Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

11–20 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#11
post #6

Earlier quoted context omitted.

The irony of using a shortened link in a comment on cyber security.

Non-shortened link: https://supportannouncement.us.dlink.com/announcement/public...

"D-Link takes the issues of network security and user privacy very seriously. " ... "These products have entered End of Service Life. There is no support or development for these devices. We recommend replacing the device with an new device that is actively supported."

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#12
post #9

This is precisely why I chose to install DD-WRT on all my routers. Not only does it give me more fine grain control over all my admin privileges, I know I don't have to rely on some company making the cost-benefit decision over if it's worth patching security bugs.

DD-WRT doesn't necessarily provide more security, typically models will get one release and then not get any more updates.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#13
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50?

You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase.

Then again, I buy stuff that can be flashed with OpenWRT ...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#14
post #7

It's times like this i'm glad my home router is a x86 mini PC running Arch Linux + iptables + Unifi (Complete with DNS MITM forcing all DNS out of my apartment over TLS)

How high-touch is this kind of setup? I have a separate access point and I am using a consumer-grade "wireless router" for DHCP. (and other things?)

I'm more of an app developer that does DevOps stuff when I have to. Is this something I can get done in a day or so? Is a Raspberry Pi enough, or do I need something more powerful?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#16
I'm aware of the "but what if the router is connected to an ICU bed? A patient's life depends on it!" straw man but let's be honest, it would only be the ICU's admin fault.

Having sorted this out, let me clearly state that the only ethical solution is to brick these devices offline.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#17
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

There's also just you know, installing Custom Firmware if you're determined enough.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#18
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

$50 honestly seems expensive considering how long home routers have been around. It's not as if it's novel technology.

I'd expect cheap mass-produced routers to be around $15 - $25, like an immersion blender.. I don't quite understand why cheap ones are still $40-$60.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#19
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

Maybe this should be the way forward. We all should buy hardware that can run Software like OpenWRT

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#20
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.
Post reply on HN