Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

1–10 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#2
There was no mass exposure of sensitive data. Two paths existed for determined attackers to get the home address and possibly SSN for individually targeted accounts. The process was manual and would have been difficult to automate to compromise "millions" of accounts.

Based on the details in the article, this sounds like something that needed to be fixed, but probably not even worth the time to write this article.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#3
The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some trial and error).

I wonder how many Comcast customers were doxed with this method before it was fixed.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#4
post #2

There was no mass exposure of sensitive data. Two paths existed for determined attackers to get the home address and possibly SSN for individually targeted accounts. The process was manual and would have been difficult to automate to compromise "millions" of accounts. Based on the details in the article, this sounds like something that needed to be fixed, but probably not even worth the time to write this article.

Strongly disagree. This effectively granted anyone with basic HTTP knowledge the ability to dox anyone they interact with online, if that person is using Comcast. The attacker does not need to be "determined" at all; it's trivial to get someone's IP address (send them a link of any kind) and with this vulnerability, trivial to find most of their home address. In short, some asshole kid could send a SWAT team to your house just by knowing your IP address, with not many steps in between.

The SSN last 4 digit bruteforcing is really bad, too. I'd say arguably not as bad, since it's not very hard to get most people's SSNs on black markets these days.

This is not a breach, but these are two massive vulnerabilities and deserves many articles.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#5
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

[deleted]

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#6
post #4
post #2

There was no mass exposure of sensitive data. Two paths existed for determined attackers to get the home address and possibly SSN for individually targeted accounts. The process was manual and would have been difficult to automate to compromise "millions" of accounts. Based on the details in the article, this sounds like something that needed to be fixed, but probably not even worth the time to write this article.

Strongly disagree. This effectively granted anyone with basic HTTP knowledge the ability to dox anyone they interact with online, if that person is using Comcast. The attacker does not need to be "determined" at all; it's trivial to get someone's IP address (send them a link of any kind) and with this vulnerability, trivial to find most of their home address. In short, some asshole kid could send a SWAT team to your…

There is no shortage of asshole kids who use SWAT teams in exactly that way. See https://en.wikipedia.org/wiki/Swatting#Injuries_or_deaths_du... for a list of some notable cases.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#7
Does US federal or California law mandate that breach notifications be sent by postal mail? If not, then I wouldn’t be surprised if Comcast sends any/all notifications to people’s Comcast email addresses. That’ll be a good way to bury the notification, since I doubt many people check or forward their Comcast email.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#8
About two years ago, I spoke with Comcast's CISO over the phone about a leak of a sysadmin's home directory. It included private keys, log files, configs, licensed binaries, splunk(!), etc etc. A week before, her staff told me that they were going to use the chance to offer me a bug as part of a non-existent bug bounty, which didn't (and doesn't) exist.

She (paraphrased) told me that since it wasn't a "bug", it didn't deserve a bounty as part of a bug bounty program. She followed that dribble by saying that for them to implement a bug bounty program would be far too expensive because it would lead to them having to fix all of the security flaws at Comcast. No joke.

Dear Comcast: put out a fucking bug bounty!

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address?

I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them.

I'm trying to understand the other side of this.

Post reply on HN