Wednesday, February 20, 2019

Web Services Terms of Service


Web Services Terms of Service


Web Services Terms of Service


Within these Web Services Terms of Service ("Terms") the term "Comcast" or "we" (and related pronouns) will refer to Comcast Cable Communications Management, LLC, and its respective subsidiaries and affiliates that own and operate websites and Internet services on its behalf. The term "you" (and related pronouns) refers to you as a user of Comcast's websites and Internet services described below.

Note: These Terms contain a binding arbitration provision in Section 20 that affect your rights under these Terms with respect to all of the Comcast Web Services.

These Terms set forth the terms and conditions through which Comcast will permit you to use these Comcast-owned and operated websites and services:

  • Comcast-branded websites and web services that link to these Terms, such as: comcast.net, xfinitytv.com, my.xfinity.com, xfinityhomesecurity.com, www.plaxo.com, and see.it, excluding certain co-branded websites and web services provided by third parties through contractual arrangements with Comcast, as further described below ( (the "Comcast Sites");

  • all mobile applications provided by Comcast that link to these Terms (such as Xfinity TV Go, Xfinity TV Remote, and Xfinity Connect applications) (the "Comcast Apps"); and

  • all software and services provided by Plaxo, including those services made available by Plaxo through its application programming interfaces ("APIs") (collectively the "Plaxo Service");

  • XFINITY Wi-Fi services, if you are not an XFINITY Internet subscriber; and

  • a Comcast-provided email address (such as yourname@comcast.net), if you are not an XFINITY Internet or XFINITY Voice subscriber (collectively, (1) through (5) are referred to as the "Comcast Web Services").

What is outside the scope of these Terms?

These Terms do not apply to your use of any other products or services provided by Comcast such as XFINITY TV, XFINITY Voice, XFINITY Internet, and XFINITY Home. If you subscribe to or use one or more of these services (including using the Comcast Web Services to place or receive XFINITY Voice calls), you can see the terms that apply to the residential versions of these services by visiting http://www.comcast.com/Corporate/Customers/Policies/Policies.html.

Some of the Comcast Web Services contain links to other websites, including websites of third parties who are acting on our behalf as our agents, suppliers, or providers. These other websites are not operated by Comcast and have their own terms of service that you should read before you use them. Other sites that we link to may contain Comcast branding or co-branding, but these non-Comcast websites and resources are provided by companies or persons other than Comcast. Examples of these non-Comcast websites include websites where you are required to log-in using a username and password other than your username and password for the Comcast Web Services, such as the "Jobs" channel and the "Dating" channel on Comcast.net or Xfinity.com. These Terms do not apply to those non-Comcast sites. Those sites will have their own terms of use that you should read before you use them. You acknowledge and agree that Comcast is not responsible for the availability of any of these websites or resources, and does not endorse any advertising, products or other materials on or available from these websites or resources. You acknowledge and agree that Comcast is not liable for any loss or damage which may be incurred by you as a result of the availability of those websites or resources, or as a result of any reliance placed by you on the completeness, accuracy or existence of any advertising, products or other materials on, or available from, these websites or resources.

2. Accepting These Terms

In order for you to use any of the Comcast Web Services, you must first accept these Terms. You can accept these Terms by:

  1. Checking the box next to "I have read and agree to the Terms of Service" (or similar language); or

  2. Using any of the Comcast Web Services, in which case you understand and agree that these Terms will apply to your use of those services (or any parts of them) (the earlier of the dates you checked such box or first used the Comcast Web Services, the "Effective Date").

You may wish to print or save a local copy of the Terms for your records.

3. Registration

In order to use the Comcast Web Services you may be required to provide information about yourself (such as identification or contact details). You agree that any registration information you give to Comcast will be accurate, complete, and current. You will notify Comcast immediately of any changes to any of the foregoing information. You are responsible for updating your email address, so that if you use any of the account management features of the Comcast Web Services, such as online bill pay, Comcast can send you notices relating to these features, such as notice that your online bill has posted. If your email address is not current, you will not receive online bill postings; however, your payment due date will remain unchanged.

4. Prohibited Uses

You specifically agree not to:

  • use the Comcast Web Services to undertake or accomplish any unlawful purpose, including but not limited to, posting, storing, transmitting or disseminating information, data or material which is libelous, obscene, unlawful, threatening or defamatory, or which infringes the intellectual property rights of any person or entity, or which in any way constitutes or encourages conduct that would constitute a criminal offense, or otherwise violate any local, state, federal, or non-U.S. law, order, or regulation;
  • post, store, send, transmit, or disseminate on the Comcast Web Services any information or material which a reasonable person could deem to be unlawful;
  • upload, post, publish, transmit, reproduce, create derivative works of, or distribute on the Comcast Web Services in any way information, software or other material that is protected by copyright or other proprietary right, without obtaining any required permission of the owner;
  • post on or distribute through the Comcast Web Services unsolicited bulk or commercial messages commonly known as "spam;"
  • send very large numbers of copies of the same or substantially similar messages, empty messages, or messages which contain no substantive content, or send very large messages or files that disrupt a blog, newsgroup, chat, or similar feature of the Comcast Web Services;
  • initiate, perpetuate, or in any way participate in any pyramid or other illegal scheme through the Comcast Web Services;
  • participate in the collection of very large numbers of email addresses, screen names, or other identifiers of others (without their prior consent) from the Comcast Web Services, a practice sometimes known as spidering or harvesting, or participate in the use of software (including "spyware") designed to facilitate this activity;
  • collect responses from unsolicited bulk messages posted on or distributed through the Comcast Web Services;
  • impersonate any person or entity, engage in sender address falsification, forge anyone else's digital or manual signature, or perform any other similar fraudulent activity (for example, "phishing") on the Comcast Web Services;
  • restrict, inhibit, or otherwise interfere with the ability of any other person, regardless of intent, purpose or knowledge, to use or enjoy the Comcast Web Services (except for tools for safety and security functions such as parental controls, for example), including, without limitation, posting or transmitting any information or software which contains a worm, virus, or other harmful feature, or generating levels of traffic sufficient to impede others' ability to use, send, or retrieve information;
  • register under the name of, nor attempt to use the Comcast Web Services under the name of, another person;
  • allow another person to access the Comcast Web Services using your credentials;
  • access (or attempt to access) the Comcast Web Services through any automated means (including use of scripts or web crawlers), except through APIs or other interfaces specifically provided for this purpose, or violate the instructions set out in any robots.txt or similar file present within the Comcast Web Services;
  • engage in the systematic retrieval of data or other content from the Comcast Web Services, except though APIs or other interfaces specifically provided for this purpose, to create or compile, directly or indirectly, a collection, compilation, database or directory, without Comcast's prior written consent;
  • capture, rip, download, or otherwise create a copy of any content that is shown on the Comcast Web Services without obtaining any required permission of the content owner;
  • take any actions for the purpose of manipulating or distorting, or that may undermine the integrity and accuracy of, any ratings or reviews of any movie or other entertainment program, service or product that may be presented by the Comcast Web Services; or
  • attempt to or actually circumvent any method used by Comcast to control access to Comcast Web Services, including, but not limited to, spoofing or otherwise impersonating an IP address for your computer that is not actually assigned to your computer or setting up a proxy or other device that allows others to access the Comcast Web Services through it.

If you are an XFINITY Internet customer, you can find the guidelines for acceptable use of the Internet service, including any XFINITY email or webmail services, at http://www.comcast.com/Corporate/Customers/Policies/Policies.html.

5. Your Passwords and Unauthorized Use of Your Account

You are responsible for maintaining the confidentiality of your Comcast Web Services account and its password(s). In addition you are responsible for controlling access to any PCs, mobile devices, or other end points that you allow to store your password, or on which you enable a "Remember Me" or similar functionality ("Activated Device"). Accordingly, you agree that you will be solely responsible to Comcast for all activities that occur under your Comcast Web Services accounts, including the activities of any individual with whom you share your Comcast Web Services account or an Activated Device, and will be responsible for any breach of these Terms caused by these activities. If you become aware of any unauthorized use of your password or of your account, you agree to notify Comcast immediately. To protect your privacy, Comcast recommends logging out of the Comcast Web Services after each visit when you are using a public or shared PC, mobile device, or other end point.

6. Privacy and Your Personal Information

To understand how Comcast collects and uses information through the Comcast Web Services, please read the Web Services Privacy Policy at http://www.comcast.net/privacy/.

Comcast is not responsible for any information provided by you to third parties, and this information is not subject to the Web Services Privacy Policy. You assume all privacy, security, and other risks associated with providing any information, including personally identifiable information, to third parties via the Comcast Web Services. For a description of the privacy protections associated with providing information to third parties, you should refer to any privacy policies provided by those third parties.

If you use any of the voice control features of the Comcast Web Services, like the voice control feature of the X1 Remote app, all voice commands are sent to Comcast or its contracted service provider. Comcast, and its provider, use these voice commands to provide the voice control service (including quality assurance, troubleshooting, and customer support), improve Comcast's products and services, and improve their voice recognition algorithms. If you use any of the voice control features of the Comcast Web Services, you consent to Comcast and its contracted service provider recording, storing, and using your voice input as described herein.

7. Content on the Comcast Web Services

The Comcast Web Services will allow you to access content and information, such as collections of data, video, audio, or other multimedia, and photographs and other static images (the "Content"). This Content may be owned by Comcast, other companies that give Comcast the right to distribute their Content (like movie publishers), or users of the Comcast Web Services (like you). Comcast grants you a limited, non-exclusive, non-assignable license to view the Content and to use the Comcast Web Services for personal, non-commercial purposes as set forth in these Terms or in a manner that does not require a license. Unless the Content was legally posted by you on the Comcast Web Services, you may not distribute copies of the Content in any form (including by email or other electronic means), without prior written permission from its owner except as permitted by law. Of course, you are free to encourage others to access the Content and to tell them how to find it.

In addition, our Content providers want to remind you that you must not remove, alter, interfere with, or circumvent any copyright, trademark, or other proprietary notices marked on the Content or any digital rights management mechanism, device, or other content protection or access control measure associated with the Content. The copying, downloading, stream capturing, reproduction, duplication, archiving, distribution, uploading, publication, modification, translation, broadcast, performance, display, sale, or transmission of the Content is strictly prohibited unless it is expressly permitted by Comcast in writing or otherwise permitted by law. You may not incorporate the Content into any hardware or software application. This prohibition applies even if you intend to give away the derivative materials free of charge.

You understand that by using the Comcast Web Services you may be exposed to Content that you may find offensive, indecent or objectionable. In this respect, you use the Comcast Web Services at your own risk. If you would like to use them, there are commercially available services and software that can limit exposure to material that you may find objectionable. The XFINITY Internet service provides security information and tools for all users, including parents, at http://constantguard.comcast.net. Some of the tools may require that you be a registered XFINITY Internet user in order to download and use them.

You understand that Comcast has the right to change the Comcast Web Services at any time with or without notice to you. We also may rearrange, delete, add to, or otherwise change Content or other features or functionality contained within the Comcast Web Services. If we do give you notice of these changes, it may be provided on any of the Comcast Web Sites, or via email, newspaper, bill insert, or any other reasonable means of communication. If you find a change in the Comcast Web Services unacceptable, you have the right to cancel your Comcast Web Services account or to stop using the Comcast Web Services. However, if you continue to use the Comcast Web Services after the change, this will constitute your acceptance of the change.

8. User Submissions

Some of the material appearing on the Comcast Web Services will be provided by users. Comcast does not claim ownership of any material that users submit or post on the Comcast Web Services. You agree that you are solely responsible for (and that Comcast has no responsibility to you or to any third party for) any material that you create, transmit, or display while using the Comcast Web Services, and for the consequences of your actions (including any loss or damage which Comcast may suffer) by doing so. Further, you agree that, with respect to any communication you submit to us for posting on the Comcast Web Services, you will not: (i) include any content that violates a third party's copyright or other proprietary or privacy rights; (ii) publish falsehoods or misrepresentations portrayed as fact; (iii) include any advertising or solicitations; or (iv) submit any material that is unlawful, obscene, defamatory, libelous, threatening, pornographic, harassing, hateful, racially or ethnically offensive, or encourages conduct that would be considered a criminal offense, give rise to civil liability, violate any law, or is otherwise clearly inappropriate.

If you post any content to the Comcast Web Services, you hereby grant Comcast and its licensees a worldwide, perpetual, royalty-free, non-exclusive right and license to use, reproduce, publicly display, publicly perform, modify, sublicense, and distribute the content, on or in connection with the Comcast Web Services or the promotion of the Comcast Web Services, and incorporate it in other works, in whole or in part, in any manner. You represent and warrant that you own the content or otherwise have sufficient rights in it to grant to Comcast the license set forth in this section without infringing or violating the rights of any third party. If you remove content that you have posted to the Comcast Web Services or terminate your Comcast Web Services account, this license will automatically expire, with a few limited exceptions. Comcast may retain copies of your content that were archived in the normal course of Comcast's systems operations. In addition, copies of content that you have shared with other users of the Comcast Web Services may be retained by Comcast and associated with those other users' accounts in order to provide them with the Comcast Web Services. Comcast does not assert any ownership over content that you post to the Comcast Web Services; rather, as between us and you, subject to the rights granted to us in these Terms, you retain full ownership of and/or licenses to all content you post to the Comcast Web Services and any intellectual property rights or other proprietary rights associated with that content.

The Comcast Web Services may also contain links to community forums, bulletin boards, chat rooms, and blogs about the various Comcast Web Services. Children under the age of 13 should not post in any of the forums, boards, chat rooms, blogs, other editorial sections of the Comcast Web Services. Participants in these forums, bulletin boards, chat rooms, and blogs are solely responsible for all content that they post there. Comcast retains the right, but not the obligation, to correct any errors or omissions in any of this content, as it may determine in its sole discretion. Comcast further reserve the right to delete or remove any content from the forums or blogs without prior notice or liability. You agree that your participation in these forums, bulletin boards, chat rooms, and blogs will at all times conform with the posted comment policy for that forum, bulletin board, chat room, or blog.

Comcast reserves the right, but does not assume any obligation, to review any user submission prior to its display on the Comcast Web Services using automated tools or manual processes. Comcast may refuse to display or remove any user submission from the Comcast Web Services for any reason in our sole discretion. However, we will typically only do so when we become aware that the material in question is harmful, clearly illegal, or likely to be considered highly offensive or objectionable to a large segment of our users.

9. Feedback

Comcast welcomes your feedback about the Comcast Web Services. Comcast asks that you limit your feedback to the Comcast Web Services. Any communications you send to Comcast are deemed to be submitted on a non-confidential basis. By sending a communication or submitting feedback to Comcast, you grant Comcast, its affiliates, and their licensees a worldwide, perpetual, irrevocable, royalty-free, non-exclusive right and license to make, use, sell, offer for sale, import, export, have made, reproduce, publicly display, publicly perform, modify, sublicense, and distribute the content and inventions embodied therein, in any way and for any purpose. All of these uses shall be without liability or obligation of any kind to you. These uses may include, for example, use of the content of any of these communications, including any works, marks or names, ideas, inventions, concepts, techniques or know-how disclosed therein, for any purpose without any obligation to compensate the originator of the communications and without liability to that person.

10. Proprietary Rights

You acknowledge and agree that Comcast (or Comcast's licensors) own all legal right, title, and interest in and to the Comcast Web Services, including any intellectual property rights which subsist in the Comcast Web Services (whether those rights happen to be registered or not, and wherever in the world those rights may exist).

Unless you have agreed otherwise in writing with Comcast, nothing in the Terms gives you a right to use any of Comcast's trade names, trade marks, service marks, logos, domain names, and other distinctive brand features except as permitted by law. If you have been given an explicit right to use any of these brand features in a separate written agreement with Comcast, then you agree that your use of these features shall be in compliance with that agreement, any applicable provisions of the Terms, and Comcast's brand feature use guidelines as updated from time to time.

Unless you have been expressly authorized to do so in writing by Comcast or are otherwise permitted by law, you agree that in using the Comcast Web Services, you will not use any trade mark, service mark, trade name, logo of any company or organization in a way that is likely or intended to cause confusion about the owner or authorized user of these marks, names or logos.

11. Linking to the Comcast Sites

Comcast welcomes links to any of the Comcast Sites. You are free to establish a hypertext link to these websites so long as the link does not state or imply any affiliation, connection, endorsement, sponsorship, or approval of your site by Comcast.

12. Term; Provisions That Remain in Effect after Termination

The Terms apply to all users of the Comcast Web Services, and will be in effect from the Effective Date until terminated by either Comcast or you as set forth below.

Unregistered Users

If you use any of the Comcast Web Services (or parts of those services) that are accessible without registration, you can simply discontinue use of those services at any time. Doing so will terminate the applicability of these Terms to you with respect to those services. If you breach any provision of these Terms or other applicable policies, or for any other reason, Comcast reserves the right to restrict, suspend, or terminate your use of the Comcast Web Services and terminate the Terms. We may take these actions with or without notice to you. Because unregistered users are generally unknown to us, in most cases we will be unable to give notice of these actions.

Registered Users

If you use any of the Comcast Web Services (or parts of those services) as a registered user, you may delete your registered user account at any time. Doing so will terminate these Terms with respect to that Comcast Web Service. If you breach any provision of these Terms or other applicable policies, or for any other reason, Comcast reserves the right to restrict, suspend, or terminate your registered user account for any or all of the Comcast Web Services and terminate the Terms. We may take these actions with or without notice to you. Because registered users are known to us, however, we will generally use reasonable efforts to give notice of these actions.

Currently, registered user accounts for Comcast.net and Xfinity.com are associated with Xfinity TV, Xfinity Internet (including Xfinity Wi-Fi), or Xfinity Voice service and cannot be deleted without also terminating the associated service.

Sections 8 through 10, 12 through 15, 20, and 21 of these Terms will survive termination, and shall continue to apply indefinitely.

13. EXCLUSION OF WARRANTIES

YOU AGREE THAT YOUR USE OF THE COMCAST WEB SERVICES IS AT YOUR SOLE RISK. BECAUSE OF THE NUMBER OF POSSIBLE SOURCES OF INFORMATION AVAILABLE THROUGH THE COMCAST WEB SERVICES, AND THE INHERENT HAZARDS AND UNCERTAINTIES OF ELECTRONIC DISTRIBUTION, THERE MAY BE INTERRUPTIONS, DELAYS, OMISSIONS, INACCURACIES, OR OTHER PROBLEMS WITH THIS INFORMATION. IF YOU RELY ON THE COMCAST WEB SERVICES OR ANY MATERIAL AVAILABLE THROUGH THEM, YOU DO SO AT YOUR OWN RISK. YOU UNDERSTAND THAT YOU ARE SOLELY RESPONSIBLE FOR ANY DAMAGE TO YOUR COMPUTER SYSTEM OR LOSS OF DATA THAT RESULTS FROM ANY MATERIAL AND/OR DATA DOWNLOADED FROM OR OTHERWISE PROVIDED THROUGH THE COMCAST WEB SERVICES.

THE COMCAST WEB SERVICES ARE PROVIDED TO YOU "AS IS," "WITH ALL FAULTS," AND "AS AVAILABLE." COMCAST AND ITS AGENTS AND LICENSORS CANNOT AND DO NOT WARRANT THE ACCURACY, COMPLETENESS, USEFULNESS, TIMELINESS, NONINFRINGEMENT, MERCHANTABILITY OR FITNESS FOR A PARTICULAR PURPOSE OF THE INFORMATION AVAILABLE THROUGH THE COMCAST WEB SERVICES, NOR DO THEY GUARANTEE THAT THE COMCAST WEB SERVICES WILL BE ERROR-FREE, OR CONTINUOUSLY AVAILABLE, OR THAT THE COMCAST WEB SERVICES WILL BE FREE OF VIRUSES OR OTHER HARMFUL COMPONENTS.

14. LIMITATION OF LIABILITY

UNDER NO CIRCUMSTANCES SHALL COMCAST (INCLUDING ITS PARENTS, SUBSIDIARIES, AND AFFILIATES) OR THEIR OFFICERS, DIRECTORS, AGENTS OR LICENSORS BE LIABLE TO YOU OR ANYONE ELSE FOR ANY DAMAGES ARISING OUT OF ANY USE OR MISUSE OF THE COMCAST WEB SERVICES, INCLUDING, WITHOUT LIMITATION, LIABILITY FOR CONSEQUENTIAL, SPECIAL, INCIDENTAL, INDIRECT, OR SIMILAR DAMAGES, EVEN IF ADVISED BEFOREHAND OF THE POSSIBILITY OF THESE DAMAGES, REGARDLESS OF THE FORM OR CAUSE OF ACTION INCLUDING, BUT NOT LIMITED TO, CONTRACT, NEGLIGENCE, AND OTHER TORT ACTIONS. BECAUSE SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF CERTAIN CATEGORIES OF DAMAGES, THE ABOVE LIMITATION MAY NOT APPLY TO YOU. IN THESE STATES, THE LIABILITY OF COMCAST AND ITS AGENTS AND LICENSORS IS LIMITED TO THE FULLEST EXTENT PERMITTED BY APPLICABLE STATE LAW. YOU AGREE THAT THE LIABILITY OF COMCAST (INCLUDING ITS PARENTS, SUBSIDIARIES, AND AFFILIATES) AND THEIR OFFICERS, DIRECTORS, AGENTS AND LICENSORS, IF ANY, ARISING OUT OF ANY KIND OF LEGAL CLAIM IN ANY WAY CONNECTED TO THE COMCAST WEB SERVICES SHALL NOT EXCEED THE AMOUNT YOU PAID TO COMCAST FOR THE USE OF THE COMCAST WEB SERVICES.

15. Indemnification

You agree to indemnify, defend, and hold harmless Comcast (including its parents, subsidiaries, and affiliates and all of their respective officers, directors, employees, agents, licensors, suppliers and any third-party information providers) against all claims, losses, expenses, damages and costs (including reasonable attorney fees) resulting from any breach of the Terms or use of the Comcast Web Services. Comcast reserves the right, at its election to assume the exclusive defense and control of any matter subject to indemnification by you and you agree to cooperate with Comcast in connection with our defense.

16. Copyright Infringement

Comcast is committed to complying with U.S. copyright and related laws, and requires all users of the Comcast Web Services to comply with these laws. Accordingly, you may not use the Comcast Web Services to store any material or content, or disseminate any material or content, in any manner that constitutes an infringement of third-party intellectual property rights, including rights granted by U.S. copyright law.

If you are the owner of any copyrighted work and believe your rights under U.S. copyright law have been infringed by any material on the Comcast Web Services, you may take advantage of certain provisions of the Digital Millennium Copyright Act (the "DMCA") by sending Comcast's authorized agent a notification of claimed infringement that satisfies the requirements of the DMCA. Upon Comcast's receipt of a satisfactory notice of claimed infringement, Comcast will respond expeditiously either directly or indirectly (i) to remove the allegedly infringing work(s) accessible through the Comcast Web Services or (ii) to disable access to the work(s). It is Comcast's policy in accordance with the DMCA and other applicable laws to reserve the right to terminate access to the Comcast Web Services (or any part of those services) for any user who is either found to infringe third-party copyright or other intellectual property rights, including repeat infringers, or who Comcast, in its sole discretion, believes is infringing these rights. Comcast may terminate access to the Comcast Web Services at any time with or without notice for any affected customer or user. If the affected user believes in good faith that the allegedly infringing works have been removed or blocked by mistake or misidentification, then that person may send a counter notification to Comcast. Upon Comcast's receipt of a counter notification that satisfies the requirements of DMCA, Comcast will provide a copy of the counter notification to the person who sent the original notification of claimed infringement and will follow the DMCA's procedures with respect to a received counter notification. In all events, you expressly agree that Comcast will not be a party to any disputes or lawsuits regarding alleged copyright infringement.

Copyright owners may send Comcast a notification of claimed infringement to report alleged infringements of their works to:

Comcast Cable Communications Management, LLC

Attn: General Counsel / Comcast Web Services DMCA Notice

One Comcast Center

Philadelphia, PA 19103

DMCA_Notice at Comcast dot com

1-888-565-4329

Any notification of claimed infringement must be in a form that satisfies the requirements of Section 512(c)(3) of the U.S. Copyright Act. Under the DMCA, anyone who knowingly makes misrepresentations regarding alleged copyright infringement may be liable to Comcast, the alleged infringer, and the affected copyright owner for any damages incurred in connection with the removal, blocking, or replacement of allegedly infringing material.

If a notification of claimed infringement has been filed against you, you can file a counter notification with Comcast's designated agent using the contact information shown above. All counter notifications must satisfy the requirements of Section 512(g)(3) of the U.S. Copyright Act.

17. Changes to the Terms

Comcast reserves the right to change these Terms from time to time. When these changes are made, Comcast will make a copy of the updated Terms available at this web page and will also make any updated Terms available to you by email, direct mail, or other reasonable means as selected by Comcast.

Comcast will make the updated Terms available to you before they take effect. You understand and agree that if you use the Comcast Web Services after the date on which the Terms take effect; Comcast will treat your use as acceptance of the updated Terms.

18. Trademarks

Comcast®, the Comcast design logo, XFINITY®, the XFINITY design logo, Plaxo®, and the Plaxo design logo are all trademarks or service marks of Comcast Corporation or its subsidiaries. All other trademarks and service marks appearing on the Comcast Web Services are the properties of their respective owners.

19. Special Note about Plaxo

Plaxo is not intended for use by, and should not be used by, children under the age of 13. You may not use www.plaxo.com if you are under the age of 13, or to solicit information from children under the age of 13.

20. Binding Arbitration

a. Purpose. If you are a subscriber to Xfinity TV, Xfinity Voice, XFINITY Home, and/or Xfinity Internet, please refer to the Binding Arbitration section of the Comcast Agreement for Residential Services, which section applies to any dispute, claim, or controversy between you and Comcast regarding any aspect of your relationship with Comcast, available here: http://www.comcast.com/Corporate/Customers/Policies/Policies.html. If you are not a subscriber to these services, and have a Dispute (as defined below) with Comcast that cannot be resolved through an informal dispute resolution with Comcast, you or Comcast may elect to arbitrate that Dispute in accordance with the terms of this section (the "Arbitration Provision") rather than litigate the Dispute in court. Arbitration means you will have a fair hearing before a neutral arbitrator instead of in a court by a judge or jury. Proceeding in arbitration may result in limited discovery and may be subject to limited review by courts.

b. Definitions. The term "Dispute" means any dispute, claim, or controversy between you and Comcast regarding the Comcast Web Services, whether based in contract, statute, regulation, ordinance, tort (including, but not limited to, fraud, misrepresentation, fraudulent inducement, negligence, or any other intentional tort), or any other legal or equitable theory, and includes the validity, enforceability or scope of this Arbitration Provision. "Dispute" is to be given the broadest possible meaning that will be enforced. As used in this Arbitration Provision, "Comcast" means Comcast and its parents, subsidiaries and affiliated companies and each of their respective officers, directors, employees and agents.

c. Right to Opt Out. IF YOU DO NOT WISH TO BE BOUND BY THIS ARBITRATION PROVISION, YOU MUST NOTIFY COMCAST IN WRITING WITHIN 30 DAYS OF THE LATER OF YOUR FIRST ACCESS TO OR USE OF THE COMCAST WEB SERVICES, OR APRIL 5, 2013, BY VISITING WWW.COMCAST.COM/WEBARBOPTOUT, OR BY MAIL TO COMCAST 1701 JOHN F. KENNEDY BLVD., PHILADELPHIA, PA 19103-2838, ATTN: LEGAL DEPARTMENT/ARBITRATION. YOUR WRITTEN NOTIFICATION TO COMCAST MUST INCLUDE YOUR NAME, ADDRESS AND ACCOUNT NUMBER (IF YOU ARE A COMCAST SUBSCRIBER) OR TELEPHONE NUMBER (IF YOU ARE NOT A COMCAST SUBSCRIBER) AS WELL AS A CLEAR STATEMENT THAT YOU DO NOT WISH TO RESOLVE DISPUTES WITH COMCAST THROUGH ARBITRATION. YOUR DECISION TO OPT OUT OF THIS ARBITRATION PROVISION WILL HAVE NO ADVERSE EFFECT ON YOUR RELATIONSHIP WITH COMCAST OR THE DELIVERY OF SERVICES TO YOU BY COMCAST. IF YOU HAVE PREVIOUSLY NOTIFIED COMCAST OF YOUR DECISION TO OPT OUT OF ARBITRATION, YOU DO NOT NEED TO DO SO AGAIN.

d. Initiation of Arbitration Proceeding/Selection of Arbitrator. If you or Comcast elect to resolve your Dispute through arbitration pursuant to this Arbitration Provision, the party initiating the arbitration proceeding may open a case with the American Arbitration Association - Case Filing Services, 1101 Laurel Oak Road, Suite 100, Voorhees, NJ 08043, 877-493-4185, www.adr.org under the Commercial Arbitration Rules of the American Arbitration Association "AAA".

e. Arbitration Procedures. Because the Comcast Web Services concern interstate commerce, the Federal Arbitration Act ("FAA"), not state arbitration law, shall govern the arbitrability of all Disputes. However, applicable federal law or the law of the state where you access the Comcast Web Services may apply to and govern the substance of any Disputes. No state statutes pertaining to arbitration shall be applicable under this Arbitration Provision.
If there is a conflict between this Arbitration Provision and the rules of the arbitration organization, this Arbitration Provision shall govern. If the AAA will not enforce this Arbitration Provision as written, it cannot serve as the arbitration organization to resolve your dispute with Comcast. If this situation arises, the parties shall agree on a substitute arbitration organization. If the parties are unable to agree, the parties shall mutually petition a court of appropriate jurisdiction to appoint an arbitration organization that will enforce this Arbitration Provision as written. If there is a conflict between this Arbitration Provision and the rest of these Terms, this Arbitration Provision shall govern. A single arbitrator will resolve the Dispute. The arbitrator will honor claims of privilege recognized by law and will take reasonable steps to protect customer account information and other confidential or proprietary information. The arbitrator will make any award in writing but need not provide a statement of reasons unless requested by a party. An award rendered by the arbitrator may be entered in any court having jurisdiction over the parties for purposes of enforcement. If an award granted by the arbitrator exceeds $75,000, either party can appeal that award to a three-arbitrator panel administered by the same arbitration organization by a written notice of appeal filed within 30 days from the date of entry of the written arbitration award. The members of the three-arbitrator panel will be selected according to the rules of the arbitration organization. The arbitration organization will then notify the other party that the award has been appealed. The three-arbitrator panel will issue its decision within 120 days of the date of the appealing party's notice of appeal. The decision of the three-arbitrator panel shall be final and binding, except for any appellate right which exists under the FAA.

f. Restrictions:
1. YOU MUST CONTACT US WITHIN 1 YEAR OF THE DATE OF THE OCCURRENCE OF THE EVENT OR FACTS GIVING RISE TO A DISPUTE, OR YOU WAIVE THE RIGHT TO PURSUE ANY CLAIM BASED UPON SUCH EVENT, FACTS, OR DISPUTE.
2. ALL PARTIES TO THE ARBITRATION MUST BE INDIVIDUALLY NAMED. THERE SHALL BE NO RIGHT OR AUTHORITY FOR ANY CLAIMS TO BE ARBITRATED OR LITIGATED ON A CLASS ACTION OR CONSOLIDATED BASIS OR ON BASES INVOLVING CLAIMS BROUGHT IN A PURPORTED REPRESENTATIVE CAPACITY ON BEHALF OF THE GENERAL PUBLIC (SUCH AS A PRIVATE ATTORNEY GENERAL), OTHER SUBSCRIBERS, OR OTHER PERSONS

g. Location of Arbitration. The arbitration will take place at a location convenient to you in the area where you access the Comcast Web Services.

h. Payment of Arbitration Fees and Costs. COMCAST WILL ADVANCE ALL ARBITRATION FILING FEES AND ARBITRATOR'S COSTS AND EXPENSES UPON YOUR WRITTEN REQUEST GIVEN PRIOR TO THE COMMENCEMENT OF THE ARBITRATION. YOU ARE RESPONSIBLE FOR ALL ADDITIONAL COSTS THAT YOU INCUR IN THE ARBITRATION, INCLUDING, BUT NOT LIMITED TO, FEES FOR ATTORNEYS OR EXPERT WITNESSES. IF THE ARBITRATION PROCEEDING IS DECIDED IN COMCAST'S FAVOR, YOU SHALL REIMBURSE COMCAST FOR THE FEES AND COSTS ADVANCED TO YOU ONLY UP TO THE EXTENT AWARDABLE IN A JUDICIAL PROCEEDING. IF THE ARBITRATION PROCEEDING IS DETERMINED IN YOUR FAVOR, YOU WILL NOT BE REQUIRED TO REIMBURSE COMCAST FOR ANY OF THE FEES AND COSTS ADVANCED BY COMCAST. IF A PARTY ELECTS TO APPEAL AN AWARD TO A THREE-ARBITRATOR PANEL, THE PREVAILING PARTY IN THE APPEAL SHALL BE ENTITLED TO RECOVER ALL REASONABLE ATTORNEYS' FEES AND COSTS INCURRED IN THAT APPEAL. NOTWITHSTANDING ANYTHING TO THE CONTRARY IN THIS ARBITRATION PROVISION, COMCAST WILL PAY ALL FEES AND COSTS THAT IT IS REQUIRED BY LAW TO PAY.

i. Severability. If any clause within this Arbitration Provision is found to be illegal or unenforceable, that clause will be severed from this Arbitration Provision, and the remainder of this Arbitration Provision will be given full force and effect. If the class action waiver clause is found to be illegal or unenforceable, the entire Arbitration Provision will be unenforceable, and the dispute will be decided by a court. If this entire Arbitration Provision is determined to be illegal or unenforceable for any reason, or if a claim is brought in a Dispute that is found by a court to be excluded from the scope of this Arbitration Provision, you and Comcast have each agreed to waive, to the fullest extent allowed by law, any trial by jury.

j. Exclusions from Arbitration. YOU AND COMCAST AGREE THAT THE FOLLOWING WILL NOT BE SUBJECT TO ARBITRATION: (1) ANY CLAIM FILED BY YOU OR BY COMCAST THAT IS NOT AGGREGATED WITH THE CLAIM OF ANY OTHER SUBSCRIBER OR COMCAST WEB SERVICES USER AND WHOSE AMOUNT IN CONTROVERSY IS PROPERLY WITHIN THE JURISDICTION OF A COURT THAT IS LIMITED TO ADJUDICATING SMALL CLAIMS; (2) ANY DISPUTE OVER THE VALIDITY OF ANY PARTY'S INTELLECTUAL PROPERTY RIGHTS; (3) ANY DISPUTE RELATED TO OR ARISING FROM ALLEGATIONS ASSOCIATED WITH UNAUTHORIZED USE OR RECEIPT OF COMCAST WEB SERVICES; (4) ANY DISPUTE THAT ARISES BETWEEN COMCAST AND ANY STATE OR LOCAL REGULATORY AUTHORITY OR AGENCY THAT IS EMPOWERED BY FEDERAL, STATE, OR LOCAL LAW TO GRANT A FRANCHISE UNDER 47 U.S.C. § 522(9); AND (5) ANY DISPUTE THAT CAN ONLY BE BROUGHT BEFORE THE LOCAL FRANCHISE AUTHORITY UNDER THE TERMS OF THE FRANCHISE.

k. Continuation. This Arbitration Provision will survive the termination or expiration of these Terms.

21. General Legal Terms

The Terms constitute the whole legal agreement between you and Comcast and govern your use of the Comcast Web Services, and completely replace any prior agreements between you and Comcast in relation to the Comcast Web Services.

Nothing in these Terms shall be construed to limit Comcast's rights and remedies available at law or in equity. Upon termination of these Terms for any reason, Comcast and its suppliers reserve the right to delete all your data, files, electronic messages, or other information that is stored on Comcast's or its suppliers' servers or systems. Comcast shall have no liability whatsoever as the result of the loss of any such data.

You agree that Comcast may provide you with notices, including those regarding changes to the Terms, by email, regular mail, or postings on the Comcast Web Services.

You agree that if Comcast does not exercise or enforce any legal right or remedy which is contained in the Terms (or which Comcast has the benefit of under any applicable law), this will not be taken to be a formal waiver of Comcast's rights and that those rights or remedies will still be available to Comcast.

If any court of law, having the jurisdiction to decide on this matter, rules that any provision of these Terms is invalid, then that provision will be removed from the Terms without affecting the rest of the Terms. The remaining provisions of the Terms will continue to be valid and enforceable.

You acknowledge and agree that each member of the group of companies of which Comcast Corporation is the parent shall be third-party beneficiaries to the Terms and that these other companies shall be entitled to directly enforce, and rely upon, any provision of the Terms which confers a benefit on (or rights in favor of) them. Other than this, no other person or entity shall be third-party beneficiaries to the Terms.

The Terms, and your relationship with Comcast under the Terms, shall be governed by the laws of the Commonwealth of Pennsylvania, without regard to its conflict of laws provisions. By using the Comcast Web Services, you consent to the exclusive jurisdiction of the state and federal courts in Philadelphia, Pennsylvania, in all disputes arising out of or relating to the Terms or Comcast Web Services.

22. Special Note About Content Provided as Part of Your XFINITY TV Subscription.

If you are a residential subscriber to XFINITY TV and XFINITY Internet, you may be entitled to use your Internet connection to access certain video content that is related to your XFINITY TV subscription in addition to the content that is generally available on the Comcast Sites. For example, if you subscribe to HBO as part of your XFINITY TV subscription, in addition to the content that is generally available on the Comcast Sites, you may be entitled to access HBO content on the Comcast Sites as well. This additional video content is intended to be used as a complement to your XFINITY TV subscription, and therefore should only be viewed by members of the residence at which you have an XFINITY TV subscription and others who you have invited to view the content without charge of a fee or other consideration. This specifically excludes any public presentation (e.g., a presentation in a dorm lounge) and any presentation by a place of public accommodation or other commercial establishment (e.g., a bar or restaurant), even if no fee is charged. You may not simultaneously view more than three video streams of this additional content per residence at which you already have an XFINITY TV subscription.

23. Special Note about XFINITY Wi-Fi for Users who are not XFINITY Internet Subscribers.

If you are not a residential subscriber to XFINITY Internet, the following applies to your use of XFINITY Wi-Fi ("Wi-Fi Service"):

Using the Wi-Fi Service

In order to access and use the Wi-Fi Service, you must:

  • provide Comcast with accurate and complete registration information;

  • have a wireless-enabled device (compliant with the IEEE 802.11g or n standards, and or any later standard we support) with a web browser or its equivalent;

  • provide all equipment and software necessary to connect to the Wi-Fi Service (other than the access point provided by Comcast);

  • protect the password, username and security information you use to access the Wi-Fi Service and notify Comcast immediately of any unauthorized use of your account that you become aware of,

  • comply with applicable laws and regulations, including but not limited to copyright and intellectual property rights laws, and

  • be at least 18 years of age. If you are not a subscriber to the XFINITY Internet Performance Tier or above, you can generally use XFINITY Wi-Fi for up to two hours without having to sign in again. Certain locations ("Venues") may offer you free use of Xfinity Wi-Fi ("Amenity Wi-Fi"). Your use of amenity Wi-Fi is subject to these Terms and any other terms and conditions made available by the Venue ("Venue Policies"). Comcast is not responsible for the Venue Policies or the actions of the Venue. You should read the Venue Policies before using Amenity Wi-Fi. After 20 minutes of inactivity, you’ll be automatically logged off. If you pay to access the Wi-Fi Service on a pay-per-use ("PPU") basis, these Terms incorporate the payment and support terms presented as part of the PPU sign in and payment process as described at http://www.comcast.com/wifi/trial.htm.

Whenever you log in to the Wi-Fi Service, we help protect your privacy and the safety of your login ID and password by providing 128-bit encryption on the sign-in page. This is the same standard used by thousands of online banking and financial services sites around the world to protect your critical transactions. When online with any Wi-Fi service, remember that Wi-Fi is not an inherently secure technology and that wireless communications can be intercepted. For more information on your security options, please see the Security Tips for Comcast Wi-Fi at http://customer.xfinity.com/help-and-support/internet/wifi-security/.In addition to the online resources at http://wifi.xfinity.com, Comcast provides limited telephone support for this Service, available at 1-800-XFINITY.

Termination

Comcast reserves the right at any time to terminate your use of the Wi-Fi Service if you fail to comply in full with any term of these Terms, or any other terms, agreements, or policies that apply to this Wi-Fi Service and the use of it. If you paid to access the Wi-Fi Service on PPU (pay per use) basis, you may contact Comcast by phone at 1-866-366-5756 to terminate the Wi-Fi Service.

Restrictions on Use

You will not use the Wi-Fi Service to do any of the following:

  • falsify, alter, or remove message headers;
  • falsify references to Comcast or its network, by name or other identifier, in messages;
  • violate the rules, regulations, terms of service, or policies applicable to any network, server, computer database, service, application, system, or web site that you access or use;
  • access any other person's computer or computer system, network, software, or data without his or her knowledge and consent; breach the security of another user or system; or attempt to circumvent the user authentication or security of any host, network, or account. This includes, but is not limited to, accessing data not intended for you, logging into or making use of a server or account you are not expressly authorized to access, or probing the security of other hosts, networks, or accounts without express permission to do so;
  • use or distribute tools or devices designed or used for compromising security or whose use is otherwise unauthorized, such as password guessing programs, decoders, password gatherers, keystroke loggers, analyzers, cracking tools, packet sniffers, encryption circumvention devices, or Trojan Horse programs. Unauthorized port scanning is strictly prohibited;
  • copy, distribute, or sublicense any proprietary software provided in connection with the Wi-Fi Service by Comcast or any third party, except that you may make one copy of each software program for back-up purposes only;
  • distribute programs that make unauthorized changes to software (cracks);
  • use or run dedicated, stand-alone equipment or servers, also commonly referred to as public services or servers. Examples of prohibited equipment and servers include, but are not limited to, email, web hosting, file sharing, and proxy services and servers;
  • use or run programs that provide network content or any other services, except for personal and non-commercial use;
  • service, alter, modify, or tamper with any Comcast equipment or service or permit any other person who is not authorized by Comcast to do so;
  • use the Wi-Fi Service for operation as an Internet service provider or for any business, other legal entity, or organization purpose (whether or not for profit);
  • resell or otherwise make available the Wi-Fi Service, in whole or in part, directly or indirectly;
  • interfere with computer networking or telecommunications service to any user, host or network, including, without limitation, denial of service attacks, flooding of a network, overloading a service, improper seizing and abusing operator privileges, and attempts to "crash" a host;
  • falsify, alter, spoof, or otherwise modify or change any IP or MAC address assigned to or associated with your device to access the Wi-Fi Service; or
  • access and use the Wi-Fi Service with anything other than a dynamic IP address that adheres to the dynamic host configuration protocol ("DHCP"). You may not configure your device to use this Wi-Fi Service or any related equipment to access or use a static IP address or use any protocol other than DHCP or for any unlawful purpose.

24. Special Note about Comcast Email for Users who are not XFINITY Internet Subscribers.

If you are not a subscriber to our residential XFINITY Internet or XFINITY Voice service, the following applies to your use of a Comcast-provided email address such as yourname@comcast.net ("Email Service"):

Modifications, Suspension, and Termination

You understand that, subject to applicable law, Comcast has the right to modify or discontinue the Email Service at any time with or without notice to you. If we do give you notice, it may be provided on any of the Comcast Services, or via email, newspaper, or any other communication permitted under applicable law. You understand that Comcast may suspend or terminate your access to the Email Service for any suspected or actual violation of these Terms. In addition, you understand that Comcast may suspend or terminate your access to the Email Service if you have not used the Email Service at least once within a nine-month period. If Comcast suspends or terminates your Email Service, your email will be deleted without the ability to be recovered.

Acceptable Use and Network Management

You will not use the Email Service to communicate or distribute email or other forms of communications in violation of these Terms. As described in Section III of our Acceptable Use for XFINITY Internet policy, Comcast uses reasonable network management tools and techniques to protect customers from receiving spam and from sending spam (often without their knowledge over an infected computer). Comcast's anti-spam approach is explained in the FAQs under the topic "What is Comcast doing about spam?" located here.

Comcast is not responsible for deleting or forwarding any email sent to the wrong email address by you or by someone else trying to send email to you. Comcast is also not responsible for forwarding email sent to any Email Service account that has been suspended or terminated. This email will be returned to the sender, ignored, deleted, or stored temporarily at Comcast's sole discretion. If you cancel or terminate your Email Service account for any reason, all email associated with that account (and any secondary accounts) will be permanently deleted as well.

If Comcast believes in its sole discretion that any subscriber name, account name, or email address (collectively, an "Identifier") on the Email Service may be used for, or is being used for, any misleading, fraudulent, or other improper or illegal purpose, Comcast (i) reserves the right to block access to and prevent the use of any of these Identifiers and (ii) may at any time require any customer to change his or her Identifier. In addition, Comcast may at any time reserve any identifiers on the Email Service for its own purposes.

Revised and Effective: April 12, 2016



Elyssa D. Durant
Policy & Research Analyst

Thursday, February 14, 2019

Tweet by Palm Bitch 🐧 on Twitter

Palm Bitch 🐧 (@PalmBitchin)
⁦‪@SLATUKIP‬⁩ In a civilized society, we have an obligation to take care of the weakest among us.

We don't ask for disabling health condition. We must all pay into the system to achieve "community ratings"

Some people will always need more resources. We aren't born equally. Some need more pic.twitter.com/Bknbn6SC63


Wednesday, February 13, 2019

U.S. Cyberweapons, Used Against Iran and North Korea, Are a Disappointment Against ISIS - The New York Times

U.S. Cyberweapons, Used Against Iran and North Korea, Are a Disappointment Against ISIS - The New York Times
If at first you don't succeed try try again. 



U.S. Cyberweapons, Used Against Iran and North Korea, Are a Disappointment Against ISIS

National Security Agency headquarters in Fort Meade, Md. Operation Glowing Symphony, launched against the Islamic State, was initially deemed a success because battlefield videos disappeared, but the results were temporary.Jim Lo Scalzo/European Pressphoto Agency

National Security Agency headquarters in Fort Meade, Md. Operation Glowing Symphony, launched against the Islamic State, was initially deemed a success because battlefield videos disappeared, but the results were temporary.Jim Lo Scalzo/European Pressphoto Agency

WASHINGTON — America's fast-growing ranks of secret cyberwarriors have in recent years blown up nuclear centrifuges in Iran and turned to computer code and electronic warfare to sabotage North Korea's missile launches, with mixed results.

But since they began training their arsenal of cyberweapons on a more elusive target, internet use by the Islamic State, the results have been a consistent disappointment, American officials say. The effectiveness of the nation's arsenal of cyberweapons hit its limits, they have discovered, against an enemy that exploits the internet largely to recruit, spread propaganda and use encrypted communications, all of which can be quickly reconstituted after American "mission teams" freeze their computers or manipulate their data.

It has been more than a year since the Pentagon announced that it was opening a new line of combat against the Islamic State, directing Cyber Command, then six years old, to mount computer-network attacks. The mission was clear: Disrupt the ability of the Islamic State to spread its message, attract new adherents, pay fighters and circulate orders from commanders.

But in the aftermath of the recent attacks in Britain and Iran claimed by the Islamic State, it has become clear that recruitment efforts and communications hubs reappear almost as quickly as they are torn down. This is prompting officials to rethink how cyberwarfare techniques, first designed for fixed targets like nuclear facilities, must be refashioned to fight terrorist groups that are becoming more adept at turning the web into a weapon.

"In general, there was some sense of disappointment in the overall ability for cyberoperations to land a major blow against ISIS," or the Islamic State, said Joshua Geltzer, who was the senior director for counterterrorism at the National Security Council until March. "This is just much harder in practice than people think. It's almost never as cool as getting into a system and thinking you'll see things disappear for good."

Even one of the rare successes against the Islamic State belongs at least in part to Israel, which was America's partner in the attacks against Iran's nuclear facilities. Top Israeli cyberoperators penetrated a small cell of extremist bombmakers in Syria months ago, the officials said. That was how the United States learned that the terrorist group was working to make explosives that fooled airport X-ray machines and other screening by looking exactly like batteries for laptop computers.

Adm. Michael S. Rogers, right, at a Senate hearing in January. The Obama administration's frustration with the lack of success against the Islamic State was one factor in its effort to oust him as director of the N.S.A., several former administration officials said.Stephen Crowley/The New York Times

Adm. Michael S. Rogers, right, at a Senate hearing in January. The Obama administration's frustration with the lack of success against the Islamic State was one factor in its effort to oust him as director of the N.S.A., several former administration officials said.Stephen Crowley/The New York Times

The intelligence was so exquisite that it enabled the United States to understand how the weapons could be detonated, according to two American officials familiar with the operation. The information helped prompt a ban in March on large electronic devices in carry-on luggage on flights from 10 airports in eight Muslim-majority countries to the United States and Britain.

It was also part of the classified intelligence that President Trump is accused of revealing when he met in the Oval Office last month with the Russian foreign minister, Sergey V. Lavrov, and the ambassador to the United States, Sergey I. Kislyak. His disclosure infuriated Israeli officials.

The Islamic State's agenda and tactics make it a particularly tough foe for cyberwarfare. The jihadists use computers and social media not to develop or launch weapons systems but to recruit, raise money and coordinate future attacks.

Such activity is not tied to a single place, as Iran's centrifuges were, and the militants can take advantage of remarkably advanced, low-cost encryption technologies. The Islamic State, officials said, has made tremendous use of Telegram, an encrypted messaging system developed largely in Germany.

The most sophisticated offensive cyberoperation the United States has conducted against the Islamic State sought to sabotage the group's online videos and propaganda beginning in November, according to American officials.

In the endeavor, called Operation Glowing Symphony, the National Security Agency and its military cousin, United States Cyber Command, obtained the passwords of several Islamic State administrator accounts and used them to block out fighters and delete content. It was initially deemed a success because battlefield videos disappeared.

A Predator drone at an air base in the Persian Gulf last year. The base is used to launch drone strikes against the Islamic State in Iraq and Syria.John Moore/Getty Images

A Predator drone at an air base in the Persian Gulf last year. The base is used to launch drone strikes against the Islamic State in Iraq and Syria.John Moore/Getty Images

But the results were only temporary. American officials later discovered that the material had been either restored or moved to other servers. That setback was first reported by The Washington Post.

The experience did not surprise veteran cyberoperators, who have learned, through hard experience, that cyberweapons buy time but rarely are a permanent solution. The attacks on Iran's Natanz nuclear facility, begun in the George W. Bush administration and code-named Olympic Games, destroyed roughly 1,000 centrifuges and set back the Iranians by a year or so — the amount of time is still hotly disputed. But it created some room for a diplomatic negotiation.

The attacks on North Korea's missile program, which President Barack Obama accelerated in 2014, were followed by a remarkable series of missile failures that Mr. Trump noted in a conversation, which leaked recently, with the president of the Philippines. But recent evidence suggests that the North, using a different kind of missile, has overcome at least some of the problems.

The shortcomings of Glowing Symphony illustrated the challenges confronting the government as it seeks to cripple the Islamic State in cyberspace.

The disruptions often require fighters to move to less secure communications, making them more vulnerable. Yet because the Islamic State fighters are so mobile, and their equipment relatively commonplace, reconstituting communications and putting material up on new servers are not difficult. Some of it has been encrypted and stored in the cloud, according to intelligence officials, meaning it can be downloaded in a new place.

"There were folks working hard on this stuff, and there were some accomplishments that had an impact, but there was no steady stream of jaw-dropping stuff coming forward as some expected," said Mr. Geltzer, who now teaches law at Georgetown University Law Center. "There was no sort of shining cybertool."

The Obama administration's frustration with the lack of success against the Islamic State was one factor in its effort to oust Adm. Michael S. Rogers, the director of the N.S.A. and the commander of Cyber Command, according to several former administration officials. They complained that the organizations were too focused on traditional espionage and highly sophisticated efforts to use networks to blow up or incapacitate adversary facilities, like those in Iran and North Korea.

The former defense secretary Ashton B. Carter traveled to Admiral Rogers's headquarters in Fort Meade, Md., on several occasions, the officials said, to voice his displeasure at the slow pace of the effort and to stoke new initiatives, like Glowing Symphony.

Obama administration officials backed off around the time that President-elect Trump appeared to be considering Admiral Rogers, who had run the Navy's Fleet Cyber Command operations, as director of national intelligence — and the Trump administration appears to have embraced him.

But the fundamental problem of how to use cybertechniques effectively against the Islamic State remains.

That was evident in the frustration voiced by Prime Minister Theresa May of Britain after the recent attack on London Bridge and in nearby restaurants. She focused on how the internet creates "a safe space" for radical ideology, and said that "the big companies that provide internet-based services" would have to join the fight more fully.

They already police for gruesome videos and overt recruitment, and a former N.S.A. official noted recently that Cyber Command was also highly attuned to taking down anything that seemed to celebrate the deaths of Americans or other Westerners.

A photo released by North Korea in May purported to show the test firing of a ballistic missile in North Korea. The United States has used computer code and electronic warfare to sabotage North Korea's missile launches.Korean Central News Agency, via Agence France-Presse — Getty Images

A photo released by North Korea in May purported to show the test firing of a ballistic missile in North Korea. The United States has used computer code and electronic warfare to sabotage North Korea's missile launches.Korean Central News Agency, via Agence France-Presse — Getty Images

But in the United States, any crackdown is likely to run headlong into First Amendment issues, where the advocacy of an ideology, short of direct incitement to violence, is protected speech.

American officials say that even with the loss of territory in Syria and Iraq, and a broad military effort to disrupt the Islamic State's activities, the militants have proved remarkably resilient.

"The global reach of ISIS right now is largely intact," Nicholas Rasmussen, the director of the National Counterterrorism Center, said in a speech in Washington last month. "The group also continues to publish thousands of pieces of official propaganda and to use online apps to organize its supporters and inspire attacks."

Mr. Rasmussen's assessment came a year after some of the best of the newly created cyber mission teams joined more traditional military units in the fight. The teams are the cyber equivalent of Special Forces teams, dispatched around the world to work on defending Pentagon networks or launching cyberattacks in coordination with more traditional operations.

Cyberoperations are also closely integrated with Iraqi ground combat and allied air missions to maximize the impact on Islamic State fighters hunkered down in the extremist group's two major strongholds: Mosul, Iraq, and Raqqa, Syria.

"We're able to either blind them so they can't see or make sure they can't hear us," Lt. Gen. Jeffrey L. Harrigian, the allied air commander, said in an interview at his headquarters in Qatar in December. "There are things we are doing both with space and cyber that are being effectively synchronized to achieve important effects even in Mosul and Raqqa."

Lt. Gen. Sean MacFarland, who was the top American military commander in Iraq until August, said specialists at Cyber Command had assisted his troops in "disrupting enemy command and control during our offensive operations, and that support improved over the time I was in command."

Other senior military officials said the number and quality of tools in the United States' cyberarsenal against the Islamic State had expanded over the past year. Some of the effects are employed repeatedly over days. Locking Islamic State propaganda specialists out of their accounts — or using the coordinates of their phones and computers to target them for a drone attack — is now standard operating procedure.

General Harrigian said allied countries were also employing cyberweapons and techniques against the Islamic State that the United States did not. Without identifying specific countries or skills, he said the allies "can do things we can't do — some cyberactivities that they have authorities to execute that we do not."

A version of this article appears in print on , on Page A5 of the New York edition with the headline: Digital Weapons That Worked in Iran Miss Mark Against ISIS, Officials Say. Order Reprints | Today's Paper | Subscribe

You have 1 article left. Create an account or log in to get more.

You have 1 article left. Create an account or log in to get more.



Elyssa D. Durant 
Research & Policy Analyst

Friday, January 25, 2019

Remote Code Execution via XMeye P2P Cloud in Xiongmai IP Cameras, NVRs and DVRs

Remote Code Execution via XMeye P2P Cloud in Xiongmai IP Cameras, NVRs and DVRs

Remote Code Execution via XMeye P2P Cloud in Xiongmai IP Cameras, NVRs and DVRs

SEC Consult also published a blog post regarding the identified security issues with further background information: 
"Xiong-who?! And Why We Care"


Vendor description

"Hangzhou Xiongmai Technology Co., Ltd concentrates on security surveillance, Video intelligent research and development. We devote ourselves to providing good products, technical services for manufacturers, wholesaler and service provider, in order to offer better experience for our customers.  We are global leading providers in security video products and technology. Established from 2009, many years development, the headquarter of XM locate in Yinhu Innovation Center, Fuyang district, Hangzhou now. Total registered capital reach to 60 million.
Now we owns nearly 2000 employees including a strong R&D team (more than 300 experienced engineers)."

Source: http://www.xiongmaitech.com/en/index.php/about/company/18

Business recommendation

SEC Consult has identified highly critical vulnerabilities in Xiongmai products and the "XMeye P2P Cloud" feature which is being used in many 3rd party OEM devices as well.

The vendor does not provide proper mitigations and hence it is recommended not to use any products associated with the XMeye P2P Cloud until all of the identified security issues have been fixed and a thorough security analysis has been performed by professionals.

Vulnerability overview/description

1) Predictable XMEye Cloud IDs (CVE-2018-17915)

All Xiongmai devices come with a feature called "XMeye P2P Cloud". It is a proprietary, UDP-based protocol that allows users to access their IP cameras or NVRs/DVRs via the internet. The feature is enabled by default, no setup by the user is required.

The device initiates and keeps a connection to a Xiongmai cloud server. All connections between clients and the devices are established via Xiongmai cloud servers. This approach allows users to connect to devices that are behind firewalls, NATed etc.

The unique, per-device identifier is the cloud ID. It is a 16 character long hexadecimal string (e.g. f7e708f21de0fde0). Anyone who knows the device identifier and the admin credentials can establish a connection to a device using the XMEye apps (Android, iOS) or a "VMS" desktop application.

The Cloud ID may be unique, but it is not random. It is derived (at boot time) from the device MAC address using a few simple operations (see get_sn_from_mac()) below.

An attacker can enumerate potential MACs/cloud IDs and find valid ones. Then use the weak default credentials to log in. This allows the attacker to watch the video feed, change the device configuration and possibly gain remote code execution using other vulnerabilities. The XMEye functionality allows an attacker to attack devices that are behind firewalls, NATed networks etc.

MAC addresses have a well defined structure: 3-octet OUI (Vendor) + 3-octet NIC ID OUIs are assigned by the IEEE. Interestingly Xiongmai does not own an OUI, but instead uses the OUIs of other companies.

The following OUIs are used by Xiongmai devices (OUIs based on internet research, scanning, company names based on https://regauth.standards.ieee.org/standards-ra-web/pub/view.html#registries):

001210 WideRay Corp  001211 Protechna Herbst GmbH & Co. KG  001212 PLUS Corporation  001213 Metrohm AG  001214 Koenig & Bauer AG  001215 iStor Networks, Inc.  001216 ICP Internet Communication Payment AG  001217 Cisco-Linksys, LLC  001218 ARUZE Corporation  003E0B - Not assigned  

We developed a cloud ID scanner that queries the Xiongmai cloud server. The responses indicate if there is a device online that uses the given cloud ID, plus provide the IP of a Xiongmai Cloud hop server that is geographically close to the device. One query is one UDP packet.

We scanned 0.02% of the devices (random choice) in each OUI range (16 Million devices per range) and extrapolated the results.

OUI: 001210; IDs checked 3,365;  Devices online 3; Success rate: 0.1%; extrapolated devices online: 14,957  OUI: 001211; IDs checked 3,363;  Devices online 9; Success rate: 0.3%; extrapolated devices online: 44,898  OUI: 001212; IDs checked 3,351;  Devices online 492; Success rate: 14.7%; extrapolated devices online: 2,463,261  OUI: 001213; IDs checked 3,402;  Devices online 218; Success rate: 6.4%; extrapolated devices online: 1,075,083  OUI: 001214; IDs checked 3,440;  Devices online 67; Success rate: 1.9%; extrapolated devices online: 326,765  OUI: 001215; IDs checked 3,347;  Devices online 255; Success rate: 7.6%; extrapolated devices online: 1,278,216  OUI: 001216; IDs checked 3,377;  Devices online 448; Success rate: 13.3%; extrapolated devices online: 2,225,701  OUI: 001217; IDs checked 3,315;  Devices online 286; Success rate: 8.6%; extrapolated devices online: 1,447,446  OUI: 001218; IDs checked 3,196;  Devices online 1; Success rate: 0.0%; extrapolated devices online: 5,249  OUI: 003E0B; IDs checked 4,224;  Devices online 21; Success rate: 0.5%; extrapolated devices online: 83,409  

We estimate that there are about 9 Million devices online in the given OUI ranges.

The responses from the cloud server allow us to estimate the geographic distribution of the devices:

Hop server location: CN; extrapolated devices 5,438,757  Hop server location: DE; extrapolated devices 1,319,845  Hop server location: JP; extrapolated devices 577,743  Hop server location: SG; extrapolated devices 697,276  Hop server location: TR; extrapolated devices 189,260  Hop server location: US; extrapolated devices 742,101  

We assume the hop server locations serve devices on the same continent.

2) Default admin password

The devices include an empty password for the admin user account which has the highest privileges on the devices and allows attackers to view the video feed or change the configuration.

3) Insecure default credentials for user "default" (CVE-2018-17919)

In the default configuration, the user account "default" exists on the device. The purpose of this user is not documented.

These user credentials can be used to log in to a device via the XMEye cloud (checked via custom client using the Xiongmai NetSDK).

This user seems to at least have permissions to access video feeds (more investigation required!).

4) Multiple unencrypted communication channels (CVE-2018-1791

All device communication is not encrypted. This includes the XMeye service and firmware update communication.

  • An attacker can eavesdrop on video feeds or steal XMeye login credentials to get control over the device.
  • An attacker can also impersonate the update server and offer malicious firmware updates.

5) Firmware update integrity not checked

Firmware updates are not signed. It is possible to create a firmware update file that contains malicious code (CWE-494). This is either possible by modifying the filesystems contained in a firmware update or modifying the "InstallDesc" file in a firmware update file. The "InstallDesc" is a text file that contains commands that are executed during the update.


Combining the vulnerabilities makes a very powerful attack, "The worst case scenario":

  1. Attacker exploits Predictable XMEye Cloud IDs to get list of valid IDs.
  2. Attacker exploits Insecure default credentials for user "admin" and possibly user "default", to get access to devices via the XMEye cloud.
  3. Attacker changes the DNS configuration of the devices to impersonate the update server "upgrade.secu100.net".
  4. Attacker sets up fake firmware update webserver.
  5. Attacker creates firmware updates containing malicious code. Imagination is the limit here, could be a Mirai-like agent or something focused on lateral movement in the target environment (local network of the organization using the devices).
  6. Attacker performs a firmware update on devices via the XMEye cloud API command H264_DVR_Upgrade_Cloud()(custom client using the Xiongmai NetSDK). The malicious firmware update is persisted on the devices. If the attacker desires, it cannot be removed by rebooting the device.

Proof of concept

1) Predictable XMEye Cloud IDs (CVE-2018-17915)

The Python code to derive the cloud ID from the MAC address of the device has been removed from this advisory.

2) Default admin password

The default username and password is admin:[BLANK].

3) Insecure default credentials for user "default" (CVE-2018-17919)

The credentials for the hardcoded user "default" are "tluafed"

4) Multiple unencrypted communication channels (CVE-2018-17917)

No proof of concept available for this advisory.

5) Firmware update integrity not checked

The following "InstallDesc" contents would launch an arbitrary command, in this case starting the telnet daemon.

   "UpgradeCommand" : [        {           "Command" : "Shell",           "Script" : "/bin/busybox telnetd"        },  

Vulnerable / tested versions

Xiongmai acts as an OEM. Various vendors sell branded devices with Xiongmai hardware/firmware inside. More information can be found in the blog post: "Xiong-Who?! And Why We Care"

Vendor contact timeline

2018-03-15:Contacting ICS-CERT for coordination support.
2018-03-26:ICS-CERT assigns ICS-VU-638768 for this case.
2018-05-04:ICS-CERT provides answer from Xiongmai, the vendor argues that SEC Consult tested the "old" firmware/devices. Furthermore, per default user passwords need to be changed upon first login since 2016. They informed their key customers to update to the latest firmware & change default passwords.
2018-05-07SEC Consult anwser: we verified that we are running the latest firmware versions and they are affected. Furthermore, there is no password change request implemented.
2018-05-15SEC Consult sends further/newly identified vulnerabilities to ICS-CERT for Xiongmai, describing worst case scenario, asking to inform FTC about this case.
2018-05-15ICS-CERT: Xiongmai is very slow in responding, and requests for affected firmware versions have been sent to them already.
2018-05-25Asking ICS-CERT for a status update.
2018-05-29ICS-CERT: small update from Xiongmai received:
–Vendor Response–
Regarding the device information from Researcher, it is our "old" model and "old" firmware version, that's why there is no more update. Even for DVR model it is already discontinued, therefore we will work a new "latest" version based on current baseline version, for those Researcher's devices specially.
–End Vendor Response–
Xiongmai also said they will provide version numbers for fixed & vulnerable versions, but no answer.
2018-06-04ICS-CERT: Xiongmai provided a firmware update for our test devices.
2018-06-11SEC Consult: tested firmware "SimpGeneral_General_AHB7804R-ELS_V4.02.R11.Nat.OnvifC.20180525.bin" There are no apparent changes, it uses the same cloud ID, the admin password is still empty and there are no warnings to change the password (checked via web interface and VMS software)
2018-06-15ICS-CERT: received an update from Xiongmai as to why the firmware did not seem to fix anything:
–Vendor Response–
After check the message we believe there is some misunderstanding on IE operation due to the Plug-in ( or called as ActiveX ) issues, As currently this ActiveX technology even is quite an "ancient" technology but still widely used in most of Video Surveillance products. The issues that Researcher have met, it is due to his PC still have "old" plug-in installed, and with new update of firmware we provided, The camera and NVR already have functions but his PC with "old" plug-in, it is like using same "old" computer to connect new devices, that's why he still didn't see anything new.
So the solution is quite simple, just delete and uninstall "old" Plug-in, and then install new one from devices with new version. Please kindly check attached file, we have some instructions and steps, on how to renew this ActiveX, please help to forward to this Researcher and we believe he could understand the reason, and he could recheck about the new firmware we had sent.
–End Vendor Response–
2018-06-18SEC Consult: the ActiveX controls are unrelated to any of the issues we reported. For the sake of completeness, SEC Consult tested it anyways and all the security issues are still not fixed. Raising doubts that the vendor understands the impact.
2018-06-21ICS-CERT: concurs with our opinion and if Xiongmai does not fix the issues we will have to publish. Xiongmai did not yet react to the additional findings reported on 2018-05-15.
2018-07-24ICS-CERT: Xiongmai provided "improved" instructions to help ensure the forced password change happens.
2018-07-27SEC Consult: the default admin password is just a small subset of the identified critical issues. Intention to publish end of September.
Asking further questions to Xiongmai:
  • What devices are affected by the vulnerabilities?
  • What is the plan/timeline to fix the issues?
  • Are there issues that will not be fixed? Why?
  • Are there devices that will not receive fixes for the vulnerabilities? Which ones?
  • Will the updates be rolled out automatically or are manual steps by the user required?
  • Will Xiongmai publish a public warning/advisory on their website?
  • Will Xiongmai inform their OEM customers about the vulnerabilities so they can inform end users?
2018-08-01ICS-CERT: questions & deadline have been passed to Xiongmai. Possibility of contacting CNCERT/CC.
2018-09-04ICS-CERT: Still waiting for a response from Xiongmai. CNCERT/CC has responded.
2018-09-24SEC Consult: Asking for a status update. Proposed release date 8th October Recommendations are to stop using the devices, other workarounds are not effective.
2018-09-27ICS-CERT: CNCERT/CC only replied with generic email response. ICS-CERT proposes Tuesday or Thursday for releases. Decided for the 9th October.
2018-10-04Informing CERT-Bund and CERT.at about the security issues and release.
2018-10-09Coordinated release of security advisory.

Solution

The vendor did not provide proper mitigations and solution attempts since ICS-CERT contacted them back in March 2018.

SEC Consult advises not to use the products of Xiongmai and any 3rd party OEM device associated with the XMeye cloud feature.

Workaround

There are no workarounds available as the devices are connected via the cloud, the usual recommendations changing default passwords, strict firewalling and network segmentation unfortunately do not mitigate the whole range of discovered issues.

Advisory URL

https://www.sec-consult.com/en/vulnerability-lab/advisories/index.html

EOF Stefan Viehböck / @2018

Interested to work with the experts of SEC Consult? Send us your application.
Want to improve your own cyber security with the experts of SEC Consult?
Contact our local offices.
  • ProductXiongmai IP Cameras, NVRs and DVRs incl. 3rd party OEM devices


  • Elyssa D. Durant
    Policy & Research Analyst