Live data from Hacker News

Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

badpackets.net

11–20 of 38 posts

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#11
post #7
post #6

Earlier quoted context omitted.

Asking your ISP to cripple your connection like that is a horrible "solution", and usually isn't a change they're prepared to make by request. If you have the option of shopping around for ISPs, the one that doesn't do CG-NAT is usually the best choice.

I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.

NAT is not a security layer. It's possible through techniques like STUN and such to discover and reach hosts behind a NAT.

CG-NAT is crippling because I want to receive incoming connections like anyone else who has a connection to the Internet should be able to. Router manufacturers can do better. The world does not have to consist solely of cloud-based middle-men who take full advantage of the fact that all your data has to pass through them, and that you have to trust them.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#12
post #9
post #7

Earlier quoted context omitted.

I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.

Stop breaking the internet for goodness sake. Blithely throwing more power into the ISP's hands does no one any good in the long run. Also it is very likely you are still vulnerable from other users on the same ISP attacking you.

This is very unlikely. Any ISP with some experience will make sure customers are not able to interact any more than they could from outside the network. That's network 101.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#13
post #9

Earlier quoted context omitted.

Stop breaking the internet for goodness sake. Blithely throwing more power into the ISP's hands does no one any good in the long run. Also it is very likely you are still vulnerable from other users on the same ISP attacking you.

This is very unlikely. Any ISP with some experience will make sure customers are not able to interact any more than they could from outside the network. That's network 101.

Having worked for large ISP's for around a decade, cheap comes first, customer safety comes last.

Also, QUIT BREAKING THE INTERNET. CGNAT is complete crap that breaks the internet peer model. Even ISPs not using CGNAT are pushing complete crap on users. For example last week I had a user that VOIP stopped working. They received a new integrated cable modem router from their ISP. If you rebooted the unit VOIP worked about an hour, after that it would stop passing VOIP packets (ran tcpdump on the server and watched them stop). If we ran VOIP over another port it would work (but had different issues related to changing around 50 phones so we only used it for testing). There were no options to disable SIP_NAT, nor any other settings that would fix the problem. Since this ISP also provided their own phone service I found the whole debacle rather anti-competitive. They simply have no interest in contacting the modem vendor and having them fix the problem.

We ended up supplying our own modem and router in this case and the problem was resolved.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#16
post #5

This is not a problem if you are behind a CG-NAT. If you are not (that should be the default) then ask your ISP to put you behind one. If they don't offer that service, then it's time to shop around.

CG NAT is a solution for ISPs that don't have enough IPv4 addresses to give to their customers.

It's not security nor a service. And also breaks a lot of use cases like P2P VoIP/gaming etc.

I assume if the ISP gives you an IPv6 subnet, you'd disable it? Or if you can't do that, switch ISP?

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#17

Are there any routers that come out by default with Tomato or OpenWRT?

The Turris Omnia and soon-to-be Turris Mox are the only ones that I'm aware of. I know Linksys has a special line of WRT "open source ready" routers that are supposedly OpenWRT compatible, but the Amazon reviews are completely trash. They're a little more pricey, but my next router will be a Turris.

https://www.turris.cz/en/turris-omnia/

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#18

Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…

You bought a router to use as a NAS? I think that's your problem right there.

How is this even voted to the top?

Edit: Looks like I hit a nerve. God forbid anyone buy hardware for a purpose it was actually designed for.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#19

Linksys just doesn't give a shit. At all. I specifically bought one of their top end routers to use it as a NAS with USB storage, only to discover that their best of the best router serves files over.....Samba 1.0. Even though Samba 2.0 has been available for over a decade and Samba 3.0 is common place now. Which means that Windows 10 doesn't allow you to actually browse it by default anymore, since it's a huge secur…

You bought a router to use as a NAS? I think that's your problem right there. How is this even voted to the top? Edit: Looks like I hit a nerve. God forbid anyone buy hardware for a purpose it was actually designed for.

Because your comment is not contributing.

Linksys produces and advertises a "best of the best" router with inbuilt alternative NAS feature that not only is so poorly maintained that it's insecure but also unusable by modern OS.

Some people find that appalling because they want a basic NAS without breaking the bank and more "stuff" lying around, expecting a high end router to cheaply fill that gap.

Some other people will find it appalling because it shows how little Linksys actually cares about the product and security as a whole.

Re: Over 25k Linksys routers vulnerable to sensitive information disclosure flaw

#20
post #7

Earlier quoted context omitted.

I disagree with you. The majority of users don't care about being behind a CG-NAT (what you call "crippling"), and CG-NAT offers a very big layer of protection that avoids problems like the one on this article.

NAT is not a security layer. It's possible through techniques like STUN and such to discover and reach hosts behind a NAT. CG-NAT is crippling because I want to receive incoming connections like anyone else who has a connection to the Internet should be able to. Router manufacturers can do better. The world does not have to consist solely of cloud-based middle-men who take full advantage of the fact that all your dat…

What's somewhat ironic to this discussion is that some Linksys routers modify STUN responses, which breaks legitimate functionality if the router is used with dual-NAT or CG-NAT:

https://www.voip-info.org/stun

Both Linksys and CG-NAT need to be avoided.

Post reply on HN