Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

331–340 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#332
post #292

Earlier quoted context omitted.

That's a weird HN-ism, though, not how writing or paraphrasing works anywhere else. The goal is understandable and laudable but 'redefining the meaning of quotes' is a thing only hardcore lispers can love.

This is not an "HN-ism". It is not proper to use quotation marks when paraphrasing. Doing so is explicitly attributing words to someone that they did not say. > not how writing or paraphrasing works anywhere else That's simply false. If you want to use Reddit et al as your standard reference on the use of language and punctuation, have at it. But you can't reasonably expect every other forum to use that lowest common…

That's simply false.

No, it isn't. I'm saying what somebody else is saying, in their voice. This goes in quotes, because it's someone else's speech, even if it's my version of their speech. The fact that they didn't actually say it comes from context. Punctuation is not semantic markup.

This doesn't come from reddit, it comes from, you know, the way people actually write. The fact that it requires repeated and lengthy explanations is a pretty decent indication it's not how anyone else writes.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#334

Comcast forced me to upgrade a perfectly acceptable modem so I would have to option to have higher speed service (which I do not want)! Here's what they did: 1. asked me to upgrade the modem (emails and letters) 2. Inserted a filter on my line so I lost my connection 3. I bought a new modem (not realizing they stuck a filter there) 4. They removed the filter I guess this approach does not scale as well as the 400 lin…

I don't understand the general attitude against forced modem upgrades. If you lease your modem it's as easy as walking into a Comcast store and swapping it for a new one. If you own your modem, pick the newest model of modem that fits your needs.

The newer modems support more channels and newer modulation/technology. This isn't just about supporting newer speeds. In order for them to support those newer speeds for other customers they have to upgrade their equipment to support more channels and newer modulation/technologies.

At some point these older technologies are not just wasting resources by being less efficient, but are preventing the company from upgrading their equipment.

The reason I don't understand, is because it's common to see people complaining about the state of broadband in America compared to other countries. Yet Comcast is probably the most progressive as far as pushing the technology goes. Don't misunderstand me, I believe Comcast holds a near/total monopoly in many locations around America but at least they're progressive with their network and technology despite the lack of meaningful competition.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#335
From Comcast's RFC that's linked in the thread:

> R3.1.1. Must Only Be Used for Critical Service Notifications

> Additional Background: The system must only provide critical notifications, rather than trivial notifications. An example of a critical, non-trivial notification, which is also the primary motivation of this system, is to advise the user that their computer is infected with malware, that their security is at severe risk and/or has already been compromised, and that it is recommended that they take immediate, corrective action NOW.

Not only is Comcast trying to justify this awful practice, they picked one of the worst possible examples to do so. There is no set of circumstances under which a 'You have malware!' popup should be taken seriously.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#336

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

I think it's amazing Comcast documented their MITM attack as an RFC. Are those still literally Requests for Comments? Are the comments collected anywhere?

Just because they have an RFC doesn't make it a standard, or socially acceptable. Anyone can submit an independent RFC.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#337

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

Wait wait WHAT?

This standard seems like a terrible mistake. Isn't this exactly what malware creators want? To condition users to click the browser pop up that says "YOUR COMPUTER IS INFECTED WITH MALWARE, CALL THIS NUMBER/INSTALL THIS HORRIBLE THING TO FIX IT?"

Why on Earth would anyone issue a standard that says that ISPs should deliver that kind of notification, thus training consumers to believe them?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#338

Earlier quoted context omitted.

In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?

With all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.

Maybe in the bill? Or online bill notification?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#339
post #308
post #142

Earlier quoted context omitted.

If his modem is actively interfering with your network I could see that this is critical. If he has been hacked and is actively DDOSing sites, that’s critical. We can debate the correct response in those cases (getting on the phone and calling seems to work really well when you want people to pay you, as does turning off service). Unless I’m misunderstanding, this was not causing such a problem. Casting it as a custo…

It's true that if there's a vulnerability discovered, and you have 50000 modems with the vulnerability, you cannot wait for the modems "to be hacked" to act. It is reasonable to try to replace EOL modems ASAP.

In this scenario do you honestly believe the best course of action is to insert a popup on web pages? If you are truly concerned you will act to preserve your network for all customers by blocking traffic from the problematic modem and then call the person. This is legally less risky than doing traffic inspection. (Losing common carrier status would be a very big deal.)

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#340

I'm annoyed by this on several levels. The biggest issue is that I'm using an Arris SB 6121 and I'm getting notifications that my modem is EOL. However, the SB6121 is listed as a supported modem for my speed level on their supported modems page. If I go to their supported modem page, I literally get a page where my current modem is shown as not supported, and the exact same modem is shown next to it as "supported." I…

FCC complaints are usually more effective, never dealt with one in the current shitty administration, but legally the FCC requires resolution within 7 business days, or at least a plan of action if resolution isn't possible for completion. I used to receive the emails and all the people on an FCC chain put pressure on the lower levels.

I can confirm that Comcast responds to FCC complaints effectively. I used that route when they were my provider after a series of unhelpful technical support requests.
Post reply on HN