Comcast says hackers stole data of close to 36M Xfinity customers
techcrunch.com
techcrunch.com
The main competitor in most cases, after the cable company and the telephone company, is LTE. Also faster and cheaper than Starlink in a suburban area, but in dense areas the speeds really suffer. I was on LTE home internet for a good while and enjoyed 100+ Mbps at night but only 20 during the day, due to living too close to downtown. Only $45/mo though!
Competing with this using satellite or 5G Cellular is going to be difficult, both need more spectrum and an order of magnitude more hardware (cell towers or satellites) to reach those kinds of speeds.
"Comcast does so much lobbying that it says disclosing it all is too hard" https://arstechnica.com/tech-policy/2019/05/comcast-does-so-...
1- Nobody else gets permits to lay cables in that area. Governments can't even share the data about cable locations/network detail. You can ask, as a property owner if it is around a specific location and they will say yes or no.
2-The agreements also prohibit local governments from laying out public cables, like roads.
3-Xfinity won't share that network with anybody else.
Customers are stuck whatever Comcast deoes. These breaches have no meanining other than getting a check for $5-100 when they settle the lawsuit claims.
Just about anyone in the US knows what this means, you Comcast Bill will go up at least 10% as soon as the Fed Gov stop watching them for this breach.
Makes opportunities for 5G and other wireless providers to get some customers. It would be even better if this encouraged the wireless providers to provide better service.
The only Telcom ever to have literally told me "you're just lucky you have a dial tone".
If you're one of those people stuck in perpetual 00's time how you think of the 70's is how the 90's are now.
We need to come up with a new plan for human authentication, that isn't straight from a dystopian landscape.
@Home was a coalition of cable providers who didn’t have the technical knowledge or funds to implement their own cable ISP. FWIW, when Comcast finally bought out our neighborhood cable co (mid-2005ish), we never got 24/8 addresses
Also throwing more water on your story, Comcast’s internal network was entirely 10/8 for a very long time. Around 2008 or so they went to ipv6 because they ran out of private addresses.
It's entirely possible that as a Comcast customer parent OP was on @home
Comcast was one of the cable companies that founded @Home. This would've been about 5 years before Comcast bought out Adelphia.
> Also throwing more water on your story, Comcast’s internal network was entirely 10/8 for a very long time
Dunno, maybe I'm wrong and you actually know more about the network setup at center square 23 years ago.
This reads like "we didn't patch until weeks after the vulnerability and patch were provided" but it's worded intentionally unclear to differ blame.
> Q: How will Comcast prevent another incident from occurring?
> A: We have robust security programs in place which help us to discover criminal activity such as this one
You have to love how their response to their own question is, functionally, "we won't prevent your information from being stolen, but boy howdy we'll sure know when it happens though!"
As a long-time disgruntled comcast customer, i have to say none of this surprises me. But local monopolies mean my wallet doesn't really get a vote in this matter.
1. https://assets.xfinity.com/assets/dotcom/learn/Notice%20To%2...
Ah, yes, it truly gives me hope for the future of humanity when these hackers break in to a corporate database like this, have total access to all this sensitive data, and then, out of a sense of fair play and comity, run "SELECT * FROM customers LIMIT UNSPECIFIED" rather than just "SELECT * FROM customers". It's so nice of them to access only an "unspecified" number of customer's data rather than all of them.
https://github.com/GossiTheDog/scanning/blob/main/CitrixBlee...
You've got a single curl request to a web service that for magical reasons is running as root. There's no SELinux/jails/etc, and no logs written for this request.
Remember this next time someone wants to sell you a WAF: The Netscaler isn't some wiki application, one of the things it is sold for is specifically as a WAF.
It is clear to me that security is theater to these companies, and that is why companies that resell TLS tunnels with 2000s technology bolted on like Citrix get away with charging so much. It should be assumed that there was no security to begin with. If you told me in 2 years that a foreign adversary had compromised all American companies since 2012 I would not even blink. It is more or less something I expect to eventually hear.
And besides Ethernet and DSL jacks, they had an unused coaxial connection on the back, the kind that connects to TV cables, but it was not involved with their Uverse TV offering?
"You can tell a lot about a culture by its instruments."
Plus right around then, almost 20 years ago now, a consortium of internet communication companies formed the Home Gateway Initiative[0] whose original manifesto[1] is a technical document that could form the basis for achieving uniformity among the hardware suppliers and their firmware, especially when DSL was the top offering from AT&T and very few cable providers were any faster.
2wire modems bumped that up a notch for a while by pushing the physical limit for AT&T's aging network of symmetrical copper wire pairs, but Comcast's aging network of coaxial TV cable is still 30 to 50 years newer, plus with its cable having the outer grounded shield surrounding the sensitive data conductor within, it's physically capable of reliably carrying more data faster. Even though the entire cable infrastructure was far from symmetrical, more like a water faucet where content just pours out more so than could be pushed back up. At least the old POTS was a two-way communication network by design.
It was only a matter of time before useful cable speeds outran telco infrastructure, and back then I would expect 2wire to have focused on that coming date more so than anyone else.
2wire modems bumped performance up a notch for a while by pushing the physical limit for AT&T, but Comcast wasn't going to quit even though cable was a latecomer and missed the AOL boat that was made possible only by the old telco wiring.
All you have to do is read the non-technical first 13 pages of the HGI manifesto[0] to see the way that user flexibility was to be curtailed and completely replaced by "business requirements".
The final bullet point of the 13th page is what got me:
>o The Home Gateway must support QoS both in the operator network and on the home network side when different simultaneous broadband services are used. In addition, the Home Gateway must support QoS on in-home flows.
Different simultaneous broadband services.
You mean like telco and cable at the same time?
What would that be like, and who would want that anyway?
I don't think customers would want to be paying two different ISP's so the initiative must have been initiated by somebody else for some other reason, not disclosed.
One thing's for sure, AT&T was poised with their exceptional 2wire modems already in place, a single firmware change away from a merger with cable, not necessarily by starting out with some exchange of shares on Wall Street, but instead by connecting the networks from the bottom up, physically in your home(s). In a way that could have as significant an effect on shareholder value regardless.
Now what would that be like?
I can only imagine that to make the very best use of all infrastructure resources for all concerned, that sophisticated hardware/firmware could combine elements from all resources by all providers, at a price of course.
If you were an AT&T customer, IOW you responded positively to their sales "person", then you would expect to be provided your on-line service over AT&T infrastructure and pay only one bill to that single vendor. But the "perks" of the future could include a special arrangement between AT&T with local cable where their cable service would be connected to the AT&T modem at no additional effort or cost to the consumer, so that on those occasions where you (or others sharing your bandwith in aggregate) might want to effectively download data way faster than the 2 wires of AT&T could provide, well the dual modem would be able to temporarily switch over to the cable source seamlessly.
And likewise if you had responded favorably to the cable sales effort instead of telco, and the cable company wanted to provide you with more two-way or upload bandwidth than their infrastructure had at the time, then using the same type of modems AT&T could reciprocate by allowing cable companies to access AT&T's underutilized bandwidth, automatically on demand also.
For the most rewarding customer experience?
It would have to be by special arrangement like never before.
How could you get more convenient than a system that could automatically, with the help of QOS and stuff, provide the best that can be delivered to your exact premises regardless of whether a "competitive" service might have better performance for some types of data compared to others? Whichever provider you have they'll just generously lease any helpful infrastructure from the competitor as needed. Automatically, involving a sophisticated modem. As you go along. And resell it to you at a profit, even if you never see any sign of this on your bill if it did take place.
It's got to be rewarding to somebody.
Some would say that would be like having somebody's cash register in your house that you are paying for and were not ever aware of to begin with.
And it would kind of reduce to a battle of the salespeople who could duke it out after that.
Well, that didn't happen.
Then again the same 2wire hardware would have physically facilitated a more recognizable top-down merger if one would have materialized, and that didn't happen either.
I think 2wire spent more money than the company was worth, just trying to figure out what could be accomplished using the plain old unshielded wire pairs that their network to the premisies consisted of. And was probably no slouch at more accurately determining what Comcast's infrastructure was capable of in the long run also, much more aware much earlier than Comcast itself.
Not exactly "their" network, rather AT&T's network.
After that Comcast started buying up everyone else.
2wire rode off into the sunset.
And here we are now.
Customer service worth the money has been smoothly bedamned by all providers, with consumers ending up as predicted in a certain type of hell.
.
[0] https://en.wikipedia.org/wiki/Home_Gateway_Initiative
[1] https://web.archive.org/web/20070124064123/http://www.homega...
This might be what a fly on the wall would be hearing at the hotel bar when a couple executives run into each other after an early HGI meeting almost 20 years ago;
Comcast: "We have a network and streaming content to go with it, not you guys at AT&T WTF?"
AT&T: "Ha, we started as a monopoly and have always had seamless operation along with our divested subsidiaries ever since. We're everywhere."
Comcast: "Well, we'll get a monopoly and whacha doin' with a monopoly and not jacking up prices to the moon?"
AT&T: "OK, we'll deliver some content but can't we just call this whole thing off?"
2wire, a small player hidden in AT&T's pocket silently casting a voodoo spell: "Merge, merge, merge, ca-ching, ca-ching, ca-ching . ."
Includes security questions and last four of social security for tens of millions.
Couldn’t happen to a nicer company either.
Boilerplate response from them:
https://assets.xfinity.com/assets/dotcom/learn/Notice%20To%2...
what makes it worse is Comcat's quasi-monopoly status as a non-optional public utility with, in many areas, no competitors. your only choice is to give away your secrets to a company which will manage them irresponsibly and then act like victims about it.
The PDF could have been authored at any time.
Looks like the created date embedded in the metadata is as follows:
2023-12-18T21:21:19.000Z
Created with MS Word. But even that isn't definitive.
"What is your mother's maiden name?"
"bidah6shee8Dahkouju"
"Wait, what, that is correct how ?"
Every time I hear their confusion and shock, I get a bit more depressed that more people aren't doing this.
Using a different made up mother's maiden name at each site is a good idea, but you can use short names that are easy to pronounce and spell for that to get the security benefits without drawing out the time you have to spend with support.
They never seem to mind when you just say "litmus secrecy ruckus nest reason send", they don't even skip a beat.
Like all good Bitwarden things, feel free to spit^W vote for a similar feature request https://community.bitwarden.com/t/security-questions-track-a...
# 1Password Steps
1. Tap Edit
1. Click "add more"
1. Click "Security Questions"
1. (optionally choose one of the common questions from a drop down)
1. click in the answer field
1. click Create a New Answer
1. Observe the prefilled battery-horse-stable-ish answer
1. Click Use
1. Repeat "add another question" as needed
1. Press Save
# Bitwarden Version 2023.12.0 (15279) Steps
1. Tap Edit
1. Scroll to the very bottom
1. Drop down the select widget under New Custom Field to select Hidden
1. Press the +
ok, cool, I guess as there's no generation option on that Hidden Value field
1. search around and find "Generate" under the "View" menu, because of course it is (I'll meet you half-way on this one, since maybe a long-time Bitwarden user would know the command-G shortcut already)
1. Expand the Options section
1. Choose Passphrase
1. search for the "OK" button, realize there is no such thing, so use the Copy button to nuke whatever's in your clipboard when you started this process
1. Click Close
1. Click back into the Hidden field's Value text area which has mysteriously lost UI focus from that exercise
1. Press Paste
1. Click in the Name field and type the question the site asked you
1. Repeat as needed for other questions
1. Press Save
So, yeah, "akshully" one can do this with a vivid imagination and a piece of paper, too, but let's not pretend those two experiences are in the same universe as each other
"What is your mother's maiden name?"
"Oh, some random collection of letters and numbers... I think there was an a and a d in it?"
"Ah, okay, what info or money do you want?"
Good job all around guys.
No word about a compromise or anything, just corporate bland.
Also I got a kick out of their screen "obfuscating" my email to j***rf@jerf.org. Fantastic job there. (Anyone not quite sure what I'm getting at are invited to consider the domain name and my Hacker News nym and come to the obvious conclusion about the clandestine character hiding behind those three secret stars.) Now truly I am safe from those thousands of spams a year I get from spammers shoulder-surfing my email address. I really ought to do something about them. Their harsh whispers as they furtively read my email address into their phones for their accomplices to copy every time it's on the screen make it difficult to concentrate on work sometimes.
Periodic reminder that these are just passwords too. They should be treated as such by users (generate random responses) and devs (hash and salt them).
I agree for tech savvy users it's prudent to treat them as passwords, but it doesn't extend to the general public. If they should be treated as passwords, what's the point of having them then? They're most often used in password reset flows. If it's a random string/phrase, they're basically useless in that use case. In what situation would you have the randomly chosen string for the security question, but not the randomly chosen string for the password?
As a user, if you want guessable recovery codes, that's fine. It's all in the threat model. The password for this account is very guessable. It used to be 000000. I don't care about any possible threat to it.
Their purpose these days is to provide a way for anyone to reset your account credentials using public information or the answers to Facebook quizes to find out your secret pirate name.
1) Don't answer the question that was asked. Mentally translate it to a different question entirely. "Name of first pet" is always answered as "color of first car", for instance.
2) Make the answers full sentences, not just single words. If the answer you're providing is "color of first car", the answer shouldn't be "white", it should be "The color of my first car was white".
1. That is likely to exceed the maximum length allowed for the form fields you have to use to enter it on web pages or in apps.
You might find that on the page where you initially set it up the page silently truncated it to say 1000 bits, and that's what got stored on the server. But the page where you need to use it for password recovery handles 1500 bits, and the form in their app only handles 500.
So you cannot get it to work in the app no matter what, and can only use it on the recovery page if you somehow figure out that only 1000 bits are on the server and truncate to that yourself.
2. Some places use the same security questions when you phone support. The support person asks you one of the security questions and can read the answer from the database. They compare that to what you tell them over the phone.
You probably don't want to go through that with a random 4096 bit string.
Fascinating. This is something I never encountered, so it never occurred to me that this might be done.
Honestly, I don't know if there's a point to having these questions. At least one security expert feels similarly: https://www.schneier.com/essays/archives/2005/02/the_curse_o...
None for the end user! (Although I assume there must be some corporate career incentives or something for implementing security theater like this, since they keep doing it anyway.)
Unfortunately this is not how almost any business treats them; they are frequently used as challenge/response authentication over the phone, so using a random response or hashing and salting them doesn't work.
Authenticating a user over the phone is a major unsolved problem IMO, and responsible for a huge swath of modern account takeover issues.
No one except hackers or certain federal agencies would be able to compare the results of security questions across independent identity management systems.
For my part, I have put in a credit freeze with all three credit bureaus. I am wondering what else I should be doing.
It's all been exposed, somewhere, by someone who didn't exercise due care for protecting it.
Until this data becomes a liability and not an asset that can be sold and expoited, it will continue.
I've had my identity stolen. The SSA office essentially does nothing to resolve it, they place the burden upon you as the victim to fix an unfixable problem. I didn't even bother. The whole thing is fucked.
What could go wrong?
This is why my ISP account at the house where I sleep (as well as all other utilities and services for the address) is not in my name, and does not have my phone number or email address on it.
You’re just one data leak away from people from the internet being able to show up at your house in the middle of the night with guns (or outsourcing same to the police with a swatting).
I spend a lot of time and money protecting against this type of attack. It’s annoying. There should be real, actual, criminal liability for putting people at risk like this.
Maybe if someone publishes the excerpts from these with everyone with the same residential zip code and last name as all sitting US senators, something will happen. Then again, when weev did that (with just email addresses), instead of going after AT&T who leaked the PII through simple negligence, they prosecuted the guy who downloaded it and alerted the press.
It’s almost as if everyone not wealthy enough to have staff/managers/shell companies is just expected to not have any privacy.
The way to do it is to have your attorneys be the managers of your holding companies, then you can direct them (under privilege, afaik) to sign what you like. This is how I do it. Alternately if you have staff you trust and expect to have a long time (I don’t), they can be your holding company’s manager(s).
What is a "non-public" address? All addresses are public information. It is not at all clear what you're protecting and from whom; there is a distinct lack of a coherent threat model.
Everyone knows the address on your DL and vehicle registrations is basically public record, it’s sold to data brokers and is searchable. Same with any property held directly. This is why you have a holding company own the properties, and keep your name off the public records for the holding company.
Utilities might still be in your name, however, as not everyone knows how to obtain those under aliases or remembers to have their staff do it for them. They often want credit checks on a normal person for non-commercial service plans, or for residential addresses.
App location histories, mobile service location histories, Uber trip logs, food delivery order history, all of these are potential vectors for leakage, too.
There’s a big gap between “wealthy enough to be able to pay for some measure of privacy/safety for one’s family” and “wealthy enough to warrant spending salaries for three shifts of armed guards 24/7/365”.
Also, what do you think will happen if someone learns you live at a particular address? Literally what risk is there?
It’s not just data brokers who can search DL/vehicle data. It only costs a few bucks to access it. That’s their whole business model.
I know people who have been swatted, had their vehicles smashed, their children threatened, their houses shot up or vandalized or broken into, mail or packages stolen, et c. Fortunately I don’t personally know of any kidnappings or home invasions, but such an attack enables same for a sufficiently determined attacker.
People at risk like this either take steps to keep their residential addresses non-public, or hire 24/7 security forces, or both.
For all practical purposes I’m sure my info, and almost everyone’s, is out there.
Genuinely curious: Does it even matter anymore. I think all one can do is freeze the credit and hope for the best.
https://assets.xfinity.com/assets/dotcom/learn/Notice%20To%2...
I tried to go to the first fraud alert link in the document:
https://equifax.com/personal/creditreport-services/credit-fr...
404
You can already seek financial compensation through the tort system[1]. It just sucks right now because you have to demonstrate harm, which is hard. Having a law that's like "each breach equals $50" makes lawsuits go much more smoothly.
[1] eg. https://en.wikipedia.org/wiki/2017_Equifax_data_breach#Litig...
When a bank fails, the FDIC typically facilitates new ownership over the course of a weekend. The workers still have jobs and the branches reopen on Monday. The top executives are out and the investors take a loss.
If it is impossible for any other company to take over the service than the company is too big in the first place and should be broken up or nationalized. The free market doesn't work without meaningful competition.
But sure, I'm amenable to a sufficiently large fine. Even just allowing class action lawsuits (despite their flaws) would be a lot better than the status quo.
I'm just saying that a "corporate death penalty" doesn't necessarily harm customers. A large fine that an entrenched monopolistic provider can just pass on to customers the same way they do other "compliance costs" doesn't really help much.
There's no way the company could be killed overnight, and one would have to be living under a rock to not hear about such a big business dying.
$1 for name
$2 for address
$3 for email
$4 for phone number
$5 for social security number
--------
and multiply for combinations thereof.
There's also the fact that a large number of companies were and still are being popped with citrixbleed, ransomware has gotten in line for this ride, and i bet it will take 6+ months for 80% of vuln systems to be patched/purged. Again, 9 days?
Ars technica's Dan Goodin has two articles about this (ive shortened them a bit): Comcast waits 9 days to patch critical vuln The latest high severity citrix vuln isn't easy to fix
come on...
Idk which systems were hacked but I worked on thier innermost apps, and they were a dumpster fire.
This is just tinfoil hat speculation of course lol.
When this Citrix zero day was disclosed to the public a few months ago, they mentioned nationstate actors.
It seems that Santa Clause is finishing up his naughty or nice list before rejoining the little lost island of elves with the rest of mainland North Pole.