Live data from Hacker News

Linksys CherryBlossom Advisory

linksys.com

21–30 of 46 posts

Re: Linksys CherryBlossom Advisory

#22
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Perhaps I'm missing something, but are you saying you trusted that the malware documentation is correct?

Re: Linksys CherryBlossom Advisory

#23
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Hey man- professional courtesy here: "if linksys users believe their routers are compromised" is possibly the worst way to frame this. You should flatly advise users to update.

Re: Linksys CherryBlossom Advisory

#24
post #22

Earlier quoted context omitted.

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Perhaps I'm missing something, but are you saying you trusted that the malware documentation is correct?

Yeah this is a bit worrying. But since it was leaked, this actually doesn't seem so bad. What incentive would the CIA have to lie internally?

Re: Linksys CherryBlossom Advisory

#25
post #22

Earlier quoted context omitted.

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Perhaps I'm missing something, but are you saying you trusted that the malware documentation is correct?

Didn't really have any other choice. We had tons of users calling in last week panicking over what to do about cherryblossom.

Without a sample of the implant or confirmation from the CIA that the documents are legitimate & unaltered, this advisory is pretty much all we can do for those users.

Re: Linksys CherryBlossom Advisory

#26
post #22

Earlier quoted context omitted.

Perhaps I'm missing something, but are you saying you trusted that the malware documentation is correct?

Didn't really have any other choice. We had tons of users calling in last week panicking over what to do about cherryblossom. Without a sample of the implant or confirmation from the CIA that the documents are legitimate & unaltered, this advisory is pretty much all we can do for those users.

Understood. Thank you. It makes sense that you would move on this urgently and confirm it's success only after.

Re: Linksys CherryBlossom Advisory

#27
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

You can disable management via the WAN port and/or wi-fi if you put OpenWRT on them.

Re: Linksys CherryBlossom Advisory

#28
post #11
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Download from non-TLS site, yeah, what could go wrong.

Sadly true.

Re: Linksys CherryBlossom Advisory

#29

Earlier quoted context omitted.

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Hey man- professional courtesy here: "if linksys users believe their routers are compromised" is possibly the worst way to frame this. You should flatly advise users to update.

There's no patch. The fix is just to reflash Linksys firmware to make sure you're not running compromised firmware.

Re: Linksys CherryBlossom Advisory

#30
post #7

> If users believe their router firmware may have been compromised, What would make them believe that? Wish they had a detection tool as well. Anyone know of one?

I wonder if there are easy way to dump the firmware and do a sign / hash check on another machine
Post reply on HN