Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

241–250 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#241
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> Can you provide an “enterprise class embedded OS” to device manufacturers and address post-deployment updates?

How about Microsoft’s Azure Sphere Linux/cloud product with “10-year lifetime” support?

> Azure Sphere will feature a turnkey cloud security service that guards every Azure Sphere device, including the ability to update and upgrade this security protection for a 10-year lifetime of the device.

https://blogs.microsoft.com/blog/2018/04/16/using-intelligen...

Samples: https://github.com/Azure/azure-sphere-samples

Pricing, with support through July 2031: https://azure.microsoft.com/en-ca/pricing/details/azure-sphe...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#242
post #89

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

> Until consumers are willing to spend on subscription services... Ok, I’m willing. Where do I sign up? Which manufactures are offering this service for residential grade equipment?

There is none. Everyone should have a Meraki security appliance in their home.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#243
post #224
post #220

Earlier quoted context omitted.

See also the Charter lawsuit where it was revealed that Charter was renting very old equipment to their customers for years and didn't care.

AT&T didn't just come out and install a newer telephone because they had a newer model. If the equipment is fit for the service why replace it?

I should have said they were renting very old and inadequate equipment; it wasn't fine and they knew it.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#244
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> Can you provide an “enterprise class embedded OS” to device manufacturers and address post-deployment updates? How about Microsoft’s Azure Sphere Linux/cloud product with “10-year lifetime” support? > Azure Sphere will feature a turnkey cloud security service that guards every Azure Sphere device, including the ability to update and upgrade this security protection for a 10-year lifetime of the device. https://blog…

Azure Sphere looks awesome but they need more SoC models for different use cases.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#245

Earlier quoted context omitted.

>"Today's manufacturers cannot afford to update software for hardware devices they have already moved on from." What is this statement based on? None of your links show any kind of unit economics that support the assertion that providing critical security patches for a defined support window is infeasible for manufactures and their business models.

I agree wholeheartedly, and outright reject the premise of the original statement. This is a choice that they make. Yes, having a legacy support team is going to cost a bit of money, but not a ridiculous amount. Maybe instead of having a ridiculous number of barely-differentiated SKUs, they could lighten the support burden a bit by making a smaller number of solid well-supported models. Edit: also, basing the models…

basing the models on a common platform would help too. I assume they generally do this already, but if not...

They don't, because they save a few dollars by re-bidding each product. So each company is shipping a random assortment of Broadcom, Marvell, and Qualcomm reference designs, all running incompatible software stacks.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#246
post #245

Earlier quoted context omitted.

I agree wholeheartedly, and outright reject the premise of the original statement. This is a choice that they make. Yes, having a legacy support team is going to cost a bit of money, but not a ridiculous amount. Maybe instead of having a ridiculous number of barely-differentiated SKUs, they could lighten the support burden a bit by making a smaller number of solid well-supported models. Edit: also, basing the models…

basing the models on a common platform would help too. I assume they generally do this already, but if not... They don't, because they save a few dollars by re-bidding each product. So each company is shipping a random assortment of Broadcom, Marvell, and Qualcomm reference designs, all running incompatible software stacks.

> random assortment of Broadcom, Marvell, and Qualcomm reference designs, all running incompatible software stacks

How... what... c'mon! You're totally right [1], and even within similar model numbers (e.g. the DIR-300 B-series uses Ralink chips, but the DIR-330 uses Broadcom). Yeesh.

Well... I guess I'll just keep on picking devices supported by OpenWRT and not rely on vendor firmware at all. Yuck.

[1] https://openwrt.org/toh/start?dataflt%5BBrand*~%5D=d-link

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#247

We don’t have cable or a phone line, so I recently bought a D-Link router with a 4G SIM card slot and a massive yearly data plan that corresponds to the approx. amount of data I use yearly at home as a light non-streaming user (400gb at approx. $1 per gb). I’m open to hardware suggestions that are/more open source capable or robust in the first place, but my use case was really niche and the shop(s) had nearly nothin…

Mikrotik has an interesting outdoor LTE router (although I couldn't find anywhere reputable to buy it in the US). You could also get a USB or MiniPCIe modem and put it in whatever Linux box you want.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#248
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> Today's manufacturers cannot afford to update software for hardware devices they have already moved on from.

Well, they could (D-link has millions), but they won't because it would eat into their obscene profits.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#249
post #182

Earlier quoted context omitted.

There is an even better solution. Simply use open source firmware on these devices and this will not be an issue. It's much less effort to maintain one common firmware rather than a new one for every device.

Some subset of the code may be common. A lot of code that is specific to a particular device won't be. I'm actually open to the idea that vendors could benefit from working with open source firmware and differentiate in other ways. But "use open source" doesn't magically reduce the effort. They probably already have core software bases that they don't need to change all that much for new devices.

If they used open source the drivers could be mainlined and then you really could just drop one standard OS on it

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#250
post #191

Earlier quoted context omitted.

> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.

How long do vehicle recalls last for, if something like an airbag turns out to be defective and dangerous?

You want to equate a consumer electronics device with an incendiary device legally mandated to be installed in every vehicle that may explode and kill people?

Well, the legal answer is 10-years for a no-charge repair [0].

If D-Link routers start burning down homes I'm sure the Consumer Product Safety Commission will take an interest, but if it's more than a few years old the recommendation will likely be to throw it out and buy a replacement.

[0] https://www-odi.nhtsa.dot.gov/recalls/recallprocess.cfm

Post reply on HN