Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

51–60 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#51
post #34

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

How do I know if I have an independent local ISP? I only see a large ISP advertising in my area.

Advertising is rarely a good way to learn anything.

I heard about Monkey Brains from a pal. From a quick search, the only comparison site that seems to mention them is Yelp.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#52
post #46

Earlier quoted context omitted.

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

Yeah. Homeowner in Seattle? http://gismaps.kingcounty.gov/parcelviewer2/ has your address publically available, unless you made special plans to purchase with an LLC or something. (And you probably need to be sure your LLC's mailing address is a PO box as well.)

That's beside the point. Resolving parcel numbers to owners is also problematic, likewise resolving license plate numbers to owners (used to be possible in Switzerland), but we're talking resolving IP addresses to owners. I wonder how many porn sites could blackmail viewers, or Honeypot mpaa operatos could sue torrent users more easily...

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#53
post #52
post #46

Earlier quoted context omitted.

Yeah. Homeowner in Seattle? http://gismaps.kingcounty.gov/parcelviewer2/ has your address publically available, unless you made special plans to purchase with an LLC or something. (And you probably need to be sure your LLC's mailing address is a PO box as well.)

That's beside the point. Resolving parcel numbers to owners is also problematic, likewise resolving license plate numbers to owners (used to be possible in Switzerland), but we're talking resolving IP addresses to owners. I wonder how many porn sites could blackmail viewers, or Honeypot mpaa operatos could sue torrent users more easily...

It sounds like you think we disagree, but we don't disagree. Parcel lookup is just an interesting public information database many people are unaware of — so I felt it was worth sharing.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#54
post #15

Earlier quoted context omitted.

> But even then, the police are there. Just call them. Uh, isn't that the exact problem? Once someone knows your address you're a voip call away from swatting.

Ah, yeah, I completely forgot about swatting. Good point. The sooner that problem gets solved, the better.

> The sooner that problem gets solved, the better.

We could just stop having SWAT teams. The events that supposedly justify them are so exceedingly rare that most members of SWAT teams go their entire careers without ever seeing one. But once they exist they get used for all kinds of routine operations that don't actually require them, where all they do is raise tensions and unnecessarily escalate matters.

There is a reason there is supposed to be a hard wall between the police and the military. If you really need a military presence, the governor can call in the National Guard. But when does that happen? Even they mostly end up getting called in for hurricane relief and that sort of thing.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#56
post #50
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

You know its almost trivial to buy millions of people's full names, addresses, estimated income, etc., from legit data brokers right? It's how credit card start-ups know who to send direct mail to and it's 100% legal.

This is different though, no?

Say you go post on Infowars anonymously (but not through Tor/VPN/Proxy). They can now know where you live.

Of course the address is public. The relation between your IP address and your actual address isn't...

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#57
post #50

Earlier quoted context omitted.

You know its almost trivial to buy millions of people's full names, addresses, estimated income, etc., from legit data brokers right? It's how credit card start-ups know who to send direct mail to and it's 100% legal.

This is different though, no? Say you go post on Infowars anonymously (but not through Tor/VPN/Proxy). They can now know where you live. Of course the address is public. The relation between your IP address and your actual address isn't...

Yeah, that is indeed very differenr and troubling. I misunderstood.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#58
post #52
post #46

Earlier quoted context omitted.

Yeah. Homeowner in Seattle? http://gismaps.kingcounty.gov/parcelviewer2/ has your address publically available, unless you made special plans to purchase with an LLC or something. (And you probably need to be sure your LLC's mailing address is a PO box as well.)

That's beside the point. Resolving parcel numbers to owners is also problematic, likewise resolving license plate numbers to owners (used to be possible in Switzerland), but we're talking resolving IP addresses to owners. I wonder how many porn sites could blackmail viewers, or Honeypot mpaa operatos could sue torrent users more easily...

> likewise resolving license plate numbers to owners (used to be possible in Switzerland)

Still is, depending on the canton. For Zürich you get 5 lookups per day per IP[0]. For other cantons they might charge you a swiss franc or so [1]. Cantons that charge 10-20 CHF and require a reasoning for why you need this data are in the minority.

[0] https://stva.zh.ch/internet/sicherheitsdirektion/stva/de/StV...

[1] https://www.linker.ch/eigenlink/autonummern_index.htm

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#60
post #52
post #46

Earlier quoted context omitted.

Yeah. Homeowner in Seattle? http://gismaps.kingcounty.gov/parcelviewer2/ has your address publically available, unless you made special plans to purchase with an LLC or something. (And you probably need to be sure your LLC's mailing address is a PO box as well.)

That's beside the point. Resolving parcel numbers to owners is also problematic, likewise resolving license plate numbers to owners (used to be possible in Switzerland), but we're talking resolving IP addresses to owners. I wonder how many porn sites could blackmail viewers, or Honeypot mpaa operatos could sue torrent users more easily...

"Honeypot mpaa operatos could sue torrent users more easily"

Irrelevant, since Comcast already hands this information over to such parties willingly.

Post reply on HN