Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

81–90 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#81
post #58

Earlier quoted context omitted.

Cheaper and older alternative is the Ubiquity Unifi Security Gateway + 8 port switch + UAC AP-PRO if you don't want the Edgerouter X cost. Less customizeable but if you're buying an EdgeRouter you know what you want.

how does power consumption compare with a setup like this vs some consumer all-in-one thing?

to be honest, most routers like this have very low power usage. I think an edgerouter X has a power consumption of something like 5W under load.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#82
post #27

For national security sake all routers should be required to support open firmwares.

Open source software on routers is a little complicated. FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-…

The FCC is certainly the problem in this case. If someone modifies the product to break the law the person is at fault not the manufacturer. That someone could do modify their radio to do bad things shouldn't stop me from modifying mine to do good things.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#83
post #18

Earlier quoted context omitted.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

$50 honestly seems expensive considering how long home routers have been around. It's not as if it's novel technology. I'd expect cheap mass-produced routers to be around $15 - $25, like an immersion blender.. I don't quite understand why cheap ones are still $40-$60.

They are that cheap... e.g. Microcenter has models in the $15-$25 range. They're pretty much at the too cheap to not work level as they can't afford to develop complex, bloated features at that price point.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#84

I have a D-Link DIR-655 (which is on this list) as my home router. Ironically, I was going to replace it a few months ago, but the speed is still fast enough for my network. A few posts mentioned installing a different (open source) firmware. But, both OpenWrt and DD-Wrt aren't compatible. Am I missing another option? As an aside, can anyone recommend a wifi router that runs either OpenWrt or DD-Wrt well, for $100-$1…

Works very well for me:

https://www.amazon.com/Linksys-AC1900-Source-Wireless-WRT190...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#85
post #16

I'm aware of the "but what if the router is connected to an ICU bed? A patient's life depends on it!" straw man but let's be honest, it would only be the ICU's admin fault. Having sorted this out, let me clearly state that the only ethical solution is to brick these devices offline.

i hope an intensive care unit doesn't really on a bottom of the barrel consumer device for their network reliability.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#86

I have a D-Link DIR-655 (which is on this list) as my home router. Ironically, I was going to replace it a few months ago, but the speed is still fast enough for my network. A few posts mentioned installing a different (open source) firmware. But, both OpenWrt and DD-Wrt aren't compatible. Am I missing another option? As an aside, can anyone recommend a wifi router that runs either OpenWrt or DD-Wrt well, for $100-$1…

You aren't missing another option. The 655 is based on an exotic architecture (Ubicom32) that never had the specs released for it to develop 3rd party firmware. Its why I trashed my 655 years ago.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#87
> D-Link last week told Fortinet’s FortiGuard Labs, which first discovered the issue in September, that all four of them are end-of-life and no longer sold or supported by the vendor (however, the models are still available as new via third-party sellers).

OK, let's say I am someone who actually knows "end-of-lifed" is a thing, and a thing you don't want...

How would I check to see if a certain router was end-of-lifed before buying it?

If I can figure that out, and I know it's not end-of-lifed, is there any way for me to see how much time is left in it's life before it's end-of-lifed, how would I check to make sure a router I was buying woudln't become end-of-lifed tomorrow, or next week, but has, say, a year or two of supported life left at least.

Obviously, what D-Link is counting on is that most customers won't know that this is even a thing, wont' know what questions to ask, won't realize their router is end-of-lifed, won't realize their router is vulnerable, won't realize it if their router gets hacked, and it wont' effect their likelyhood of buying another D-link router or telling others to. It's not that they think this kind of support is going to be considered acceptable to their customers -- it's that they think their customers won't even be able to figure out what kind of support or security they are getting, mostly won't even realize this is even a question to ask.

And they're probably right.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#88
post #76

Earlier quoted context omitted.

Medical equipment more and more often has networked embedded software that can't be updated. They won't throw away a multimillion-dollar device just because it can't be upgraded from Windows XP.

I'll bet they still have service agreements for those devices though, even if the software is old. Consumer routers do not have support like that.

Oh, yes, they're usually still serviced- the systems are babied and locked down and generally taken care of, and if Microsoft releases an emergency XP patch I expect it would be applied. Still, there's a lot of old stuff floating around since medical hardware can last a lot longer than an OS support lifetime.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work.

Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet.

So they'd have to physically drive around looking for these three specific D-Link routers.

And then what would they get out of a successful exploit? Access to your network's traffic and unprotected file shares (most people don't even have any file shares), and even that level of access will be rather useless for getting important information like bank credentials (protected by HTTPS).

Am I wrong about any of this?

A lot of non-technical people use old Android phones, old printers, etc, and never experience any serious security breach. Some of them do experience a security breach, but it's far more likely to happen in a social exploit (phishing, whaling, etc) or institutional breach (your reused password being breached from a database hack of a popular website). In a lot of ways, ignorance is bliss.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#90
post #80
post #72

Earlier quoted context omitted.

> the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.

They're not necessarily lemons at the time of sale though. In general, we don't legislate that products need to upgraded and maintained after they're sold. (Yes, there are lemon laws and warranty requirements for defects--which are at least related.) However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein?…

They were lemons at time of sale, though, we just didn't know it yet. Between that and the ecosystem/society argument, I think it's a no-brainer.

> However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein?

This analogy doesn't work for me; software bugs are defects, they aren't something getting old and falling apart. I think that a defect in an automobile should be repaired at manufacturer expense whether it's a year old or twenty.

Post reply on HN