Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

31–40 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#31

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?

I use Monkey Brains. I have very occasionally experienced a momentary drop in connectivity which immediately recovered. These have been less frequent than the times I had to call up Comcast and debug an outage over the phone.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#32

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

If only it was that easy. I can't remember which was which, but one company needed to put an aerial on the roof which my landlord rejected (even though it would save the 15 tenant units here shitloads of money), and the other one simply didn't have lines to our unit, and this is right on Russian hill so pretty Central SF in my opinion.

Comcast has a functional monopoly in my area, and that has been true my entire life except when I lived abroad. Our suburban home in Wisconsin, and again in South Carolina. Five different homes in Houston. Three in California. I shudder to think about the amount of information Comcast has on me, particularly if they snoop my network activity.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#33
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

If you operate any kind of Bitcoin related service where someone discusses their wealth (message board, wallet provider, etc), then being able to turn an IP address into a physical address could have resulted in very lucrative forced-entry events where threat of force was used to leverage private keys.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#34

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

How do I know if I have an independent local ISP? I only see a large ISP advertising in my area.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#35
post #6
post #4

Earlier quoted context omitted.

Strongly disagree. This effectively granted anyone with basic HTTP knowledge the ability to dox anyone they interact with online, if that person is using Comcast. The attacker does not need to be "determined" at all; it's trivial to get someone's IP address (send them a link of any kind) and with this vulnerability, trivial to find most of their home address. In short, some asshole kid could send a SWAT team to your…

There is no shortage of asshole kids who use SWAT teams in exactly that way. See https://en.wikipedia.org/wiki/Swatting#Injuries_or_deaths_du... for a list of some notable cases.

Absolutely, but this exposure made it much easier to do en masse, plus made it possible to dox targets who otherwise have good OPSEC and aren't easily identified.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#36

Earlier quoted context omitted.

Finding a location by IP address is not always reliable. The first result when googling my IP address yields a city 1,000 miles away (other results have the correct city). Then, knowing the first digit of a street address gets you a range of addresses that can represent anywhere from 1 to hundreds of homes. It's theoretically possible to get a specific address from this method but it's unlikely and not reliable.

The point of the article is that you could essentially get the exact address house address from just the IP of a Comcast customer

Right, and my point is that you essentially can't. For my address the best you could do is narrow it down to ~30 or so homes that share the same first digit as my address. For this to work you have to:

(1) Have the IP address return the right location

(2) Not have duplicate street names in that location

(3) Have a single digit address OR be the only home starting with that number

That's going to be a pretty rare combo. Probably less than 1%.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#37
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

If you operate any kind of Bitcoin related service where someone discusses their wealth (message board, wallet provider, etc), then being able to turn an IP address into a physical address could have resulted in very lucrative forced-entry events where threat of force was used to leverage private keys.

How is this different than just breaking into houses in rich neighborhoods?

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#39

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?

sonic.net (and pair.com, for hosting) are two companies where I have always been delighted on the few occasions when I had to call tech support, due to the intelligence and effectiveness of the people on the other end of the line.

It's just such a pleasure to talk to someone who is actually listening to and thinking about your problem, instead of simply reading from a script.

Post reply on HN