Comcast says hackers stole data of close to 36M Xfinity customers
A major hack of Comcast’s Xfinity service exposed data for tens of millions of customers, including contact details, dates of birth, partial Social Security numbers, and security questions and answers. Commenters argue that such breaches have effectively made traditional identity markers (like SSNs and “secret questions”) unusable for secure authentication, and call for stronger penalties, regulation, and even structural changes such as municipal broadband or breaking up telecom monopolies. Others note that the breach exploited a Citrix vulnerability, raising questions about patch timelines and the reliability of widely used enterprise security products.
Scope and Nature of Breach
- Hackers accessed data for tens of millions of Xfinity customers, including contact details, dates of birth, last four digits of SSNs, and security questions/answers.
- Some commenters assume full SSNs and broad credit-bureau-style profiles are already “out there” from prior breaches, so this is seen as incremental rather than unique.
- People note Comcast’s notice language is vague (“unspecified number of customers”) and framed as routine security review rather than a clear disclosure.
Security Questions, SSNs, and User Practices
- Strong consensus that security questions are effectively passwords and should use random or non-truthful answers.
- Suggestions: use passphrases, treat questions as alternate prompts (“pet name” → “color of first car”), or reuse a consistent fake pattern and store it in a password manager.
- Pushback: random answers reduce usability, especially for phone-based verification; many businesses still store and use them in plaintext for call-center auth.
- Broader view: SSNs and similar static identifiers are fundamentally broken as authenticators.
Comcast Security Culture and CitrixBleed Response
- Multiple anecdotes describe lax internal security practices and prioritizing sales metrics over authentication.
- The CitrixBleed exploit is criticized as embarrassingly simple; some say Comcast patched “promptly,” others read the timeline as weeks late.
- Skepticism that Comcast’s “robust security programs” are meaningful beyond detecting incidents after the fact.
- Past refusal to do bug bounties is cited as evidence of systemic apathy.
Liability, Penalties, and Regulation
- Many call for statutory per-user fines, scaled by type and combination of leaked data, and possibly punitive enough to threaten corporate existence.
- Debate over whether large fines or some form of “corporate death penalty” would actually help customers versus costs being passed on.
- Some advocate making personal data a liability rather than an asset to discourage hoarding.
Monopolies, Competition, and Infrastructure
- Widespread frustration that Comcast often operates as a local monopoly or duopoly; customers feel unable to “vote with their wallet.”
- Discussion of cable/telco lobbying, restrictive municipal agreements, and bans on municipal fiber.
- Some argue core infrastructure (like broadband) should be publicly owned or tightly regulated, as private provision tends toward monopoly.
User Risk, Mitigations, and “It’s All Leaked Anyway”
- Many have frozen credit with major bureaus and recommend it as baseline hygiene.
- Some feel repeated leaks make individual actions almost futile beyond credit freezes and monitoring.
- Others emphasize physical risk: address exposure can enable stalking, swatting, or targeted crime, especially for high-profile individuals. Techniques like using shell companies or third parties for utilities are discussed for those with means.
Broader Security Takeaways
- Commenters criticize overengineered enterprise products (Citrix, WAFs) versus simpler, well-understood stacks; see much corporate security as theater.
- Authenticating users over the phone is described as an unresolved problem that drives many insecure practices.