Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

141–150 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#141
post #22

What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.

pfSense on an old computer and a UniFi AP.

If you want to level that up, use Proxmox with pfSense VM and any other junk you want to throw on it.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#142
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

I expect them to not sell devices at unmaintainable price-points.

You know, like tons of other safety-relevant products. Anything you plug into the wall, or put gas in, or has enough torque to hurt someone ends up going through safety checks.... except software.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#143
post #5

Until there is some legally required amount of time to provide security updates for connected devices, I would expect the "buy a new one if you want to be protected" response to continue indefinitely.

What do you expect from companies that sell kit at $50/£50/€50? You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase. Then again, I buy stuff that can be flashed with OpenWRT ...

Kits are different. Every router kit I've seen doesn't come with any software. Some come with a blank SD card and you can load what you want on it. Here's a tutorial I wrote for one kit I got:

https://battlepenguin.com/tech/using-the-banana-pi-bpi-r1-as...

but then I learned the hardware itself could fail into an insecure state, and there was no way to deal with it in software:

https://battlepenguin.com/tech/banana-pi-bpi-r1-fails-into-a...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#144
Since I have an ESX box with multiple NICs running 24x7 at home, I've been using both, pfSense [1] and OPNSense [2] on a VM for years, with excellent performance, stability and top notch features.

Combine that with 2 UniFi APs, multiple SSIDs each landing on separate VLANs, all converging on the router VM as separate "interfaces", so you can very selectively do policy-based routing per MAC address, and whitelist/blacklist IoT devices from accessing the Internet or specific sites. It gives you a huge amount of control that is very hard to do otherwise.

[1] https://www.pfsense.org/ [2] https://opnsense.org/

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#145
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

Until consumers are willing to spend on subscription services...

You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor.

In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases).

Where manufacturers, or as seems more likely given the industry concentration around sales points, retailers, are liable for the consequences of unfit-for-purpose devices and services, a reasonable set of minimum requirements (including life-of-product and update requirements) can be specified, then you might see a shift to some mix of time-of-sale plus subscription service pricing and payment models.

More likely you'll see devices bundled with services (which sometimes happens), though preferably in a far more user-friendly basis than is presently the case (e.g., cable service set-top boxes).

There's actually a long history of leased-equipment business in the IT sector, most notably as pioneered by IBM in the 1950s and 1960s.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#146
post #7

It's times like this i'm glad my home router is a x86 mini PC running Arch Linux + iptables + Unifi (Complete with DNS MITM forcing all DNS out of my apartment over TLS)

How to make a PC talk over a DSL cable? I assume a specialised chip would need to be plugged in at which point the potential for vulnerabilities of that PCB need to be considered...

Back when I had an ISP-provided cable modem I just put it into "modem mode" (disables NAT and all the builtin firewall and parental crap) and connected it via Ethernet

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#147
I tell everyone who will listen don't buy consumer networking gear. Buy from Ubiquity or get the enterprise routers/APs from your favorite brand. They are much more likely to be updated and don't really cost much more. Sure, it takes some know how to set up, but they can call me if they take my recommendations.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#148
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

As others pointed out JavaScript can try to access stuff but even more than that, the 400 apps on your phone, the 50 on your Mac and all your Steam games on your PC, all have full network access that JavaScript in the browser does not have. They can access every port, send corrupted packets, and scan your entire network for exploitable devices.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#149

Earlier quoted context omitted.

I'm not really sure there is enough evidence behind your assertion. Google wifi APs have got continuous updates from Sep. 2015 to current day. Sonos players have been continuously supported for 15 years. Apple's just-released OS runs on 7-year-old hardware. There are and have always been fly-by-night organizations that sell junk with bad software and no updates. That's not new, nor is the existence of reputable vendo…

All the brands you've cited are "luxury" brands whose proposition includes long-term support. It's a different market segment that doesn't refute GP's point.

i have a $30 netgear router from walmart that has gotten security updates for at least three years

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#150

Earlier quoted context omitted.

I'm not really sure there is enough evidence behind your assertion. Google wifi APs have got continuous updates from Sep. 2015 to current day. Sonos players have been continuously supported for 15 years. Apple's just-released OS runs on 7-year-old hardware. There are and have always been fly-by-night organizations that sell junk with bad software and no updates. That's not new, nor is the existence of reputable vendo…

I’m not going to be hacked because of my Apple TV or my google Wifi router; it’s going to be my light switch that does me in.

Your Apple TV runs 3rd party apps, any of which could be hacking you.
Post reply on HN