Comcast is leaking the names and passwords of customers' wireless routers


Olde Hornet

Well-Known Member
https://www.yahoo.com/finance/news/comcast-leaking-names-passwords-customers-232749716.html

The problem is threefold:
  1. You can "activate" an account that's already active
  2. The data required to do so is minimal and it is not verified via text or email
  3. The wireless name and password are sent on the web in plaintext
This means that anyone with your account number and street address number (e.g. the 1425 in "1425 Alder Ave," no street name, city, or apartment number needed), both of which can be found on your paper bill or in an email, will instantly be given your router's SSID and password, allowing them to log in and use it however they like or monitor its traffic. They could also rename the router's network or change its password, locking out subscribers.

This only affects people who use a router provided by Xfinity/Comcast, which comes with its own name and password built in, though it also returns custom SSIDs and passwords, since they're synced with your account and can be changed via app and other methods.
 
Back
Top