Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

11–20 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#11
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

I'm actually with you to a degree - but on the flip side, should we expect repercussions for something like this? Should we just be ok with it? As an industry we tend to play it pretty fast and loose compared to other engineering disciplines.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#13
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

> But even then, the police are there. Just call them.

Uh, isn't that the exact problem? Once someone knows your address you're a voip call away from swatting.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#14

Does US federal or California law mandate that breach notifications be sent by postal mail? If not, then I wouldn’t be surprised if Comcast sends any/all notifications to people’s Comcast email addresses. That’ll be a good way to bury the notification, since I doubt many people check or forward their Comcast email.

Actual legal text on CA data breach law from the following link. Notification requirements are near the bottom, starting with the section labeled "(j) For purposes of this section, “notice” may be provided by one of the following methods:"

https://leginfo.legislature.ca.gov/faces/codes_displaySectio...

Email notice is an option if meeting the restrictions listed in the Federal law linked below. I think the relevant part is section (c), with the major restriction being "affirmative consent."

https://www.law.cornell.edu/uscode/text/15/7001

Alternatively if the breach affects over half a million people, they can send notifications by email, but also have to plaster their homepage and send "Notification to major statewide media." The homepage banner would only affect people who pay electronically but not by autopay. There are ways to minimize the effect of news broadcast, e.g. send the press release at 4 o'clock on a Friday when no one watches the news.

So, it's not quite as easy as you think but Comcast does have options to minimize the impact of notification.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#15
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

> But even then, the police are there. Just call them. Uh, isn't that the exact problem? Once someone knows your address you're a voip call away from swatting.

Ah, yeah, I completely forgot about swatting. Good point. The sooner that problem gets solved, the better.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#17
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

Think of it this way: Two people are playing an online game, and one gets mad at the other. He or she then sends a link to an image or something else to the player they are mad at, effectively siphoning off their IP address. By using this flaw, it could make it trivial to find their real address if it was a comcast customer, and send the SWAT team to their house.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#18
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

The information you obtain from vulnerabilities like these are used to obtain “original” social media accounts, and are then sold for a lot of money. To define what “original” is, take for instance “@shawn” on Instagram or Twitter. When these people target celebrities, they are mainly looking for a laugh and believe their “method” is about to be patched.

For example, T-Mobile and Verizon vulnerabilities are used to SIM swap and get around 2FA on instagram or twitter. Usually, they first try to find an employee who works at the store and has access to the database, before going through all the trouble of finding a vuln.

This has been an “underground” space for quite some time, but is slowly coming to light.

Source: I use to be in this space and made so much money off original usernames. To give you an idea of what a username goes for, I sold the Instagram @b*ss for $20,000.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#19
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

In many jurisdictions, the police will do little or nothing until a crime is committed. It's possible to experience a life-altering amount of harassment before the police will intervene in any meaningful way.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#20
post #17
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

Think of it this way: Two people are playing an online game, and one gets mad at the other. He or she then sends a link to an image or something else to the player they are mad at, effectively siphoning off their IP address. By using this flaw, it could make it trivial to find their real address if it was a comcast customer, and send the SWAT team to their house.

Finding a location by IP address is not always reliable. The first result when googling my IP address yields a city 1,000 miles away (other results have the correct city). Then, knowing the first digit of a street address gets you a range of addresses that can represent anywhere from 1 to hundreds of homes. It's theoretically possible to get a specific address from this method but it's unlikely and not reliable.
Post reply on HN