Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

231–240 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#231
post #89

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

Until consumers are willing to spend on subscription services... You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor. In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases). Where manufacturers, or as…

As soon as warranty/support expires, the device must be free for DRM/reverse-engineering. This will incentivize manufacturers to offer longer support.

Edit: Rather they should actually provide the spec, drivers etc

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#232
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

ASUSWRT is based on (and contributes to?) openWRT

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#233
post #89

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

Until consumers are willing to spend on subscription services... You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor. In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases). Where manufacturers, or as…

[deleted]

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#234
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

> Until consumers are willing to spend on subscription services...

Ok, I’m willing. Where do I sign up?

Which manufactures are offering this service for residential grade equipment?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#235
post #224
post #220

Earlier quoted context omitted.

See also the Charter lawsuit where it was revealed that Charter was renting very old equipment to their customers for years and didn't care.

AT&T didn't just come out and install a newer telephone because they had a newer model. If the equipment is fit for the service why replace it?

If you rent a $100 device at $10 a month for 10 years you end up paying $1200 and still not owning it.

I can see why consumers and consumer advocate groups don’t like this.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#236
post #231

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services... You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor. In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases). Where manufacturers, or as…

As soon as warranty/support expires, the device must be free for DRM/reverse-engineering . This will incentivize manufacturers to offer longer support. Edit: Rather they should actually provide the spec, drivers etc

There are a lot of routers using GPL code that have open source firmware available (ddwrt,openwrt,tomato,etc.) I think once support for a device ends it should be mandated that the company release the source code for future development.

There is a worrying increase in the amount of IoT devices that will remain forever unpatched due to the (cheap overseas) manufacturers never updating them or ending support for them.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#237
Another issue that could be avoided by using free software. Ideally D-Link would ship with free software so that the community can keep their gear working well. In practice something like OpenWRT may need to be installed by users, and depending on the hardware, support could be difficult.

If you're looking to be more careful in the future, I suggest only buying routers with OpenWRT support.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#239
post #174
post #90

Earlier quoted context omitted.

They were lemons at time of sale, though, we just didn't know it yet . Between that and the ecosystem/society argument, I think it's a no-brainer. > However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein? This analogy doesn't work for me; software bugs are defects , they aren't something getting old and fa…

The operative difference is that intelligent adversaries are not coming up with new and better methods of making your bumper fall off. The economics of providing 5 years of defensive patching on a $100 device simply does not work.

> The operative difference is that intelligent adversaries are not coming up with new and better methods of making your bumper fall off.

Not yet.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#240

Earlier quoted context omitted.

Those Espressif blobs are running on the same processor as the application/OS and are responsible for a lot more functionality than the typical radio firmware for a Broadcom/Qualcomm/Mediatek WiFi NIC that connects over PCIe. That firmware is also entirely different from the RF regulatory data I was talking about; the regulatory data should be in a ROM somewhere but the WiFi firmware generally needs to be stored alon…

Most routers have the SoC integrating the radio chip, and running firmware and the OS on the same silicon.

Wireless router SoCs usually have at most one radio integrated, and the 5Ghz radio is still usually attached over PCIe. And even the integrated 2.4Ghz radio's firmware is running on entirely separate processor cores and in a different memory address space from the application processor.
Post reply on HN