Earlier quoted context omitted.
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…
First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…
Comcast is injecting 400+ lines of JavaScript into web pages
301–310 of 498 posts
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#302Earlier quoted context omitted.
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…
Can you discuss why DOCSIS 3.0 users get this notice? I have a 3.0 modem, and received the notice, but it looks like my modem will still support my speed tier (75mbps in Chicago)
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#303I'm annoyed by this on several levels. The biggest issue is that I'm using an Arris SB 6121 and I'm getting notifications that my modem is EOL. However, the SB6121 is listed as a supported modem for my speed level on their supported modems page. If I go to their supported modem page, I literally get a page where my current modem is shown as not supported, and the exact same modem is shown next to it as "supported." I…
There is a reason they are doing this. After signing up for Xfinity I noticed that the modem we were leasing was broadcasting a public access point with no way to disable it. I purchased my own modem immediately. Then some time later they rolled out their mobile services, which you guessed it, rely’s on those open access points and Sprint as a fall-back. So now customers are paying monthly to host Xfinity mobile serv…
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#304I'm annoyed by this on several levels. The biggest issue is that I'm using an Arris SB 6121 and I'm getting notifications that my modem is EOL. However, the SB6121 is listed as a supported modem for my speed level on their supported modems page. If I go to their supported modem page, I literally get a page where my current modem is shown as not supported, and the exact same modem is shown next to it as "supported." I…
FCC complaints are usually more effective, never dealt with one in the current shitty administration, but legally the FCC requires resolution within 7 business days, or at least a plan of action if resolution isn't possible for completion. I used to receive the emails and all the people on an FCC chain put pressure on the lower levels.
Getting support after a while wasn't working (to be polite he was getting the runaround), but the FCC complaint got their attention and got the issue resolved. This was with the previous administration, which was was more sympathetic, but still worth a try.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#305Earlier quoted context omitted.
All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.
Indeed. Whoever thinks this is fine would probably also be okay with the telephone company injecting jingles into your phone conversations every 30 seconds.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#306Earlier quoted context omitted.
First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…
> Snailmail is fine; you try to upsell me constantly through that channel already. Implying you’d probably miss it and, if not you, the customers they’re trying to reach.
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#307Earlier quoted context omitted.
> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…
Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. And if Comcast can afford to send that much junk mail, I should tend to think Comcast can afford to send one or two, or five, mail pieces that carry a warning like ACTION REQUIRED TO MAINTAIN SERVICE on the envelope, to those of who…
Lots of reasons, including years of experience with response rates for particular types of messages / calls to action. Clearly one particular communications channel won't work for everyone - each person has their own preferences. One of the things we're working on is to better enable you to control just that - basically one person may ask for SMS messages, another alerts via their mobile app, another via email, another via phone call, etc. You can see the beginnings of that in MyAccount / Settings / Communication & Ad Preferences.
> But with Let's Encrypt, browser manufacturers, and friends leading the charge toward TLS everywhere or as nearly so as is practical, and with most sites that most people use already employing TLS, the attack surface is closing for even an other-than-innocuous variant of your notification methodology.
Agree. And more TLS is better IMHO. I also like the work that Let's Encrypt has been doing - they've had a really big impact on the adoption of TLS. (See also http://labs.comcast.com/innovation-fund-spotlight-lets-encry...)
> Of course, that also means that that methodology itself is reaching a natural end-of-life, as it cannot work anywhere that TLS exists, and the majority of the web where it does exist continues to grow. If this low-latency notification scheme is of unique value to your business, then now is the time to consider replacing the outdated technology that underpins it with something which will continue to work reliably over the next decade or two.
You bet - totally agree! One of the places we're engaging to try to do that is in the IETF's CAPPORT working group and I think the charter describes reiterates all the points you made: https://datatracker.ietf.org/wg/capport/about/
> All that said, I appreciate your decision to engage in this forum. That's unprecedented in my experience from someone in a position like yours, and I wouldn't mind seeing more of it.
My pleasure & thanks for being a customer that's willing to offer constructive criticism. :-)
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#308Earlier quoted context omitted.
> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…
If his modem is actively interfering with your network I could see that this is critical. If he has been hacked and is actively DDOSing sites, that’s critical. We can debate the correct response in those cases (getting on the phone and calling seems to work really well when you want people to pay you, as does turning off service). Unless I’m misunderstanding, this was not causing such a problem. Casting it as a custo…
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#309As a site owner, could I prosecute Comcast for infringing on my rights by altering the content of my pages?
Re: Comcast is injecting 400+ lines of JavaScript into web pages
#310Earlier quoted context omitted.
Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. And if Comcast can afford to send that much junk mail, I should tend to think Comcast can afford to send one or two, or five, mail pieces that carry a warning like ACTION REQUIRED TO MAINTAIN SERVICE on the envelope, to those of who…
> Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. Lots of reasons, including years of experience with response rates for particular types of messages / calls to action. Clearly one particular communications channel won't work for everyone - each person has their own preferences.…
The fact that Comcast has and abuses its monopoly is bad enough. That you would try to standardize your abusive behavior is appaling.