For national security sake all routers should be required to support open firmwares.
Not exactly what you’re asking for, and it has its own problems [0], but the US military has a “trusted foundry program” [1] for sourcing chips. [0] https://semiengineering.com/a-crisis-in-dods-trusted-foundry... [1] https://en.m.wikipedia.org/wiki/Trusted_Foundry_Program
D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
41–50 of 306 posts
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#42Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.
What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...
Often times when defective products are sold there is some responsibility for some time to correct or notify people. Cars, child seats, and many other things fall into that.
The defective devices that get updates or notifications are often safety related. Yet, safety and security are not talked about much with regard to technology. Maybe it's time to start doing that.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#43This applies to every "connected device:" printers, cell phones, home routers, refrigerators, thermostats -- you name it. Michael DeGusta did a great infographic demonstrating this for Android phones in 2011 [1, 2]. Sadly, this hasn't materially changed in the eight years since. Just this year, Google added new terms to the Android license requiring security patches, but even then only for "popular devices." [3] Imagine those dynamics in the secondary and tertiary markets of printers and refrigerators.
As an industry, we've been to this rodeo before. The advancements we've made in operating system and core applications security over the last 20 years have more about patching speed and agility than shipping fewer bugs. However, those areas have backing and control from Apple and Microsoft, managing the end to end ecosystem. There is not a similarly equipped manufacturer of embedded operating systems with the scale to provide post-sale/post-deployment patching infrastructure.
Since this is Hacker News, I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over.
1 - https://theunderstatement.com/post/11982112928/android-orpha...
2 - img link is broken in his post, the graphic itself: http://media.theunderstatement.com/016a_android_orphans.png
3 - https://www.theverge.com/2018/10/24/18019356/android-securit...
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#44> D-Link last week told Fortinet’s FortiGuard Labs, which first discovered the issue in September, that all four of them are end-of-life and no longer sold or supported by the vendor First released in 2011, EOL in 2018. Can't say I blame 'em, EOL is EOL, but it's also the new planned obsolescence. (Better buy a new router every 7 years or the hackerman'll get ya!)
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#45What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.
Probably some low tier mikrotik. It's not for dummies though, it requires to know a bit of networking.
https://www.techrepublic.com/article/unpatched-vulnerability...
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#46Earlier quoted context omitted.
> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.
Somebody can conceivably receive significant financial damage though. Why they shouldn't be liable?
Not just financial damage, the owners of defective routers can be targets of criminal lawsuits if their connections are used as proxies for attacks, death threats, bank fraud, etc.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#47For national security sake all routers should be required to support open firmwares.
Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#48For national security sake all routers should be required to support open firmwares.
Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#49What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.
Probably some low tier mikrotik. It's not for dummies though, it requires to know a bit of networking.
Many QoL things that a consumer level router + TomatoUSB firmware does for you are either difficult to set properly set up (NAT reflection) or are not available at all (per-IP traffic accounting).
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#50Earlier quoted context omitted.
If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.
> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.
I find it regrettable that the architecture commonly in use does not make a clear distinction between devices for convenience and for security.
It’d be crazy if in our homes the main entrance lock always came as an afterthought in the package of all the inside doors, and we didn’t have an obvious way to replace it separately on our own.