19 ms·
Xfinity Is Man-in-the-Middle Attacking My Internet
- jbob2000 7y ago> They injected 581 lines of JavaScript code, resulting in a total of 48.5kb data resulting in additional data towards my data cap, as well as my page becoming interactive ~250ms slower. This means that even though my internet is faster than before, my computer performs worse when utilizing Xfinity internet. I get the complaints, it sucks, it degrades the internet experience. But come on. This is the most contrived complaint I can think of. You get at least, what, 40GB of data a month? Please tell me about how using 0.0000048% of your data cap is affecting you. You used more data writing this blog post than that javascript code would use in 10 years. It sucks, but stop contriving bullshit about it. It's not that bad, it's just ugly and intrusive. Take your stand on that hill, not this one.
- josefresco 7y agoPretty sure the Xfinity data cap is 1TB. I just checked, and I've used just over 1.3TB this month (yay streaming TV), no notice, no MTM, maybe I'm .... lucky? Update: I used 1.6TB the month prior - also no notices. Maybe it's because I have Xfinity at my office too? No idea why they aren't harassing me.
- withinrafael 7y agoInteresting data point. Would also be good to know that your bill doesn't reflect your overage either.
- BubRoss 7y agoThey won't be able to to MITM encrypted connections.
- slimginz 7y agoI believe they give you 2 months of going over before they start charging you as a 'warning' that you're over the data limit. Not sure if they warn you if you go over in those two months or not.
- josefresco 7y agoEgad. If you see my updated comment I went well over last month (1.6TB), and now this month as well. We'll see what they say. Like most people, Xfinity is my only high speed Internet option.
- bdcravens 7y agoThey will likely encourage you to upgrade to the unlimited plan (+$50 each month)
- josefresco 7y agoI looked back, and over the summer I used well over 1TB for several months. Not a peep from Comcast. I'm going to shut up now, before Murphy's law applies.
- jgrowl 7y agoThe injections where particularly annoying for me because I was planning on getting the capped removed, but wanted to use those two months before doing so. I started getting those warnings about 2-3 weeks in for both months.
- swasheck 7y agoi wonder if the data cap is just at the router level or if they charge you for whenever you use any of the other xfinity hotspots that they set up on their customers' routers.
- LocalPCGuy 7y agoIn my experience, they do warn you during the 2 months where the overage fee is warned. The injected message might be slightly different to indicate that it is one of your 2 months where the fee is waived.
- rhinoceraptor 7y agoAFAIK, if you have a plan that comes with the Xfinity router, you don't have a data cap. Otherwise, you need to pay for unlimited data (which is pretty hard to explain to the call center people who really want to sell you cable and/or a landline).
- LocalPCGuy 7y agoIt's only the XFi router that gives the "free" unlimited service, and even that I believe may only be in certain areas.
- josefresco 7y agoI lease my modem from Comcast (not Xfinity combo) and have exceeded my cap repeatedly since switching to steaming TV without any notice.
- oblongx 7y agoIt depends on where you have service, the caps are not active in all markets. https://dataplan.xfinity.com/faq/ https://dataplan.xfinity.com/faq/
- josefresco 7y agoThanks for the link. My state (MA) was not in the list.
- metamet 7y agoIf you've gone over before, they will charge you $10/50GB of additional data, capping at $200 more a month. You can pay them an extra $50/mo to remove the data cap. This is coming from someone who unknowingly got a $200 bill one month because of Comcast. I left them and don't regret a second of it. Terrible customer service all around, and just an evil company from the top down, especially after having read Farrow's recent book Catch and Kill.
- munk-a 7y agoThe issue is that most people can't change off of it due to a lack of competing service providers.
- yellowapple 7y agoWhen I moved to Daly City my options were either Comcast or DSL. I picked DSL (w/ Sonic), at significantly slower speeds. Sonic's DSL is just resold AT&T DSL, which I also hate, but I hate Comcast more. If my only options were Comcast or dial-up, I'd probably still pick dial-up.
- zentiggr 7y agoI would love to see the news story about Comcast having fewer remaining subscribers than the DSL provider... still wouldn't make them change their practices, I believe they are too far corrupted to ever 'heal', but it would be hilarious if they gave up serving an area because it wasn't economically viable anymore.
- yellowapple 7y agoWell a man can dream, right? :)
- crooked-v 7y agoAlso, the cap is still 1 TB even if you're paying them $127/mo for the 1000 Mbps service, so you may as well just consider that +$50 an extra hidden fee for anything over 250 or 500 Mbps, assuming you're actually using it.
- synzachsynzach 7y agoNot all areas have data caps, it seems to be localized to specific regions.
- dcow 7y agoBecause it’s happens with every single request. But also that doesn’t matter it’s just wrong.
- grepsedawk 7y ago250ms is a lot. 50kb isn't a lot on it's own... but when it happens consistently then it adds up quickly. Also, it's just plain wrong to charge me for what I didn't ask for.
- bdamm 7y agoThe argument is weak, but it's also desperate. These days trying to influence companies often comes down to some argument based on objective costs. "You are modifying my content against my wishes and adding latency to my Internet browsing experience" isn't objective. Personally I think it is morally wrong, and it also is definitely impacting a person's Internet experience. 1/4 of a second is an eternity if you're sensitive to latency. So yeah it is "that bad", it is ugly, it is intrusive, and it speaks volumes about Comcast.
- Davertron 7y agoAgreed. > The way this code was implemented, the code blocks the page from loading for 250ms, resulting in a much slower internet experience. Of all the things to complain about that load on almost every web page you visit this seems like the least of your worries. I agree this is in poor taste, pretty annoying, and could be leveraged to dupe unsuspecting people into coughing up their Xfinity credentials, but complaining about it slowing down page load is like complaining about the heat in hell.
- jbob2000 7y agoThat’s what I’m saying! I must have really hit a sour nerve, my comment was apparently so bad that it got flagged and my post history was torn through to add tons of downvotes.
- xeromal 7y agoYeah, they've been doing this for years. It sucks.
- grepsedawk 7y agoTotally aware it's old news... and I was hoping to paint a better picture than the previous artists.
- xeromal 7y agoYeah, I'm not hating at all. Just signalling frustration with you.
- kdbg 7y agoCurrently down, here is an archived version: https://web.archive.org/web/20191029172726/https://rietta.com/blog/comcast-insecure-injection/ https://web.archive.org/web/20191029172726/https://rietta.co...
- grepsedawk 7y agoCheers, back up now. Might have been scaling.
- josefresco 7y agoHow do you know that their (Xfinity) JavaScript code counts against your data cap?
- kevin_nisbet 7y agoI'm curious about this as well. When I worked on content-based billing in Canada years ago, we zero-rated content that was served by us, so it wouldn't contribute towards data usage. That was a different time though and likely a different implementation.
- BoorishBears 7y agoSo much of the tone of this article is vaguely alarmist, which is a little annoying... seeing as the issue described is already extremely alarming It didn't need the theatrics and intentionally misleading garnishments (like quoting Comcast's own RFC that's describing their own recommended behavior for themselves, then pointing out you can phish people, and then awkwardly trying to glue those tangential points together) The bad behavior is bad enough that it'd stand on it's own, and if it instead focused on things like accessibility up front, it'd be much stronger of an article (and people would be more likely to read it all the way through)
- yellow24 7y agoI am also curious! I want to know how the author got to their conclusion.
- B-Con 7y agoEven if it does, that's way overnight on the article. A few 50KB here and there aren't your problem if you're blowing past a 250Gb or 1TB data cap.
- swasheck 7y agodoesnt fort collins have municipal internet now? reading here: https://www.fcgov.com/connexion/ https://www.fcgov.com/connexion/ i guess i didnt realize all of fort collins wasnt yet covered.
- grepsedawk 7y agoOut where I am we don't have fiber yet :( We'll be switching ASAP when it's available.
- swasheck 7y agoi love fort collins so much and it gets even better the further north and/or west you get.
- Jaepa 7y agoEven if that is a case for this specific user, that doesn't really resolve the underlying uses that is also affecting spaces that have a regional monopoly (e.g. me). EDIT: I understand that's not your point. And I whole heartedly support people leaving and supporting municipal ISP.
- swasheck 7y agoi understand your perspective. i live in denver and xfinity and whatever comcast lets centurylink have are my choices. i was initially reacting to the sentence in the post that mentioned that xfinity was the only available option and that struck me as wrong. i did a bit of research before firing off a post and discovered that my thought was incorrect and based off of incomplete information, but i left it there in case anyone else was under the same impression as me.
- Vpr99 7y agoYeah very few houses actually have been signed up so far. They're doing it on a street-by-street basis starting in the old town area.
- 7y ago
- chrisjc 7y agoThey can do this on any site including secured ones? I don't think the link makes this clear.
- criddell 7y agoI don't think this would affect requests over an https connection.
- vips7L 7y agoYou can MITM https.
- _vertigo 7y agoHow? Excluding cases where the attacker already has some sort of secret
- generalpass 7y agoThat's interesting. Can someone elaborate on this? My understanding is once the session is established, that's it. just encrypted traffic. How to inject something into ecrypted traffic?
- grepsedawk 7y agoDPI units can unwrap and re-wrap SSL
- yellowapple 7y agoComcast's RFC (6108) states that it designed the system described therein specifically to not need to use DPI. Not saying Comcast definitely doesn't use it; rather, that it'd be hilarious to see Comcast lie to everyone's faces yet again.
- boomlinde 7y ago
- RickS 7y agoDoes changing your DNS modify this behavior? I had some similar issues with Cox in DC, and switching to run everything through 8.8.8.8 resolved the issues. It also resolved a problem with CenturyLink in Seattle where for whatever reason I couldn't speedtest through fast.com.
- irq 7y agoCurrent Comcast user here, I can confirm that it does not.
- BonoboIO 7y agoDoes an allways on VPN help?
- grepsedawk 7y agoyes
- grepsedawk 7y agoNope, they physically open your packets, change the content of the HTML, and send the packets along the way. Even if you access the IP directly, it still injects code via MITM attack.
- bloody-crow 7y agoI saw the MITM injection from Comcast exactly once and it served as a reminder to go and change the DNS settings on my routers. Never seen the injection since, and I've been on Comcast for years.
- AtomicHyper 7y agoThat is odd, I recently got a MITM injection even while running everything on openDNS.
- cjsawyer 7y agoI used to live in Fort Collins and I was _floored_ the first time that an xfinity data limit popup appeared on a random website. Colorado needs a better provider.
- grepsedawk 7y agoFoCo is getting giga fiber!
- nolroz 7y agoThis makes me want to move back. https://ourcity.fcgov.com/citybroadband https://ourcity.fcgov.com/citybroadband
- cjsawyer 7y agoI’m glad that someone is benefiting from my vote :)
- fred_is_fred 7y agoI have GB fiber from CenturyLink for $85 until the city broadband, the city has had FTTH for at least 10 years or so, so anything new this should be doable.
- daviesgeek 7y agoI just got this as well. I’m appalled at the complete lack of thought put into this. I’ve had numerous emails & push notifications telling me I’m over my data cap; I don’t need injected content into my page in addition.
- grepsedawk 7y agoThey have my #. They have my email. They have my address. Those are the ways I want to be contacted.
- giancarlostoro 7y agoWonder where this falls under the Computer Missuse act?
- VonGuard 7y agoFirst time I saw one of these 4 years ago was when it popped into a Steam sale advertising window. Really creeped me out. A sure sign Comcast is pretty much 100% infected with Bovine Spongiform Encephelopathy. Still they offer Internet that is 10 times faster than the competition. Ah, the tyranny of the last mile. I went with Comcast Business, and they don't have data caps...
- floatingatoll 7y agoPost author, what website were you visiting that was served over http:// http:// allowing a data injection to occur? Have you contacted them to warn them that Xfinity is injecting JS into their site, and asked them to implement HTTPS+HSTS to protect against that?
- ProAm 7y agohttp://xfinity.com http://xfinity.com
- grepsedawk 7y agoHahaha they have mixed content
- wil421 7y agoI have Xfinity and they’ve done this to me. It only happened to my wife when she was browsing. My data Cap has hit 90% this month but I haven’t seen the message. 4K Netflix is no joke and can easily make me hit 1TB. Safari is my main browser and I recently stopped using Chrome. I believe my wife uses Chrome. Maybe this doesn’t work on Safari?
- jwilk 7y agoUgh: <style> body { display: none; } </style> To read the article without JS, disable also CSS.
- grepsedawk 7y agoDoes your browser not load <noscript>?
- jwilk 7y agoIt doesn't, which is admittedly pretty unusual. Never mind. Sorry for the noise.
- grepsedawk 7y agoOh okay! I just wanted to make sure there wasn't anything I could do to make this a better experience for you! Enjoy.
- inetknght 7y agoBetter solution: use Firefox and just prepend `about:reader?url=` to any URL you load. This article loads very nicely in Reader mode. about:reader?url=https://rietta.com/blog/comcast-insecure-injection/ https://rietta.com/blog/comcast-insecure-injection/
- grepsedawk 7y agoOne of the things I tried really hard to do is make the HTML _really_ clean for things like this. Is reader mode "really good" or do you think it loads very nicely because of the work we put in to make the HTML nice?
- inetknght 7y agoI think it's a mix of both. Honestly I vastly prefer Reader mode's presentation than any other layout, and especially any layout which changes if I interact with it (resize window, move mouse, click mouse button, press key, send window to background, whatever). I have seen some sites that completely break when using Reader mode. I have seen sites that are very well done in Reader mode complete even with pictures.
- regcapture 7y agoThis is why regulatory capture matters: https://en.m.wikipedia.org/wiki/Regulatory_capture https://en.m.wikipedia.org/wiki/Regulatory_capture Big govt bureaucracy is terrible, but a private one (which is confident they won’t face any trouble or practical consequences) is still trouble. There hopefully won’t be “mask off” moments for these providers & get really gnarly but this kind of behavior can screw over regular Joe’s & Janes
- lostcolony 7y agoI'm intrigued by why you created a one off account just to post this. To address something that stuck in my craw though - "Big govt bureacracy is terrible, but a private one (etc)" You're implying big government bureaucracy is the only option here. How about, you know, regulating internet as a utility? The thing we've been wanting since forever? Unless there's actively a shortage of water or power, I can get those and use them as I feel like, paying extremely low fees. I don't care if my internet is pay for use, provided it's priced close to the actual cost.
- KingMachiavelli 7y ago> This attack entirely breaks tab ordering, deeming the internet unusable for people requiring software assistance to provide accessibility to the World Wide Web. Additionally, the “escape” key, which is often used to close dialogs, doesn’t close the Xfinity notice. A few weeks (months?) back there was an article about ongoing litigation on if websites are required to have accessibility compliance under the ADA act. I would be very happy to see Xfinity sued for this practice under that precedent and hopefully any injection would be considered a violation. Status of supreme court case: https://www.scotusblog.com/case-files/cases/dominos-pizza-llc-v-robles/ https://www.scotusblog.com/case-files/cases/dominos-pizza-ll...
- hypersoar 7y agoThe litigation is over. The Supreme Court declined to hear the case a few weeks ago. The "Petition DENIED" at the bottom of that status page is referring to the petition for cert.
- AaronFriel 7y agoThat is inaccurate for many reasons. The Supreme Court declined to overturn the Ninth Circuit, because there was no circuit split or other issue of such urgency to require the Supreme Court to weigh in. The US Court of Appeals for the Ninth Circuit ruled (somewhat) in favor of the plaintiffs, and remanded the matter to the district court having reversed the lower court on some questions of law. I think it is still a live controversy in the district court, but it seems likely that the plaintiffs will win on the merits or obtain a settlement. https://cdn.ca9.uscourts.gov/datastore/opinions/2019/01/15/17-55504.pdf https://cdn.ca9.uscourts.gov/datastore/opinions/2019/01/15/1...
- bumbledraven 7y agoYou wrote "That is inaccurate", but you didn't cite a single inaccuracy in the gp comment. You wrote some other sentences, but they don't appear to contradict anything gp wrote.
- DaniloDias 7y agoCan we get technical details here? What JavaScript is being injected? What destinations are they adding? Edit: I missed it: https://rietta.com/blog/comcast-insecure-injection/injection-attack.js https://rietta.com/blog/comcast-insecure-injection/injection...
- inetknght 7y agoTechnical details are in the RFC submitted by Comcast: https://tools.ietf.org/html/rfc6108 https://tools.ietf.org/html/rfc6108
- grepsedawk 7y agoJavascript is in the blog post
- yellow24 7y agohow was it being injected? was it all pages http? could it be a plugin you have? did you try multiple browsers?
- masswerk 7y agoOn a broader level this is why the FCC is IMHO wrong in not considering broadband a telecommunication service. As ISPs inject their content (including advertising) into third party content, they essentially take over said content. E.g., if someone requests access to my content via their service, besides any corruption of functionality, artistic work and even intended meaning, any revenue generated by this is directly drawn from my content without license. From my perspective as a potential content provider, this is clearly a violation. It may be even a violation of existing contracts, e.g., if there's a no third parties clause involved in an existing advertising contract the content provider has agreed to.
- masswerk 7y agoFrom which quite naturally follows, if broadband providers in the US consider themselves content services rather than telecommunication services, they have to acquire licenses for the content they provide, as well. (Xfinity, may have your billing address?)
- jopsen 7y agoAs a content provider this is why you need HTTPS, and it's why you should ensure you certificate is in the transparency logs, and that your site requires CT entries.
- masswerk 7y agoHowever, this is more like "better have a lock so that thieves have a harder time breaking the door". If the US are making IP violations legal, they put themselves in danger to be treated like other countries who are considered notoriously ignoring IP as part of their overall business model.
- jopsen 7y agoTrue.. The sad thing is that with many kinds of cybercrime, it's easier to fix the security vulnerability, than it is to track down the criminals and make them stop :) In this case, the vulnerability is using HTTP, not HTTPS.
- api 7y agoEncrypt all the things.
- generalpass 7y agoWhy not get a $5/mo VPS and use VPN?
- grepsedawk 7y agoI'm paying plenty for internet. It's simple really, transmit my packet from point a to point b. Don't mutate it.
- aaomidi 7y agoDoing this doesn't change the fact that comcast is messing with http packets.
- LinuxBender 7y agoThis is a valid work around for an invalid problem. If your ISP is tampering with packets, that is the anti-pattern that needs to be remediated ASAP. In my opinion, the only packet change behavior that an ISP should be involved in is adhering to QoS headers. 0x08, it's bulk. 0x04 reliability, 0x10 low latency. And if they want to charge me more for 0x04, that is fine if it's clearly spelled out in the contract.
- generalpass 7y agoHow is the problem invalid? I mean, seriously - those guys spend a lot of money greasing the wheels of your local town council, and they gotta' put food on their plates like everybuddy else.
- LinuxBender 7y agoThe problem is invalid, because it is not a "problem". It is an "incident". Specifically a security incident that needs remediation.
- gregmac 7y agoOne of the problems with this is the same as any other bad behaviours companies often do that are indistinguishable from an attack, such as asking for your PIN on the phone, or sending account-related e-mails with links: They condition the user to expect this is "legitimate". As the article points out, an attacker could do something on an unrelated web server that injects this same notice (using the same code [1] as a basis), with a link that says something like "Extend your limit for free by 1GB", which loads a fake "Xfinity login" in a pop-up to phish their Xfinity account credentials. Because the link was presented using the familiar UI, it could easily trick someone and it would be nearly impossible for most users to realize it's not legitimately Xfinity. [1] https://rietta.com/blog/comcast-insecure-injection/injection-attack.js https://rietta.com/blog/comcast-insecure-injection/injection...
- fortran77 7y agoCan someone tell me for sure if XFinity is managing to inject this in Https pages? And, if they are, how are they doing it?
- grawprog 7y agoI'm not sure if it still works like this or not, but up here in Canada with Shaw cable for the longest time, it just started out of nowhere one day, I'd always get redirected to a Shaw landing page or have Shaw ads injected into pages when I was browsing. I finally really noticed it one day so I did some searching at the time and found out Shaw has an option in their account page(enabled by default), I can't remember what it's called, something like 'Shaw enhanced browsing' or some shit, but basically this 'feature' allows shaw to route traffic through their servers and inject content into sites. There was no description of this option in the account settings, they were buried 3 or 4 layers deep, there was no mention of this 'feature' from any of Shaw's customer service people, the only way I discovered this was through some random forum conversation I found. There was also people mentioning (this never happened to me)that despite switching the option off, they would find it turned back on again a day or two later and have to repeat the process. I have no idea if this is still the case, this would have been quite a while ago now, but I was pretty unimpressed when I figured it out and realized what was going on.
- grepsedawk 7y agoIMHO getting redirected would be WIDELY more acceptable than injecting content.
- ianmobbs 7y agoI mean I suppose, but even that seems wildly inappropriate.
- grepsedawk 7y agoI agree, but I still think it's "better"
- thenewnewguy 7y ago> 'm not sure if it still works like this or not, but up here in Canada with Shaw cable for the longest time, it just started out of nowhere one day, I'd always get redirected to a Shaw landing page or have Shaw ads injected into pages when I was browsing.
- shmerl 7y agoStates should ban data caps. That's the only way to deal with those ISP crooks.
- captncraig 7y agoThis is orthogonal to data caps. We could debate separately if people should be allowed to have contracts with those limits, but the actual problem here is that the ISP is modifying the traffic I requested before they deliver it. In this case it was for data cap notices, but next time it might be for ads or malware or anything else they want to inject.
- nishmastime 7y agoDisagree. Paying per byte is a critical part of making people realize they are part of botnets and to create the only incentives that have a shot at working naturally like pressure against poorly secured smart devices. Unlimited bandwidth just forces everyone behind Cloudflare and breaks the internet.
- RaiseProfits 7y agoOh so if I use a gig, I only pay for a gig? That doesn’t sound like a date cap, that sounds like a going rate for data. They still charge you for all the data you never consumed, which makes no sense as a transaction.
- shmerl 7y agoPay per byte is a fleecing scheme, nothing more. You already pay more for more bandwidth. ISPs get more than enough doing that without any monthly data caps.
- RaiseProfits 7y agoIt’s an extortion scheme.
- LinuxBender 7y agoAnd if there is a data cap, it should be proportionate to the data bw plan I am paying for. I had a 100mb/s plan with a 1TB cap. I moved to a 400mb/s plan and I still have a 1TB cap. So I can burst faster, but my overall usage is expected to stay the same. That said, I do most of my downloading on VPS provider, then what I finally want to keep, I compress and pull it down over my VPN. This still doesn't help for things like streaming movies, game updates, etc...
- simpsond 7y agoCox does this as well. I was recently staying a hotel and they were doing something similar prompting me to rate my experience. I started thinking about standards to make this kind of thing impossible... Ultimately TLS solves this issue. We should be bullish on making TLS standard.
- GhettoMaestro 7y agoTLS is pretty much standard. Unless you mean in some other way I am not paying attention to.
- simpsond 7y agoI agree it is "pretty much standard" but the ISPs and other network providers are not doing this with TLS traffic. They are only injecting the scripts in HTTP requests without TLS, at least in my experience.
- tekknik 7y agoCox is absolutely MITM this too. HTTP/HTTPS it doesn’t matter. Terminate the tunnel, forge a cert and QED.
- grepsedawk 7y agoTwitter thread: https://twitter.com/grepsedawkward/status/1189222349763235841 https://twitter.com/grepsedawkward/status/118922234976323584...
- Sephr 7y agoXfinity is most likely committing data usage measurement fraud due to their implementation of this banner. I asked the person responsible for the banner if it counted towards data caps and was ignored. https://twitter.com/sephr/status/941067958096244741 https://twitter.com/sephr/status/941067958096244741
- grepsedawk 7y agoRT'd
- WillPostForFood 7y agoThey typically don't count traffic within their network towards the data cap (e.g. streaming Xfinity TV), so I don't think it is safe to make an assumption about the banner one way or another.
- grepsedawk 7y agoIt's delivered alongside the webpage so there's no technical way to split the data logically... Unless they're using "rough math".
- diminoten 7y agoYes there is, it has to come from somewhere, and we know it's not coming from the actual site being visited...
- Havoc 7y ago>it has to come from somewhere Very much doubt they count their traffic by adding up all the origin addresses contributions individually
- diminoten 7y agoYeah, I doubt any of it counts at all, and honestly this is the least compelling part of this argument... It's kb vs. 100GB, hardly matters.
- kinghajj 7y agoThis is exactly why I cancelled my Comcast service a few years ago and switched to Sonic, even though it had orders of magnitude less bandwidth. I even offered to stay on as a customer, and pay whatever 'overage' fees they charged, if they implemented some way to make exceptions and never inject the data cap warning on my account, but they claimed that was impossible. When I returned the rental equipment, I made it absolutely clear that I considered this practice immoral and reprehensible. If anyone else considers cancelling their service, but has trouble getting Comcast to let them actually do it, just remove your payment method from the account, and let them know that if they attempt charging to it again, you'll sue them for fraud; that'll get your account closed real quick!
- nullc 7y agoI used Sonic (DSL) for five years while I lived in the south bay and I was extremely happy with the service and the company. Where I live now comcast is the only broadband available and although the service is theoretically faster and somewhat less expensive, I'd pay twice the price for sonic. Comcast is unreliable, intermittently very slow, and the company is impossible to deal with.
- LeoPanthera 7y agoI would happily switch if I had literally any other choice here. There isn’t even any phone lines running to our house, it’s Comcast cable or nothing.
- mjevans 7y agoThe suburb (outside of Seattle city limits) that I live in is a suburban area, density is easily high enough. My choices are Comcast (up to 1gbit down / 30 mbit up IIRC) or rotting exposed copper POTS (from Clink?) that has VDSL at something around 10mbit down / 1 mbit up. Thus, I have only one choice of broadband provider and due to lack of competition as well as lack of regulation, no broadband providers that offer unlimited service* (technically Comcast will happily charge me 600 extra dollars a year for no increased speed but no caps; however they shouldn't even bother with caps on their highest tier packages).
- paulmd 7y agoTheir data cap notice interstitials are seriously obnoxious, I ran into the same problems. I'd end up with "stuck" pages where it would just randomly appear even after I clicked close. What I eventually had to do was open a browser tab with no adblock (perhaps Chrome Incognito), close the notice, restart my router and modem to flush DNS, then flush locally to be sure it's gone. That usually worked.
- _bxg1 7y agoHTTPS should prevent MITM on web pages, no?
- aaomidi 7y agoYep - all websites should be using https honestly. There's barely any excuses left not to.
- yellow24 7y agoCan you post the code that was found or how they are doing this? I feel like details are needed before everyone grabs their pitchfork here.
- rootusrootus 7y agoIt's linked to in the article.
- gzer0 7y agohttps://rietta.com/blog/comcast-insecure-injection/injection-attack.js https://rietta.com/blog/comcast-insecure-injection/injection...
- Youden 7y agoHonest question: If I own the copyright to a webpage (say my personal blog) and Comcast modifies my page to insert this "helpful" warning message, is it likely I'd have a case to sue them for creating an unauthorized derivative work of my content?
- grepsedawk 7y agoI was wondering about this too. Honestly just https and at least you're gtg.
- na85 7y agoIANAL but I think you have to demonstrate harm.
- tathougies 7y agoSlower pages are clearly linked to lost revenue (even a few milliseconds has been shown to affect conversion rates). This would be an easy case, I think.
- pdkl95 7y agoRegarding actual damages, popups about data limits that appear to come from my page can easily damage my reputation or give the false impression that I have so9me kind of relationship with Comcast. Since they are making a new derivative work without the authorization of the copyright holder, they are probably guilty of copyright infringement. The remedy for that could include statutory damages for each work they infringed of "a sum of not less than $750 or more than $30,000 as the court considers just"[1]. However, since the infringement was patently willful (they published an RFC explaining their intentions and methods), "the court in its discretion may increase the award of statutory damages to a sum of not more than $150,000."[2] [1] https://www.law.cornell.edu/uscode/text/17/504#c_1 https://www.law.cornell.edu/uscode/text/17/504#c_1 [2] https://www.law.cornell.edu/uscode/text/17/504#c_2 https://www.law.cornell.edu/uscode/text/17/504#c_2
- evantahler 7y agoTake a screen shot of the banner covering up a contact form or subscribe button, and you may have damages!
- tolmasky 7y agoSetting up your own VPN with something like Streisand should protect against this right?
- grepsedawk 7y agoyes
- corn13read 7y agoWe need a class action for this
- auiya 7y agoSo the decision then becomes which do you trust more, your ISP, or your VPN provider? I choose to only give my money to businesses which perform in good faith to their customers, regardless of competitive advantages in other areas.
- celeritascelery 7y agoI am in Fort Collins as well. Can’t wait for the city broadband to come to my area and ditch Comcast permanently.
- useful 7y agoThis is related but what is the best trade-off for security vs privacy? Personally, I'd love the ability to inspect what goes over my network and devices. I should be able to choose to intercept/log unencrypted content. (I guess this is actually the NSA-lite argument) With key pinning and HSTS it makes seeing what the content of a packet is really hard. On android you actually have to hack apk's to replace the keys. It used to be very easy to put everything through a proxy server or mitmproxy and install a certificate on a device. While I value privacy and security it seems like everyone tech company moves to "protect users" is really a way to keep their adware and spyware running on their walled gardens.
- deleted 7y ago[deleted]
- pdkl95 7y agoThis is copyright infringement. >> 17 U.S.C. § 106 ...the owner of copyright under this title has the exclusive rights to do and to authorize any of the following: (2) to prepare derivative works based upon the copyrighted work; Instead of conveying the authorized copy from the webserver to its intended recipient, Comcast is intercepting the original copy of the file and making a derivative version of the work. Unless they received special permission from each website owner (which is unlikely), Comcast is infringing the someone's copyright every time they make a modified copy without permission. How many HTML files have they willfully[1] modified? [1] why willful? They published the technical details of how they modify the original work in an RFC.
- tenebrisalietum 7y agoInteresting. Here's some counterpoints. 1. Can it be considered "modified enough" to be considered derivative if it's the original file, plus some Javascript to provide a pop-up notification? 2. These MITM alerts are typically customer-beneficial and customer-relationship-oriented; the purpose is to alert that the user is getting close to a bandwidth cap. Similarly, there's current talk of somehow making ISPs or service providers deliver EAS alerts. Comcast already has to do this for EAS alerts on its television service. Does Comcast violate copyright when it interrupts a television program to show a federally required EAS alert? 3. Captive portals are a well-established instance where a page requested is not what's delivered. No one is accusing them of copyright infringement.
- curryst 7y ago> 1. Can it be considered "modified enough" to be considered derivative if it's the original file, plus some Javascript to provide a pop-up notification? They're altering the functionality of it, fairly substantially imo. I would argue that copyright should protect your IP from being subverted to serve additional, annoying pop-ups. > Does Comcast violate copyright when it interrupts a television program to show a federally required EAS alert? In that case Comcast is not altering the contents of the work, it is replacing the content with other content. I don't think that's a violation of copyright at all. > 3. Captive portals are a well-established instance where a page requested is not what's delivered. No one is accusing them of copyright infringement. Again, they are not modifying the returned content, they are refusing to display the requested content and returning alternative content.
- peterwwillis 7y ago> They injected 581 lines of JavaScript code, resulting in a total of > 48.5kb data resulting in additional data towards my data cap, as well > as my page becoming interactive ~250ms slower. Give me a fucking break! I have no massive love for Comcast, but are you seriously going to complain about 48.5 kilobytes against your data cap??? This person is desperately seeking something to complain about because they don't like Comcast, not because some harm has been done to them. It's 50 kilobytes. Your cap is what, a terabyte? That is literally 1/20,000,000th of your data capacity. > Insecure: Not only is it morally wrong to inject content into websites, > but it is also extremely dangerous. It's also impossible to do over a secure connection!! The thing happening is your ISP (the people you give your credit card to) informing you of potentially going over your data cap, by using an insecure connection you are initiating. You already trust them financially, and they're only doing this to help you. They are in no way making you any less secure than you already were. The only "dangerous" thing happening is your use of an unsecured connection! > Inaccessible to Users with Disabilities Oh, I'm sorry, are you a disabled user? Do you work on behalf of disabled users? Have you heard complaints from disabled users about this particular alert breaking the internet for them, because disabled people have never seen a pop-up before? Yeah, the web sucks if you're disabled. This particular "attack" is no different than just the regular everyday experience on the web. Please write another post just about only this subject, and I would take this seriously. But in truth, you're just piling on anything you can to make this seem worse. > Finally, this injection breaks common legacy programs. One example was > an older apt-get repository which choked up when given foreign content. > This resulted in a major loss of personal investment, as I was > unable to utilize my internet during this time. Major loss of personal investment? Are they an ambulance chaser in their spare time and the old, non-secure apt repo they're using delayed them? Dear User, please get over yourself. Sincerely, The Users With Actually Serious Problems.
- castis 7y agoPurposely sidestepping the entire spirit of the issue is not going to help whatever this is you're doing in the name of The Users With Actually Serious Problems.
- jermaustin1 7y agoAt least Xfinity is giving you information /s. Optimum Online does this and serves me advertisements for new channels or movies available through VOD [1] 1: https://imgur.com/a/UZYd7JH https://imgur.com/a/UZYd7JH
- accidentaldev 7y agoThis is happening with BSNL ISP in India. They re direct non https pages to phishing sites that claim my computer has virus. It is just shocking that ISP will re direct me to known phishing site.
- bifrost 7y agoGlad I dropped the worst ISP in the USA. You know its bad when even important morons (bureaucrats) call you a terrible company.
- LeoPanthera 7y agoI also have Xfinity and began to experience this a few years ago. When it started I configured my router (pfSense running on an APU2) to forward all outgoing connections on port 80 (and a selection of other commonly unencrypted ports) through a VPN - but leave all other ports, especially 443, alone. I’ve been doing that ever since. It works great, and for me is a good trade-off over using a VPN for literally everything.
- hansdieter1337 7y agoDid you just upload Comcast’s code to your site, made it publicity available, and glue a GPL license to it? I wouldn’t be surprised if Comcast will try to sue you for that.
- rthille 7y agoThe also MITM DNS and cache negative responses. Comcast sucks.
- peter303 7y agoComcast gives me terabyte of downloads a month. I use 5% to 10% of that, but on what I dont know.
- bdcravens 7y agoIf you have one of their newest routers, you can see a breakdown by device.
- glitcher 7y agoI have Cox Internet and they do the same thing when you reach 85% usage. I probably don't see it very often though because most of the sites I'm on are https.
- crooked-v 7y agoOf course, this whole thing is also overlooking the absurdity of a 1 TB monthly data cap on a service offering up to 1000 Mbps bandwidth.
- zeta0134 7y agoI did the numbers with the AT&T sales rep here in South Texas, which has a similar plan and cap. If my math is anywhere close to correct (questionable), actually pulling 1000 Mbps would would exhaust the 1 TB cap in about 2.3 hours. Yes, hours. That cap cannot sustain the advertised speed for even one full day before hitting overage charges. Needless to say, we went with a different service provider. We are fortunate here to have an option (alas, still a cable company) that has no data cap, but not everyone is so lucky.
- mitchty 7y agoYep, it doesn't take long. https://www.wolframalpha.com/input/?i=1Terabyte+at+1+gigabit%2Fsecond https://www.wolframalpha.com/input/?i=1Terabyte+at+1+gigabit... Think of all the "cloud" kind of things you could enable if you could use that bandwidth. Only we can't. Think backups of your entire disk etc... massive p2p cluster filesystems stuff like that. All not possible cause of these data caps.
- throwaway-mitm 7y agoI have first-hand knowledge about how Comcast's content injection happens. (they'd prefer to call it "User Messaging") I'm sure you'll find the same ability from several ISPs because they all purchased a network appliance that does the content injection. One question people are asking here: does it work over HTTPS. No it does't work over HTTPS, but if the page requests content via HTTP it is possible. Interestingly enough, the technique is very similar to what Edward Snowden revealed as Quantum Insert, where HTTP requests monitored by the ISP and are intercepted and another web server (the network appliance in question) is able to respond more quickly. It starts with a very fast response that leads to a 302 redirect. The network appliance will then serve up a modified version of a file (usually a JS asset). The injected JS will then query the network appliance for "messages" and show them if the user is "eligible" to receive them.
- syntheticcorp 7y agoCould you elaborate on this a bit please? What is the appliance called? Do all HTTP requests flow through it and anything else bypasses it? Does it store or log any of the requests or responses?
- throwaway-mitm 7y agoI'm hesitant to name the device, because thus far the company who makes it has escaped scrutiny, and I'm not the one who's going to change that right now. There was an Ars Technica article a few years ago that made reference to Xfinity doing this to notify people that they were using a hotspot. They had a follow-up article that nobody read where they pointed to the company that made the device, but they slightly misidentified them. Mostly people were upset at Comcast. The appliance is used at Cox, Shaw, and many other major ISPs all over the world: Europe, Latin America, The Middle East, Asia. There are basically two major companies operating in this space, as far as I know. It is capable of monitoring ALL http requests, which is only about <5% of traffic going through an ISP. The more traffic you have, the more devices you need, but one can take care of a LOT of traffic, and I believe it can run as a VM. I'm not sure how it works as a VM exactly, because it also contains a custom Ethernet driver. The same device directs people to the captive portal (if i'm not mistaken) used for logging into xfinity, or other public wifi from other providers. Because performance is a high priority, the logging is minimal, but it keeps track of who's been served a message and doesn't collect any PII. The device is capable of serving any content, even causing a request from a third-party. So, it's possible that the content that gets ultimately injected is able to do whatever... anything a malicious advertisement would be capable of doing. Your message eligibility is highly configurable, and can include metrics such as whether you visit certain sites, and possibly even your physical location. There's a couple phases. First the network appliance injects so light code, using the Man-On-The-Side 302 redirect method. Once that's done, the injected code is probably going to request additional content after checking if you qualify for a message.
- getcrunk 7y agoDoes and if so how does this happen over https?
- dmix 7y agoThis is why I hate those “why you shouldn’t use VPN” articles.
- turc1656 7y agoYet another reason to use a VPN. Comcast can't inject this crap if they can't see the DOM/html.
- djsumdog 7y agoI noticed this type of notification injection on a mobile phone in the EU for my own personal websites. It strongly pushed me towards implementing LetsEncrypt and redirecting my users to HTTPs. ISPs can't inject anything into the HTML if you force a secure connection (unless they've gotten the end user to install their CA and inject generated certs).
- badrabbit 7y agoOh please,this is not new. They've been doing this for at least 5 years that I know of. If you pirate,they dmca alert you with MITM'd divs in the html pages you visit. I mean the fact they inject http headers is one thing but they don't even care to do a 301 or mess with DNS responses,they will inject code in your browser tab! Lawyers on HN, how is this not a violation of CFAA? If I sat at a coffee shop and did the same thing (say a "harmless" js "alert('Hi everyone!');") that is punishable with penalty up to 5 years imprisonment. So you're saying if I was the ISP that's ok? Why is the FBI/DOJ not criminally prosecuting comcast's CEO? Preferential treatment or prosecutorial discretion? Will comcast start pushing back on dragnet sutveillance cooperation? The whole thing is so crooked! How can we bring this to the attention of lawnakers and media?? If the post office put notes in your mail (outside of a law enforcement request) would it not be a big deal?
- acdha 7y agoHave you read your ISP’s terms of service? Do you really think Comcast didn’t include language giving them the right to do almost anything to your traffic?
- badrabbit 7y agoAn agreement is invalid if it is unlawful. Think of it this way, a packet in transit belongs both to the sender and receiver but never to the intetmediary. Even if a comcast customer agreed to a ToS stating all their traffic solely belongs to Comcast, the servers sending the traffic to the Comcast customer never gave that permission,they never allowed comcast to present altered content to their customer. The only way that reasoning holds up is if comcast and comcast's customers are one legal entity(you're essentially their subject much like an employee but even then employees are distinct)
- acdha 7y agoHow is this unlawful without robust network neutrality legislation? They’re not claiming ownership or redistributing it, and I’m sure they’d argue that this shouldn’t have any side effects. I’m far from a fan of Comcast but this doesn’t seem like something we have a good legal angle for addressing.
- boomlinde 7y agoTake a screenshot of your website with this notification injected and send Comcast a standard DMCA take-down request. They are distributing illegally modified copies of your website.
- peter_d_sherman 7y agoWe need a service which tests web pages from different points on the internet, including foreign countries, at regular intervals, and compares the results to a known good version of that page, and its code. It should answer such questions as: 1) Did the website load? 2) How long did it take to load? 3) Was the content tampered with in any way, was anything added to, or deleted from the content, including any code, such as its javascript? So, be able to perform those tests, from a variety of points on the Internet, from a variety of IP addresses, at regular intervals, and report back. Noting any and all discrepancies, and storing all anomalous web page data retrieved (including code) for further analysis...
- jkoberg 7y ago> (Comcast still has datacaps. Pricing like it’s 1999…) That's not how internet was billed in 1999. You paid for the size of the pipe, not how much data came through. Per-byte pricing is pretty much a cell carrier and Comcast invention
- acdha 7y agoThis is sadly common: I’ve run Sentry (https://github.com/getsentry/onpremise https://github.com/getsentry/onpremise) for years to collect JavaScript errors on the sites I run. If you haven’t done so, it’s eye-opening how noisy the JavaScript environment is for many people: ISPs, browse extensions, anti-virus software, etc. all injecting tons of marginally-tested code, most of it written at a level which would have been shameful back in 1998, and apparently little awareness of how to avoid polluting the global namespace. A similar bit of malware had a surprising twist: many ISPs, especially mobile, used an image compressor which made things look terrible but, unexpectedly, it honored Cache-Control: no-transform. See https://stackoverflow.com/a/4113511/59984 https://stackoverflow.com/a/4113511/59984. I’m curious whether Comcast does that – it would be surprising but also possible as a way to reduce the risk of lawsuits.
- corford 7y ago1. Grab a cheap VPS with a decent monthly b/w quota and datacentres near you (Linode or Scaleway come to mind) 2. Buy whatever meets your criteria on https://openwrt.org/toh/start https://openwrt.org/toh/start and install OpenWRT on it (I use a Mikrotik RB750GR3 with a Ubiquiti UAP-AC-LITE for wifi) 3. Setup Wireguard (https://lists.openwall.net/netdev/2018/08/02/124 https://lists.openwall.net/netdev/2018/08/02/124) on the VPS and OpenWRT 4. Be happy
- ekimekim 7y agoI made a complaint to the FCC about this when they started to do this to me. A month later I got a cookie-cutter response from Comcast, but it felt good to at least cost them some tiny amount of time to need to respond. I ended up moving house to get away. ISP options are now my #1 factor in deciding where to live, and if Comcast is the only viable option then I'm happy to tell apartment managers I'll look elsewhere.