Xfinity Is Man-in-the-Middle Attacking My Internet
rietta.com
rietta.com
A few weeks (months?) back there was an article about ongoing litigation on if websites are required to have accessibility compliance under the ADA act. I would be very happy to see Xfinity sued for this practice under that precedent and hopefully any injection would be considered a violation.
Status of supreme court case: https://www.scotusblog.com/case-files/cases/dominos-pizza-ll...
The Supreme Court declined to overturn the Ninth Circuit, because there was no circuit split or other issue of such urgency to require the Supreme Court to weigh in.
The US Court of Appeals for the Ninth Circuit ruled (somewhat) in favor of the plaintiffs, and remanded the matter to the district court having reversed the lower court on some questions of law.
I think it is still a live controversy in the district court, but it seems likely that the plaintiffs will win on the merits or obtain a settlement.
https://cdn.ca9.uscourts.gov/datastore/opinions/2019/01/15/1...
I am all for web accessibility, and I think companies and developers should consider it a priority, but I do not think a law like the ADA is a good fit for this issue. The parts of the ADA that are good are the prohibition on actively discriminating against people with disabilities and requiring reasonable changes in policies. Requiring buildings to be rebuilt and taking down websites are excessive infringements on freedom and would best be addressed by the free market.
Here are some links you might find interesting: https://www.the-american-interest.com/2013/06/11/the-disabli... https://attorneyatlawmagazine.com/ada-trolls-and-unintended-... https://www.city-journal.org/beyonce-lawsuit-ada https://www.phoenixnewtimes.com/news/parking-lot-trolls-laws... https://adadefense.net/
Only if the marginal cost of developing them is less than the revenue attained by developing them, which is also limited by the amount of funds that disabled people have.
Disabled people existed before ADA, and the reason ADA was popular was because it didn’t make business sense to serve the disabled population. There’s no way construction costs of ADA accessible features of a building will ever be recouped by sales to disabled people needing it.
A free market solution would require the government to give sufficient cash to disabled people, enough to make businesses want to compete for them. But that is also wrought with possibilities for corruption.
Profit is just one form of incentive that we can align for increasing compliance with directives with a positive social benefit. All incentives are abusable if you design them incorrectly, so I see no reason to vilify profit over other kinds of incentives.
When you say you'd shrug what you are really saying is that you care about your HOA and don't give a crap about people with disabilities. If you did care you'd be proposing ways to close loopholes like the one Plaintiff was exploiting.
My issue with this system is the animosity it causes. Panzagl had one interaction with this method and it was enough for them to be ambivalent about the ADA.
A friend of mine does public outreach for an organization for the blind in Seattle, and 99% of ADA non-compliance that they see stems from ignorance and is solved by education.
The disabled aren't the only people who care. Take care of your sidewalk, it's your legal fucking responsibility.
In your mind, is it possible to be on the side of those with the disability and yet still against the ADA?
Put another way, given the two concrete examples mentioned (UCB and Stanford) did actual people with actual disabilities gain greater access to the content that was taken offline (in order to comply with the ADA)? Lots of laws have good intentions and bad effects. I think we should judge them by their effects, not their intentions.
That said, perhaps an improvement to the ADA would be budget to help producers of free content to become ADA compliant.
Absent liability, the other alternatives are some sort of executive branch enforcer (which does things to the whim of the executive) or some kind of onerous licensing/certification scheme (e.g. doctors), and both are IMO worse outcomes.
>> 17 U.S.C. § 106
...the owner of copyright under this title has
the exclusive rights to do and to authorize
any of the following:
(2) to prepare derivative works based upon
the copyrighted work;
Instead of conveying the authorized copy from the webserver to its intended recipient, Comcast is intercepting the original copy of the file and making a derivative version of the work. Unless they received special permission from each website owner (which is unlikely), Comcast is infringing the someone's copyright every time they make a modified copy without permission.How many HTML files have they willfully[1] modified?
[1] why willful? They published the technical details of how they modify the original work in an RFC.
1. Can it be considered "modified enough" to be considered derivative if it's the original file, plus some Javascript to provide a pop-up notification?
2. These MITM alerts are typically customer-beneficial and customer-relationship-oriented; the purpose is to alert that the user is getting close to a bandwidth cap. Similarly, there's current talk of somehow making ISPs or service providers deliver EAS alerts. Comcast already has to do this for EAS alerts on its television service. Does Comcast violate copyright when it interrupts a television program to show a federally required EAS alert?
3. Captive portals are a well-established instance where a page requested is not what's delivered. No one is accusing them of copyright infringement.
They're altering the functionality of it, fairly substantially imo. I would argue that copyright should protect your IP from being subverted to serve additional, annoying pop-ups.
> Does Comcast violate copyright when it interrupts a television program to show a federally required EAS alert?
In that case Comcast is not altering the contents of the work, it is replacing the content with other content. I don't think that's a violation of copyright at all.
> 3. Captive portals are a well-established instance where a page requested is not what's delivered. No one is accusing them of copyright infringement.
Again, they are not modifying the returned content, they are refusing to display the requested content and returning alternative content.
The fact that you can easily describe what their modifications do as a new feature (w notification) that wasn't part of the original work is stro9ng evidence that their modifications were transforative.
> These MITM alerts are typically customer-beneficial and customer-relationship-oriented;
That doesn't give them the right to make a derivative work based on my webpage. I'm not their customer!
> the purpose is to alert that the user is getting close to a bandwidth cap
So what? Communicating with their customers doesn't require violating the copyrights of many 3rd parties. 3rd parties shouldn't even be involved.
Instead of vandalizing a lot of webpages, they could:
* Simply send only their own page instead of appending of trying to mix it into other people's copyright protected works. This is how captive portals worked ever since they were invented.
* Instead of trying to notify their customers in-band with the service they provide, send any necessary warnings to the phone number (or other contract information) listed on the customer's account. This is what many businesses did in the past, and many still do.
* (re: bandwidth limits) They could stop trying to impose artificial scarcity and use a business model with more honest pricing.
* They could add a small message display and alert light (and buzzer?) to the modem/router.
This can be a crummy, anti-consumer practice without having to invoke copyright.
But this line of reasoning got me thinking...I've seen some pretty loose interpretations of the CFAA over the years. I'm not sure what the law says about Comcast's privileged position as an ISP, but I would think that in most cases, specifically altering data between two networks counts as unauthorized access, no?
The same as using a blue light filter on your computer (modifying the output of every program, copyrighted work, website, and text) vs wearing blue-blocker (yellow) sunglasses to the movie theater or library.
You're free to tear up your copy of Harry Potter once you buy it from the bookstore, but you're not free to (as the bookstore) add a prologue to every book and sell it as Harry Potter by Comcast.
Modifying your private copy and redistributing a modified copy are two different things.
I can't find any Supreme Court decision, but the Ninth Circuit has ruled on this and it's found that ad-skipping is legal:
https://www.techdirt.com/articles/20130724/10340723925/appea...
There's a German Supreme Court case that explicitly says the AdBlock Plus browser extension is legal, however:
https://www.reuters.com/article/us-germany-trial-adblocking/...
When I download a page and modify it for myself without distributing the modified copy, it is not subject to copyright laws.
As the article points out, an attacker could do something on an unrelated web server that injects this same notice (using the same code [1] as a basis), with a link that says something like "Extend your limit for free by 1GB", which loads a fake "Xfinity login" in a pop-up to phish their Xfinity account credentials. Because the link was presented using the familiar UI, it could easily trick someone and it would be nearly impossible for most users to realize it's not legitimately Xfinity.
[1] https://rietta.com/blog/comcast-insecure-injection/injection...
One question people are asking here: does it work over HTTPS. No it does't work over HTTPS, but if the page requests content via HTTP it is possible.
Interestingly enough, the technique is very similar to what Edward Snowden revealed as Quantum Insert, where HTTP requests monitored by the ISP and are intercepted and another web server (the network appliance in question) is able to respond more quickly. It starts with a very fast response that leads to a 302 redirect. The network appliance will then serve up a modified version of a file (usually a JS asset). The injected JS will then query the network appliance for "messages" and show them if the user is "eligible" to receive them.
What is the appliance called? Do all HTTP requests flow through it and anything else bypasses it? Does it store or log any of the requests or responses?
It is capable of monitoring ALL http requests, which is only about <5% of traffic going through an ISP. The more traffic you have, the more devices you need, but one can take care of a LOT of traffic, and I believe it can run as a VM. I'm not sure how it works as a VM exactly, because it also contains a custom Ethernet driver.
The same device directs people to the captive portal (if i'm not mistaken) used for logging into xfinity, or other public wifi from other providers.
Because performance is a high priority, the logging is minimal, but it keeps track of who's been served a message and doesn't collect any PII. The device is capable of serving any content, even causing a request from a third-party. So, it's possible that the content that gets ultimately injected is able to do whatever... anything a malicious advertisement would be capable of doing.
Your message eligibility is highly configurable, and can include metrics such as whether you visit certain sites, and possibly even your physical location.
There's a couple phases. First the network appliance injects so light code, using the Man-On-The-Side 302 redirect method. Once that's done, the injected code is probably going to request additional content after checking if you qualify for a message.
I can't remember what it's called, something like 'Shaw enhanced browsing' or some shit, but basically this 'feature' allows shaw to route traffic through their servers and inject content into sites. There was no description of this option in the account settings, they were buried 3 or 4 layers deep, there was no mention of this 'feature' from any of Shaw's customer service people, the only way I discovered this was through some random forum conversation I found.
There was also people mentioning (this never happened to me)that despite switching the option off, they would find it turned back on again a day or two later and have to repeat the process. I have no idea if this is still the case, this would have been quite a while ago now, but I was pretty unimpressed when I figured it out and realized what was going on.
Edit:i did find this discussion on hacker news about Shaw's hijacking from 2014.
I have a feeling, if this ever happened, it was closer to a decade ago.
Stuff like this makes me wish it were a criminal offense to dishonestly describe a feature as an "enhancement" or "improvement" when 9/10 users would not see it that way.
The sad thing is that with many kinds of cybercrime, it's easier to fix the security vulnerability, than it is to track down the criminals and make them stop :)
In this case, the vulnerability is using HTTP, not HTTPS.
Edit: Also, what stops those ISPs from impersonating the requested host by means of their own root certificate, just like antivirus software does it?
Terms and conditions of this comment: This comment is provided for free to <https://news.ycombinator.com> AKA "Hacker News", including any redistribution to be considered under the clause of fair use. Any other redistribution, including injection of third party content or surrounding content, chrome, or any other HTML element(s), be it in static or generated code, is considered a violation of the terms of this contribution.
You mean like that "setup software" Comcast spent ages trying to pretend I had to install just to get things running?
I ran Linux in those days, which always meant a little extra support time but I never had to install jack.
> Chrome does not perform pin validation when the certificate chain chains up to a private trust anchor. A key result of this policy is that private trust anchors can be used to proxy (or MITM) connections, even to pinned sites.
> Late on December 24, Chrome detected and blocked an unauthorized digital certificate for the "*.google.com" domain.
https://security.googleblog.com/2013/01/enhancing-digital-ce...
If anyone else considers cancelling their service, but has trouble getting Comcast to let them actually do it, just remove your payment method from the account, and let them know that if they attempt charging to it again, you'll sue them for fraud; that'll get your account closed real quick!
Where I live now comcast is the only broadband available and although the service is theoretically faster and somewhat less expensive, I'd pay twice the price for sonic. Comcast is unreliable, intermittently very slow, and the company is impossible to deal with.
My choices are Comcast (up to 1gbit down / 30 mbit up IIRC) or rotting exposed copper POTS (from Clink?) that has VDSL at something around 10mbit down / 1 mbit up.
Thus, I have only one choice of broadband provider and due to lack of competition as well as lack of regulation, no broadband providers that offer unlimited service* (technically Comcast will happily charge me 600 extra dollars a year for no increased speed but no caps; however they shouldn't even bother with caps on their highest tier packages).
I asked the person responsible for the banner if it counted towards data caps and was ignored. https://twitter.com/sephr/status/941067958096244741
Very much doubt they count their traffic by adding up all the origin addresses contributions individually
This is not a technical impossiblity, I'm sorry if you're invested emotionally in it being impossible.
Though, seriously, I have a hard time understanding the reasoning for data caps on DOCSIS infrastructure. On LTE, yes. WISP, yeah - kinda. DOCSIS, DSL and GPON? Absolutely no!
Not to mention the horrifying realization of most uninformed people that their ISP can and will intercept, log, modify or restrict access to content that the user has requested, even though the user has the right to such content, having paid the monthly subscription fee for the connection. But hey, I don't work at a large cable ISP, I couldn't possibly understand their reasoning and advanced calculations. /s
It really $houldn't be that hard to under$tand.
Those are the ways I want to be contacted.
Since they are making a new derivative work without the authorization of the copyright holder, they are probably guilty of copyright infringement. The remedy for that could include statutory damages for each work they infringed of "a sum of not less than $750 or more than $30,000 as the court considers just"[1]. However, since the infringement was patently willful (they published an RFC explaining their intentions and methods), "the court in its discretion may increase the award of statutory damages to a sum of not more than $150,000."[2]
A similar bit of malware had a surprising twist: many ISPs, especially mobile, used an image compressor which made things look terrible but, unexpectedly, it honored Cache-Control: no-transform. See https://stackoverflow.com/a/4113511/59984.
I’m curious whether Comcast does that – it would be surprising but also possible as a way to reduce the risk of lawsuits.
https://web.archive.org/web/20191029172726/https://rietta.co...
It didn't need the theatrics and intentionally misleading garnishments (like quoting Comcast's own RFC that's describing their own recommended behavior for themselves, then pointing out you can phish people, and then awkwardly trying to glue those tangential points together)
The bad behavior is bad enough that it'd stand on it's own, and if it instead focused on things like accessibility up front, it'd be much stronger of an article (and people would be more likely to read it all the way through)
Yes, hours. That cap cannot sustain the advertised speed for even one full day before hitting overage charges.
Needless to say, we went with a different service provider. We are fortunate here to have an option (alas, still a cable company) that has no data cap, but not everyone is so lucky.
https://www.wolframalpha.com/input/?i=1Terabyte+at+1+gigabit...
Think of all the "cloud" kind of things you could enable if you could use that bandwidth. Only we can't.
Think backups of your entire disk etc... massive p2p cluster filesystems stuff like that. All not possible cause of these data caps.
That's not how internet was billed in 1999. You paid for the size of the pipe, not how much data came through.
Per-byte pricing is pretty much a cell carrier and Comcast invention
Not saying Comcast definitely doesn't use it; rather, that it'd be hilarious to see Comcast lie to everyone's faces yet again.
https://wiki.mozilla.org/CA/Included_Certificates https://docs.microsoft.com/en-us/security/trusted-root/parti...
Good luck :)
This is why TLS1.3 and HSTS exists.
That said, Comcast is big enough that it might be in cahoots with at least one less-than-scrupulous CA (or might even be a CA; I don't follow these sorts of things closely enough).
The moment that was discovered, the CA would stop being a trusted CA.
Also, given the existence of Let's Encrypt, there's much less reason to be using a paid CA, and planned migration to a new CA provider isn't too much to ask. There'd likely be some work within browsers to provide clear error messages, and sites would need some amount of time to migrate, but I think we're talking days-to-weeks before there's a warning banner on the sites and months at most before the CA is dead.
Finally, there is certificate transparency logs, you can set CT headers on your site to require the certificate to be in CT logs. Then you can monitor if anyone's creates certificates for your domain. And updated clients can validate that certificates is in the CT logs.
HTTPS is pretty robust these days. There's still a few corner cases around SNI, but that only leaks what host your visiting, wouldn't allow injection -- and specs are slowly closing those holes too.
But really, if you don't trust what installed on your machine it's game over.
I think you mean 10 year old software, which is a much smaller bucket than 10 year old devices. And if you're browsing the web with 10 year old software, you have much bigger problems including but not limited to committing security-suicide.
Eh? I was thinking the opposite, that's such a ludicrous latency overhead that it would be trivial to go to any VPS provider even sort of nearby and spin up a $5 instance with Algo. The only concern normally for some of them is the super cheap simple managed instances often have data caps too (though some provides are bandwidth limits only), but in this use case even that doesn't matter because the limits are still higher than Comcast's regardless. There are datacenters in Denver, but even if you had to go all the way to SF and it's a worst case adding 1800 miles RTT that should still only be around 10-14ms or so right? The article seems a little silly to go on so much about a few kb of data out of tens of gigabytes or a TB or whatever Comcast's caps are, but 250ms is wild, even without all the other breakage.
Although I've always heard that if you're ever forced to go Comcast, the average HN type would be best off seeking a Comcast Business connection that has actual support and customers that use the internet fully.
This was possible because my server was well connected and very low latency talking to Comcast, and also very low latency talking to the rest of the Internet via Level-3, Time Warner, QWest and InterNAP. Where directly routed traffic would run over the Comcast network most of the way across the country.
I’ve been doing that ever since. It works great, and for me is a good trade-off over using a VPN for literally everything.
It should answer such questions as:
1) Did the website load?
2) How long did it take to load?
3) Was the content tampered with in any way, was anything added to, or deleted from the content, including any code, such as its javascript?
So, be able to perform those tests, from a variety of points on the Internet, from a variety of IP addresses, at regular intervals, and report back.
Noting any and all discrepancies, and storing all anomalous web page data retrieved (including code) for further analysis...
Big govt bureaucracy is terrible, but a private one (which is confident they won’t face any trouble or practical consequences) is still trouble.
There hopefully won’t be “mask off” moments for these providers & get really gnarly but this kind of behavior can screw over regular Joe’s & Janes
"Big govt bureacracy is terrible, but a private one (etc)"
You're implying big government bureaucracy is the only option here. How about, you know, regulating internet as a utility? The thing we've been wanting since forever? Unless there's actively a shortage of water or power, I can get those and use them as I feel like, paying extremely low fees. I don't care if my internet is pay for use, provided it's priced close to the actual cost.
That said, I do most of my downloading on VPS provider, then what I finally want to keep, I compress and pull it down over my VPN. This still doesn't help for things like streaming movies, game updates, etc...
Lawyers on HN, how is this not a violation of CFAA? If I sat at a coffee shop and did the same thing (say a "harmless" js "alert('Hi everyone!');") that is punishable with penalty up to 5 years imprisonment. So you're saying if I was the ISP that's ok? Why is the FBI/DOJ not criminally prosecuting comcast's CEO? Preferential treatment or prosecutorial discretion? Will comcast start pushing back on dragnet sutveillance cooperation?
The whole thing is so crooked! How can we bring this to the attention of lawnakers and media?? If the post office put notes in your mail (outside of a law enforcement request) would it not be a big deal?
I’m far from a fan of Comcast but this doesn’t seem like something we have a good legal angle for addressing.
Again, this should be illegal but I think we need strong network neutrality laws to make that so. Wishful thinking won’t save us the trouble of passing them.
With comcast,the expected privacy of the traffic by the server is violated, until delivered the content belongs to the sender. An intetmediary transports content but does not own it,has no right to manipupate it. Vandalizing other people's property is a crime everywhere,the question is does it apply to network packets in transit?
It's kind of insane that they get away with charging customers $10-15/month for the privilege of a router without any privileges.
It is another reason they're flagrantly against encrypting DNS and attempting to get laws passed against it.
It used to be very easy to put everything through a proxy server or mitmproxy and install a certificate on a device. While I value privacy and security it seems like everyone tech company moves to "protect users" is really a way to keep their adware and spyware running on their walled gardens.
EDIT: I understand that's not your point. And I whole heartedly support people leaving and supporting municipal ISP.
2. Buy whatever meets your criteria on https://openwrt.org/toh/start and install OpenWRT on it (I use a Mikrotik RB750GR3 with a Ubiquiti UAP-AC-LITE for wifi)
3. Setup Wireguard (https://lists.openwall.net/netdev/2018/08/02/124) on the VPS and OpenWRT
4. Be happy
ISP options are now my #1 factor in deciding where to live, and if Comcast is the only viable option then I'm happy to tell apartment managers I'll look elsewhere.
What I eventually had to do was open a browser tab with no adblock (perhaps Chrome Incognito), close the notice, restart my router and modem to flush DNS, then flush locally to be sure it's gone. That usually worked.
Edit: I missed it: https://rietta.com/blog/comcast-insecure-injection/injection...
Have you contacted them to warn them that Xfinity is injecting JS into their site, and asked them to implement HTTPS+HSTS to protect against that?
<style>
body {
display: none;
}
</style>
To read the article without JS, disable also CSS.Never mind. Sorry for the noise.
about:reader?url=https://rietta.com/blog/comcast-insecure-injection/
I have seen some sites that completely break when using Reader mode. I have seen sites that are very well done in Reader mode complete even with pictures.
Safari is my main browser and I recently stopped using Chrome. I believe my wife uses Chrome. Maybe this doesn’t work on Safari?
If your ISP is tampering with packets, that is the anti-pattern that needs to be remediated ASAP.
In my opinion, the only packet change behavior that an ISP should be involved in is adhering to QoS headers. 0x08, it's bulk. 0x04 reliability, 0x10 low latency. And if they want to charge me more for 0x04, that is fine if it's clearly spelled out in the contract.