Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

31–40 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#31
post #22

What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.

It doesn't meet your hackability requirements, but I suggest Ubiquiti for wifi AP's at a price point that home owners can afford. I personally prefer keeping my wifi separate from the router, which this affords you.

See this for a crash course in an entire Unifi setup, https://www.youtube.com/watch?v=f_-iuY_xxFY

I personally run pi-hole on a pi, use an edgerouter x and unifi aps for the house.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#32
post #23

Earlier quoted context omitted.

There's also just you know, installing Custom Firmware if you're determined enough.

I'll never use vendor firmware again. If the router doesn't support OpenWRT, it's a time bomb waiting to go off, as this article shows; plus, of course, OpenWRT has sufficient additional functionality that that alone makes it worthwhile. And once again, we're all reminded of the divide between people who know how to do things like this and people who don't, and how the people who do know have an advantage in life.

I don't usually install CFW on mine, but it's something I look for the possibility of doing in case something like this D-Link issue occurs.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#33
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

> You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase.

Let's unpack this:

You get what you pay for... yet you also say that OpenWRT solves this problem and is available free of charge.

If you pay for a support contract, you get support right up to the point where the company decides to stop that support. If you have a contract worded the right way, you might be able to take the company to court over it, but if the company's willing to settle, you end up with some go-away money and an insecure router nobody's supporting. Does the money pay for next week's massive outage due to someone taking over your routers?

Finally, the product as it was at time of purchase was a product fit to be sold, without major defects. In other industries, that's a standard companies are held to: If a ball joint goes out completely after 10,000 miles, Ford's kinda on the hook for that, neh? They can't say that you have the car you purchased because the car you purchased was driveable and not sitting on the side of the road.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#34
post #20

Earlier quoted context omitted.

If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

Somebody can conceivably receive significant financial damage though. Why they shouldn't be liable?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#35
post #7

It's times like this i'm glad my home router is a x86 mini PC running Arch Linux + iptables + Unifi (Complete with DNS MITM forcing all DNS out of my apartment over TLS)

How to make a PC talk over a DSL cable? I assume a specialised chip would need to be plugged in at which point the potential for vulnerabilities of that PCB need to be considered...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#36
post #20

Earlier quoted context omitted.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.

You have warranties for those, though. Also, no lives are in risk in dlink's case. It's more comparable with a shirt that falls apart after washing a few times.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#37

Earlier quoted context omitted.

How high-touch is this kind of setup? I have a separate access point and I am using a consumer-grade "wireless router" for DHCP. (and other things?) I'm more of an app developer that does DevOps stuff when I have to. Is this something I can get done in a day or so? Is a Raspberry Pi enough, or do I need something more powerful?

If you want a less touchy solution (not completely plug and play though!) I can't recommend Ubiquiti products enough. I run an EdgeRouter X and Unifi AP at home. Not big enterprise gear but way more enterprisey than whatever you'll find on the shelf at Best Buy. Updates are released regularly and once you get your initial configuration done they just chug along, no random 'internet is down, need to reboot something'…

Cheaper and older alternative is the Ubiquity Unifi Security Gateway + 8 port switch + UAC AP-PRO if you don't want the Edgerouter X cost. Less customizeable but if you're buying an EdgeRouter you know what you want.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#38
post #20

Earlier quoted context omitted.

If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

It's not just "one unpatched router". It could be millions. Or millions or billions or IOT devices in the future that are unpatched.

That does have the potential to create some damage if anyone takes control of them. Maybe even kill some people, if say they DDoS the V2I network for self-driving cars in the future, or a hospital network over which remote surgeries are performed, etc.

I feel like this argument that "you get what you pay for" is pretty lazy. Usually, or ideally, consumer regulations are about setting standards and raising the bar.

So that means that if there were strong laws for stuff like this, then the minimum router price may become $70 instead of $50 - but everyone would be reasonably protected for the large majority a device's lifecycle (only a small portion of the customers should be affected by leftover bugs when support ends, like say <5%, as others will have moved on to new products by then).

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#39
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

Xiaomi sells routers in this price range that ship with OpenWrt. The buildroot even has config options for branding! It costs them nothing for the OS. It costs D-Link more to produce their mess.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#40
post #27

For national security sake all routers should be required to support open firmwares.

Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…

The solution is that there is no preemptive solution, any more than there is a preemptive solution to using an axe dangerously. You can build a transmitter out of a Raspberry Pi and a short length of wire; for extra credit, you can buy a cheap amplifier and really go to town, but the simple fact you can strobe a GPIO pin fast enough to transmit on unauthorized frequencies is the final nail in the coffin for any plan to restrict broadcasting by restricting radio sales.

The enforcement comes down to this: If you transmit in an obnoxious way and you annoy someone, you get squashed. If you kill someone, you get squashed harder. That doesn't bring the dead back to life, but sending someone to prison for killing someone else with an axe doesn't bring the dead back to life, either.

Post reply on HN