Earlier quoted context omitted.
In an hospital, someone could die from a hacked device.
I should really, really hope hospitals are not using routers like these.
D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
121–130 of 306 posts
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#122Earlier quoted context omitted.
Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…
Most routers I've seen have a setting to enable "remote management". The DIR 655 does (see pg. 75 of its manual). If you have enabled that, then its login page is accessible via the Internet. Many small businesses not only have unprotected file shares, and have remote admin turned on so that their IT person can administer the router remotely (as silly as it is). I saw this so many times when I worked in IT. People ma…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#123Earlier quoted context omitted.
What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...
Xiaomi sells routers in this price range that ship with OpenWrt. The buildroot even has config options for branding! It costs them nothing for the OS. It costs D-Link more to produce their mess.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#124Earlier quoted context omitted.
Right. There are differences in incentives and how easy it is to make receiving updates mandatory or the default. But it's reasonable to assume that, however implemented and legislated, everyone ends up--from a financial perspective--having to pay for an ongoing support subscription.
Can you explain to me how a subscription, for which only subscribers get fixes, is not a perverse incentive to ship broken software? Normal software has an argument towards subscriptions if it's adding features. But routers shouldn't be adding features. Routers should be fixing bugs .
Companies do buy subscriptions for older software even though they may only be getting security fixes at this point.
That said, I do think bundling longer-term updates into the cost is better insofar as it means buyers don't get a choice to just use the unpatched software. But it does mean that companies can cut costs by just not patching software at all or for a short period (as today).
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#125Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#126Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#127Earlier quoted context omitted.
Can you explain to me how a subscription, for which only subscribers get fixes, is not a perverse incentive to ship broken software? Normal software has an argument towards subscriptions if it's adding features. But routers shouldn't be adding features. Routers should be fixing bugs .
Companies seem to be doing a pretty good job of shipping broken software today without the perverse incentive of a subscription. Companies do buy subscriptions for older software even though they may only be getting security fixes at this point. That said, I do think bundling longer-term updates into the cost is better insofar as it means buyers don't get a choice to just use the unpatched software. But it does mean…
Sure. Hence the use of a very big stick.
The lack of restraint on bad actors is a societal problem, not an economic one.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#128Earlier quoted context omitted.
> This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. Ubiquiti has a number of CVEs and has addressed them in a timely manner, IMHO. If you’re buying t…
Ubiquiti isn't really consumer, though. They want to target enterprises and businesses. Sure, their hardware ends up in residential deployments more often than perhaps any other kind of enterprise computer stuff, but if you're not willing to call them "enterprise", I'm going to insist they be practically alone in their own category of "pro-sumer but actually professional-consumer, and not the yuppie garbage that you…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#129This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…
I'm not really sure there is enough evidence behind your assertion. Google wifi APs have got continuous updates from Sep. 2015 to current day. Sonos players have been continuously supported for 15 years. Apple's just-released OS runs on 7-year-old hardware. There are and have always been fly-by-night organizations that sell junk with bad software and no updates. That's not new, nor is the existence of reputable vendo…
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#130Am I correct that this allows administrator access to the router, but requires connecting to the router's network (either via having the WiFi password or having physical access)?
IIRC, the DIR-655 is also stuck on WPA2, which was broken, so the WiFi password doesn't offer any protection either. In which case, anyone within range of the access point could access the admin panel.
On one hand, this sucks because aside from these vulnerabilities, the DIR-655 works fine. On the other hand, I think I bought it over a decade ago.