Live data from Hacker News

A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

buzzfeednews.com

41–50 of 81 posts

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#41

Does US federal or California law mandate that breach notifications be sent by postal mail? If not, then I wouldn’t be surprised if Comcast sends any/all notifications to people’s Comcast email addresses. That’ll be a good way to bury the notification, since I doubt many people check or forward their Comcast email.

To be fair, I dont read physical mail from Comcast either. I'm constantly flooded with junkmail from them.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#42
post #18
post #9

Earlier quoted context omitted.

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

The information you obtain from vulnerabilities like these are used to obtain “original” social media accounts, and are then sold for a lot of money. To define what “original” is, take for instance “@shawn” on Instagram or Twitter. When these people target celebrities, they are mainly looking for a laugh and believe their “method” is about to be patched. For example, T-Mobile and Verizon vulnerabilities are used to S…

Wow, this is a fascinating answer. Thanks for sharing.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#43
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

> The address exposure vulnerability is really, really bad

I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him!

Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN.

There are many ways to dox people. If you have a specific target, you probably know their name; if not, you can phish it, and any other information you want. If you have their IP, you know their ISP. With their name and their ISP, and maybe some extra info gleaned from various sources like social media, you can get pretty much anything you want. Account access, phone numbers, billing information, socials, etc. With their phone number you can take over their phone, and then all their SMS-linked accounts.

Is this scary? Yes. Did I need to slowly extract their home address using a vendor's web form and their IP? No.

The last 4 of the social is much worse. It makes all of this incredibly easy and gives access to much more sensitive information, like medical records, payroll, government service information, etc.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#44
I know shitposting is completely frowned upon here, but I can't help but have the image of that South Park comcast guy in my head right now. "Oh, you had your personal address and social security numbers stolen? Ooh that's too bad. "

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#45
post #9
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

So, at the risk of getting murdered for this sentiment: Who cares? So what if someone knows your address? I guess it's a bigger problem for celebrities or for those who are targeted. But even then, the police are there. Just call them. I'm trying to understand the other side of this.

The "other side" consists of:

- a select few with good reasons to avoid their address being widely known. Because stalkers etc.

- All those infsec bros with their "attack vectors" and their "threat landscape". They'll scream "security by obscurity" when you're using an unlisted URL to share holiday photos, but get really miffed if someone finds out where they live, or where they go running.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#46
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

Yeah. Homeowner in Seattle? http://gismaps.kingcounty.gov/parcelviewer2/ has your address publically available, unless you made special plans to purchase with an LLC or something. (And you probably need to be sure your LLC's mailing address is a PO box as well.)

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#47
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

> The address exposure vulnerability is really, really bad I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him! Exposing information about someone that is largely already public is somewhat bad, but it's not "really, really bad". And it's certainly not worse than exposing the last 4 of their SSN. There are many ways to dox people. If you have a specific target, you pr…

> I have the President of the United States' address. 1600 Pennsylvania Avenue. Oh no! I done dox'd him!

If only we all had access to the Secret Service. Lots of modern games make use of P2P behind the scenes (e.g. for voice chat), which means that maladjusted script kiddie I just sniped already has my IP and might decide to forego DDoSing me and skip straight to calling in a hostage situation at my home address. Being able to easily resolve a concrete address from an IP is certainly a bigger deal than being able to determine its ISP.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#48

I know shitposting is completely frowned upon here, but I can't help but have the image of that South Park comcast guy in my head right now. "Oh, you had your personal address and social security numbers stolen? Ooh that's too bad. "

https://www.youtube.com/watch?v=rja7tCtxSN4

It fits too well.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#49
post #28

Earlier quoted context omitted.

When I brought up those two ISPs to coworkers, they said they experienced frequent enough outages. Do you use them? What has your experience been like?

Sonic quality depends on the quality of the AT&T wiring to your home. At my old house in Oakland, Sonic meant 3mbit DSL because AT&T had not updated the old twisted pair. It meant I bailed and signed up for Comcast. My new place in San Jose has fiber to the premise, so I signed up for Sonic again. Good bandwidth, Rock solid service.

In SF, at least, Sonic has started stringing their own fiber. But it’s not in every neighborhood yet, and even in places where they are installing fiber, some streets may be left dark, (Including, frustratingly, a big swath of Portrero Hill where the utility poles are “overloaded”.)

If you’re in a larger building (15+ units), there are a couple of other fiber providers that may be an option, if building management is up for it.

MonkeyBrains is a wireless ISP. I regularly get 25-40 Mbps from them (though they don’t guarantee that). I’ve had only occasional slowdowns and one outage lasting a few hours. (So, more reliable than Comcast had been, at least for me.) I’d heard rumors MonkeyBrains was planning some equipment upgrades that would let them deliver 60-80 Mbps, but no official announcement or timetable.

Re: A Comcast Security Flaw Exposed Millions of Customers’ Personal Information

#50
post #3

The address exposure vulnerability is really, really bad. Just about anyone was able to impersonate another Comcast customer by sending their home IP address in the X-Forwarded-For header to Comcast's device activation page, and easily see a masked version of their address (first number of street number and partial street name; street name is trivial to figure out with IP geolocation, street number would need some tr…

You know its almost trivial to buy millions of people's full names, addresses, estimated income, etc., from legit data brokers right? It's how credit card start-ups know who to send direct mail to and it's 100% legal.
Post reply on HN