Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

21–30 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#21
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

So when these devices reboot, the FBI is now going to have control of ~500,000 home routers? That's, uh, "reassuring".

Presumably if they intended to use this maliciously, they wouldn't have told you about it. But in most cases, the FBI having control is still better than a random malicious actor having control, unless you belong to a certain high risk segment of the population.

In the long term, you want a fix for your router, or you want a new router.

Mine is similar to one of the affected units, enough so that it's likely vulnerable. I'm looking at replacing it.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#22

"There's no easy way to determine if a router has been infected. It's not yet clear if running the latest firmware and changing default passwords prevents infections in all cases." Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as: Linksys E1200 Linksys E2500 Linksys WRVS4400N Netgear DGN2200 Netgear R6400 Netgear R7000 Netgear R8000 Netgear WNR1000 Netgear WNR2000…

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#23
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

So when these devices reboot, the FBI is now going to have control of ~500,000 home routers? That's, uh, "reassuring".

[deleted]

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#24
post #17

If you're infected, you need a new router. Period. Telling people that they can resecure their routers with just a reboot is irresponsible.

The reboots are about making the infected routers hit the C2 server so that ISPs can identify and notify users whose routers were infected.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#25
post #17

If you're infected, you need a new router. Period. Telling people that they can resecure their routers with just a reboot is irresponsible.

It’s the most accessible way to do it. Most people don’t buy their routers, they lease from the ISP. Major ISPs replacing 100k+ devices will take a while and they’ll drag their feet. FBI commandeering the C&C domain and instructing users to reboot is not the long term fix but it is most effective

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#26

"There's no easy way to determine if a router has been infected. It's not yet clear if running the latest firmware and changing default passwords prevents infections in all cases." Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as: Linksys E1200 Linksys E2500 Linksys WRVS4400N Netgear DGN2200 Netgear R6400 Netgear R7000 Netgear R8000 Netgear WNR1000 Netgear WNR2000…

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

I've read three articles about this today (this one included), and they all specified the same Mikrotik models:

- Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#27
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

As I say below, a reboot will force the router to hit the now-sinkholed domain. This will let the ISP identify customers with affected equipment and notify them.

The core message here that everyone should reboot their router is simple enough to survive on Twitter and be understood, whereas specific instructions about which devices are bad will likely be screwed up.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#28
post #17

If you're infected, you need a new router. Period. Telling people that they can resecure their routers with just a reboot is irresponsible.

I wonder how the cost-benefit analysis goes between creating yet more e-waste, and letting some malware persist...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#29

Earlier quoted context omitted.

So when these devices reboot, the FBI is now going to have control of ~500,000 home routers? That's, uh, "reassuring".

Presumably if they intended to use this maliciously, they wouldn't have told you about it. But in most cases, the FBI having control is still better than a random malicious actor having control, unless you belong to a certain high risk segment of the population. In the long term, you want a fix for your router, or you want a new router. Mine is similar to one of the affected units, enough so that it's likely vulnerab…

> unless you belong to a certain high risk segment of the population.

I don't think we are so far from the day that "high risk" will mean anyone who opposes the government.

> Mine is similar to one of the affected units, enough so that it's likely vulnerable. I'm looking at replacing it.

That's probably wise.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#30
Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked?

At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

Post reply on HN