Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

41–50 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#41
post #20

Glad now have Google WiFi. Most secure consumer router you can get, imo.

I’m very happy with my Ubiquiti UniFi setup. Don’t know if it’s more secure than a google product but I trust it more.

What’s your setup? I have an EdgeRouter Lite but I’m looking for one or more WiFi access points to add to my network.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#42

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

>Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked?

Because there is no law that says so?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#43

"There's no easy way to determine if a router has been infected. It's not yet clear if running the latest firmware and changing default passwords prevents infections in all cases." Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as: Linksys E1200 Linksys E2500 Linksys WRVS4400N Netgear DGN2200 Netgear R6400 Netgear R7000 Netgear R8000 Netgear WNR1000 Netgear WNR2000…

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

damn, enterprise I used to work at uses mikrotik for critical services...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#44

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#45
What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :)

From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its unmaintained vendor firmware with something more solid running Tomato/OpenWRT. Disagreements?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#46
post #41
post #20

Earlier quoted context omitted.

I’m very happy with my Ubiquiti UniFi setup. Don’t know if it’s more secure than a google product but I trust it more.

What’s your setup? I have an EdgeRouter Lite but I’m looking for one or more WiFi access points to add to my network.

Cloud Key, USG, Switch 8 POE, and two AP-Lites. The UniFi console makes management easy compared to the edge router UI. I also have one of those but it’s just sitting right now.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#48

Does anyone know if this affects routers flashed with LEDE/DD-WRT?

Yes and how do we find out if we're infected? It can't be that hard, now can it? Once you know what you have to be looking for - it has to be some kind of file or altered binary since stage 1 is persistent.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#49

"There's no easy way to determine if a router has been infected. It's not yet clear if running the latest firmware and changing default passwords prevents infections in all cases." Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as: Linksys E1200 Linksys E2500 Linksys WRVS4400N Netgear DGN2200 Netgear R6400 Netgear R7000 Netgear R8000 Netgear WNR1000 Netgear WNR2000…

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

Using a vulnerability fixed last March.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#50

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

"Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked?"

The sheer impossibility to guarantee 100% secure and functional software due to the actual way doped silicon works. That's why there is no actual software warranty in existence.

Post reply on HN