Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

371–380 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#371

Earlier quoted context omitted.

Writing style guides are a thing & a thing that have been around for a long time. All 3 of the style guides I’ve had reason to use (AP, MLA & CMS) all require that quoted material be direct quotes. Now, I think that it’s a fair argument that a web forum needn’t have the same formality as other written word, but your assertion that “it’s not how anyone writes” is clearly untrue. And just as a single data point, I expe…

I agree with pvg. The notion that a comment on HN is, in some sense, in poor form because it doesn't adhere to AP/MLA/CMS specifications is ridiculous. Nobody agreed to that, and I doubt anyone would even agree that that's accepted informally as a norm.

I didn’t mean to imply that the web should follow those style guides (and said as much). I was refuting his claim that no one expects that quotes imply an assertion of verbatim quote.

I certainly default to assuming it does and in many contexts it is an explicit rule.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#372

I'm annoyed by this on several levels. The biggest issue is that I'm using an Arris SB 6121 and I'm getting notifications that my modem is EOL. However, the SB6121 is listed as a supported modem for my speed level on their supported modems page. If I go to their supported modem page, I literally get a page where my current modem is shown as not supported, and the exact same modem is shown next to it as "supported." I…

There is a reason they are doing this. After signing up for Xfinity I noticed that the modem we were leasing was broadcasting a public access point with no way to disable it. I purchased my own modem immediately. Then some time later they rolled out their mobile services, which you guessed it, rely’s on those open access points and Sprint as a fall-back. So now customers are paying monthly to host Xfinity mobile serv…

So if they let themselves into your house while you were away and left a note in your dining table, you’d say there’s a reason they’re doing this?

There is not a reason to access and modify your private data. This is not some kind of out of band multiplexed signal, they are reaching into your applications and changing their behavior.

There are other ways to communicate with people you have a billing relationship with already in place.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#373
post #210

Earlier quoted context omitted.

As a web developer this feels like an absolutely terrible practice. I have to support contracts for website performance, quality and behavior with clients and you could be putting us in breach. If I got a bug report of unexpected ads popping up, we'd probably waste thousands trying to figure this out.

Exactly. The first thing I thought about when I saw this was the implications of having JavaScript that has not been tested in the context of a website running. You have no clue how it will conflict. As a website owner you should have the right to verify all code that will run on your website to be sure that it won’t cause issues since only you have the context needed to make that call. What if there’s a global DIV s…

I’ve had to patch against this in the past when it turned out my system was breaking for a set of users whose company was installing a browser extension that injected JS that broke the app. Never did find out exactly what it did, but I worked around it but fixing the progressive enhancement to work properly in the context of broken JS as well as no JS.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#374
post #300

Earlier quoted context omitted.

> edit: Proof https://imgur.com/lzKBkMs If you look at the far right device you see a non-EOL SB6121. The one on the left that is EOL is the leased one, and the retail one is still allowed. I'm not sure if you have a leased device or retail device.

Is there any technical difference between the two?

Technically, one makes money for Comcast.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#375

Earlier quoted context omitted.

I mean, the end-user who requested the page certainly has a right to voluntarily inject script into the page they requested as it is rendered in their own browser running on a machine they own connected to an upstream internet provider they pay for access? Nice try at false equivalence however.

What "false equivalence"? I was just pointing out an exception to the statement "There is no ethical excuse to ever inject code into a webpage".

It's false equivalence because you (and everyone else) knows that the case of an end user injecting script into a page on the receiving end of the connection is not the scenario under discussion, and is not the behavior that the rule implied by the earlier comment would be intended to prohibit. If the comment was tongue in cheek then I have misunderstood you and withdraw my objection :).

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#376

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.

Treating anyone this rudely is a bannable offence on Hacker News. Please take the civility requirement more deeply to heart (https://news.ycombinator.com/newsguidelines.html), and please don't do this again.

If a fellow community member has a first-hand involvement with a situation under discussion, such as working for a company that some people are mad at or does some wrong thing, we're all responsible for reacting responsibly. Otherwise bad things happen, such as first-hand observers being scared to post because they'll get lashed out at, and the already-weak community bonds we have here getting weaker. We all know what the culture of online shaming has led to and it's all our job not to do it on HN.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#377

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

Wait wait WHAT? This standard seems like a terrible mistake. Isn't this exactly what malware creators want? To condition users to click the browser pop up that says "YOUR COMPUTER IS INFECTED WITH MALWARE, CALL THIS NUMBER/INSTALL THIS HORRIBLE THING TO FIX IT?" Why on Earth would anyone issue a standard that says that ISPs should deliver that kind of notification, thus training consumers to believe them?

They're the ones who issued the standard. https://tools.ietf.org/html/rfc6108

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#379
post #332

Earlier quoted context omitted.

This is not an "HN-ism". It is not proper to use quotation marks when paraphrasing. Doing so is explicitly attributing words to someone that they did not say. > not how writing or paraphrasing works anywhere else That's simply false. If you want to use Reddit et al as your standard reference on the use of language and punctuation, have at it. But you can't reasonably expect every other forum to use that lowest common…

That's simply false. No, it isn't. I'm saying what somebody else is saying, in their voice. This goes in quotes, because it's someone else's speech, even if it's my version of their speech. The fact that they didn't actually say it comes from context. Punctuation is not semantic markup. This doesn't come from reddit, it comes from, you know, the way people actually write. The fact that it requires repeated and length…

> I'm saying what somebody else is saying, in their voice. This goes in quotes, because it's someone else's speech, even if it's my version of their speech.

That's fine, when you're writing fiction. But in most online forums, fiction is frowned upon.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#380
post #355

Earlier quoted context omitted.

The HN rule is never use quotes to say something someone didn't say. It seems, unless I'm misunderstanding you, you agree this is a silly rule.

I don't think that's the rule? I think the rule is if you're using quotes and it's ambiguous as to whether the person the quotes are attributed to actually said it, then the person better have actually said it. (For what it's worth: this little subthread is about 10x more interesting than the story and the rest of the thread it's attached to).

That's as generous an interpretation of the rule as mine is overly literal. But it's worth comparing it to some of the other rules:

Don't be an ass.

Don't call other people asses.

Don't complain about votes.

And then:

Some weird thing about quotes we can't even sort out as well-intentioned nerds who love to talk about rules.

I don't think that's a good rule. I think what it's trying to address is probably a good rule. But it's addressing it in the dumbest possible way.

Post reply on HN