Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

11–20 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#12

How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?

Modem-routers often have subtly different models (sometimes even under the same model number and SKU!) in different regions. "Subtly different" can mean in this instance: completely different OS, different chipset/hardware/board supplier etc.

It's possible that the models affected by this particular attack aren't sold in other places, or perhaps they are, but are actually still different (enough). Or they are just not widely used.

I say this because govt. organisations have often issued warnings and recommendations like this in similar circumstances, e.g. a while ago some modem-routers widely used in this country were attacked, and a warning very much like this has been issued.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#13
post #5

Earlier quoted context omitted.

What about a factory reset? (by pressing on the pinhole button for a few secs)

A factory reset, according to Cisco, will fix it. Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...

According to talos, a reboot will remove stage 2 and 3 but not 1.

It's not clear how stage 1 installs. Is it into the (hidden) base Linux install in rc.local or whatever, does it get into the bios/firmware of the computer.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#14

Glad now have Google WiFi. Most secure consumer router you can get, imo.

How would you know if this were true? Is it just branding/reputation?

I use a peplink, which doesn’t target the “consumer” market. Is that better? Seems impossible to know.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#15
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

If they've seized the C&C domain, can't they push an update that disable the malware?

As far as I know, they typically won't do this to avoid responsibility for bricking safety- and mission-critical routers.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#16
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

So when these devices reboot, the FBI is now going to have control of ~500,000 home routers?

That's, uh, "reassuring".

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#18
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

If they've seized the C&C domain, can't they push an update that disable the malware?

That would be illegal hacking on the part of the FBI. Do you really want the federal government installing software on your devices?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#19
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

[deleted]
Post reply on HN