Comcast injecting JS
gist.github.com
gist.github.com
Here's my writeup on it for whoever is interested
http://blog.ryankearney.com/2013/01/comcast-caught-intercept...
I forgot to install the gist plugin so my blog post no longer contained the code. I also had 3 different domains serving the same blog due to a misconfiguration with Nginx which caused my blog to take a temporary hit on Google.
I've since addressed those things so hopefully those will make my post actually appear in a google search.
I do not see any downsides to contact the FBI about the matter, if you think of any please let me know.
This is the old "windows alert" nonsense. Everybody and their brother that touched the windows system thought the user would want a popup when their program did something. So the user experience was/is full of annoying popups, warnings, and information messages. Log onto a heavily-customized windows machine that hasn't been used in a month or two and it's like visiting Los Vegas. Good luck trying to get anything done.
Comcast. All kinds of other internet providers manage to communicate these things to their subscribers without this nonsense. Take a hint.
inject.ly isn't registered (yet) so let's presume some enterprising HN reader uses that.
As a web dev, all I need to do is <script src="//inject.ly/detect.js"></script> and it will detect this (and any future variant) ISP injected content.
Extra points for someone implementing this to have it optionally make a JS call to another function or inject a customisable HTML widget on the page.
;-)
If I'm not wrong, this is implementation of JSONP to avoid cross-domain AJAX request block, right?
I don't really understand the point of this, either. Couldn't they starting redirecting users to a static page somewhere if there were a real need for a "critical and time sensitive" alert? If the supposed alerts aren't critical enough to justify doing that, use email, IM, RSS or twitter, or even build a custom notification notification app.
Rogers has been doing this for years in Canada already..
They use it to notify subscribers when they are approaching their bandwidth quota (75%) and then again when they hit 100%. You actually have to click a "I understand" button to have it not show up over and over.
Shame on you, Comcast.
This is, of course, if you trust these companies enough and [list of security implications].
(disclosure - I start working with OpenDNS soon).
Your bank, for another. Indeed there are far too many parties with an interest in keeping https secure, that you needn't worry about it.
But that ridiculous, right? Since everyone verifies SSL cert signatures...
I suppose the logical next step is that Comcast requires you to install a "Comcast Internet Helper" program that also installs a Comcast root certificate into the system so they can mitm anything.. But Firefox and Chrome would probably release updates mere hours later, blocking that cert from being used from those browsers.
Alternatively, it's not that outrageous to think that Comcast et al could get certs into the major browsers if they wanted to do so. It's not even implausible to think that at some point, browsers will be legally required to distribute ISP certs to allow for the "safety" of users.
If Comcast makes you install a custom application to keep your certs up, it won't matter if Fx and Chrome block each cert within hours, because Comcast can keep generating and pushing new ones out. And, as above, if the ISP is going to fiddle like this, the actual power held by browsers is greatly diminished -- users aren't going to use a browser that doesn't let them browse without nag screens on every page, even if it is "for their own good".
This is part of why the trust model of the current CA system is fundamentally broken. We need to add a layer that can ensure that we are in fact using the SSL certificate that the site owner wants us to use.
There are multiple solutions being proposed out there to add this trust layer. I am a strong advocate of DANE ( http://www.internetsociety.org/deploy360/resources/dane/ ) but there are others out there, too.
There was a good talk about this at Black Hat USA 2011 on "SSL and the Future Of Authenticity" at: http://www.youtube.com/watch?v=Z7Wl2FW2TcA
Actually, this is fairly common for firewalls and other edge devices to do and is one of the problems with the "trust" in the CA system. You can get a "signing certificate" from various legitimate sources (ex. http://www.sslshopper.com/article-trusted-root-signing-certi... ) that allows your product/service to terminate SSL connections and then recreate a SSL connection. The user still sees their "lock" icon and thinks they have a secure https connection to their original site, when in fact they don't.
They do have a SSL connection to their site using a certificate - it's just NOT the certificate that the original site issued. This is why many of us are looking to protocols like DANE that uses DNSSEC to add a layer of integrity protection so that you can know that you are using the correct SSL certificate. (See http://www.internetsociety.org/deploy360/resources/dane/ )
Note that no new certificates need to be added to browsers. The signing certificates work with the existing root certificates that are already in browsers.
Edit: read the DANE article, seems very sensible and simple to implement that the server specifies valid certificates.
I don't even like the thought that they're running some kind of hardware that makes this possible. They're sending packets impersonating a web server you actually want to talk to, pretending to be part of a response you requested?
Just because you can do this doesn't mean you should (i will stay away from comcast xfinity).
i have had these types of issues a while back at coffee shops that try to inject ads, it was breaking my XML.
It's called a proxy server. They're actually really common - many ISPs use them. Any hotspot that shows a log-in page in your browser will, and I know my University's internet goes through one.
Squid [1] is one of the most well-known, and it's open source.
For example: http://iainchalmers.org/e8f6b078-0f35-11de-85c5-efc5ef23aa1f...
;-)
1. The code is not encapsulated in an IIFE, so it clobbers any global variables (like 'image_url') in the page, breaking any scripts relying on those variables.
2. The code spends an inordinate time checking if you're running Netscape Navigator 6.
3. Strangely, they include a whole bunch of code allowing the message to be dragged around the window (which is nice) but they don't allow it to be closed. Of course, it closes itself after making a single AJAX request into a black hole, so there's that. Bugs piled on top of each other make this entire message mostly harmless, if it weren't for the variable clobbering & bandwidth usage (see the next item...)
4. Upon load, checkBulletin() is immediately invoked. This does an AJAX call to '/e8f6b078-0f35-11de-85c5-efc5ef23aa1f/aupm/notify.do?dispatch=checkBulletin'. I assume this is to check if the bulletin has changed, to see if there are new messages, or maybe to check if the user has acknowledged the message yet. Unfortunately:
* This URL is relative, which means it will never actually reach its intended target (instead filling your web logs with this request)
* Upon xmlhttp.readystate=4 (request finished, successful or not, so this will change to 4 even on a 404 error), the comcast message is hidden. This means that the entire 'bandwidth exceeded' message will actually be hidden as soon as this request completes, which may be in <500ms, giving the user absolutely no time to see or acknowledge it.
* The author makes an attempt to not continue sending AJAX requests to this URL after a successful attempt, but botches it, so this request is actually sent indefinitely, every 5000ms, while every any page is open. This means every single tab on your system is popping AJAX requests every 5 seconds for the whole month that your account is nearing its quota. This likely brings you over quota pretty quickly if you leave your computer on all day.
That's right, this code causes every page served on your system to pop an AJAX request to the wrong URL every 5 seconds, as long as the tabs are open.
We can sit and argue all day whether or not it's ethical to display messages by injecting code into the DOM, but it is certainly unethical to write such awful javascript that clobbers global variables and drives up bandwidth costs by making AJAX requests to the wrong url every 5 seconds until the cows come home. Whoever wrote this script should be fired.
EDIT: Similarly, back in the dialup days, some ISPs would inject ads into their content. One way this was stopped was to argue that it was not legal for the ISP to charge you for data, then artificially inflate the size of that data by injecting ads. This script is doing just the same in a measurable way by causing these AJAX requests to be run every 5 seconds on every tab in your system.
Not to mention the potential GPL violation for cut-n-pasting brainjar code.
The little HN/Twitter/Reddit "awesome programmer" bubble is just that... a bubble. It's easy for us to forget that lots of people write lots of bad, untested code all day long. As much as it frustrates me, lots of people code who don't care about code - it's just their job.
> R3.1.1. Must Only Be Used for Critical Service Notifications Additional Background: The system must only provide critical notifications, rather than trivial notifications. An example of a critical, non-trivial notification, which is also the primary motivation of this system, is to advise the user that their computer is infected with malware, that their security is at severe risk and/or has already been compromised, and that it is recommended that they take immediate, corrective action NOW.
So much for that.
I'm an intern, just moving past S.O. copy-pasta jobs and generally get scared at what the hacker news crowd might say about my code... seeing this caliber of shit get pushed live by a major ISP is almost comical, if an admitted novice such as myself can see that it should be a sign as to the ineptitude of our current crop of ISPs.
One thing I can say is don't use exec[1] if you can avoid it:
$string = 'rm /var/www/Giftest/*.gif';
exec($string);
While there's nothing * technically* wrong, it's platform specific and I think it would be better to use PHP's unlink[2] function. Also, sorry if this is wrong, I haven't looked at the regex but it seems your parsing YouTube URLs? Have you looked at oEmbed[3] - it may be an easier way to accomplish what your doing? You can use it with json_decode[4] to get an object.[1] https://github.com/Machtap/GiffyTube/blob/master/download.ph...
[2] http://php.net/manual/en/function.unlink.php
https://github.com/Machtap/_ctv/blob/master/_www/model/commo...
- keep config variables in a separate file that is in your .gitignore and won't get pushed to github.
- keep config file outside of any web accessible directory in case the file renders in plaintext for some reason.
Regardless of db only accepting local connections - an attacker is one step closer to dumping the db.
Still very valuable things to be aware of in future situations where the above might not apply, thank you very much.
Don't let the macho attitude of HN infect you too much - a lot of people here (and elsewhere) are great in criticizing others.
Though, I have to admit, bitching about other peoples' code is fun.
Ha, you give them too much credit.
This code is from a 10-year veteran "consultant," probably charging over $200/hour, brought on by the Global Services company hired by the Consulting Agency that Comcast brought in to assist in completing the critical time-sensitive project as quickly as possible.
It was also deemed a great success, and presentations were made about how effective it was, how smart the manager who hired the consulting agency is, and how skilled the global services contractors were who implemented it were, all only 2 weeks behind schedule—a new record for a project of this scope.
That manager got a promotion and is now VP of something or other. He sleeps like a baby and makes 100 times more than you.
Also, even for a suit, "Maintainability is only a concern once lack of such starts impacting your actual customers." is only true if by "actual customers" you mean shareholders. If you really want to get down to it and make an obnoxious out of place point, you can technically fuck over the customers all you want so long as doing so does not actually hurt the business (meaning: hurt the shareholders). Bonus points for figuring out how this could be done by a consulting company.
A typical example is, "If we don't get something out the door, we'll be out of business. 'Shit' is something that can be shipped quickly, therefore we must ship 'shit'."
But companies that ship 'shit' generally go out of business anyway. Either their customers find it unappealing and leave, or ongoing maintenance quickly becomes so difficult and expensive that the product can not improve except by being rewritten under new management.
With something like a secure website (or script injected into arbitrary websites by a large ISP) the severity of the security vulnerabilities that tend to result from "shipping shit" often you only get one or two chances as a company.
I'm not jealous. They don't make more than me. I said they make more than you. And I'm not hating—I'm just telling it exactly like it is, because I understand it, and it's insane, like the truth tends to be when you have huge amounts of power and money being controlled by puny incompetent humans.
When I was issued my company laptop, the software had been installed by hand (OS and all). I offered to setup an imaging system for them... but the "IT guy" from the "IT consulting firm" wasnt exactly sure what that was and needed to find out who to get approval from first...
Personally, I consider google search (and stack overflow) as an extension of my development environment and I'd recommend using it and melding your dev env with google search as much as possible. It really helps and speeds things up.
I've come across lots of situations where the accepted answer isn't the best answer.
So I'm talking about knowing vs. cargo-culting.
Is it because we don't like Comcast?
It's a rockstar developer thing. You wouldn't understand.
It likely doesn't matter that the URL is relative. It contains a GUID to be unlikely to resemble any real URL, and it's clear enough that they are capable of deep-packet-inspecting all of your web traffic from the way this is already used, so they likely hijack any request to this URL path within their network to capture its contents, and return a 200.
I don't have Comcast so I can't verify, but it would be interesting for somebody to check whether that URL is masked for all Comcast users.
> That's right, this code causes every page served on your system to pop an AJAX request to the wrong URL every 5 seconds, as long as the tabs are open.
I can only hope that they infinitely hang requests to their special URL in the case that user is under the quota so that this is not true. But if it is true, and they are not perfect about masking the URL (edit: it seems like people below on this thread have seen requests to this URL in their server logs), this could be construed as a DDOS attack by Comcast on every owner of an HTTP server via their own customers.
Surely a class action against Comcast is in order here? They're charging everyone for bandwidth they're not using.
function Browser() {
var ua, s, i;
this.isIE = false;
this.isNS = false;
this.version = null;
ua = navigator.userAgent;
s = "MSIE";
if ((i = ua.indexOf(s)) >= 1) {
this.isIE = true;
this.version = parseFloat(ua.substr(i + s.length));
return;
}
s = "Netscape6/";
if ((i = ua.indexOf(s)) >= 0) {
this.isNS = true;
this.version = parseFloat(ua.substr(i + s.length));
return;
}
s = "Gecko";
if ((i = ua.indexOf(s)) >= 0) {
this.isNS = true;
this.version = 6.1;
return;
}
}
But it's not just these people. Code like this is everywhere! Here's what I ran into on www.safeco.com today (NSFL!): function setupAddress(frm, i, clickevent) {
if (frm["USERESADDASMAILINGMAIN" + i].checked) {
if (frm.NEWRESIDENCEADDRESS1.value == "" && frm.NEWRESIDENCEADDRESS2.value == "") {
alert("Resident address must be entered for this option.");
frm.NEWRESIDENCEADDRESS1.focus();
frm["USERESADDASMAILINGMAIN" + i].checked = false;
}
if (frm.NEWRESIDENCEADDRESS1.value == "" && frm.NEWRESIDENCEADDRESS2.value != "") {
FieldSwap(document.frmMain.NEWRESIDENCEADDRESS1, document.frmMain.NEWRESIDENCEADDRESS2);
}
frm["NEWMAILINGADDRESS1" + i].value = frm.NEWRESIDENCEADDRESS1.value;
frm["NEWMAILINGADDRESS1" + i].disabled = true;
frm["NEWMAILINGADDRESS1" + i].onfocus = frm["NEWMAILINGADDRESS1" + i].blur;
frm["NEWMAILINGADDRESS2" + i].value = frm.NEWRESIDENCEADDRESS2.value;
frm["NEWMAILINGADDRESS2" + i].disabled = true;
frm["NEWMAILINGADDRESS2" + i].onfocus = frm["NEWMAILINGADDRESS2" + i].blur;
frm["NEWMAILINGCITY" + i].value = frm.NEWRESIDENCECITY.value;
frm["NEWMAILINGCITY" + i].disabled = true;
frm["NEWMAILINGCITY" + i].onfocus = frm["NEWMAILINGCITY" + i].blur;
frm["NEWMAILINGSTATE" + i].value = frm.NEWRESIDENCESTATE.value;
frm["NEWMAILINGSTATE" + i].disabled = true;
frm["NEWMAILINGSTATE" + i].onfocus = frm["NEWMAILINGSTATE" + i].blur;
frm["NEWMAILINGZIPCODE" + i].value = frm.NEWRESIDENCEZIPCODE.value;
frm["NEWMAILINGZIPCODE" + i].disabled = true;
frm["NEWMAILINGZIPCODE" + i].onfocus = frm["NEWMAILINGZIPCODE" + i].blur;
if (i != 0) {
frm["EXPLANATIONVEH" + i].value = "";
frm["EXPLANATIONVEH" + i].disabled = true;
frm["EXPLANATIONVEH" + i].onfocus = frm["EXPLANATIONVEH" + i].blur;
}
} else {
frm["NEWMAILINGADDRESS1" + i].disabled = false;
frm["NEWMAILINGADDRESS1" + i].onfocus = null;
frm["NEWMAILINGADDRESS2" + i].disabled = false;
frm["NEWMAILINGADDRESS2" + i].onfocus = null;
frm["NEWMAILINGCITY" + i].disabled = false;
frm["NEWMAILINGCITY" + i].onfocus = null;
frm["NEWMAILINGSTATE" + i].disabled = false;
frm["NEWMAILINGSTATE" + i].onfocus = null;
frm["NEWMAILINGZIPCODE" + i].disabled = false;
frm["NEWMAILINGZIPCODE" + i].onfocus = null;
if (i != 0) {
frm["EXPLANATIONVEH" + i].disabled = false;
frm["EXPLANATIONVEH" + i].onfocus = null;
}
if (clickevent) {
frm["NEWMAILINGADDRESS1" + i].value = '';
frm["NEWMAILINGADDRESS2" + i].value = '';
frm["NEWMAILINGCITY" + i].value = '';
frm["NEWMAILINGSTATE" + i].value = '';
frm["NEWMAILINGZIPCODE" + i].value = '';
}
}
}That's a quite strong assertion. What's wrong with your first example? I can think of very few criticisms (s isn't needed for example) but there's lots of things they did well:
- It follows the best practices for an OO constructor (doesn't return the object, just sets properties of `this`)
- All temporary variables are local. No global pollution (besides the "Browser" function itself, but because you're quoting it out of contect, I can't tell if even that's local or not)
- Degrades gracefully (everything is null) instead of picking a default incorrect choice
Sure, I would have written it differently, but so would everyone else here.
As for your second example, sure, it's not great, but I can sort of imagine some sleep-deprived developer coding up that to interop with some auto-generated DOM elements from an old PHP script left behind by a forgotten intern. We need more context here.
All your points are well taken, and a better analysis of the code by far than my hasty reaction.
So what was bothering me about the first example? Probably the repetition of the indexOf() tests, combined with one of the indexOf() tests being >= 1 and the rest >= 0.
But you're right, it's not nearly as bad as I made it out to be.
Since I've put my foot in my mouth, I guess I'll put my money there too and show how I might have done it. If I were doing UA detection at all, that is:
function Browser() {
function is( ua, result ) {
var start = navigator.userAgent.indexOf( ua );
if( start < 0 ) return false;
result.version = result.version ||
parseFloat( navigator.userAgent.substr( start + ua.length ) );
return result;
}
return(
is( 'MSIE', { isIE: true } ) ||
is( 'Netscape6/', { isNS: true } ) ||
is( 'Gecko', { isNS: true, version: 6.1 } ) ||
{}
);
}
But that fails on one of your points, since it returns an object instead of setting properties of 'this'. It's also less flexible - what if one of the tests needed more than a simple string comparison? At least it's simpler?So who am I to criticize? :-)
On the second example, it's not just that function - the entire web page is full of similar code. Here's another snippet:
addressCheckMsg="";
if(!type)
{
iLen = line1.value.length;
for(i=0; (i<4) && (i<iLen); i++)
{
var ch = line1.value.substring(0,i+3);
chUpper=ch.toUpperCase();
switch(chUpper)
{
case 'PO BOX':
addressCheckMsg += " Resident address can not be a P.O. Box.\n";
i=iLen;
break;
case 'P.O. BOX':
addressCheckMsg += " Resident address can not be a P.O. Box.\n";
i=iLen;
break;
case 'P. O. BOX':
addressCheckMsg += " Resident address can not be a P.O. Box.\n";
i=iLen;
break;
case 'P O BOX':
addressCheckMsg += " Resident address can not be a P.O. Box.\n";
i=iLen;
break;
case 'POB':
addressCheckMsg += " Resident address can not be a P.O. Box.\n";
i=iLen;
break;
default:
break;
}
}
}
Yikes. I'd better not say more or I'll start foaming again... :-)Compressed code is often not the best way to do it; adding a few lines of verbosity can reduce the time it takes to understand the code to a fraction while sacrificing very little in terms of performance.
Using that system they can selectively notify customers. Like if they detect your system is infected with a virus. Or warn you your service will be discontinued if you don't pay your bill.
IANAL, but I can't really see how it would be infringement, though.
1) building a webpage where you own the copright
2) Have someone in one of the cities where this is happening browse to your page.
3) Copyright violated, and you get to be the test case!
A lower court would probably just throw the case out.
And if it didn't, the higher courts, which would set a widely binding precedent, would exercise their discretion simply not to hear the case. Yes: they get to pick and choose what appeals to hear.
So sometimes their systems work...
I was very sad about switching from my other carrier (Sonic.net), but they ultimately couldn't deliver very much bandwidth. And Comcast was actually cheaper.
At least for the first 6/12 months. Then you get to haggle and threaten disconnection for a day, then you are good for another 6/12 months.
The one good thing is that CenturyLink isn't part of that 6 strikes deal.
c-75-65-181-xxx.hsd1.la.comcast.net West Monroe, LA
c-174-52-141-xxx.hsd1.ut.comcast.net Provo, UT
c-69-137-179-xxx.hsd1.az.comcast.net Tuscon, AZ
c-76-109-127-xxx.hsd1.fl.comcast.net Miami, FL
cpe-72-225-230-xxx.nyc.res.rr.com New York, NY
c-68-48-154-xxx.hsd1.md.comcast.net Washington, DC
c-98-224-83-xxx.hsd1.ca.comcast.net Fresno, CA
c-66-41-214-xxx.hsd1.mn.comcast.net Minneapolis, MN
I bet the permission to do it is part of the ToS agreement.
• derivative works
• public performance
• willful infringement
• GPL violation
• patent infringement
[1] http://blog.ryankearney.com/2013/01/comcast-caught-intercept...
If there are not major down sides please file a complaint with the FBI, I believe the url is:http://www.ic3.gov/default.aspx.
I encourage you to explain
* your evidence that when accessing various websites they appear to be tampered with between the server and your computer.
* Your worry that it impacts your bill with Comcast as it seems to be eating up you bandwidth. An estimate of the amount of money being eaten up if you have reason to suspect it is a city wide occurrence how much money is lost for everyone across the city?
* If you have packet logs of these occurrences I encourage you to include them.
* Unless you have hard evidence that points to Comcast that is doing the tampering I would not accuse any party of responsibility.
* If you have concerned friends who can independently verify similar conditions, it would probably be valuable to have them file similar complaints, referencing each other where applicable.
This project had potential ( it detected torrent traffic shaping) but it seems to no longer be under dev. http://broadband.mpi-sws.org/transparency/results/
Also this is a good read and contains comcast traffic shaping info: https://www.eff.org/wp/detecting-packet-injection
ps. Who cares about the shit JavaScript, this discussion should be about detecting packet injection and shaping.
I agree that the ethical discussion is likely the paramount concern here and should be discussed, but the code they're using floods the global namespace which in theory could actually degrade service for end-users (by potentially breaking commonly visited JS-powered sites that happen to use globals of the same name).
Its worth pointing out that it would take minimal effort to make this code not suck as much (wrapping it in a closure for a start). IMO it gives more context to the initiative on Comcast's part. No time, effort, or care was put into considering the ethical implications of this practice nor its practical effect on the end-user.
http://www.google.com/patents/US20110264729
Which I can tell you for certain that they don't own. Bastards.
Inventors Denis Kulgavin
Applicant Kulgavin Denis
Which one are you?The worst part is that once I was griping about the horribleness of Comcast on Twitter, and a Verizon representative chimed in cheerily to tell me to check out FIOS. Only thing being, it's been ten years since they first announced FIOS was "coming soon" to my neighborhood and it still isn't here yet.
Sometimes you don't know whether to laugh or cry, you know?
I've now resorted to using a remote VPN for all of my traffic.
[0]: A reddit post in which I discuss it: http://www.reddit.com/r/self/comments/19zhl6/my_isp_is_injec...
I do not currently see a downside, if you see one let me know.
WOW.
- Other duties and responsibilities as assigned.
No developer in their right mind would apply for this job.
> Tasks
> Consistent exercise of independent judgment and
> discretion in matters of significance.
This one literally stipulates that you will be expected to think for yourself on a regular basis. Why on earth is this in there?It basically optimizes images and replaces all image alt text with text saying to hit CTRL+R to load full-versions of images.
I know that VodafoneUK and VodafoneAU do the same.
On the bright side, at least they respect the no-transform cache-control header directive.
Just scanned my logs more fully and have serious concerns. As people have noted, this really does make requests every 5 seconds. My 404 page is currently 18KB, which means these users (who are being warned about their bandwidth) are being forced by their ISP to download extra web traffic from the site they're sitting on. For me that number is 1/3MB / minute and I'm seing users who sit around a very long time.
Also, this isn't restricted to the two metros Tuscon and Nashville people have mentioned. Here is a sample of hits I'm seeing (removing final octet from IP/hostname):
c-75-65-181-xxx.hsd1.la.comcast.net West Monroe, LA
c-174-52-141-xxx.hsd1.ut.comcast.net Provo, UT
c-69-137-179-xxx.hsd1.az.comcast.net Tuscon, AZ
c-76-109-127-xxx.hsd1.fl.comcast.net Miami, FL
cpe-72-225-230-xxx.nyc.res.rr.com New York, NY
c-68-48-154-xxx.hsd1.md.comcast.net Washington, DC
c-98-224-83-xxx.hsd1.ca.comcast.net Fresno, CA
c-66-41-214-xxx.hsd1.mn.comcast.net Minneapolis, MN
So what do we do about this?
Use TLS, warn customers about a malicious ISP attacker their connection, set up an encrypted proxy/VPN service for people to use, etc.
Most of the time these appliances act as a 'cache' device. They will sit some where in the network ( inline, out of band, or as a WCCP device ) that will answer common router cache lookups.
In the case of WCCP, User behind cable modem X requests www.google.com ( HTTP Non Secure Traffic ONLY! ) and the router asks the appliance, "Hey, do you have a cache record for this request from this user behind modem X?". At this point, the appliance will do a DHCP Lease Query for that IP and get Option 82 from the lease record. Most of the time this is the mac address of the Modem. Then it takes this Mac address and either looks up in an internal database or an external one to check if this user has a message 'waiting', IE: Over allotted bandwidth, billing note, spam or just BS. If there is a message waiting, the appliance will tell the router, "YUP, i've got it. Let me send back this small .JS response". From my experience, this small JS ( Even if it is horribly written ) will be returned to the user with some code in it that does another request to the website originally requested in a frame of some sort. Request is made again, but this time the "message" waiting for the user has already been delivered, so the initial process returns "Nope, nothing for that user" and the content originally requested is loaded upon the 2nd round trip. Its still your PC with a fake original response. I won't pretend to know how Comcast or Rogers does this, but I know one Vendor I have used did it this way. I fought it till I was told to put it in production or find other employment. It sucks, but if done correctly on HTTP Non Secure traffic only in a manner that is described above, I think its a better idea than products like procera or sandvine do which IS MITM forged responses. Hope this helps explain a little better what maybe going on in this situation.
What are the legal recourses you have with regards to this type of forced advertisement?
* ISP - 'six strikes' of content abuse
http://www.techradar.com/us/news/internet/broadband/six-stri...
* EBS - Emergency Broadcast System
http://www.washingtonpost.com/blogs/blogpost/post/wheres-an-...
http://news.cnet.com/8301-19882_3-57321623-250/wheres-the-em...
That said, this was probably only noticed as quickly as it was due to its stupidity and intrusiveness.
IMO what should be championed for is good decentralized end-to-end security, something like opportunistic IPSEC / anonymous SSL everywhere by default.
Sure, there are holes in it you can fly planes through, but it's a world better than it being cost effective for whoever to inject and MITM everything.
I'm not even going to touch on the pros/cons of over-subscription and business models which rely on it. (IMO most do, at least implicitly, and I'm not sure how to normalize analysis of that.)
Yes, the javascript is crappy, but no reason for their customers to be outraged. I don't know any other ISP that is helping out with the botnet problem.
I'm guessing this is their clever way of reminding you to pay the bill when you're late?
Pay your bill or they'll stuff ugly JavaScript in your browser, you've been warned!
You have reached 90% of your <b>monthly data usage allowance</b>.
Another effective way of combatting this is to detect what's happening and add a "This ad was sponsored by Comcast:" message.
I can sort of see the intent behind this. I just wish they'd tell their customers about their service usage out-of-band, like sending them a text message or an email.
One part of me realized "OMG they're going to track which websites I visit by looking at the HTTP Referer!" But then I quickly realised that as my ISP, they already have access to that information anyway...
"Your ISP (Comcast) adds terrible Javascript to the code of this page without our knowledge or permission, therefore if you have any problems with this application please contact their support line in the first instance and not us. While your ISP is modifying our code, especially while they are modifying it by adding such terrible code of their own, we simply cannot support you, sorry."
https://news.ycombinator.com/item?id=5227923
Yes, the code sample suggests someone clueless about programming in general, even more than being clueless about the particular language of this program. So on what basis was the coder hired?
I'm curious if they have some deal with FB to do it.
I have an iPhone at Orange and never saw this.
Also: https everywhere, now.
We switched to CenturyLink and we're really happy. I'm regularly getting 35-40 Mbps for half the price of 6 Mbps on Comcast. It is a little unnerving to know that 40 is literally the limit of their DSL technology though.
This seems bad, but the warning (exceeding your bandwidth quota) seems valuable. I can't think of another, better way to message this.
I wonder isn't there any law in US that forbids carriers from fiddling with messages?
They can do pretty much whatever they want to.
Injecting into a webpage is unacceptable.
// Intended use is to display browser notifications for critical and time sensitive alerts.
I imagine you can rack up a fair amount of usage before checking emails, only to find you went over your cap a few hours ago.1. They could email you. 2. They could send you a SMS. 3. They could let you view your bandwidth usage by logging into their site. 4. They could provide an application (desktop or mobile) to keep track of your bandwidth and alert you at certain points.
They still send interstitial content warning me that I've exceeded my fair-use limit. It's a bit annoying because I very carefully checked what the limits were before I signed up.
What's worse is that they use weird, broken, IP addresses and horrible proxies for image mangling.
EDIT: Here's a pastebin.
(http://pastebin.com/k6ddD0sJ)
EDIT: Here's a Security \\\stack Exchange question about it: (http://security.stackexchange.com/questions/9368/mobile-carr...)
But yeah, if you have service with Comcast they have your home phone, email addresses, and physical address. They can get in touch with you every way that every company that CAN'T read all of your internet traffic already gets in touch with you.
The method they've chosen is terrible for at least the following reasons: - The alert will not work on many platforms & devices. - The alert may not reach the account owner. - The alert will not work on SSL traffic. - There is no record that the customer saw the alert (contrast with phone call) - There are serious privacy issues involved in parsing user's web traffic.
If you look at what Comcast does on the TV side, things like adding ads to the guide so it's barely usable, you can see where this is going. But the federal regulators of the monopolies are asleep at the switch, we can't even get network neutrality passed. The monopolies know how to play the lobbying game as well as how to slowly turn up the heat so the users aren't all outraged at once. But we can expect more abuses, more ads, more monitoring, more restrictions, more unwanted 'value adds' as time goes on.
| It's extremely bad. The fact that ISP monopolies
| are not regulated in favor of consumers is slowly
| going to destroy the openness that has made the
| web so successful.
This is a little over the top. Whether or not to use this to notify users of time-sensitive information could be a question posed at even a small ISP without such 'evil ambitions.'It's probably more useful to discuss the pros/cons of this approach to notifying users than it is to decry over-arching problems with the entire industry. These (over-arching industry issuse) have been discussed ad nauseum, and action is more useful than discussion at this point (at least on technical forums such as this).
| But the federal regulators of the monopolies
| are asleep at the switch
Look up regulatory capture.The right way would be to ask the customer when they sign up for service what method they would like to receive service notices through. Phone, email, SMS, lettermail, twitter, Facebook, there's a million better ways than to modify my data.
Since you're a comcast employee, maybe go ask the guys running your SMTP/POP3/IMAP servers. I have faith that you guys can come up with some way to communicate with the people using them.
[1] https://chrome.google.com/webstore/detail/https-everywhere/g...
[2] http://security.stackexchange.com/questions/8145/does-https-...
If you would like to see the content of the script, I can show it to you, it's bit different than the one posted here.
The whole document.write block 27-51 (possibly the CSS-block too, but I'm not sure about this) could be written far more elegant in jQuery.
But the real saving is that "drag and drop" code - jQuery would abstract all that isIE/isNS crap from them.
...unless you're still being sarcastic?
a 1 page script written for comcast does not demand jQuery.
That's not to say it would have improved it.
The difference in size is 85.1 KB (according to an above post). 85.1 KB * 100,000,000 (Just an example of the number of times it is loaded) = 7.92555511 terabytes of wastes resources.