Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

161–170 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#161
post #12
post #7

I wonder if a website could sue Comcast for copyright violation.

Unfortunately if this were to happen and it succeeded, the precedent would kill the Web Archive. :(

Not necessarily. Comcast derives from your work in order to exploit it for commercial purposes. Archive does not. A significant difference.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#162
post #10
post #3

Most interesting part was the reply from the Comcast employee.

Yes, indeed it was. It's a fairly standard, unsurprising response for this situation; doesn't try to be defensive, doesn't try to provoke. [Edit: I'm horribly under-perceptive, after reading other comments I see I'm a bit off.] But... this bit. > ... [JL] This is our web notification system, documented in RFC 6108 https://tools.ietf.org/html/rfc6108 , which has been in place for many years now. ... Oh, interesting, w…

An RFC is not always a standard - often they are simply 'informational'. For us, when we wrote the document, it was a way to document as transparently as possible how the system worked so that folks would not need to speculate about it and for us to explain the rationale and alternatives considered. This seemed to me at the time far better than being evasive about it. And a request for comment is often a way to solicit exactly that - good comments (e.g. suggestions on alternatives). In this case, it has led in part to things like the IETF's new(ish) CAPPORT working group being created to develop a better Internet-wide standard for how to interact with so-called captive portals. See https://datatracker.ietf.org/wg/capport/about/ for more details and feel free to join the mailing list and contribute!

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#163
post #109

Earlier quoted context omitted.

I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. It was an automated advertisement done in a very not good way; Comcast's own billing system notifies you of just about everything else; you can forward your billing statements and other such information to other emails, why not this? The reason everyone is freaking out is because they feel p…

> I sincerely disagree, especially as per the report Comcast's own second level confirmed there was no need to replace the modem. I am skeptical of this - maybe we made a mistake in telling the customer that. The people that are sent notifications are carefully checked to match the EOL/EOS modem criteria or speed mismatch criteria and would not be sent otherwise. It is sometimes the case that a customer has recently…

> It was not an ad - it was a request

As a Comcast customer, I request you discontinue this injecting of javascript into webpages for ANY reason, unreasonably limiting an INFINITE RESOURCE and monopolizing localities so you are the only viable choice. This should not be the behavior of the largest telecom provider in the continental US. We deserve better.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#164

I thought HTTPS was supposed to prevent this sort of man in the middle attack? (Or at least make it harder) -- and I thought that most websites used HTTPS these days... or am I misunderstanding? If they are able to do this, and are injecting JavaScript for something as low-return as online ads, then what is to prevent them from changing the news headlines on , or the stock ticker feed... How do we know that they aren…

As the other comment said, HTTPS does prevent this, and this only happens on HTTP pages.

> Do we, as a community, have any mechanism to detect if these sorts of attacks are occurring?

Yes, Caddy can detect whether a connection is being MITM'ed: https://caddyserver.com/docs/mitm-detection

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#165

Earlier quoted context omitted.

>As composed as Livingood's response was, a modem at EOL and/or incapable of supporting an incremental speed upgrade doesn't strike me as critical. Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system.

> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…

Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. And if Comcast can afford to send that much junk mail, I should tend to think Comcast can afford to send one or two, or five, mail pieces that carry a warning like ACTION REQUIRED TO MAINTAIN SERVICE on the envelope, to those of whom action is indeed required to maintain service. You guys shipped me a whole new unsolicited modem! (One which I'll put into service, too, just as soon as I've worked out how to disable all the routing and wireless smarts I don't want, don't need, and won't suffer messing with my network.) Surely you can afford bulk rate.

And mail pieces don't produce the potentially rather widespread indignation that traffic injection does. Granted, I don't see the harm in it that a lot of people here do. Unencrypted traffic is unencrypted traffic - open to tampering by anyone, not just Comcast, and for many less innocuous reasons than the one for which you've chosen to do so. But with Let's Encrypt, browser manufacturers, and friends leading the charge toward TLS everywhere or as nearly so as is practical, and with most sites that most people use already employing TLS, the attack surface is closing for even an other-than-innocuous variant of your notification methodology. Of course, that also means that that methodology itself is reaching a natural end-of-life, as it cannot work anywhere that TLS exists, and the majority of the web where it does exist continues to grow. If this low-latency notification scheme is of unique value to your business, then now is the time to consider replacing the outdated technology that underpins it with something which will continue to work reliably over the next decade or two.

All that said, I appreciate your decision to engage in this forum. That's unprecedented in my experience from someone in a position like yours, and I wouldn't mind seeing more of it.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#166
post #70

Earlier quoted context omitted.

In a natural monopoly regulation /increases/ competition and freedom for the consumer. The BBC had an article about this a few years ago [0]. Basically the highly regulated countries had cheaper and faster internet. > Rick Karr, who made a PBS documentary in which he travelled to the UK to find out why prices were lower, says that the critical moment came when the British regulator Ofcom forced British Telecom to all…

It might be easier to convince me ISPs were a natural monopoly if they weren't also a legally protected monopoly where they are, and generally have plenty of competition where they aren't.

I’m not sure that’s evidence against their natural monopoly position. It might be that we’re in a world where in some places, it’s plausible to have two ISPs, and in many it’s not—but if two try, they’ll both fail to get enough people to be profitable. Then any sane provider wants to demand exclusivity as the cost of pulling fiber through a community, and unhappily acknowledges that they’ll have to cover all of their exclusive territory. If we’re in that world, and the service is nearly essential, we’ll see legal monopolies in lots of places, and some places with no legal monopoly and no service—they can’t agree on a price.

I’m prone to suspicion of their business practices too, but every one of the Comcast technical staff I’ve met, from Jason down, has been an excellent person deeply committed to the best mission of a telecoms company, enabling human communication. Is that a marketing campaign? Yes, but as far as I can tell it’s an honest campaign of showing the world who they are and what they care about.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#167
post #37

Earlier quoted context omitted.

> I mean, I know the answer is "government" and government making them a monopoly, but still. WTF. Eh, telco infrastructure is a natural monopoly. No government needed for that.

Bs. Heard about the 1996 telecommunicatins act? The government payed for their monopoly, and now it lets them keep it and not share it.

Is that when they subsidized the ISPs with billions to build out infrastructure, which they never did?

The problem with anti-government rhetoric in the US is it creates a self-fulfilling prophecy. Government is not inherently as incompetent and weak as yours often is.

There is no reason why a regulatory solution cannot work in the US when they work well in many other countries of greatly varying size and population density.

If your government fails you, that is not a failure of government: it is a failure of your government.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#168
post #123

Earlier quoted context omitted.

If only there were some way to notify your users that wasn't so scummy... like via email or regular mail

In the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?

With all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#169

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

All that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.

I think the mindset is that at least he’ll be embarrassed on his yacht. Short of that thinking, you’d have to assume a few solid layers of cognitive dissonance.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#170

Earlier quoted context omitted.

Would HTTPS help at all in this case, though..?

Yes. You can’t inject code in a TLS-secured connection unless you can MITM TLS and if they can do that, all is lost anyways.

It would make it harder, perhaps.
Post reply on HN