Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

291–300 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#291
post #191

Earlier quoted context omitted.

> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.

How long do vehicle recalls last for, if something like an airbag turns out to be defective and dangerous?

Until all affected vehicles are fixed or scrapped. This works out to forever because it isn't practical to prove either. The law might allow less, but any smart company is going to have the above policy because you can pull it out in unrelated court cases to show that you care about safety and so whatever the current situation is doesn't warrant punitive damages.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#292
post #277

Earlier quoted context omitted.

AT&T later in its history, 1960s - 1970s, offered the option of uplines (touch-tone, "Streamline", "Princess", and eventually Mickey Mouse telephones) as service upgrades. So there wasn't no interest in innovation, though I'd agree with the general view that the interest was low .

None of those were real technical improvements over the 500/2500 set however, they were upgrades designed to please the customer aesthetically. Meaning, all of those sets performed more or less (in some cases less, specifically in certain special service applications) identically to a 2500/500, and at least one of those was a 2500 in a mouse shaped box. Touch-Tone was actually a value add for the telco because it red…

Thanks, yes, Trimline.

I'm really not going to try to defend AT&T's specific level of innovation.

I'm noting, however, that the possibility of offering a range of hardware at a range of price levels and allowing for volitional subscriber updates is possible, and was practiced.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#293
post #193
post #182

Earlier quoted context omitted.

Some subset of the code may be common. A lot of code that is specific to a particular device won't be. I'm actually open to the idea that vendors could benefit from working with open source firmware and differentiate in other ways. But "use open source" doesn't magically reduce the effort. They probably already have core software bases that they don't need to change all that much for new devices.

The thing is that for a new device you only need hardware enablement in the kernel - something largely one off that manufacturers can do in the same cadence as device sales so their priorities align. What should be happening is that the FCC / international communications bodies should be directly funding a project like OpenWRT and using regulation to compel device manufacturers seeking approval by the bureau to submi…

> What should be happening is that the FCC / international communications bodies should be directly funding a project like OpenWRT ...

The exact opposite is what actually happened. In late 2016, the FCC specifically banned owner-based firmware upgrades[0]. It was ostensibly due to RF configuration, it could also be seen as a concession to the manufacturers.

0 - https://hackaday.com/2016/02/26/fcc-locks-down-router-firmwa...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#294

I think there is a simple solution: if the seller doesn't support it, then they have to open source it. Own (key word) an old RPG that won't run because the publisher decided the servers were no longer profitable? RPG gets opened sourced. Have a John Deer remote operated tractor that John Deer won't fix a bug that allows attackers to operate remotely? John Deer's tractor software gets open sourced. No support? No leg…

Then the problem gets moved to encryption keys, which aren't part of the "open source". All the code's there - you just don't have the right to change it!

I don't mean that the code is merely published.

Full access to the device you own, signing keys and all.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#295
post #191
post #71

Earlier quoted context omitted.

At one "legal training" class our lawyers said that there is the potential that we could be required to recall and fix any product we have ever made. We have machines we made in the 1950s that are still regularly used for the purpose they were bought for, but without modern safety standards. We believe we can argue in court that the modern safety devices didn't even exist back then so we shouldn't have to update thos…

> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.

In my jurisdiction, consumer device must have "reasonable lifetime" by law. This lifetime of course is not to be determined by the manufacturer, but by the courts in the event of a disagreement. Ten years is bit long, but it's not absurd to think (i.e. reasonable) it should work ten years after the time of purchase even if the technology becomes obsolete.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#296
post #137

Earlier quoted context omitted.

>Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet. Nope. Not at all. Most router attacks these days are malicious JavaScript (like in ads and trackers) that send H…

Would this not also require some sort of exploitable CORS vulnerability?

Normal form posts don't require pre-flight requests. DNS rebinding attacks can be used too.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#297

Earlier quoted context omitted.

If you want a less touchy solution (not completely plug and play though!) I can't recommend Ubiquiti products enough. I run an EdgeRouter X and Unifi AP at home. Not big enterprise gear but way more enterprisey than whatever you'll find on the shelf at Best Buy. Updates are released regularly and once you get your initial configuration done they just chug along, no random 'internet is down, need to reboot something'…

What WAN throughput can you get on an Edgerouter X with moderate Firewall and some basic QoS rules enabled?

I can't give you a good answer for that as the fastest plan my ISP provides in my area is 100/10. This setup maxes that out no problem (which isn't surprising or impressive), usually hitting about 130/15 due to turboboost or whatever word they're using for temporary speed increases these days.

I think you can find some better info with a search though.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#298
post #89

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

> Until consumers are willing to spend on subscription services... Ok, I’m willing. Where do I sign up? Which manufactures are offering this service for residential grade equipment?

Eero doesn't charge for updates, but they do have a subscription service for value-add services that cost them money, and have a pretty good track record of pushing automatic updates.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#299
post #191

Earlier quoted context omitted.

> I would expect a consumer router to run without problem for not less than 10 years That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.

In my jurisdiction, consumer device must have "reasonable lifetime" by law. This lifetime of course is not to be determined by the manufacturer, but by the courts in the event of a disagreement. Ten years is bit long, but it's not absurd to think (i.e. reasonable) it should work ten years after the time of purchase even if the technology becomes obsolete.

Nobody would sell consumer electronics in your jurisdiction if they thought it were a remote possibility that courts would endorse "Purchase date + 10 years" or even "First sale date + 10 years" for software updates.

An original iPad isn't even 10 years old and is many years past being able to run an iOS version that receives security updates. A 10 year old MacBook Pro is a few years beyond having a supported OS with security updates. Cisco, with a support contract on actual Enterprise gear, offers up to 5 years from the end-of-sale date and do not actually promise to provide security updates for that whole period.

To expect a $50 junk router to provide an industry-leading support lifecycle is absurd.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#300
post #280
post #195

Earlier quoted context omitted.

> This is the new normal, folks. Consumer technology is manufactured for six to twelve months. Not completely true. For example, just something I discovered recently is that some e-book readers have very long lifespan if you look inside and ignore the battery. There's not even an electrolytic or tantalum capacitors there. Really nothing that will expire. If you don't kill it mechanically, these will survive for 10 ye…

What model is that?

http://linux-sunxi.org/PocketBook_Touch_Lux_3

But I hope people will buy second-hand or broken + replacement display instead of supporting the company and buying new, if they want to play with it. They don't really deserve any support for abusing the free work of others and violating the GPL license.

Post reply on HN