3 ms·
There was no mass exposure of sensitive data. Two paths existed for determined attackers to get the home address and possibly SSN for individually targeted acc
by eric_b 8y ago
There was no mass exposure of sensitive data. Two paths existed for determined attackers to get the home address and possibly SSN for individually targeted accounts. The process was manual and would have been difficult to automate to compromise "millions" of accounts.
Based on the details in the article, this sounds like something that needed to be fixed, but probably not even worth the time to write this article.
- meowface 8y agoStrongly disagree. This effectively granted anyone with basic HTTP knowledge the ability to dox anyone they interact with online, if that person is using Comcast. The attacker does not need to be "determined" at all; it's trivial to get someone's IP address (send them a link of any kind) and with this vulnerability, trivial to find most of their home address. In short, some asshole kid could send a SWAT team to your house just by knowing your IP address, with not many steps in between. The SSN last 4 digit bruteforcing is really bad, too. I'd say arguably not as bad, since it's not very hard to get most people's SSNs on black markets these days. This is not a breach, but these are two massive vulnerabilities and deserves many articles.
- btilly 8y agoThere is no shortage of asshole kids who use SWAT teams in exactly that way. See https://en.wikipedia.org/wiki/Swatting#Injuries_or_deaths_due_to_swatting https://en.wikipedia.org/wiki/Swatting#Injuries_or_deaths_du... for a list of some notable cases.
- meowface 8y agoAbsolutely, but this exposure made it much easier to do en masse, plus made it possible to dox targets who otherwise have good OPSEC and aren't easily identified.
- oh_sigh 8y agoThis wouldn't necessarily be about determined attackers. Maybe a crazy guy you were beefing with in an online game has your IP address, and from that could get your physical address.