The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
11–20 of 81 posts
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#12Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#13The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
Uh, isn't that the exact problem? Once someone knows your address you're a voip call away from swatting.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#14Does US federal or California law mandate that breach notifications be sent by postal mail? If not, then I wouldn’t be surprised if Comcast sends any/all notifications to people’s Comcast email addresses. That’ll be a good way to bury the notification, since I doubt many people check or forward their Comcast email.
https://leginfo.legislature.ca.gov/faces/codes_displaySectio...
Email notice is an option if meeting the restrictions listed in the Federal law linked below. I think the relevant part is section (c), with the major restriction being "affirmative consent."
https://www.law.cornell.edu/uscode/text/15/7001
Alternatively if the breach affects over half a million people, they can send notifications by email, but also have to plaster their homepage and send "Notification to major statewide media." The homepage banner would only affect people who pay electronically but not by autopay. There are ways to minimize the effect of news broadcast, e.g. send the press release at 4 o'clock on a Friday when no one watches the news.
So, it's not quite as easy as you think but Comcast does have options to minimize the impact of notification.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#15Earlier quoted context omitted.
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
> But even then, the police are there. Just call them. Uh, isn't that the exact problem? Once someone knows your address you're a voip call away from swatting.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#16Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#17The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#18The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
For example, T-Mobile and Verizon vulnerabilities are used to SIM swap and get around 2FA on instagram or twitter. Usually, they first try to find an employee who works at the store and has access to the database, before going through all the trouble of finding a vuln.
This has been an “underground” space for quite some time, but is slowly coming to light.
Source: I use to be in this space and made so much money off original usernames. To give you an idea of what a username goes for, I sold the Instagram @b*ss for $20,000.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#19The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information
#20Earlier quoted context omitted.
So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.
Think of it this way: Two people are playing an online game, and one gets mad at the other. He or she then sends a link to an image or something else to the player they are mad at, effectively siphoning off their IP address. By using this flaw, it could make it trivial to find their real address if it was a comcast customer, and send the SWAT team to their house.