Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

21–30 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#21
If you have an independent local ISP, use them!

In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#22
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

I’m close with someone who actively keeps her address from public records to keep an old stalker from finding her.

The psychological effect of having someone treat you like an object, repeatedly hunt you down after moves, and gaslight you/landlords/cops into believing it’s not happening is harmful as it is—let alone the not-so-unlikely chance that someone with this high degree of intelligence and mental health issues will physically hurt you if they find you.

There’s not much you can do besides a paper restraining order. By the time the cops come it’s too late.

This possibility is a very real part of many people’s lives, but maybe less talked about with men like me because statistically female victims are more common.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#23
post #17

Earlier quoted context omitted.

Think of it this way: Two people are playing an online game, and one gets mad at the other. He or she then sends a link to an image or something else to the player they are mad at, effectively siphoning off their IP address. By using this flaw, it could make it trivial to find their real address if it was a comcast customer, and send the SWAT team to their house.

Finding a location by IP address is not always reliable. The first result when googling my IP address yields a city 1,000 miles away (other results have the correct city). Then, knowing the first digit of a street address gets you a range of addresses that can represent anywhere from 1 to hundreds of homes. It's theoretically possible to get a specific address from this method but it's unlikely and not reliable.

The point of the article is that you could essentially get the exact address house address from just the IP of a Comcast customer

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#24

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#25
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

[deleted]

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#26
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

The police? That sounds like a very ineffective solution. People aren't safe because of the police, they're safe because of the trustworthiness of their neighbors. The police can't be there to intercept most crimes; instead they show up to write a report post-fact. But at that point, you're calling the police for documentation of a crime for insurance.

Police can't be there to intercept the metaphorical brick through your window. The reason why we feel safe walking outside everyday is because of the fabric of trust in our community.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#27

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?

See dslreports for up to date local isp speed and reliability records.

http://www.dslreports.com/

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#28

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?

Sonic quality depends on the quality of the AT&T wiring to your home. At my old house in Oakland, Sonic meant 3mbit DSL because AT&T had not updated the old twisted pair. It meant I bailed and signed up for Comcast.

My new place in San Jose has fiber to the premise, so I signed up for Sonic again. Good bandwidth, Rock solid service.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#29
post #18
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

The information you obtain from vulnerabilities like these are used to obtain “original” social media accounts, and are then sold for a lot of money. To define what “original” is, take for instance “@shawn” on Instagram or Twitter. When these people target celebrities, they are mainly looking for a laugh and believe their “method” is about to be patched. For example, T-Mobile and Verizon vulnerabilities are used to S…

How did you get that username?

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#30
post #18
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

The information you obtain from vulnerabilities like these are used to obtain “original” social media accounts, and are then sold for a lot of money. To define what “original” is, take for instance “@shawn” on Instagram or Twitter. When these people target celebrities, they are mainly looking for a laugh and believe their “method” is about to be patched. For example, T-Mobile and Verizon vulnerabilities are used to S…

How do users in this space securely transfer money without the FBI kicking down their door the next day?
Post reply on HN