nanog mailing list archives

Re: Comcast storing WiFi passwords in cleartext?


From: Tom Beecher <beecher () beecher cc>
Date: Wed, 24 Apr 2019 10:24:03 -0400

The Stackexchange post does NOT say that they got their own AP. It says
they got their own DOCSIS Modem / Router / Wifi combo device. That's an
important distinction.

When I worked at Adelphia many years ago, the only distinction between
customer owned CPE and company owned CPE was billing. All modems received
the same DOCSIS config file when they booted up. While I have not worked in
that industry for many years now, from what I am aware of the same behavior
still applies. The modem management and configuration is 100% in the hands
of the MSO.

This is why, in my opinion, people should avoid modem/router combo units
whenever possible. Any information/configuration entered into such a device
could be accessible to the MSO (intentionally or otherwise) , as is
happening here. I'm sure they would come back and say this is necessary to
provide support for customers who pay them for WiFi service, but it clearly
shows they don't turn off that functionality for customers who don't.

Treat you cable modems as foreign network elements. Cause that's what they
are.

On Wed, Apr 24, 2019 at 9:28 AM Töma Gavrichenkov <ximaera () gmail com> wrote:

On Wed, Apr 24, 2019 at 3:27 PM Matt Hoppes
<mattlists () rivervalleyinternet net> wrote:
If you’re really running something that requires that kind
of security you may want to get your own wireless access point.

Like I said: the OP claims that's what s/he did.

--
Töma


Current thread: