Comcast to Customer Who Noticed Secretly Injected Code: Maybe It’s Your Fault
thenextweb.com
thenextweb.com
How about NO?
Phone company says that I'm too far for DSL, and they haven't deployed fiber to this area.
It would be nice if I had some kind of actual choice.
I rather doubt that Comcast tried the phone route, and the article indicates that the modem was not EOL, so overall I think the injection was ridiculous.
[1] Modifying an HTML file[2] (or any other protected work) creates a "derivative work"[3\. Without permission from the original author, distributing a copy of a derivative work is copyright infringement.
[2] Any "original work of authorship"[4] gains copyright protection when "fixed in any tangible medium of expression ... from which they can be perceived, reproduced, or otherwise communicated, either directly or with the aid of a machine or device."[4].
[3] "A work consisting of editorial revisions, annotations, elaborations, or other modifications which, as a whole, represent an original work of authorship, is a 'derivative work'."[5]
[4] 17 U.S. Code § 102 https://www.law.cornell.edu/uscode/text/17/102
[5] 17 U.S. Code § 101 https://www.law.cornell.edu/uscode/text/17/101
They may or may not be, but you are foolish to assert that they are infringing based on on a few select quotes. Are you also going to assert that it's also a copyright infringement every time a browser caches part of a web page to disk, or when a user runs an script to change the layout of a page? Both arguments have been made, but as far as I know, there is no clear precedent for either. For better or worse, US law is based on case-law, and unless you can point to some previous cases where modifying a web page on the fly has been judged to be copyright infringement, there is nothing open-and-shut about it.
I only included a few quotes for reference. My argument is based on my study of copyright law over the last ~25 years.
> browser caches part of a web page to disk
Obviously not a derivative work as the HTML file is not changed. Also, this is a fair use that doesn't publish additional copies (and thus doesn't impact the market for the original work).
> a user runs an script to change the layout of a page
First Sale doctrine states that the publisher's rights do not extend to how someone uses their (legitimately acquired) copy.
> there is no clear precedent for either
The only part that is at all unclear are the few cases that ruled on the temporary, ephemeral copies that a computer makes during normal use. These cases all resulted in different rulings, but the most recent of which (which may only have limited precedent) came to what should be the obvious conclusion that technically necessary temporary copies were a fair use.
None of this, however, is relevant to Comcast making new derivative works based other people's HTML files without a license and providing a copy of those derivative works to their customers. Providing unauthorized edited copies to 3rd parties has never been argued to be a fair use. ]
Well, it's definitely been argued, although you are right that eventually the court decided that it was not fair use to distribute "family friendly" version of movies. Perhaps counterintuitively, despite ruling strongly against CleanFlicks, the judge ruled that the because the changes were based only on redaction, the edited version was not to be considered a derivative work! https://freedom-to-tinker.com/2006/07/10/cleanflicks-ruled-i...
The Family Movie Act of 2005 further codified this right to redact, using the argument that if the edited version was only used for a "private home viewing", it did not violate the right of distribution: https://www.copyright.gov/docs/regstat061704.html.
None of this, however, is relevant to Comcast making new derivative works based other people's HTML files without a license and providing a copy of those derivative works to their customers.
Would a similar argument as to single viewer experience work in Comcast's case? I don't know, but in the absence of settled case law, I wouldn't bet against Comcast's lawyers getting a court to give the answer they want.
But maybe I can make it an easier question: Based on what they've done so far, what are the chances that Comcast will be sued for copyright infringement and lose? I don't have a lot of money to bet, but I think the chances are low that successful lawsuit against Comcast will be brought for what they've done. Do you think otherwise?
And they're getting it all wrong, sending it to customers who's modems do _not_ need upgrading... Doesn't exactly inspire confidence in their ability to manage and secure the Javascript injection mechanism...
I got what I think is this same message from Comcast a little over a year ago at my father-in-laws house. It alerted me that I needed to upgrade his still working but End-Of-Life cable modem to a newer model to keep continuity of service. I recall being slightly alarmed by the injection, and then somewhat disappointed that they weren't going to continue support for the old modem, but my eventual conclusion was that this was a useful last ditch effort to contact a customer. His contact email for for Comcast is in unchecked comcast.net address, the mailed notifications probably were thrown away as junk mail, he gets multiple spam phone calls per day which he usually ignores, but this message got through.
Surreptitiously modifying web pages would be atrocious, but a last-ditch effort at notifying a customer that they are about to lose service is not the same as Man-In-The-Middle attack for nefarious purposes. I agree that there is a legitimate fear that once it becomes known within the company that this capability exists it will eventually be used for something worse, but (even as someone who despises a lot of Comcast's business practices) alerting customers that they are about to lose service is not something evil in itself.
Everyone technical knows (or should know) that their ISP can modify the content of non-encrypted pages. I can't help but think that most people who complaining about this are actually more distraught at having their illusion of security broken than they are at Comcast's behavior. Getting mad at this is like threatening to sue the locksmith you hired for demonstrating how easily your current locks are easily bypassed with a bump key. The problem is not with the legitimate uses of this sort of injection, but the potential for misuse, which has not yet been demonstrated.
Personally, I'd guess it's because (like far too many parts of the internet) their implementation is subtly broken, and not because of anything nefarious. I don't recall the details of how it worked when I was the recipient, but I think the message correctly went away after I acknowledged it. I'm OK with treating repeated notification as a serious bug, just against equating a failed attempt at customer notification with a man-in-the-middle attack. I'm not universally against flooding Comcast executives and board members with feedback, but I'd prefer to reserve it for the cases where their intent, rather than their buggy implementation, is the issue. Like increasing transparency about how much they spend lobbying against municipal broadband: https://www.publicintegrity.org/2017/06/09/20917/comcast-sha...