Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

101–110 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#101
post #78
post #72

Earlier quoted context omitted.

> the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.

It drives prices up in equivalence with subscription pricing over the typical lifespan. (i.e. not obviously better or worse)

Subscriptions are ongoing cash-flow. There's no reward to doing a good job, and there's only a perverse reward to not doing a good job--it keeps people subscribed.

Frankly I think the better option might actually be the reverse: a mandatory payout to every customer for every nontrivial security defect. Not sure how you'd adjudicate it, so it's pie-in-the-sky, but take it out of the realm of the class-action lawsuit and see how serious these manufacturers become about correctness.

Businesses fear only the big stick; it should be swung on the consumer's behalf.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#102
post #79
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. Ubiquiti has a number of CVEs and has addressed them in a timely manner, IMHO. If you’re buying t…

Ubiquiti isn't really consumer, though. They want to target enterprises and businesses.

Sure, their hardware ends up in residential deployments more often than perhaps any other kind of enterprise computer stuff, but if you're not willing to call them "enterprise", I'm going to insist they be practically alone in their own category of "pro-sumer but actually professional-consumer, and not the yuppie garbage that you usually call pro-sumer that's just the normal consumer crap but priced at 4x with a slick black plastic case."

I agree with GP in that the spectrum you are suggesting ("you get what you pay for" actually looks more like this:

----------- ----[huge $$$ gap]-----

Which I would reify into the realm of, for example, computer hardware, as follows:

--------- ---------------

The best buy laptop and the alienware desktop are going to have the same issues with regards to control and privacy, and you need to make a huge jump to get to anything remotely respecting you.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#103
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

>"Today's manufacturers cannot afford to update software for hardware devices they have already moved on from."

What is this statement based on? None of your links show any kind of unit economics that support the assertion that providing critical security patches for a defined support window is infeasible for manufactures and their business models.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#104
post #7

It's times like this i'm glad my home router is a x86 mini PC running Arch Linux + iptables + Unifi (Complete with DNS MITM forcing all DNS out of my apartment over TLS)

I do something similar. Fanless PC (but I do have a heppa filter pointed at it for hot days) running CentOS 7 and El-Repo 5.2.x kernel. I enable power management on everything except for the network cards and disable most other devices on it. On UPS it can run about 3 hours.

I have unbound DNS and iptables to intercept all DNS requests destin for the internet, so I can block some ads. I null route the DoH servers and some hostile countries. Works great.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#105
post #74
post #65

Earlier quoted context omitted.

>anyone who can address that problem If no one addresses this problem, regulations will be imposed.

Do you think it’s possible to regulate all of the internet connected consumer devices coming from China? Routers, WiFi lightbulbs, toasters, etc?

Of course it is. Nations regulate lots of imported goods, from foodstuffs to cars. Nations also have the power to impound cargo deliveries if the importer is notorious for not validating that their cargo is compliant with local regulations.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#106
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

Mikrotik or Ubiquiti. My >10yo hardware still receives updates (latest version, not a few backported changes).

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#107
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

androidauthority.com has been pretty good about tracking this more recently:

Android Oreo: https://www.androidauthority.com/android-oreo-fastest-manufa...

Android Pie: https://www.androidauthority.com/android-pie-fastest-manufac...

Then they put out this weird update: https://www.androidauthority.com/counterpoint-android-update...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#108
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

Ubiquiti does really nice. It is not a "here is a pizza box device that does internet" device though.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#109
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

I'm not really sure there is enough evidence behind your assertion. Google wifi APs have got continuous updates from Sep. 2015 to current day. Sonos players have been continuously supported for 15 years. Apple's just-released OS runs on 7-year-old hardware. There are and have always been fly-by-night organizations that sell junk with bad software and no updates. That's not new, nor is the existence of reputable vendo…

All the brands you've cited are "luxury" brands whose proposition includes long-term support.

It's a different market segment that doesn't refute GP's point.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#110
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

Most routers I've seen have a setting to enable "remote management". The DIR 655 does (see pg. 75 of its manual). If you have enabled that, then its login page is accessible via the Internet.

Many small businesses not only have unprotected file shares, and have remote admin turned on so that their IT person can administer the router remotely (as silly as it is). I saw this so many times when I worked in IT. People make all sorts of assumptions about LAN privacy when setting up their network and devices.

Post reply on HN