam store. I'd hope the steam store is using https though...