Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

61–70 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#61

Earlier quoted context omitted.

If you operate any kind of Bitcoin related service where someone discusses their wealth (message board, wallet provider, etc), then being able to turn an IP address into a physical address could have resulted in very lucrative forced-entry events where threat of force was used to leverage private keys.

How is this different than just breaking into houses in rich neighborhoods?

Most rich people don't have huge volumes of cash or anything as liquid as Bitcoin lying around.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#62
post #22
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

I’m close with someone who actively keeps her address from public records to keep an old stalker from finding her. The psychological effect of having someone treat you like an object, repeatedly hunt you down after moves, and gaslight you/landlords/cops into believing it’s not happening is harmful as it is—let alone the not-so-unlikely chance that someone with this high degree of intelligence and mental health issues…

There’s not much you can do besides a paper restraining order. By the time the cops come it’s too late.

The cops don't have a specific obligation to "come" to help you. Nor to enforce a restraining order.

https://en.wikipedia.org/wiki/Warren_v._District_of_Columbia https://en.wikipedia.org/wiki/Town_of_Castle_Rock_v._Gonzale...

Everyone should read those two Wiki entries. The law often isn't what people think it is.

OTOH if someone breaks into your house and you smoke 'em, then in most states you're in the clear, even without a restraining order.

I know that's not what most people here want to read, but it is "the law of the land" in terms of legal precedent.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#63

Meanwhile, DirectTV still requires SSN to sign up. Until something changes, (create a liability?) this will keep happening.

It is a hard problem for all these companies. How else do you authenticate someone remotely?

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#64
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

Strongly disagree here.

> Exposing information about someone that is largely already public

A home address may be public, but the connection between that address and online activity, like posts on reddit / HN / some forum (political? fetish/porn? extremist? etc etc), is very much not public. Last 4 of social is not uniquely identifiable, but a (partial) home address almost is.

> If you have a specific target, you probably know their name

Not if they're being careful, like anyone would be if they don't want their posts online mapped back to them. But now you can DM them a link (or email them an image if you have an email address or redirect) and turn their IP into a home address. That's very bad.

Doxing someone isn't just exposing an arbitrary address, it's connecting a purportedly anonymous online account with personally identifying info.

Going back to the president, what if you could find out that some angry anonymous person posting racial slurs online was actually the POTUS? That is doxing.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#65
post #2

There was no mass exposure of sensitive data. Two paths existed for determined attackers to get the home address and possibly SSN for individually targeted accounts. The process was manual and would have been difficult to automate to compromise "millions" of accounts. Based on the details in the article, this sounds like something that needed to be fixed, but probably not even worth the time to write this article.

This wouldn't necessarily be about determined attackers. Maybe a crazy guy you were beefing with in an online game has your IP address, and from that could get your physical address.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#66

Earlier quoted context omitted.

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

Strongly disagree here. > Exposing information about someone that is largely already public A home address may be public, but the connection between that address and online activity, like posts on reddit / HN / some forum (political? fetish/porn? extremist? etc etc), is very much not public. Last 4 of social is not uniquely identifiable, but a (partial) home address almost is. > If you have a specific target, you pro…

> Going back to the president, what if you could find out that some angry anonymous person posting racial slurs online was actually the POTUS? That is doxing.

While I agree with your general sentiment, I hope you appreciate the irony of this particular example.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#67

Earlier quoted context omitted.

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

Strongly disagree here. > Exposing information about someone that is largely already public A home address may be public, but the connection between that address and online activity, like posts on reddit / HN / some forum (political? fetish/porn? extremist? etc etc), is very much not public. Last 4 of social is not uniquely identifiable, but a (partial) home address almost is. > If you have a specific target, you pro…

It's still not that difficult to trace an IP back to a person. Besides the private marketing databases you can tap into, geoip, crappy ISP support, DNS cache poisoning, phishing, consumer internet router hacking, web service hacking, and other attacks on an address space itself, there's attacks in a social space that give away much more.

Saying this is a really bad vuln because you aren't as private as you think you are online is like saying lock picking is a really bad vuln because you didn't know door locks could be opened by anyone with a bent piece of metal or a shaved down key. Locks don't actually keep bad people out. They just make people feel safe. Same with this idea that your IP is anonymous. It's really not. It's a literal address.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#68
post #47

Earlier quoted context omitted.

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

> I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! If only we all had access to the Secret Service. Lots of modern games make use of P2P behind the scenes (e.g. for voice chat), which means that maladjusted script kiddie I just sniped already has my IP and might decide to forego DDoSing me and skip straight to calling in a hostage situation at my home address. Bei…

This is sad but exposed the actual problem: militarization of our police. Of course, that is a completely different problem.

The last time I mentioned how disciplined our military was compared to seemingly trigger happy police though someone said quietly to let the military our of the barracks and live in my neighborhood as well as occupy public space everywhere within the country and my opinion will change within a few years. I suspect this is true. I don't have any solutions to this militarization, just wanted to point out that doxxing isn't there real problem but rather the swatting is.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#69
post #68
post #47

Earlier quoted context omitted.

> I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! If only we all had access to the Secret Service. Lots of modern games make use of P2P behind the scenes (e.g. for voice chat), which means that maladjusted script kiddie I just sniped already has my IP and might decide to forego DDoSing me and skip straight to calling in a hostage situation at my home address. Bei…

This is sad but exposed the actual problem: militarization of our police. Of course, that is a completely different problem. The last time I mentioned how disciplined our military was compared to seemingly trigger happy police though someone said quietly to let the military our of the barracks and live in my neighborhood as well as occupy public space everywhere within the country and my opinion will change within a…

> just wanted to point out that doxxing isn't there real problem but rather the swatting is.

The problem is that SS7 still allows anyone and their dog to spoof phone numbers. Swatting will always work because a (real) hostage situation is among the worst things that can happen for police, the others being terrorist attacks and serial killers.

Swatting can only be prevented reasonably by fixing telephony signalling and throwing the ones doing it into jail for a couple of years.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#70
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

OK, I bite. Please post your current home address.
Post reply on HN