Jump to content

Comcast begins man-in-the-middle attacks to show copyright notices on websites

Source: http://www.neowin.net/news/comcast-begin-man-in-the-middle-attacks-to-show-copyright-notices-on-websites

 

Privacy and security fears have been raised by a Californian based developer, Jarred Sumner, who posted Github that Comcast - a US-based ISP - is using a man-in-the-middle(MITM) attack to warn users of potential copyright infringements they may have committed.

 

The message reads:

 

" An important message from Comcast. As part of the Copyright Alert System operated by the Center for Copyright Information, a copyright owned has sent Comcast a notice claiming your internet service from Comcast was used to copy or share a movie, television program or song improperly. We have sent an e-mail with more information about this notice to the comcast.net e-mail address of the primary account holder in your household."

 

The code responsible for displaying the alert is called comcast.js and spans 237 lines of code. This sort of MITM attack is only possible when users connect to an insecture website over a HTTP connection.

 

 

Usually when you enter a URL a request is made to the server, which then responds and sends the websites source code, which the browser displays. What Comcast is doing however, is intercepting the users request and then passing it to the server, in turn the server returns the data to Comcast who then inject their code and relay the modified data to the user, who then sees the alert. Criminals in the past have used this attack to trick users into releasing private information.

Man-in-the-middle attacks can be mitigated by using the secure protocol HTTPS, unfortunately many websites do not support this protocol yet, or do not have it enabled by default if problems are likely to occur with the website. The Electronic Frontier Foundation maintains an extension called HTTPS Everywhere which tries to force connection to HTTPS to help prevent HTTP connections being hijacked.

Another method to mitigate this attack, is by being permanently connected to a VPN, this will ensure that your traffic is routed through a secure connection at all times, preventing Comcast from ever intercepting a connection it can tamper with.

Source: Github via ZDNet

comcast-mitm.jpg

 

This is unacceptable for ISP to perform man-in-man-attack strategy that hackers use to gain personal information and crucial data.  

Link to comment
Share on other sites

Link to post
Share on other sites

Real dick move comcast.

ROG X570-F Strix AMD R9 5900X | EK Elite 360 | EVGA 3080 FTW3 Ultra | G.Skill Trident Z Neo 64gb | Samsung 980 PRO 
ROG Strix XG349C Corsair 4000 | Bose C5 | ROG Swift PG279Q

Logitech G810 Orion Sennheiser HD 518 |  Logitech 502 Hero

 

Link to comment
Share on other sites

Link to post
Share on other sites

That is some really douchy stuff.... 

We could have expected it to happen though, they are douche bags afterall

"Great minds discuss ideas; average minds discuss events; small minds discuss people."

Main rig:

i7-4790 - 24GB RAM - GTX 970 - Samsung 840 240GB Evo - 2x 2TB Seagate. - 4 monitors - G710+ - G600 - Zalman Z9U3

Other devices

Oneplus One 64GB Sandstone

Surface Pro 3 - i7 - 256Gb

Surface RT

Server:

SuperMicro something - Xeon e3 1220 V2 - 12GB RAM - 16TB of Seagates 

Link to comment
Share on other sites

Link to post
Share on other sites

I think I bust a blood vessel every time I see a thread about Comcast on here because it's inevitably something horrible that they're doing that further makes me question how they're so successful as a company. <--that's a rhetorical questioning

PCPartPicker link: http://pcpartpicker.com/p/R6GTGX

Привет товарищ ))))

Link to comment
Share on other sites

Link to post
Share on other sites

I think I bust a blood vessel every time I see a thread about Comcast on here because it's inevitably something horrible that they're doing that further makes me question how they're so successful as a company.

They're successful because most apartments pretty much force us to use them. At least in my area. If I had a choice i'd pay more for someone who didn't give a shit if I torrented or not, and just let the government handlle it.

Link to comment
Share on other sites

Link to post
Share on other sites

Not enough competition to keep them honest and customer oriented  :(

Folding For Linus since July 2015

Link to comment
Share on other sites

Link to post
Share on other sites

They're successful because most apartments pretty much force us to use them. At least in my area. If I had a choice i'd pay more for someone who didn't give a shit if I torrented or not, and just let the government handlle it.

 

This ^, or because they're the only option in your area that offers speeds over like 10mb/s down... (Hurry the fuck up google fibre!)

Specs: CPU - Intel i7 8700K @ 5GHz | GPU - Gigabyte GTX 970 G1 Gaming | Motherboard - ASUS Strix Z370-G WIFI AC | RAM - XPG Gammix DDR4-3000MHz 32GB (2x16GB) | Main Drive - Samsung 850 Evo 500GB M.2 | Other Drives - 7TB/3 Drives | CPU Cooler - Corsair H100i Pro | Case - Fractal Design Define C Mini TG | Power Supply - EVGA G3 850W

Link to comment
Share on other sites

Link to post
Share on other sites

So if you used a vpn would it help to stop it? I would hope so.

COMMUNITY STANDARDS   |   TECH NEWS POSTING GUIDELINES   |   FORUM STAFF

LTT Folding Users Tips, Tricks and FAQ   |   F@H & BOINC Badge Request   |   F@H Contribution    My Rig   |   Project Steamroller

I am a Moderator, but I am fallible. Discuss or debate with me as you will but please do not argue with me as that will get us nowhere.

 

Spoiler

  

 

Character is like a Tree and Reputation like its Shadow. The Shadow is what we think of it; The Tree is the Real thing.  ~ Abraham Lincoln

Reputation is a Lifetime to create but seconds to destroy.

You have enemies? Good. That means you've stood up for something, sometime in your life.  ~ Winston Churchill

Docendo discimus - "to teach is to learn"

 

 CHRISTIAN MEMBER 

 

 
 
 
 
 
 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I think I bust a blood vessel every time I see a thread about Comcast on here because it's inevitably something horrible that they're doing that further makes me question how they're so successful as a company.

 

Because most people don't have a choice. Through buying out competitors and paying cities for exclusive access the internet market in the US has become totally fucked. The lack of any real competition is one of the reasons why our internet infrastructure is so terrible.

Link to comment
Share on other sites

Link to post
Share on other sites

They're successful because most apartments pretty much force us to use them. At least in my area. If I had a choice i'd pay more for someone who didn't give a shit if I torrented or not, and just let the government handlle it.

Because most people don't have a choice. Through buying out competitors and paying cities for exclusive access the internet market in the US has become totally fucked. The lack of any real competition is one of the reasons why our internet infrastructure is so terrible.

I know, it was more or less a rhetorical question. :P

PCPartPicker link: http://pcpartpicker.com/p/R6GTGX

Привет товарищ ))))

Link to comment
Share on other sites

Link to post
Share on other sites

Obviously this is Comcast protecting content creators who don't have the ability to protect themselves from copyright infringement and of course for whom the effects are the worst.

 

It couldn't have to do with the fact that Comcast owns NBCUniversal and therefore has a vested interest in curtailing the illegal sharing of movies and TV shows. No indeed!

Link to comment
Share on other sites

Link to post
Share on other sites

Alas , Yee can kiss internet freedom goodbye in the kisser if this goes any futher.

 

Mean while , im Ok with my ISP in here at finnland.

(⌐■_■) 

Link to comment
Share on other sites

Link to post
Share on other sites

Alas , Yee can kiss internet freedom goodbye in the kisser if this goes any futher.

 

Mean while , im Ok with my ISP in here at finnland.

 

With all the dodo birds out there who say "lol I have nothing to hide" or "who cares if they do this and that?" it is no wonder Comcast/etc can get away with what they do.

 

-_-

|  The United Empire of Earth Wants You | The Stormborn (ongoing build; 90% done)  |  Skyrim Mods Recommendations  LTT Blue Forum Theme! | Learning Russian! Blog |
|"They got a war on drugs so the police can bother me.”Tupac Shakur  | "Half of writing history is hiding the truth"Captain Malcolm Reynolds | "Museums are racist."Michelle Obama | "Slap a word like "racist" or "nazi" on it and you'll have an army at your back."MSM Logic | "A new command I give you: love one another. As I have loved you, so you must love one another"Jesus Christ | "I love the Union and the Constitution, but I would rather leave the Union with the Constitution than remain in the Union without it."Jefferson Davis |

Link to comment
Share on other sites

Link to post
Share on other sites

With all the dodo birds out there who say "lol I have nothing to hide" or "who cares if they do this and that?" it is no wonder Comcast/etc can get away with what they do.

 

-_-

they say so, but so much of the stuff we do on a daily basis on the internet is in the gray area when it comes to copyright laws, that you could get sued just for sharing watermarked pictures.

And with the way the huge companies are acting (basically finding your video/song then put it up on their own site and then delivering a DMCA to the CREATOR.... yes, that has happened more then a few times)... well, the internet is turning into north korea if the US lobbyists have their way.

Link to comment
Share on other sites

Link to post
Share on other sites

they say so, but so much of the stuff we do on a daily basis on the internet is in the gray area when it comes to copyright laws, that you could get sued just for sharing watermarked pictures.

And with the way the huge companies are acting (basically finding your video/song then put it up on their own site and then delivering a DMCA to the CREATOR.... yes, that has happened more then a few times)... well, the internet is turning into north korea if the US lobbyists have their way.

Its at the point that people might as well say fuck it, buy a good internet connection (if they can), then host their own website off their own server-the pricks would need to come and physically erase the server since their DMCA abuse would be futile.

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

Meh, not the proper way to fight against copyright, but still they're trying atleast to alert the users , but not this way

Details separate people.

Link to comment
Share on other sites

Link to post
Share on other sites

Dick move

Use HTTPS Everywhere

IntelCorei54670k,Maximus VI Formula,Swift tech H220, 16gigs Corsair Dominator platinums, Asus DCUII GTX 780,1x256 840 evo, 1x 2TB Segate barracuda, Corsair AX 860, 

3 X Noctua NF-F12, 2x Noctua NF A-14, Ducky Shine 3 Blue Leds Blue switches, Razer Death Adder 2012, Corsair vengence 1400  

Link to comment
Share on other sites

Link to post
Share on other sites

guys, there's nothing wrong with this to begin with. You got nothing to hide, right? And if you do, you're probably doing something illegal and are a terrorist or rapist. Just think about the children.

One day I will be able to play Monster Hunter Frontier in French/Italian/English on my PC, it's just a matter of time... 4 5 6 7 8 9 years later: It's finally coming!!!

Phones: iPhone 4S/SE | LG V10 | Lumia 920 | Samsung S24 Ultra

Laptops: Macbook Pro 15" (mid-2012) | Compaq Presario V6000

Other: Steam Deck

<>EVs are bad, they kill the planet and remove freedoms too some/<>

Link to comment
Share on other sites

Link to post
Share on other sites

Even if it was done by the police it could easily be construed as entrapment, basically blurs away the notion that Copyright "Law" has anything to do with the legal system and it's basically being dictated and now enforced by private citizens(Corporations) with 0 fucking authority because fuck laws that's why.

-------

Current Rig

-------

Link to comment
Share on other sites

Link to post
Share on other sites

guys, there's nothing wrong with this to begin with. You got nothing to hide, right? And if you do, you're probably doing something illegal and are a terrorist or rapist. Just think about the children.

^this.

 

Also, never mind that Comcast is one of the most egregious ISP's in the US.

 

Even if it was done by the police it could easily be construed as entrapment, basically blurs away the notion that Copyright "Law" has anything to do with the legal system and it's basically being dictated and now enforced by private citizens(Corporations) with 0 fucking authority because fuck laws that's why.

 

^also this.

Ketchup is better than mustard.

GUI is better than Command Line Interface.

Dubs are better than subs

Link to comment
Share on other sites

Link to post
Share on other sites

Even if it was done by the police it could easily be construed as entrapment, basically blurs away the notion that Copyright "Law" has anything to do with the legal system and it's basically being dictated and now enforced by private citizens(Corporations) with 0 fucking authority because fuck laws that's why.

How is this entrapment? :huh:

Also, what are they enforcing? From what I see, this is just a notice being injected into a page.

Now, I don't agree with them injecting scripts into pages without the users permission, but we're not going to win this fight by making outlandish claims.

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to comment
Share on other sites

Link to post
Share on other sites

I have realized that you love copy and pasting news from other sites as your own.

This is called plagiarism. This is not allowed in the Tech News section.

Please use quotes on thing you copy over, and explain the news in your own words. I moved the news under General Discussion until you fix your post. (PM me when you do so that I can move it back to the Tech News section).

Please read the Tech News guideline: http://linustechtips.com/main/topic/11724-read-before-posting-in-this-section/

Link to comment
Share on other sites

Link to post
Share on other sites

Really... Comcast is horrible. Only if it wasn't the only provider to offer 150M down i wouldn't care and switch but i would rather take 150 over the 10 that fairpoint has in this area (not saying they are a nice company either) those are the options I'm stuck with.

I'm Probably at work so expect a reply either really fast or really slow :D

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×