Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

71–80 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#71
post #14

Glad now have Google WiFi. Most secure consumer router you can get, imo.

How would you know if this were true? Is it just branding/reputation? I use a peplink, which doesn’t target the “consumer” market. Is that better? Seems impossible to know.

The more it seems, is that I should run my own freebsd or centos linux router, and turn on the full compliment of security (Selinux, aide, firewalld, etc) and run my own. And put Openscap on there and use the US government configuration base remediation.

Itd be painful to setup initially, but once setup should be rock solid.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#72

How comes that this kind of information seems to only alerte US officials ? Is it targeted only on US soil ? I really doubt that. Why does EU (for example) authorities not warning their citizens ?

Maybe EU is busy with GDPR

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#73

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Boy is that ever not true.

https://www.woodshopnews.com/.amp/news/table-saw-suit-nets-1...

This guy was given a table saw with the guard already removed, and was using it on the floor (a table saw should be used at table height, so that you can have a foot forward to prevent falling into the blade). He was apparently not using push-sticks.

Somehow, the table saw manufacturer was found 65% liable in the case, because technology exists to reduce the likelihood of injury when flesh contacts the blade. Specifically, SawStop, which I believe senses capacitance and fires an aluminum block into the blade.

Here's a rather biased and snarky rundown of the whole thing that links some important bits of the backstory:

https://www.bob-easton.com/blog/is-it-your-table-saw-or-the-...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#74
post #60

Earlier quoted context omitted.

Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost…

> after being rooted by 4 lines of JavaScript Could you provide any sort of source for this extraordinary claim of yours?

That's probably an exaggeration, but I agree with the sentiment of what they are saying. It's not crazy hard to write quality software. Most corporations don't bother because they know they don't have to, since they can escape liability laws. It's gotten to the point where most software developers somehow view this situation as "normal".

Do you have a QA department? What do they do? If you're like most software companies, they do testing. This is not QA, though, it's QV. The role of QA is to assure that the quality of your product is high. By the time you're testing it, the product is "done" - all of the defects are already there in the product. There is now nothing you can do to affect the quality of the product - all you can do is test and measure the overall quality of the product.

I mean, your tests will find problems, and you can fix those problems. But, if you keep track of how many problems you find, and how much test effort was involved to find those problems, you can plot a weibull regression and make a prediction about how many defects you haven't found yet. On any project I've been on where we ran this analysis, it was obvious that testing was finding almost none of the problems - barely skimming the surface. And, when you ran this analysis you could predict how many defects you will find if you spend X days testing, and on any project where I've seen this analysis run, those predictions have been highly accurate.

Really good automated tests can help with this, because they can do huge amounts of test effort "for free", but really QA should be about the process you follow when you write software - making sure you have a repeatable process, and then figuring out how to improve it. Almost no one does this.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#75
post #51

Earlier quoted context omitted.

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Most of these devices are insecure not because the attackers are hyper-sophisticated, but because the software is rushed and a second-thought to the hardware. There is no one (in power) at these companies that cares about crafting quality software. They just care about crafting the bare minimum to make their devices work. I wager that "security" is something fairly far from their mind when they craft this software, w…

It's even worse: most of these companies don't even write the software for the low end consumer hardware. They just license it from a third party, usually in Asia, and pay them to turn features on or off and skin the UI for their branding.

It's no surprise that routers from competing manufacturers are vulnerable, since it's all the same under the hood. The companies that sell the finished product have zero insight into how secure the software is.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#76

Earlier quoted context omitted.

That would be illegal hacking on the part of the FBI. Do you really want the federal government installing software on your devices?

The FBI can get a court order authorizing the necessary activities.

I would hope and expect that, at least, they would need a separate court order for every modem.

Also, chances are courts would deny them such orders on the grounds that it would be easier for about everyone involved if the FBI just asked the router’s owner to restore its firmware (why would the FBI need a court order against foo because bar hacked its modem?)

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#77
post #60

Earlier quoted context omitted.

Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost…

> after being rooted by 4 lines of JavaScript Could you provide any sort of source for this extraordinary claim of yours?

I'm not sure whether you think a line of JS calling out to load a remote procedure would have been extraordinary, a root via a browser would have been extraordinary, any remote rootkit load would have been extraordinary, or whether the fact that it used to be possible to root Windows seems extraordinary. I'm no expert but none of this seems extraordinary to me. Things was loose in those days.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#78

What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…

Just search for WRT54GL on Amazon. It's selling for $34.99, which is pretty affordable. N.B. the WRT54G doesn't work with Tomato.

The WRT54 is dog slow by today's standards. My residential Comcast service is faster than it can handle; my max down almost doubled when I swapped my WRT54GL for an AC3200

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#79

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

Because, just like GPL'd software, they all come with a "no warranty, expressed or implied" disclaimer attached?

Not that in common law, some warranties cannot be evaded, such as the goods being fit for use.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#80

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
Post reply on HN