Live data from Hacker News

Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

badpackets.net

1–10 of 38 posts

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#2
Once again embedded device security is a joke. Firmware updates are provided for 2 years or less on devices that end up lingering, acting as the core of networks for 5 to 15 years.

Repeat offenders should be held accountable, standards should be enforced (like running point releases of OpenWRT, providing vendor skins as a package, thus the vendor doesn't have to deal with software updates).

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#3
Pity that the author didn't mention alternative firmwares as an option to fix the vulnerability. I recommend everyone with the affected device to go to https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=Linksys and install the OpenWRT firmware, it's pretty easy.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#4
post #3

Pity that the author didn't mention alternative firmwares as an option to fix the vulnerability. I recommend everyone with the affected device to go to https://openwrt.org/toh/start?dataflt%5BBrand*%7E%5D=Linksys and install the OpenWRT firmware, it's pretty easy.

Will add to the post, thanks for the recommendation.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#6
post #5

This is not a problem if you are behind a CG-NAT. If you are not (that should be the default) then ask your ISP to put you behind one. If they don't offer that service, then it's time to shop around.

Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#7
post #6
post #5

This is not a problem if you are behind a CG-NAT. If you are not (that should be the default) then ask your ISP to put you behind one. If they don't offer that service, then it's time to shop around.

Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.

I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#8
Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge security risk. And even when you manually install SMB 1.0 suppport, it's still not going to work on Windows 10 Pro editions. Which means that the main selling point of the router is now useless for me. Linksys of course remains completely silent, they don't see anything wrong there.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#9
post #7
post #6

Earlier quoted context omitted.

Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.

I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.

Stop breaking the internet for goodness sake. Blithely throwing more power into the ISP's hands does no one any good in the long run.

Also it is very likely you are still vulnerable from other users on the same ISP attacking you.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#10
post #7
post #6

Earlier quoted context omitted.

Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.

I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.

NAT adds latency to a number of applications (VoIP, video conferencing, gaming). Not so much in the translate IP/ports and keep some state, but in connection establishment. CG-NAT only makes this worse (not to mention it's becoming impossible to troubleshoot when issues arise).

Users don't explicitely care because they don't know. It doesn't make much difference when viewing YouTube videos, but there's more to the Internet than cat videos.

Post reply on HN