Earlier quoted context omitted.
> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.
How long do vehicle recalls last for, if something like an airbag turns out to be defective and dangerous?
D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
291–300 of 306 posts
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#292Earlier quoted context omitted.
AT&T later in its history, 1960s - 1970s, offered the option of uplines (touch-tone, "Streamline", "Princess", and eventually Mickey Mouse telephones) as service upgrades. So there wasn't no interest in innovation, though I'd agree with the general view that the interest was low .
None of those were real technical improvements over the 500/2500 set however, they were upgrades designed to please the customer aesthetically. Meaning, all of those sets performed more or less (in some cases less, specifically in certain special service applications) identically to a 2500/500, and at least one of those was a 2500 in a mouse shaped box. Touch-Tone was actually a value add for the telco because it red…
I'm really not going to try to defend AT&T's specific level of innovation.
I'm noting, however, that the possibility of offering a range of hardware at a range of price levels and allowing for volitional subscriber updates is possible, and was practiced.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#293Earlier quoted context omitted.
Some subset of the code may be common. A lot of code that is specific to a particular device won't be. I'm actually open to the idea that vendors could benefit from working with open source firmware and differentiate in other ways. But "use open source" doesn't magically reduce the effort. They probably already have core software bases that they don't need to change all that much for new devices.
The thing is that for a new device you only need hardware enablement in the kernel - something largely one off that manufacturers can do in the same cadence as device sales so their priorities align. What should be happening is that the FCC / international communications bodies should be directly funding a project like OpenWRT and using regulation to compel device manufacturers seeking approval by the bureau to submi…
The exact opposite is what actually happened. In late 2016, the FCC specifically banned owner-based firmware upgrades[0]. It was ostensibly due to RF configuration, it could also be seen as a concession to the manufacturers.
0 - https://hackaday.com/2016/02/26/fcc-locks-down-router-firmwa...
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#294I think there is a simple solution: if the seller doesn't support it, then they have to open source it. Own (key word) an old RPG that won't run because the publisher decided the servers were no longer profitable? RPG gets opened sourced. Have a John Deer remote operated tractor that John Deer won't fix a bug that allows attackers to operate remotely? John Deer's tractor software gets open sourced. No support? No leg…
Then the problem gets moved to encryption keys, which aren't part of the "open source". All the code's there - you just don't have the right to change it!
Full access to the device you own, signing keys and all.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#295Earlier quoted context omitted.
At one "legal training" class our lawyers said that there is the potential that we could be required to recall and fix any product we have ever made. We have machines we made in the 1950s that are still regularly used for the purpose they were bought for, but without modern safety standards. We believe we can argue in court that the modern safety devices didn't even exist back then so we shouldn't have to update thos…
> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#296Earlier quoted context omitted.
>Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet. Nope. Not at all. Most router attacks these days are malicious JavaScript (like in ads and trackers) that send H…
Would this not also require some sort of exploitable CORS vulnerability?
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#297Earlier quoted context omitted.
If you want a less touchy solution (not completely plug and play though!) I can't recommend Ubiquiti products enough. I run an EdgeRouter X and Unifi AP at home. Not big enterprise gear but way more enterprisey than whatever you'll find on the shelf at Best Buy. Updates are released regularly and once you get your initial configuration done they just chug along, no random 'internet is down, need to reboot something'…
What WAN throughput can you get on an Edgerouter X with moderate Firewall and some basic QoS rules enabled?
I think you can find some better info with a search though.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#298Earlier quoted context omitted.
Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…
> Until consumers are willing to spend on subscription services... Ok, I’m willing. Where do I sign up? Which manufactures are offering this service for residential grade equipment?
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#299Earlier quoted context omitted.
> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.
In my jurisdiction, consumer device must have "reasonable lifetime" by law. This lifetime of course is not to be determined by the manufacturer, but by the courts in the event of a disagreement. Ten years is bit long, but it's not absurd to think (i.e. reasonable) it should work ten years after the time of purchase even if the technology becomes obsolete.
An original iPad isn't even 10 years old and is many years past being able to run an iOS version that receives security updates. A 10 year old MacBook Pro is a few years beyond having a supported OS with security updates. Cisco, with a support contract on actual Enterprise gear, offers up to 5 years from the end-of-sale date and do not actually promise to provide security updates for that whole period.
To expect a $50 junk router to provide an industry-leading support lifecycle is absurd.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#300Earlier quoted context omitted.
> This is the new normal, folks. Consumer technology is manufactured for six to twelve months. Not completely true. For example, just something I discovered recently is that some e-book readers have very long lifespan if you look inside and ignore the battery. There's not even an electrolytic or tantalum capacitors there. Really nothing that will expire. If you don't kill it mechanically, these will survive for 10 ye…
What model is that?
But I hope people will buy second-hand or broken + replacement display instead of supporting the company and buying new, if they want to play with it. They don't really deserve any support for abusing the free work of others and violating the GPL license.