Does US federal or California law mandate that breach notifications be sent by postal mail? If not, then I wouldn’t be surprised if Comcast sends any/all notifications to people’s Comcast email addresses. That’ll be a good way to bury the notification, since I doubt many people check or forward their Comcast email.
A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
41–50 of 81 posts
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#42Earlier quoted context omitted.
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
The information you obtain from vulnerabilities like these are used to obtain “original” social media accounts, and are then sold for a lot of money. To define what “original” is, take for instance “@shawn” on Instagram or Twitter. When these people target celebrities, they are mainly looking for a laugh and believe their “method” is about to be patched. For example, T-Mobile and Verizon vulnerabilities are used to S…
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#43The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him!
Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN.
There are many ways to dox people. If you have a specific target, you probably know their name; if not, you can phish it, and any other information you want. If you have their IP, you know their ISP. With their name and their ISP, and maybe some extra info gleaned from various sources like social media, you can get pretty much anything you want. Account access, phone numbers, billing information, socials, etc. With their phone number you can take over their phone, and then all their SMS-linked accounts.
Is this scary? Yes. Did I need to slowly extract their home address using a vendor's web form and their IP? No.
The last 4 of the social is much worse. It makes all of this incredibly easy and gives access to much more sensitive information, like medical records, payroll, government service information, etc.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#44Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#45The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
- a select few with good reasons to avoid their address being widely known. Because stalkers etc.
- All those infsec bros with their "attack vectors" and their "threat landscape". They'll scream "security by obscurity" when you're using an unlisted URL to share holiday photos, but get really miffed if someone finds out where they live, or where they go running.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#46The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#47The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…
If only we all had access to the Secret Service. Lots of modern games make use of P2P behind the scenes (e.g. for voice chat), which means that maladjusted script kiddie I just sniped already has my IP and might decide to forego DDoSing me and skip straight to calling in a hostage situation at my home address. Being able to easily resolve a concrete address from an IP is certainly a bigger deal than being able to determine its ISP.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#48I know shitposting is completely frowned upon here, but I can't help but have the image of that South Park comcast guy in my head right now. "Oh, you had your personal address and social security numbers stolen? Ooh that's too bad. "
It fits too well.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#49Earlier quoted context omitted.
When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?
Sonic quality depends on the quality of the AT&T wiring to your home. At my old house in Oakland, Sonic meant 3mbit DSL because AT&T had not updated the old twisted pair. It meant I bailed and signed up for Comcast. My new place in San Jose has fiber to the premise, so I signed up for Sonic again. Good bandwidth, Rock solid service.
If you’re in a larger building (15+ units), there are a couple of other fiber providers that may be an option, if building management is up for it.
MonkeyBrains is a wireless ISP. I regularly get 25-40 Mbps from them (though they don’t guarantee that). I’ve had only occasional slowdowns and one outage lasting a few hours. (So, more reliable than Comcast had been, at least for me.) I’d heard rumors MonkeyBrains was planning some equipment upgrades that would let them deliver 60-80 Mbps, but no official announcement or timetable.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#50The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…