Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

31–40 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#31

Earlier quoted context omitted.

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

I've read three articles about this today (this one included), and they all specified the same Mikrotik models: - Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072

You're right, I just got down to the bottom of the article and those models are listed there.

I don't recall what article I read a day or two ago, but I don't believe it mentioned the specific models.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#32
post #29

Earlier quoted context omitted.

Presumably if they intended to use this maliciously, they wouldn't have told you about it. But in most cases, the FBI having control is still better than a random malicious actor having control, unless you belong to a certain high risk segment of the population. In the long term, you want a fix for your router, or you want a new router. Mine is similar to one of the affected units, enough so that it's likely vulnerab…

> unless you belong to a certain high risk segment of the population. I don't think we are so far from the day that "high risk" will mean anyone who opposes the government. > Mine is similar to one of the affected units, enough so that it's likely vulnerable. I'm looking at replacing it. That's probably wise.

People in an adversarial relationship with the government they live under would definitely be that segment of the population, yes.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#33
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

The information is in the article, I don't think the headline is misleading.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#34

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

> Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked?

Sometimes the router companies are cover ops like TCP 32764

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#35

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

Because, just like GPL'd software, they all come with a "no warranty, expressed or implied" disclaimer attached?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#36
post #17

If you're infected, you need a new router. Period. Telling people that they can resecure their routers with just a reboot is irresponsible.

I wonder how the cost-benefit analysis goes between creating yet more e-waste, and letting some malware persist...

It'd be a lot better of a situation if router boards were designed to accept firmware upgrades at a low level. After an attack, you often need to use the software updater to reset it. That can no longer be trusted if it's compromised. Consumer-level routers have been very low-quality for quite a while.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#37
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

As I say below, a reboot will force the router to hit the now-sinkholed domain. This will let the ISP identify customers with affected equipment and notify them. The core message here that everyone should reboot their router is simple enough to survive on Twitter and be understood, whereas specific instructions about which devices are bad will likely be screwed up.

They should have exfiltrated to Tor, using a DGA, or a corporate-friendly network like OneDrive.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#38

How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?

The US agencies have a very close relationship with router manufacturers. TCP 32764 for example was a backdoor many suggest they used cover ops to create and exploit.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#39
post #36

Earlier quoted context omitted.

I wonder how the cost-benefit analysis goes between creating yet more e-waste, and letting some malware persist...

It'd be a lot better of a situation if router boards were designed to accept firmware upgrades at a low level. After an attack, you often need to use the software updater to reset it. That can no longer be trusted if it's compromised. Consumer-level routers have been very low-quality for quite a while.

Many of them (judging from those supported by OpenWRT, at least) can be "flashed" / upgraded / restored via TFTP by interrupting the boot process.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#40
post #20

Glad now have Google WiFi. Most secure consumer router you can get, imo.

I’m very happy with my Ubiquiti UniFi setup. Don’t know if it’s more secure than a google product but I trust it more.

Based on Ubiquiti's track record over the last few years, I certainly wouldn't bet my money on that.
Post reply on HN