Live data from Hacker News

Linksys CherryBlossom Advisory

linksys.com

31–40 of 46 posts

Re: Linksys CherryBlossom Advisory

#31
post #17
post #4

Earlier quoted context omitted.

If the security of your router is of concern to you I would recommend setting up your own FreeBSD+pfSense router. Another option is to setup a vpn server that all your devices connect to to access the internet. In that scenario it won't matter if your router is compromised because all traffic flowing through would be encrypted.

PFSense runs PHP as root. Let that just sink in for a second, does that sound like a recipe for security? Nevermind the community, when it comes to vaguely complex things like IPTV and similar, support is either legacy or gone. At this point OpenWRT is the only sane choice, at least it doesn't run everything as root and isn't going to shove off Multicast UDP packet forwarding support in the next year or two.

OpenWRT definitely has quirks, and my vendor thinks spawning hundreds of socat processes is acceptable in production firmware: https://forum.turris.cz/t/ever-increasing-leaking-nuci-proce...

Re: Linksys CherryBlossom Advisory

#32
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

On the basis that most linksys owners never touch or upgrade their firmware, why aren't linksys (and other manufacturers) products shipped with a physical hardware 'read-only' switch for the firmware to prevent unauthorised remote upgrades?

Re: Linksys CherryBlossom Advisory

#33
post #27
post #10

> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router. Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying tha…

You can disable management via the WAN port and/or wi-fi if you put OpenWRT on them.

There should have never been management access enabled by default via WAN or WLAN on ANY router to be honest. In a misguided effort to make their consumer devices more 'friendly'[1] they've just made them more insecure.

--

[1] Even though most users have no idea the management interface even exists.

Re: Linksys CherryBlossom Advisory

#35

Earlier quoted context omitted.

Linksys security guy here - we got that firmware update tidbit from the cherryblossom documentation. The firmware implant (aka flytrap) reproduces all of the router's normal functionality. On page 122 of the cherryblossom docs, it says that the firmware upgrade feature is implemented normally by the flytrap, and that if a user attempts to upgrade their router's firmware, it will overwrite the flytrap firmware.

Hey man- professional courtesy here: "if linksys users believe their routers are compromised" is possibly the worst way to frame this. You should flatly advise users to update.

Given that there is a chance for things to go wrong, I wonder what's the real-world success rate of firmware upgrades performed by nontechnical users? Is it worth it when most devices very likely aren't infected?

Re: Linksys CherryBlossom Advisory

#36
post #22

Earlier quoted context omitted.

Perhaps I'm missing something, but are you saying you trusted that the malware documentation is correct?

Didn't really have any other choice. We had tons of users calling in last week panicking over what to do about cherryblossom. Without a sample of the implant or confirmation from the CIA that the documents are legitimate & unaltered, this advisory is pretty much all we can do for those users.

Didn't you have an infected target to test against?

Re: Linksys CherryBlossom Advisory

#37
post #22

Earlier quoted context omitted.

Perhaps I'm missing something, but are you saying you trusted that the malware documentation is correct?

Yeah this is a bit worrying. But since it was leaked, this actually doesn't seem so bad. What incentive would the CIA have to lie internally?

One good reason I can think of is to have something for leakers to leak that isn't based in reality.

Or: the CIA leaked it intentionally as smoke-screen.

I don't know. Are there organisational silos within intelligence agencies? Layers of access? It's hard to know for sure, but I'm yet to see a human organisation that doesn't have political in-fighting.

Re: Linksys CherryBlossom Advisory

#40
post #33
post #27

Earlier quoted context omitted.

You can disable management via the WAN port and/or wi-fi if you put OpenWRT on them.

There should have never been management access enabled by default via WAN or WLAN on ANY router to be honest. In a misguided effort to make their consumer devices more 'friendly'[1] they've just made them more insecure. -- [1] Even though most users have no idea the management interface even exists.

I don't mind it being on WiFi. But yeah, public facing management port is insane.
Post reply on HN