9 ms·
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using. We start telling customers that a
by jlivingood 9y ago
> Although I disagree with Comcast's method and categorization, it would be interesting to learn what modem the OP was using.
We start telling customers that a modem needs to be upgraded when one of two things happen: either they are about to or just had a speed upgrade that their modem cannot support or the modem has gone end-of-life (EOL) from the vendor.
In the former case, if the device is leased, you are send a new one to replace the device and just have to basically say ok. In the latter case, it is a customer-owned device so the customer is asked to go buy a new one someplace (e.g. Amazon, BestBuy).
And in the EOL case, the vendor may have gone out of business or shut their cable modem business down, or otherwise decided to no longer support the device due to its age. That of course means that if a security issue came up, as they do, that the vendor would not be able or willing to provide a software fix for the device. So it's best to get the ball rolling to get those devices replaced when that occurs. Most of our EOL devices today are DOCSIS 2.0 devices (10+ years old), which can only do a single upstream and downstream channel (no channel bonding) and 1st generation DOCSIS 3.0 devices (5 - 8 years old).
- davidcbc 9y agoIf only there were some way to notify your users that wasn't so scummy... like via email or regular mail
- alexpetralia 9y agoIn the spirit of efficacy, browser injection may have a better response rate than email. Taking this to its next logical step, surely showing up in-person at your door is even more effective. Is that the idea here? Or does this efficacy come at some cost (namely, the sentiment behind this thread)?
- epicide 9y agoWith all the junk mail I get from my cable company about "upgrading" my service to include some crap I don't want, I would think they could find a way to slip in a "hey, your modem's busted" notice.
- santoshalper 9y agoBut you probably wouldn't read it, because lots of people don't read their email (at least partially because of the junk).
- JoBrad 9y agoYes, but if you don’t get the speed Comcast promises you, and you paid attention to that, then you’d call them up, and find out that way. More work, but way less scummy.
- serf 9y agoregional monopolies have never cared about scummy behavior.
- epicide 9y agoAnd I'm more likely to read a pop-up?
- rietta 9y agoSo they print Important Plan Information on the envelope.
- nerdponx 9y agoTime-Sensitive, Open Immediately You know it's actually an important piece of mail when the envelope isn't imploring you to open it.
- beamatronic 9y agoThe most serious snail mail correspondence is utterly and completely plain.
- rietta 9y agoOn the from line - Office of Legal Counsel...that’s getting opened.
- metaphor 9y agoI don't know what's worse: the straw man attempt at arguing efficacy while focusing on the weaker of two suggested options, or the (presumably) unscalable slippery slope of dispatching personnel to a customer's front door. In either case, the argument does not address the fact that customers recognize unsolicited packet injection as unacceptable ISP behavior. Without support metrics, we can argue all day about the efficacy of one method of delivery over another, but the fact remains that no sensible user would perceive e-mail and/or post of official notice from their ISP as overtly intrusive. With as much internal advertising as Comcast distributes amongst its existing customers, it blows my mind that official notice generated from boilerplate and delivered via snail mail would fail to achieve the intended goal. To be sure, your pre-edited comment: > Surely showing up in-person at their door must be an even more effective "reminder" than the browser injection! Is that next?
- octalmage 9y agoTime Warner did show up at my door when they updated their speeds. I thought it was strange,and asked him to have Time Warner call and schedule a time, but it worked. He was going door to door.
- tzs 9y agoRegular mail, yes. Email, though, is largely just a waste of time. Way too much non-spam disappears down overeager spam filters, which most people only check if they are specifically expecting some particular mail and it does not show up as expected--and even then many won't check their filters. An ISP could white list their own mail in their spam filters but that would only help with the customers who use their ISP provided email. A lot of people use third party email providers instead and never use their ISP email.
- jclulow 9y agoI find the reverse is true. My USPS mailbox receives daily credit card application forms, electoral flyers, catalogues, etc. I also get frequent mail from Comcast but they are _all_ bullshit ads, trying to hoodwink me into cable TV. I don't open them anymore, they just go in the bin. I will at least _glance_ at my email.
- pbhjpbhj 9y agoThey could sign their messages? Also needs users to have easy to use mua that handles signing and shows "this is genuinely from your ISP unless they/you've been hacked". For critical service info I'd want SMS personally, from a verified number with a link on the company main domain to verify the info.
- jasonlotito 9y agoIt was noted in the thread that other attempts are made first.
- ajmurmann 9y agoThank you so much for participating in this discussion! Frequently having people like you who actually involved in what's being discussed is part of what makes HN special to me and many others. As another comment points out though, I'd also like to understand why it was decided to comminate by injecting JS into pages people are visiting rather than following a more traditional communication channel like snail mail. I assume that this solution scales better and has get immediate $ attached. However, it also seems obvious to me that it reenforces brand image and political issues people have with your company.
- ruffrey 9y agoAll that may be true. There is no ethical excuse to ever inject code into a webpage. Your own argument about it being critical is false or sophistry. If there were wildfires coming to burn someone's house down..that might qualify as critical. Not this, and deep down you know it. You should be embarrassed to attach your name to such an obviously poor decision.
- QAPereo 9y agoI think the mindset is that at least he’ll be embarrassed on his yacht. Short of that thinking, you’d have to assume a few solid layers of cognitive dissonance.
- userbinator 9y agoThere is no ethical excuse to ever inject code into a webpage. ...unless it's for adblocking... Although I do that with a MITM proxy locally (and thus filters everything on my LAN), it would certainly lead to a very interesting situation if an ISP decided to do it...
- markbnj 9y agoI mean, the end-user who requested the page certainly has a right to voluntarily inject script into the page they requested as it is rendered in their own browser running on a machine they own connected to an upstream internet provider they pay for access? Nice try at false equivalence however.
- userbinator 9y agoWhat "false equivalence"? I was just pointing out an exception to the statement "There is no ethical excuse to ever inject code into a webpage".
- markbnj 9y agoIt's false equivalence because you (and everyone else) knows that the case of an end user injecting script into a page on the receiving end of the connection is not the scenario under discussion, and is not the behavior that the rule implied by the earlier comment would be intended to prohibit. If the comment was tongue in cheek then I have misunderstood you and withdraw my objection :).
- gech 9y agoOff topic to this post but can you confirm any details on your company's intentions following the dismantling of net neutrality?
- _jal 9y agoFirst, thanks for participating. Second, I am a Comcast customer who will never see these messages precisely because you do things like MITM unprotected traffic. Because I can't trust you to leave my traffic alone, all my traffic is tunneled. So at the very least, if you feel this is a critical service you are offering (as implied by the RFC), you need an alternative communications channel for people like me who don't permit this one. Snailmail is fine; you try to upsell me constantly through that channel already.
- novaleaf 9y agodownvoting because of snarkyness. Your suggestion of alt cmu channel is good however.
- bayonetz 9y agoDownvoting because they weren't that snarky and because of your smugness. Your willingness to tell some one straight up why you downvoted them was good however.
- novaleaf 9y agowhy am I smug? I totally agree with the premise and personally hate comcast, but if _jal wants to be taken seriously by jlivingood, snarkyness isn't the way to go. I don't mind the anon downvotes though, it's par for the course anywhere.
- pooloo1 9y agoI second this, in addition, the injection is not only related to EOS/EOL for modems it is also for when you are approaching your data cap. Which is rather annoying because it actually can halt your gaming or netflix experience oddly. I have had both happen, one I was playing PlayerUnknown's Battlegrounds and the game crashed. Since the game itself uses web based tools, for its menu system, upon restarting the client a Comcast injected message popped up warning me I have used 90% of my data cap. The same thing happened on Netflix ...
- tootie 9y agoAs a web developer this feels like an absolutely terrible practice. I have to support contracts for website performance, quality and behavior with clients and you could be putting us in breach. If I got a bug report of unexpected ads popping up, we'd probably waste thousands trying to figure this out.
- sova 9y agoSo many tickets with status "unable to reproduce" ugh
- octalmage 9y agoExactly. The first thing I thought about when I saw this was the implications of having JavaScript that has not been tested in the context of a website running. You have no clue how it will conflict. As a website owner you should have the right to verify all code that will run on your website to be sure that it won’t cause issues since only you have the context needed to make that call. What if there’s a global DIV selector that hides the close button, the website visitor is screwed! And they’ll just think it’s a problem with your website. One more note, there are way better ways to do what they’re trying to do. Even with how terrible IFrames are, they prevent CSS and JavaScript conflicts. A simple position fixed div at the bottom of the screen containing an iframe seems more appropriate. If you are going to run code on my site, make sure it’s as small as possible. This could have been accomplished in 2 lines of code (excluding iframe host).
- robin_reala 9y agoI’ve had to patch against this in the past when it turned out my system was breaking for a set of users whose company was installing a browser extension that injected JS that broke the app. Never did find out exactly what it did, but I worked around it but fixing the progressive enhancement to work properly in the context of broken JS as well as no JS.
- aaronbrager 9y agoYou can avoid this by using HTTPS.
- deleted 9y ago[deleted]
- aaronbrager 9y agoCan you discuss why DOCSIS 3.0 users get this notice? I have a 3.0 modem, and received the notice, but it looks like my modem will still support my speed tier (75mbps in Chicago)
- jlivingood 9y agoIt usually means you are about to get a speed upgrade that will go beyond what your modem is capable of delivering. In that case it is possible you could have a 1st generation 4x4 modem (so it can bond 4 downstream and 4 upstream channels).
- hamiltonkibbe 9y agoI wonder if your customers would be happy enough without the speed upgrade if they weren’t wasting bandwidth downloading code they never wanted to run in the first place
- notyourday 9y agoComcast does not provide any speed on residential lines that DOCIS 3.x cannot accommodate. It is like requiring Formula car to drive on a gravel road in Alaska.
- virtuallynathan 9y agoDifferent modems can use different numbers of DOCSIS channels. A 4x4 DOCSIS 3 modem is only capable of, at most, 150Mbps and on average 75-100Mbps. A new DOCSIS 3.1 model can do >1.2Gbps.
- notyourday 9y agoYeah, no. https://en.wikipedia.org/wiki/DOCSIS https://en.wikipedia.org/wiki/DOCSIS 3.0 spec does up to 1.2Gbit/sec, just like Comcast. You know up to 200Mbit/sec, which is more like 20 because of all the "extreme complexities of the internet service".
- zacwest 9y agoThe ARRIS SB6141 [1] is a DOCSIS 3.0 modem which is considered EOL by Comcast. This device is still being actively sold by the manufacturer. It handles the maximum throughput of most Comcast plans. It's not 5-8 years old. However, the supported device list [2] shows that it's still an allowed modem to use for a e.g. 200mbit connection. A user that's looking to purchase a modem isn't discouraged from getting one from Amazon. Since Comcast considers it EOL, any interaction with Comcast support includes the stipulation that it's likely the modem that's causing the problem, and the customer will be liable for a surcharge if a technician decides it's the modem causing a problem. For a brand new modem, purchased from Amazon right now. There seems to be a disconnect between EOL for the purpose of leasing a modem and EOL from the vendor. [1] https://www.arris.com/surfboard/products/cable-modems/sb6141/ https://www.arris.com/surfboard/products/cable-modems/sb6141... [2] https://mydeviceinfo.xfinity.com/device/arris-sb6141-336 https://mydeviceinfo.xfinity.com/device/arris-sb6141-336
- ryanpetrich 9y agoDoes Comcast's implementation of this system respect Cache-Control: no-transform as specified in RFC 2616?
- legohead 9y agoYou should not interfere with a customer's traffic they are paying for. If you need to contact them for a critical issue, then call, email, or snail mail. You risk disrupting their experience, and in some cases the customer may not even be able to receive your critical message. Does your JS injection work for customers who have JS disabled?
- erikbye 9y agoStop trying to rationalize it; this is not OK, period. If you can't reach your customer via his contact information, too bad, consider him a lost cause. And if it was something critical resulting in the customer's loss of Internet access, you can bet he will contact you then, if he cares.
- Sir_Cmpwn 9y agoYou have our phone number. You have our address. Use them! Do not MITM our connections, that's a huge violation of trust. This is NOT okay. Any response other than "we're terribly sorry, our engineering team is rolling this back on Monday" is the wrong response.
- brandonbloom 9y agoAs an (unwilling) Comcast user, I purchased my own modem because your rental rates are preposterous. However, I wish I didn't have to think about this at all. If you force me to upgrade a modem I've purchased, I'll be very annoyed by the unanticipated cost. I get that's problematic for your modernization efforts, but in that case: eliminate modem rental fees. Bake the fees in to the standard cost of the service and don't let customers use their own equipment. I understand that non-cable competitors don't have this cost to shuffle around, and that this will mean you are forced to either A) raise prices publicly or B) have lower margins. That's your problem because of your technology legacy; don't pass the misery on to the customer. While you're at it, offer two hardware choices: one with, and one without routing/wireless. I refuse to run a wifi network in my household for your other customers and expect complete control over my LAN configuration. On the topic of injection: I get that you don't think it's immoral, but hey, 1) most people who understand it think it is totally unacceptable. And 2) the window for this approach is rapidly closing for you as the web moves to SSL everywhere. Give up on this approach now and save face.
- TheRealDunkirk 9y ago> I get that's problematic for your modernization efforts, but in that case: eliminate modem rental fees. Bake the fees in to the standard cost of the service and don't let customers use their own equipment. I love how it's in the interests of public companies to brag about how successful they are. When I see a comment like this, I like to checkout the most recent 10K. According to Comcast's stated figures, they made $8.7 BILLION last year. So, they're doing pretty well. Now, obviously, they can't just give the modems away, but if they would at least STOP BILLING THE CUSTOMER for a leased modem after their costs have been recouped, that would be a HUGE public-relations win. If we all could buy the modem of our choice, over time, say, amortized over the length of your contract, and then RELIABLY stop getting billed for it, I'd LOVE to just buy it through them. I'd argue that the reduced support costs for NOT BEING RENT-A-CENTER JERKS about the modems would save them a lot of money in the long run.
- 333c 9y agoYou explain why it is important to notify about their EOL modems, but you fail to explain why this, of all options, is the appropriate communication channel. At the very least, you have customer addresses. You should also have phone numbers and email addresses. If you have a way to bill customers, you have a way to contact them. Injecting JS into HTTP sites is disgusting. It violates both the user's and the site's expectations and is entirely unnecessary.