Comcast Turning Chicago Homes Into Xfinity Hotspots
BUL2294 writes "The Chicago Tribune is reporting that, over the next few months in Chicago, Comcast is turning on a feature that turns customer networks into public Wi-Fi hotspots. After a firmware upgrade is installed, 'visitors will use their own Xfinity credentials to sign on, and will not need the homeowner's permission or password to tap into their Wi-Fi signal. The homegrown network will also be available to non-subscribers free for several hours each month, or on a pay-per-use basis. Any outside usage should not affect the speed or security of the home subscriber's private network. [...] Home internet subscribers will automatically participate in the network's growing infrastructure, although a small number have chosen to opt out in other test markets.' The article specifically mentions that this capability is opt-out, so Comcast is relying on home users' property, electricity, and lack of tech-savvy to increase their network footprint."
Comcast tried this in the Twin Cities area, and was apparently satisfied with the results, though subscribers are starting to notice.
Not only 2.4 but 5 GHz as well.
Disgusting waste of spectrum.
So what happens when people start connecting to your router and doing unsavory things. A couple I can think of, human trafficking or child porn, or less evil but still evil trying to get on the other side of your router. What about downloading Torrents? I mean we don't really know how good that firmware is do we? What if the FBI come knocking on your door one day saying, We noticed that someone at this address is doing some bad things. Come with us please.
Mean what you say...say what you mean.
I was in the UK last year and you can pick up loads of BT open wifi hotspots you can connect to. These then piggy back on a home consumers network connection.
I'm very suss on this as I would have thought contention alone would be a hell of an issue but I assume it is rate limited in some way. I had a play for a couple of minutes trying to compromise my sister-in-laws setup and couldn't manage it but I am far from skilled in that area.
That, folks, is why you never use an ISP provided router. Of course at some point you'll be forced to "upgrade" to a modem with integrated wifi.
I am becoming gerund, destroyer of verbs.
External WIFI router and a Faraday cage. Just when you thought Comcast couldn't be more evil. Bam! F-you Comcast.
Brave Sir Robin ran away. ("No!") Bravely ran away away. ("I didn't!")
Except that it isn't...
In NL, some ISPs are doing the same. It's even a different public-facing IP address.
Of course, you can also turn it off. Though turning it off on your modem means you don't get to use it yourself on others' modems.
If you are a Comcast Internet customer, you can already use Xfinity WiFi where it's available, even if you aren't providing this service to them.
Which accomplishes nothing, as you'd be logging in as you - unless you're using somebody else's credentials. That seems to be the main weakness, at least in the NL (Ziggo) case; people intercepting login data or the public wifi being easily hacked to grant access to the internet (not to the internal network), etc.
So, yes, you could certainly access your own modem as John Doe using John Doe's credentials, and they would come knocking on John Doe's door. Best make sure John Doe is somebody who would plausibly make use of your router, of course, otherwise "yeah I was at work 50 miles from that router, tyvm" becomes a bit of an alibi and pushes the investigation into checking MAC address (don't forget to fake that), doing some surveillance on when it's getting accessed with John Doe's credentials and triangulating the signal source, etc.
Either which way, it doesn't work as an added excuse for things that happen out of your private network :)
the first thing I did when I got Comcast was have them disable the wifi on there router and set it up so it runs as a bridge instead.
But... if it is their router, it is their network. Thus they can turn it back on at their pleasure.
I'm sure their WiFi-unilaterally-reenabled router will be encountering lots of WiFi traffic once it is wrapped in aluminum foil (or any other basic Faraday cage/signal attenuation approach).
It may be their router and their network, but it sure as hell isn't their site.
Wow now Comcast should make them rent free if they want to do this.
Also Knowing how some times they can't even get cable tv right I don't really trust them to make so others can't hack in or lets say overload the box with users.
Sorry to repost - orig post was as AC... maybe someone will actually see this one. This is NOT an open Wifi network. You must sign in with a Comcast / Xfinity User ID in order to use the network, AND you are signing into SSID 'xfinitywifi', NOT your local, private, SSID 'Ithinktheskyisfalling'. I saw it pop up on my router last year and do not have a problem with it. Any activity on the xfinitywifi SSID in going to be associated with a specific user, probably not me. Looking at the current networks in my area, I see xfnintywifi on channels 3 and 6, also another 'un-named' network, on one or more channels, that is probably emanating from the same device or another close by, judging from the MAC addresses and signal strength. I have a Samsung Galaxy Tab 2, wifi only, that I use as my mobile device and connect to the XfinityWifi network, using an ID on my account, at multiple locations. I am glad they set it up and give me access to it. No, I do not have a smart phone. BTW - there are other networks, Optimum and TWC, that can also be used with your Comcast User ID. What was it that Yoda said? - 'The ignorance is strong with some of these...' or something like that.
Given what Comcast charges on a monthly basis for their routers, I don't understand why anyone uses one of theirs. You can buy a DOCSIS 3 cable modem for 60 or 70 bucks.
#DeleteChrome
We have here a similar service with a former incumbent operator, which wonders of wonders has almost a virtual monopoly of cables services. The service itself is very useful and allow us to roam in most of locations without paying anything extra. Apparently it is a roaming authentication setup where you can authenticate in the modem of another customer, in a different VLAN/network and at limited speeds. (whilst at home you have 100 Mbps, roaming speeds appear to be on the range 5 to 2 Mbps). There are no dangers of someone knocking in the door of the other because of hacking/porn/whatever, all remote usage is linked to your account due to you logging with your id/password. The downside of this setup is that the 2.4GHz band is overcrowded, with most of the neighbours taking 2 (B)SSIDs. Often this situation compromises the quality of the service itself, both for the proper customer, and to the roaming service is equipment is providing. The situation has gotten so bad, I know of people installing repeaters at home, and I myself had to migrate to a new router in the 5GHz band to be able to work properly. I also disable the operator equipment and it works only in bridging mode, as the CPU capabilities are weak, and I don not trust the security if brings to my own network. There are also some persons who piggyback on the credentials and the family/friends, and use this service permanently with a (very) reduced Internet capacity. (As a side note, in both of my 2 houses in two different cities I can count as much as 40 BSSIDs when walking around the house)
And what exactly is stopping a bad guy from setting their network's SSID to 'xfinitywifi' and hijacking traffic? That's one reason I don't trust public hotspots in general, it's too easy for someone else to impersonate them and while I can and do protect my computer against attack from malware I can't protect my network traffic from the access point I'm connected to.
As far as "logging in" with their user ID, I doubt Comcast has set up the infrastructure to do 802.1x authentication and most clients aren't configured to handle it. They're using browser-based authentication, which means your computer will connect to any AP using SSID 'xfinitywifi' without prompting you and all your traffic will be accessible by that AP. A simple Web server mimicking the signon page coded to accept any password and you won't notice a thing.
This is nothing new. BT in the UK have been doing it for a while and it all originated (I think) with the Fon project. Which may have started in Spain, (though I'm happy to be corrected).
The bandwidth available to the public network is limited and it collapses to zero if you're using your own network flat out.
Also it doesn't get included in your traffic cap.
So the obvious worries are unfounded.
Whether you trust them technologically to get it right and keep it separate is a different matter. And yes, anyone can set up a rogue hotspot that captures credentials. But that was possible with any branded national hotspot network before.
BT have a smartphone app that will automatically connect a BT broadband subscriber to any shared private/public network of this sort that it finds, making it possible for me to walk most of the way across town with continuous wifi access on my smartphone. But it's a flaky app and also rather stupidly only allows you to search for available hotspots on a local map IF you're already online (doh !!). I'd find the same app for my laptop very useful but it seems not to exist.
The biggest pain I found with the whole dual network thing was that the public side of it is a "freely connectable, fill in your details on the first webpage you see" sort of thing. This means your PC may arbitrarily connect to it instead of your own "proper" network sometimes. (until you actively tell it not to), then find it can't actually do anything.
What they have NOT offered (and which would be rather useful) is the facility to setup a guest network in your house. What they currently offer is only a guest network for BT (or in the OP, Comcast) subscribers.
I was explicitly warned that they would no longer be able to offer remote support for troubleshooting the modem if I left it in bridge mode
Correct. I work for an ISP on the engineering side. For the very reason that modems in bridge mode cannot be remotely monitored via IP SNMP, or accessed via Telnet etc -- our policy is route always; no modems in bridge mode. No exceptions. I'm surprised Comcast even allowed that.
If a customer has their own router, then additional IP addresses can be routed to the modem and then on to their router --- otherwise, the modem will be their NAT boundary.
No customers are provided the username/password access: all config changes by support.
If monitoring finds a modem to be tampered with or no longer responsive -- most likely service will be temporarily turned off, until support clears it after the customer pays for a truck roll (in the case someone did something dumb such as insert a pin in the reset slot of our modem).
In bridge mode, the DSL/Cable modem no longer has an IP address. The only way to regain control over it is to be connected with a laptop on the LAN side of the device and know the 192.168.bla.blah address of the modem, or do a hard reset.
Lots of people do this all over the world.
The last time I was in Paris for an extended stay, back in 2009, at least one of the major ISPs was doing this on all their customer routers. The world did not seem to come to an end (or at least I haven't noticed it - maybe I'm oblivious). I can't recall if it was SRF, Numericable or Orange or "free" or one of the other big telecom companies, but they certainly had a lot of hotspots. They might have started working with FON to get an international system going I seem to recall.
https://corp.fon.com/en
The "public" wifi did not eat into the subscriber's bandwidth or whatever data caps they had. I don't know how (or if) they addressed the potential for honeypots stealing credentials.
Same principle here in Germany.
But Deutsche Telekom is not doing this as an opt-out thing, but as opt-in - plus you need a certain router model. I bought the (inexpensive) router and opted in, because now I can use all of these home router hotspots, plus all FON hotspots worldwide, all Telekom hotspots (in public places, at McDonald's, in high speed trains). The public hotspot users get very low QoS, so they don't harm my VDSL connection.
And the best thing: All I have to do to keep using it is connect the home router at least once every 30 days. So since the router is not my primary choice, 99% of time I'm freeloading and using my custom router, all the while keeping my hotspot privileges.
Wow, mind letting us know which ISP you work for so I never accidentally sign up with them?
How hard is it to set up a router with the network ssid "xfnintywifi " and gather up all the username/password combinations that people use to log on? Not hard at all.
Best Slashdot Co
I have a client (a business) in Montpelier, Vermont who had their residential cable service upgrade to "business" class. I was there while they did the work. While they were still there I checked out their work and found the extra cable modem and WiFi router and asked them about it (this was two additional devices off of a splitter). They informed me that it was part of the Xfinity service to provide a public hotspot. I said great, what is the login credentials so visitors to the office can use it. I was informed that since they were a business they (the client) was not permitted to use it and it was only for other Comcast users. I then proceeded to closet where everything was and unplugged the modem and hotspot and only left the business class modem they left. You could tell that they were pissed but could do nothing about it.
What pissed me off is that the client is paying for the electricity and hosting the device for Comcast and not allowed to use it. To top it all off, the stuck a sticker on the clients front window advertising the hotspot with out asking (this is a law office). Needless to say, I ripped that sticker off the minute I saw it.