Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

131–140 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#131
post #99

Earlier quoted context omitted.

The FCC is certainly the problem in this case. If someone modifies the product to break the law the person is at fault not the manufacturer. That someone could do modify their radio to do bad things shouldn't stop me from modifying mine to do good things.

Would you also say that Uber doesn't violate taxi laws or AirBNB doesn't violate zoning laws, and it's just the Uber drivers and AirBNB hosts who are using the products to violate the law? What's your responsibility when you hand someone a loaded gun and it goes off?

> What's your responsibility when you hand someone a loaded gun and it goes off?

Zero, as long as the person:

(1) Knew it was loaded

(2) Voluntarily accepted to receive the gun.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#133

Schneier has recently argued that there is a missing market for IOT security in the sense that devices manufacturers have no incentive to patch impose external costs on society, and that this might be hard to fix without regulation. https://www.eweek.com/security/ibm-s-schneier-it-s-time-to-r...

Also - his recent book "Click Here to Kill Everybody" discusses the problem of IoT security in depth (ie. that the lack of it will risk increasingly dire consequences). One of his solutions is regulatory: a new federal agency for consumer cybersecurity. One of the particular things he would want mandated is that IoT devices be patchable, at a minimum.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#134
post #124

Earlier quoted context omitted.

Companies seem to be doing a pretty good job of shipping broken software today without the perverse incentive of a subscription. Companies do buy subscriptions for older software even though they may only be getting security fixes at this point. That said, I do think bundling longer-term updates into the cost is better insofar as it means buyers don't get a choice to just use the unpatched software. But it does mean…

> But it does mean that companies can cut costs by just not patching software at all or for a short period (as today). Sure. Hence the use of a very big stick. The lack of restraint on bad actors is a societal problem, not an economic one.

Of course, it's a big stick for both vendors and users. Vendors need to patch the software for N years (or whatever) and, given a competitive market, users have to pay for it.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#135
post #7

It's times like this i'm glad my home router is a x86 mini PC running Arch Linux + iptables + Unifi (Complete with DNS MITM forcing all DNS out of my apartment over TLS)

How high-touch is this kind of setup? I have a separate access point and I am using a consumer-grade "wireless router" for DHCP. (and other things?) I'm more of an app developer that does DevOps stuff when I have to. Is this something I can get done in a day or so? Is a Raspberry Pi enough, or do I need something more powerful?

Low touch once it's working, but took me forever to get right. I recently added wireguard + policy based routing + a second route table + a VLAN so that all devices connected to a secondary wireless SSID are NAT'd to the Internet over a VPN. I don't know how you'd accomplish this with anything consumer, or even anything semi-Enterprise.

The primary motivation for that one is that native wireguard (UDP) is blocked by several wireless networks I use on the move. So on those networks I have to use a shitty OpenVPN configuration over tcp port 443. OpenVPN on Android is buggy and prone to crash all the god damn time. Now, at home at least, I don't have to suffer it.

The device I use has a metal case, is fanless/noiseless, the size of an AP, has 4 gigabit ports, 4 x86-64 Bay Trail cores, 8GB of RAM, runs standard Linux, and cost me like $150. Honestly I'm done with plastic off-the-shelf crap.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#136
post #99

Earlier quoted context omitted.

The FCC is certainly the problem in this case. If someone modifies the product to break the law the person is at fault not the manufacturer. That someone could do modify their radio to do bad things shouldn't stop me from modifying mine to do good things.

Would you also say that Uber doesn't violate taxi laws or AirBNB doesn't violate zoning laws, and it's just the Uber drivers and AirBNB hosts who are using the products to violate the law? What's your responsibility when you hand someone a loaded gun and it goes off?

When a router ships you can't select a licensed band. This is a different concept than "product does something bad" this is "is the manufacturer responsible when someone modifies the product to do something bad".

Clearly not, the person that knowingly modified it to do something illegal is at fault. Preventing anyone from modifying anything is a backwards response to the real problem: the guy that wants to do the illegal thing.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#137
post #89

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

>Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet. Nope. Not at all. Most router attacks these days are malicious JavaScript (like in ads and trackers) that send H…

Would this not also require some sort of exploitable CORS vulnerability?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#139

Earlier quoted context omitted.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

The damage from an unpatched router can be pretty far-reaching, especially in cases where it can be exploited over Internet (not sure about this one, but some other D-Link vulnerabilities reportedly could). I find it regrettable that the architecture commonly in use does not make a clear distinction between devices for convenience and for security. It’d be crazy if in our homes the main entrance lock always came as a…

The front door lock is actually a bad example: in single-family houses, the front door is a social and legal signifier more than it is a security device. Smash a window; go around back; use a crowbar: the lock isn't what's keeping you out, it's designating the social expectation that you don't have a right to be there without an invitation and the legal assertion that crossing the threshold violently is a bigger crime than wandering in absently.

This case is more like a golf cart being sold as a car: it's technically usable for that, but lacking any sort of safety or weather protection.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#140
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

The Nerves Project is positioning itself to address this well.
Post reply on HN