Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

311–320 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#311
post #292

Earlier quoted context omitted.

If you're rewording something someone else said, even if you're keeping it very close to the original words, don't use quotation marks. Quotes say "this is literally what was said". I got bit by this a bunch when I first got on HN; it was surprising to me how seriously it was taken. But it is, and it's not hard to work around.

That's a weird HN-ism, though, not how writing or paraphrasing works anywhere else. The goal is understandable and laudable but 'redefining the meaning of quotes' is a thing only hardcore lispers can love.

Yeah, they should probably put it in the guidelines. I just remember getting sniped by PG for using quotes that way.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#312
post #195

Earlier quoted context omitted.

First, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don'…

I second this, in addition, the injection is not only related to EOS/EOL for modems it is also for when you are approaching your data cap. Which is rather annoying because it actually can halt your gaming or netflix experience oddly. I have had both happen, one I was playing PlayerUnknown's Battlegrounds and the game crashed. Since the game itself uses web based tools, for its menu system, upon restarting the client…

TBH what kind of game doesn't use https...

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#314
post #292

Earlier quoted context omitted.

That's a weird HN-ism, though, not how writing or paraphrasing works anywhere else. The goal is understandable and laudable but 'redefining the meaning of quotes' is a thing only hardcore lispers can love.

Yeah, they should probably put it in the guidelines. I just remember getting sniped by PG for using quotes that way.

What I'm getting at is, no, they shouldn't, nor should they expect anyone to adopt some weird made-up usage of standard punctuation. Perhaps they should put 'avoid paraphrasing as a rhetorical device' or something like it in the guidelines - that would make sense and be reasonably enforceable. "Don't use quotes the way everyone uses quotes" (like I just did) is just silly and ridiculous. You might as well put "don't call anyone a butthead without using the Oxford comma" in the guidelines.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#316

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

Stop trying to rationalize it; this is not OK, period. If you can't reach your customer via his contact information, too bad, consider him a lost cause. And if it was something critical resulting in the customer's loss of Internet access, you can bet he will contact you then, if he cares.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#317

Earlier quoted context omitted.

Can you discuss why DOCSIS 3.0 users get this notice? I have a 3.0 modem, and received the notice, but it looks like my modem will still support my speed tier (75mbps in Chicago)

It usually means you are about to get a speed upgrade that will go beyond what your modem is capable of delivering. In that case it is possible you could have a 1st generation 4x4 modem (so it can bond 4 downstream and 4 upstream channels).

I wonder if your customers would be happy enough without the speed upgrade if they weren’t wasting bandwidth downloading code they never wanted to run in the first place

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#318
post #282

Does Comcast inject this code in https urls or just http urls? Since https transfer is encrypted I suspect the code injection can't be done. Can someone please tell if my reasoning is correct?

Yeah that's correct, they can't do it in https unless they did something with root certs, which would be 1000x more messed up (And that's saying a lot because this is already pretty despicable). At any rate if they were doing that browsers would revoke the CA.

Thank you, Derimagia.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#319
post #63

Earlier quoted context omitted.

They have to share the last mile infrastructure with new entrants. And the FCC can preempt local and state level requirements to help new entrants. The current problems are that a) since Trump the FCC is shit, b) local municipalities "vowing" to not enter the market (and others have no incentive). See these for b: - https://arstechnica.com/tech-policy/2017/11/voters-reject-ca... - https://www.wired.com/2013/07/we-nee…

> The current problems are that a) since Trump the FCC is $#\¥ Oh please, he’s been in office less than a year - none of this amazing ‘sharing’ happened under the previous administration either. It’s totally understandable to have (in my case many) disagreements with the Presidents and their policies, but this knee-jerk habit of blaming whoever is currently in office for everything because he’s not on our team is cou…

The FCC under Trump has been very friendly to the large enterprises at the expense of small businesses and customers. Trump himself has approved many regulatory changes which are hostile to small businesses, employees and customers across many different industries.

It's safe to say at this point that we have a clear idea of what decisions Trump and his FCC will make in the future, and that there would little to no hope for decisions which will increase competition. A year is plenty of time for assessing the character of an adminstration, and Trump's has been remarkably consistent in this regard.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#320

I'm annoyed by this on several levels. The biggest issue is that I'm using an Arris SB 6121 and I'm getting notifications that my modem is EOL. However, the SB6121 is listed as a supported modem for my speed level on their supported modems page. If I go to their supported modem page, I literally get a page where my current modem is shown as not supported, and the exact same modem is shown next to it as "supported." I…

There is a reason they are doing this. After signing up for Xfinity I noticed that the modem we were leasing was broadcasting a public access point with no way to disable it. I purchased my own modem immediately. Then some time later they rolled out their mobile services, which you guessed it, rely’s on those open access points and Sprint as a fall-back. So now customers are paying monthly to host Xfinity mobile serv…

Xfinity/Comcast deal is with Verizon, not Sprint. The deal to allow Xfinity Mobile to use Verizon happened years ago. Doesn't change much or any reasoning, but VeriOn is a lot better in terms of service area [and strength] vs Sprint.
Post reply on HN