Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

221–230 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#221
post #106
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

Mikrotik or Ubiquiti. My >10yo hardware still receives updates (latest version, not a few backported changes).

Both tend to pick pretty well-understood and supported SoCs. Large consumer brands are more cost-conscious and use cheaper chips with more custom work to support them, and the custom work ends up being buggier. IIRC, Ubiquiti started out by being based on OpenWRT. Not sure if they still are.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#222
post #215

Earlier quoted context omitted.

> not less than 10 years: they should update it to work > get dlink to pay your costs What happens when the company is gone?

For DLink, you're out $20-$100. What happens when Tesla is gone?

You get out your Tesla shop manual, diagnose the problem, order 3rd party replacement parts and fix your car yourself.

(wakes up from dream)

crap.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#223
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Partly to your point, Buffalo was using DD-WRT for their wireless routers [1]. I have two of them at home, updated to the latest LEDE/OpenWRT. They're mostly fine [2]. Buffalo's support was not great,…

I think there are other brands that allow openwrt, such as the linksys wrt ac series:

https://openwrt.org/toh/linksys/wrt_ac_series

Their support for the first models in the beginning was a little spotty, but I think they are great systems now

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#224
post #220

Earlier quoted context omitted.

Ma Bell was leasing telephones since the days of Alexander Graham Bell. In fact you weren't allowed to use any telephone except one leased from your telco until the breakup of the Bell System in the 80s. Not sure that is what we want to go back to.

See also the Charter lawsuit where it was revealed that Charter was renting very old equipment to their customers for years and didn't care.

AT&T didn't just come out and install a newer telephone because they had a newer model. If the equipment is fit for the service why replace it?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#225
post #218

Earlier quoted context omitted.

> but live in our homes for three to five years I have a wrt54g that's 10+ years old running at my grandma's house...and running dd-wrt because no one making APs 10 years ago, and even now, was that good at security and stability. What's telling is that the hardware is the part that still works, and I bet part of it is that software fixes are easier than hardware, so you can get away with lower quality software.

I think that's a great idea (I run openwrt) However - I have to ask - have you upgraded her dd-wrt?

I check in on it once a year, or so. It's not really enough, but the hardware's so limited, I don't think there are many changes getting made to it, anymore.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#226
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

I see your point but I overpay for the iPhone I’m typing this on partly for that upgrade service. It is also something I appreciate about the Tesla as opposed to every other car I’ve ever had.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#227
post #188
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Ubuntu is already doing this: https://ubuntu.com/internet-of-things For Linux distributions, security updates and maintenance are a solved problem. Ubuntu adds to this a read-only filesystem with atomi…

I've been looking forward to seeing Canonical's adoption in IoT getting better and better. Here's to hoping.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#228
post #45
post #29

Earlier quoted context omitted.

Probably some low tier mikrotik. It's not for dummies though, it requires to know a bit of networking.

Mikrotik has had quite a bit of security issues, too. https://www.techrepublic.com/article/unpatched-vulnerability...

But they patch stuff, and afaik everyone gets the update.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#230

Schneier has recently argued that there is a missing market for IOT security in the sense that devices manufacturers have no incentive to patch impose external costs on society, and that this might be hard to fix without regulation. https://www.eweek.com/security/ibm-s-schneier-it-s-time-to-r...

Canonical's pushing for a change in this space with their own embedded IoT OS.

https://techerati.com/news-hub/canonical-releases-ubuntu-cor...

Post reply on HN