Live data from Hacker News

Comcast is injecting 400+ lines of JavaScript into web pages

forums.xfinity.com

361–370 of 498 posts

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#361

Earlier quoted context omitted.

My "quote" isn't significantly different from what was actually said, in fact hews extremely closely to it, and is designed for rhetorical purpose of making clear how small a distinction is being relied upon in order to claim the statement is something other than a request for you to buy a new modem. Moreover there's nothing in the guidelines about "making up quotes" (which again isn't a reasonable interpretation of…

If you're rewording something someone else said, even if you're keeping it very close to the original words, don't use quotation marks. Quotes say "this is literally what was said". I got bit by this a bunch when I first got on HN; it was surprising to me how seriously it was taken. But it is, and it's not hard to work around.

This rule is too idiosyncratic, annoying, not found anywhere in the guidelines, and is not offering any net benefit in this context that I can see.

If the object of the rule is to produce derails like this, it's doing more harm than good. So unless someone wants to explain how it's invocation in this thread improved the quality of conversation about Comcast's javascript injection policy, I would encourage others to join me in not observing the norm.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#362
post #231

Comcast is not alone in this. Cox Communications has been injecting code into HTTP traffic for years. I think sometime around 2008 I first saw them do it (I noticed NoScript blocking a script on a page that it wouldn't normally). If I remember correctly, following it to its source hinted that it was a test for some alert system. In 2012 I saw them injecting a script to notify people that their email servers were down…

Can confirm. I didn't even notice until they started using their script to inject popups telling me I had "exceeded my data allowance". I literally canceled my Cox Communications account on the spot.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#363

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

You have our phone number. You have our address. Use them! Do not MITM our connections, that's a huge violation of trust. This is NOT okay. Any response other than "we're terribly sorry, our engineering team is rolling this back on Monday" is the wrong response.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#364
post #332

Earlier quoted context omitted.

That's simply false. No, it isn't. I'm saying what somebody else is saying, in their voice. This goes in quotes, because it's someone else's speech, even if it's my version of their speech. The fact that they didn't actually say it comes from context. Punctuation is not semantic markup. This doesn't come from reddit, it comes from, you know, the way people actually write. The fact that it requires repeated and length…

Writing style guides are a thing & a thing that have been around for a long time. All 3 of the style guides I’ve had reason to use (AP, MLA & CMS) all require that quoted material be direct quotes. Now, I think that it’s a fair argument that a web forum needn’t have the same formality as other written word, but your assertion that “it’s not how anyone writes” is clearly untrue. And just as a single data point, I expe…

I agree with pvg. The notion that a comment on HN is, in some sense, in poor form because it doesn't adhere to AP/MLA/CMS specifications is ridiculous. Nobody agreed to that, and I doubt anyone would even agree that that's accepted informally as a norm.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#365

Earlier quoted context omitted.

There is a reason they are doing this. After signing up for Xfinity I noticed that the modem we were leasing was broadcasting a public access point with no way to disable it. I purchased my own modem immediately. Then some time later they rolled out their mobile services, which you guessed it, rely’s on those open access points and Sprint as a fall-back. So now customers are paying monthly to host Xfinity mobile serv…

As far as I am aware, it is possible to disable the public 'xfinitywifi' hotspot on all Comcast modems which provide this feature (I had a stint as a TSR relatively recently). Further, I believe this is a user-configurable setting on all CC modems. I personally have this feature disabled on my Arris 1682G, and this should be their most common model in most regions.

I was told I could not disable their hotspot, nor could I set my own DNS servers. Since I kept having connectivity issues due to Comcast’s DNS being flaky, and not wanting to manually configire every client, I bought my own modem and wireless setup.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#366
They’re just business people trying make a profit and the market will work to collectively accept or reject this practice, is that what they would say?

Would you make this decision if it doubled your salary?

I love making money, helathy forms of capitalism, fierce competition, and benefiting as a consumer from other companies competing.

But I’ll not be a part of this for any job, not in a free country where there are so many opportunities to do better that this. No sir, I respectfully decline your offer.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#367

J. Livingood (a Comcast VP) responded to the OP: > [JL] We are not trying to sell you a new one. If you own your modem we're informing you that it is either end of life (EOL) or that you are about to get a speed upgrade that the modem will be unable to deliver. Incidentally, Livingood is a co-author of IETF RFC 6108, which he has conveniently linked. From the RFC's general requirements numero uno: > R3.1.1. Must Only…

> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor. In the former case, if the device is leased, you are send a…

As an (unwilling) Comcast user, I purchased my own modem because your rental rates are preposterous. However, I wish I didn't have to think about this at all. If you force me to upgrade a modem I've purchased, I'll be very annoyed by the unanticipated cost.

I get that's problematic for your modernization efforts, but in that case: eliminate modem rental fees. Bake the fees in to the standard cost of the service and don't let customers use their own equipment. I understand that non-cable competitors don't have this cost to shuffle around, and that this will mean you are forced to either A) raise prices publicly or B) have lower margins. That's your problem because of your technology legacy; don't pass the misery on to the customer.

While you're at it, offer two hardware choices: one with, and one without routing/wireless. I refuse to run a wifi network in my household for your other customers and expect complete control over my LAN configuration.

On the topic of injection: I get that you don't think it's immoral, but hey, 1) most people who understand it think it is totally unacceptable. And 2) the window for this approach is rapidly closing for you as the web moves to SSL everywhere. Give up on this approach now and save face.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#368
post #292

Earlier quoted context omitted.

That's a weird HN-ism, though, not how writing or paraphrasing works anywhere else. The goal is understandable and laudable but 'redefining the meaning of quotes' is a thing only hardcore lispers can love.

This is not an "HN-ism". It is not proper to use quotation marks when paraphrasing. Doing so is explicitly attributing words to someone that they did not say. > not how writing or paraphrasing works anywhere else That's simply false. If you want to use Reddit et al as your standard reference on the use of language and punctuation, have at it. But you can't reasonably expect every other forum to use that lowest common…

>If you want to use Reddit et al as your standard reference on the use of language and punctuation, have at it.

In terms of what contexts one should keep in mind when interpreting comments with good faith to come to a most reasonable interpretation of what they are saying, the way language is used on reddit is probably a much more reasonable benchmark than MLA style guides.

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#369
post #355

Earlier quoted context omitted.

It should include those quotes if you are asserting that I said it.

The HN rule is never use quotes to say something someone didn't say. It seems, unless I'm misunderstanding you, you agree this is a silly rule.

I don't think that's the rule? I think the rule is if you're using quotes and it's ambiguous as to whether the person the quotes are attributed to actually said it, then the person better have actually said it.

(For what it's worth: this little subthread is about 10x more interesting than the story and the rest of the thread it's attached to).

Re: Comcast is injecting 400+ lines of JavaScript into web pages

#370
post #36

Earlier quoted context omitted.

> and is instead based in open IETF standards and open source applications. Why did the IETF ever agree to standardize this? It reminds me of their standardization of Cisco's "lawful intercept" router backdoor protocol. https://tools.ietf.org/html/rfc3924 https://www.blackhat.com/presentations/bh-dc-10/Cross_Tom/Bl... I guess this is what you get when the IETF literally has NSA agents as chairs of its groups. https:/…

These are only informational RFCs, which can be published by anyone. >This RFC is not a candidate for any level of Internet Standard. The IETF disclaims any knowledge of the fitness of this RFC for any purpose

RFC stands for "Request For Comments". Some of them get turned into standards, but most are just the IETF equivalent of a forum thread. They're a way to start a discussion about a network engineering design.
Post reply on HN