Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

41–50 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#41

For national security sake all routers should be required to support open firmwares.

Not exactly what you’re asking for, and it has its own problems [0], but the US military has a “trusted foundry program” [1] for sourcing chips. [0] https://semiengineering.com/a-crisis-in-dods-trusted-foundry... [1] https://en.m.wikipedia.org/wiki/Trusted_Foundry_Program

Is there an equivalent of the Trusted program in Europe? I know of a bunch of companies capable of manufacturing chips, like STM, but because of the scattered nature of europe, I don't know how euro militaries handle this issue, specially Airbus.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#42
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

What do I expect or what does a typical consumer expect? The folks on HN are not typical consumers of these products.

Often times when defective products are sold there is some responsibility for some time to correct or notify people. Cars, child seats, and many other things fall into that.

The defective devices that get updates or notifications are often safety related. Yet, safety and security are not talked about much with regard to technology. Maybe it's time to start doing that.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#43
This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models.

This applies to every "connected device:" printers, cell phones, home routers, refrigerators, thermostats -- you name it. Michael DeGusta did a great infographic demonstrating this for Android phones in 2011 [1, 2]. Sadly, this hasn't materially changed in the eight years since. Just this year, Google added new terms to the Android license requiring security patches, but even then only for "popular devices." [3] Imagine those dynamics in the secondary and tertiary markets of printers and refrigerators.

As an industry, we've been to this rodeo before. The advancements we've made in operating system and core applications security over the last 20 years have more about patching speed and agility than shipping fewer bugs. However, those areas have backing and control from Apple and Microsoft, managing the end to end ecosystem. There is not a similarly equipped manufacturer of embedded operating systems with the scale to provide post-sale/post-deployment patching infrastructure.

Since this is Hacker News, I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over.

1 - https://theunderstatement.com/post/11982112928/android-orpha...

2 - img link is broken in his post, the graphic itself: http://media.theunderstatement.com/016a_android_orphans.png

3 - https://www.theverge.com/2018/10/24/18019356/android-securit...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#44

> D-Link last week told Fortinet’s FortiGuard Labs, which first discovered the issue in September, that all four of them are end-of-life and no longer sold or supported by the vendor First released in 2011, EOL in 2018. Can't say I blame 'em, EOL is EOL, but it's also the new planned obsolescence. (Better buy a new router every 7 years or the hackerman'll get ya!)

Apple Time Capsules [0] released in 2011 received an update last June 2019 [1] despite being also discontinued in 2018.

[0]: https://en.wikipedia.org/wiki/AirPort_Time_Capsule

[1]: https://support.apple.com/kb/DL2008?locale=en_US

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#45
post #29
post #22

What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.

Probably some low tier mikrotik. It's not for dummies though, it requires to know a bit of networking.

Mikrotik has had quite a bit of security issues, too.

https://www.techrepublic.com/article/unpatched-vulnerability...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#46

Earlier quoted context omitted.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

Somebody can conceivably receive significant financial damage though. Why they shouldn't be liable?

> Somebody can conceivably receive significant financial damage though. Why they shouldn't be liable?

Not just financial damage, the owners of defective routers can be targets of criminal lawsuits if their connections are used as proxies for attacks, death threats, bank fraud, etc.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#47
post #27

For national security sake all routers should be required to support open firmwares.

Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…

Really it seems like the radio ASICs themselves should be adding a little bit of embedded flash or OTP memory. But barring that, as the storage requirements of routers increase (having already moved from NOR to NAND flash) we may eventually reach the point where a router includes a BGA SSD whose controller can enforce permanent read-only permissions on a partition that stores RF parameters.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#48
post #27

For national security sake all routers should be required to support open firmwares.

Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…

1. FCC has only started to require home router manufacturers to prevent users from modifying transmit settings some years ago, we have lived quite long without this ban and had no problems it is supposed to prevent. 2. Put detailed transmit settings modifying tool right in the web UI of default firmwares of all the routers and you'll see just a negligible portion of the userbase ever touching it. Most of the people don't even know what a megahertz is, let alone have any clue on how to tweak transmit settings for any kind of benefit.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#49
post #29
post #22

What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.

Probably some low tier mikrotik. It's not for dummies though, it requires to know a bit of networking.

I'm generally happy with my RB3011 but you are very much correct that it isn't meant for a typical end user.

Many QoL things that a consumer level router + TomatoUSB firmware does for you are either difficult to set properly set up (NAT reflection) or are not available at all (per-IP traffic accounting).

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#50
post #20

Earlier quoted context omitted.

If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

The damage from an unpatched router can be pretty far-reaching, especially in cases where it can be exploited over Internet (not sure about this one, but some other D-Link vulnerabilities reportedly could).

I find it regrettable that the architecture commonly in use does not make a clear distinction between devices for convenience and for security.

It’d be crazy if in our homes the main entrance lock always came as an afterthought in the package of all the inside doors, and we didn’t have an obvious way to replace it separately on our own.

Post reply on HN