Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

221–230 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#221
post #195

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…

downvoting because of snarkyness. Your suggestion of alt cmu channel is good however.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#222

Earlier quoted context omitted.

> Exactly. And the response, "we're not trying to sell you a modem, we're just encouraging you to strongly consider buying a new one" is such a hair-splittingly asinine response considering the rather serious breach of trust posed by the notification system. Well, what I meant (within the response length constraints of Twitter) was that we're not saying you can only buy it from us. Just that the customer needs to buy…

Why traffic injection instead of mail pieces? I mean, I open all of mine, even the 75%+ that are upsells I don't want, on the off chance one of them will tell me something I need to know. And if Comcast can afford to send that much junk mail, I should tend to think Comcast can afford to send one or two, or five, mail pieces that carry a warning like ACTION REQUIRED TO MAINTAIN SERVICE on the envelope, to those of who…

As was mentioned in the original thread, other means of attempting to contact the individual occurred. This was apparently not the first attempt or method used to contact individuals.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#223

Ignore their spammy emails? Per their VP, they are totally going to up their game and inject their "notifications" in your everyday Web traffic. https://twitter.com/jlivingood/status/939848009386549248

What I meant in the context of that exchange was that the notifications come only after for example multiple emails have not resulted in the device being replaced.

If it is truly critical, disconnect the device and use the disconnected landing page as your means of communication.

Anything else fails to meet the criteria of "critical".

If I buy a crappy 802.11b wifi dongle, are you going to inject JS too?

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#224
post #44

So how exactly is this not criminal?

They are not blocking, throttling, or interfering (in any way that harms functionality) with legal applications; in a nutshell that is 2015 requirement. Now, if that Javascript happens to interact badly with some particular web page, then you could complain to the FCC as long as the 2015 rules remain in effect (which is more than a week, for what that's worth).

It's arguably a copyright infringement.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#225
post #214
post #123

Earlier quoted context omitted.

If only there were some way to notify your users that wasn't so scummy... like via email or regular mail

Regular mail, yes. Email, though, is largely just a waste of time. Way too much non-spam disappears down overeager spam filters, which most people only check if they are specifically expecting some particular mail and it does not show up as expected--and even then many won't check their filters. An ISP could white list their own mail in their spam filters but that would only help with the customers who use their ISP…

I find the reverse is true. My USPS mailbox receives daily credit card application forms, electoral flyers, catalogues, etc. I also get frequent mail from Comcast but they are _all_ bullshit ads, trying to hoodwink me into cable TV. I don't open them anymore, they just go in the bin.

I will at least _glance_ at my email.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#226
post #195

Earlier quoted context omitted.

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…

I second this, in addition, the injection is not only related to EOS/EOL for modems it is also for when you are approaching your data cap. Which is rather annoying because it actually can halt your gaming or netflix experience oddly. I have had both happen, one I was playing PlayerUnknown's Battlegrounds and the game crashed. Since the game itself uses web based tools, for its menu system, upon restarting the client a Comcast injected message popped up warning me I have used 90% of my data cap.

The same thing happened on Netflix ...

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#227
post #195

Earlier quoted context omitted.

First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…

downvoting because of snarkyness. Your suggestion of alt cmu channel is good however.

Downvoting because they weren't that snarky and because of your smugness. Your willingness to tell some one straight up why you downvoted them was good however.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#230

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

[deleted]
Post reply on HN