Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

51–60 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#51

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Most of these devices are insecure not because the attackers are hyper-sophisticated, but because the software is rushed and a second-thought to the hardware. There is no one (in power) at these companies that cares about crafting quality software. They just care about crafting the bare minimum to make their devices work.

I wager that "security" is something fairly far from their mind when they craft this software, which I consider especially negligent for any company that is dealing in networked devices.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#52
post #20

Earlier quoted context omitted.

I’m very happy with my Ubiquiti UniFi setup. Don’t know if it’s more secure than a google product but I trust it more.

Based on Ubiquiti's track record over the last few years, I certainly wouldn't bet my money on that.

Please elaborate.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#53

What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…

Just search for WRT54GL on Amazon. It's selling for $34.99, which is pretty affordable. N.B. the WRT54G doesn't work with Tomato.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#54

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost millions of hours and billions of dollars to simply be able to use their computers again after being rooted by 4 lines of JavaScript

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#55

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Car makers have been held liable for the lack of intentionally designed safety features

There’s plenty of precedent

I think lack of safety features that meet our current common knowledge of the potential failure scenarios should be enough to shut down a company

We can refuse to enable commerce that jeopardizes or personal safety (literal or ephemeral data theft)

Capitalists are just humans. They can be culturally pressured and shunned. Such behavior has been a hallmark of human society since they began

Physics is a vacuum of such rules. Human society has always had them

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#56
post #46
post #41

Earlier quoted context omitted.

What’s your setup? I have an EdgeRouter Lite but I’m looking for one or more WiFi access points to add to my network.

Cloud Key, USG, Switch 8 POE, and two AP-Lites. The UniFi console makes management easy compared to the edge router UI. I also have one of those but it’s just sitting right now.

I'd be wary of any Ubiquiti network kit. I only trust their APs. The ERL for example is an awful router - it has had a firmware issue for years now where it causes persistent packet loss due to reordering incoming packets. I discovered these problems in my own testing, and there is a giant thread on the forums about it which I helped kick off. The ER-X is the only thing that seems to work properly. Their switches are bad too (small buffers). UI is nice and they are cheap, but not worth the poor performance.

I sold most of my Ubiquiti gear and bought a Netgate 2440 a couple years ago, put Debian on it with Shorewall and auto updates, and haven't looked back.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#57

What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…

Just search for WRT54GL on Amazon. It's selling for $34.99, which is pretty affordable. N.B. the WRT54G doesn't work with Tomato.

A cheaper, and better (longer 5ghz and 2.5 ghz) option is the Archer C7 router as well.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#58

Earlier quoted context omitted.

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

I've read three articles about this today (this one included), and they all specified the same Mikrotik models: - Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072

The original Cisco article mentions that these aren't all of the vulnerable models, just the ones they've seen. There isn't anything fundamentally different between a 1009 and a 1016.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#59

Earlier quoted context omitted.

Mikrotik devices were reportedly affected as well, although I haven't seen any specific model identified (they all run pretty much the same software, although various models are based on different CPU architectures).

damn, enterprise I used to work at uses mikrotik for critical services...

So critical that they'd leave the web interface running on public IPs without firewalling? If not then they're probably safe.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#60

Earlier quoted context omitted.

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost…

> after being rooted by 4 lines of JavaScript

Could you provide any sort of source for this extraordinary claim of yours?

Post reply on HN