Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

71–80 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#71
post #15

Earlier quoted context omitted.

Ah, yeah, I completely forgot about swatting. Good point. The sooner that problem gets solved, the better.

> The sooner that problem gets solved, the better. We could just stop having SWAT teams. The events that supposedly justify them are so exceedingly rare that most members of SWAT teams go their entire careers without ever seeing one. But once they exist they get used for all kinds of routine operations that don't actually require them, where all they do is raise tensions and unnecessarily escalate matters. There is a…

The National Guard is called in when the local police force kills innocent civilians.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#72
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

OK, I bite. Please post your current home address.

I was thinking that exact thing in the name of experimentation. A sort of "Please come harass me, I want to see what people have to deal with."

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#73
post #68

Earlier quoted context omitted.

This is sad but exposed the actual problem: militarization of our police. Of course, that is a completely different problem. The last time I mentioned how disciplined our military was compared to seemingly trigger happy police though someone said quietly to let the military our of the barracks and live in my neighborhood as well as occupy public space everywhere within the country and my opinion will change within a…

> just wanted to point out that doxxing isn't there real problem but rather the swatting is. The problem is that SS7 still allows anyone and their dog to spoof phone numbers. Swatting will always work because a (real) hostage situation is among the worst things that can happen for police, the others being terrorist attacks and serial killers. Swatting can only be prevented reasonably by fixing telephony signalling an…

And just for the parent to your comment.

> Swatting will always work

Because ALSO most forces can't spend the money to train their police in hostage situations. It isn't just giving them big "toys" that they want to play with. It isn't that they aren't trained. It is that it is impractical to train them.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#74
post #34

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

How do I know if I have an independent local ISP? I only see a large ISP advertising in my area.

broadbandnow.com lets you see all Internet providers in your area

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#75
Comcast leaks different bits of information in all sorts of ways. It would be relatively easy to combine the information they leak with public records to gain access to someone's account. This is just icing on the cake.

You can identify addresses that are Comcast customers simply by going to their website and shopping for service. If you enter in the address of an existing customer, it tells you.

You can cross reference this with open records like tax and voter registration to determine who lives their and potential phone numbers.

You can confirm the owner of the account by using Comcast's bill pay without login feature. It allows you to specify a street address and telephone number to view/pay a bill. And based on the bill amount you might be able to determine which services they're subscribed to.

If the person is renting equipment then they'll be broadcasting a hotspot that other customers can log into and use unless they're savvy enough to disable it. That could be used to determine their IP address.

Those are just the ones I know about off the top of my head. I'm sure there are many more.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#76

If you have an independent local ISP, use them ! In SF both Monkey Brains and Sonic are excellent, pro-Net-Neutrality, pro-privacy ISPs who offer non-exploitative contracts for internet access which is unfiltered, blazingly fast, and incredibly cheap!

> If you have an independent local ISP, use them!

Lol If only. I can't remember the time I rented an apartment and had even an option other than a monopoly like Comcast. I've literally never seen it available in the midwest. You always just have the single choice, sadly.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#77

Meanwhile, DirectTV still requires SSN to sign up. Until something changes, (create a liability?) this will keep happening.

It is a hard problem for all these companies. How else do you authenticate someone remotely?

Why do you need to authenticate someone to sign them up for your service? Shouldn't a CC, name, and address be enough?

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#78
post #72

Earlier quoted context omitted.

OK, I bite. Please post your current home address.

I was thinking that exact thing in the name of experimentation. A sort of "Please come harass me, I want to see what people have to deal with."

I think that scenario was what happened with one of the more recent swattings in the news.

Person A and Person B are getting hot and bothered about something stupid. Person A says "come at me bro, here's my address." Person A gave Person B Person C's address instead.

Person B swatted Person C. Person C had no idea what was going on, went outside, maybe panicked, maybe whatever, but Person C was shot and killed because SWAT had no idea.

I believe A and B were arrested, but usually the cops don't get lucky. They couldn't find the idiot who tried swatting me, but they don't exactly have a ton of resources either.

Shit's scary, especially since it can happen anytime.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#79

Earlier quoted context omitted.

> just wanted to point out that doxxing isn't there real problem but rather the swatting is. The problem is that SS7 still allows anyone and their dog to spoof phone numbers. Swatting will always work because a (real) hostage situation is among the worst things that can happen for police, the others being terrorist attacks and serial killers. Swatting can only be prevented reasonably by fixing telephony signalling an…

And just for the parent to your comment. > Swatting will always work Because ALSO most forces can't spend the money to train their police in hostage situations. It isn't just giving them big "toys" that they want to play with. It isn't that they aren't trained. It is that it is impractical to train them.

How do medical doctors handle this? Do we train doctors for rare/exotic diseases in medical school? Do we expect them to spend time off duty to educate/train themselves?

I get that it is impractical for Olathe Kansas to train all it's police force in hostage negotiation and deescalation when most likely none of the force will ever use it but what is the alternative? We can't just bus the same negotiation team across the country every time. If we could, EPA wouldn't have its own armed servicemen, right? Also there wouldn't be a Port Authority Police Department in POrt Authority of New York and New Jersey, right?

Basically, I imagine if you wear the equipment and gear for seat, you must be trained for it and we'll qualified in it. If not, then don't carry the gear. No?

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#80
post #50
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

You know its almost trivial to buy millions of people's full names, addresses, estimated income, etc., from legit data brokers right? It's how credit card start-ups know who to send direct mail to and it's 100% legal.

This is very different. This is when you want to target a specific individual and are capable of attaining their IP address, but otherwise know none of their personal information. This, for example, greatly empowers SWATers.
Post reply on HN