Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

61–70 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#61
post #55

Earlier quoted context omitted.

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Car makers have been held liable for the lack of intentionally designed safety features There’s plenty of precedent I think lack of safety features that meet our current common knowledge of the potential failure scenarios should be enough to shut down a company We can refuse to enable commerce that jeopardizes or personal safety (literal or ephemeral data theft) Capitalists are just humans. They can be culturally pre…

It took a concerted campaign by Ralph Nader to hold car companies liable.

It isn’t clear how that would work with software. Would FOSS authors be held liable? That would mean the end of open source.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#62
post #51

Earlier quoted context omitted.

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Most of these devices are insecure not because the attackers are hyper-sophisticated, but because the software is rushed and a second-thought to the hardware. There is no one (in power) at these companies that cares about crafting quality software. They just care about crafting the bare minimum to make their devices work. I wager that "security" is something fairly far from their mind when they craft this software, w…

It would probably be best to let the market regulate by itself but the issue here might be that it’s not visible to users that their router is infected.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#63
post #36

Earlier quoted context omitted.

It'd be a lot better of a situation if router boards were designed to accept firmware upgrades at a low level. After an attack, you often need to use the software updater to reset it. That can no longer be trusted if it's compromised. Consumer-level routers have been very low-quality for quite a while.

Many of them (judging from those supported by OpenWRT, at least) can be "flashed" / upgraded / restored via TFTP by interrupting the boot process.

The security of this feature depends on whether or not it runs from code in mask ROM.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#64

Earlier quoted context omitted.

If they've seized the C&C domain, can't they push an update that disable the malware?

That would be illegal hacking on the part of the FBI. Do you really want the federal government installing software on your devices?

The FBI can get a court order authorizing the necessary activities.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#65

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

https://en.wikipedia.org/wiki/Therac-25

The idea that tool manufacturers are not responsible for misuse or hacking is quite ridiculous.

We have a legal system in the USA to hold manufacturers, both for both industrial and consumer applications, responsible when a design flaw causes harm.

Vulnerabilities are design flaws. They make a product unsafe to use. The idea that routers are still safe when Russian hackers abuse them is not reality. They become dangerous vectors for viruses and harassment. The cost to the USA economy could be enormous in the case of a mass attack on routers.

A router is military hardware. It can be used to militate. When routers are sold to consumers, this is done with the knowledge that a router can be exploited for military applications. A router is potentially an exploit that an adversary can use for reconnaissance or subversion.

If a manufacturer is selling faulty military hardware as a consumer good and making sure exploits that hackers use are not fixed, that manufacturer is a traitor. The punishment for being a traitor is summary execution.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#66
post #51

Earlier quoted context omitted.

Most of these devices are insecure not because the attackers are hyper-sophisticated, but because the software is rushed and a second-thought to the hardware. There is no one (in power) at these companies that cares about crafting quality software. They just care about crafting the bare minimum to make their devices work. I wager that "security" is something fairly far from their mind when they craft this software, w…

It would probably be best to let the market regulate by itself but the issue here might be that it’s not visible to users that their router is infected.

That is right. This malware is an externality. Externalities typically need to be mitigated through regulation.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#67

What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…

Just search for WRT54GL on Amazon. It's selling for $34.99, which is pretty affordable. N.B. the WRT54G doesn't work with Tomato.

The problem with that being a lot of people's internet is now faster than 54mbit

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#68
post #42

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

>Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? Because there is no law that says so?

This would/could fall under negligence and/or strict liability torts.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#69

What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…

I have a Netgear WNDR3700v4 that works pretty well with OpenWRT/LEDE. You just have to be careful about which version of the WNDR3700 you get, because some of them use unsupported chipsets, iirc.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#70

Earlier quoted context omitted.

So when these devices reboot, the FBI is now going to have control of ~500,000 home routers? That's, uh, "reassuring".

Presumably if they intended to use this maliciously, they wouldn't have told you about it. But in most cases, the FBI having control is still better than a random malicious actor having control, unless you belong to a certain high risk segment of the population. In the long term, you want a fix for your router, or you want a new router. Mine is similar to one of the affected units, enough so that it's likely vulnerab…

>But in most cases, the FBI having control is still better than a random malicious actor having control, unless you belong to a certain high risk segment of the population.

That's like saying liver cancer is better than pancreatic cancer - true but not comforting.

Post reply on HN