Live data from Hacker News

Netgear 0-day vulnerability analysis and exploit

blog.grimm-co.com

51–60 of 102 posts

Re: Netgear 0-day vulnerability analysis and exploit

#51

I am sick of having to assume my network hardware is trivially compromised. What will it take for me to be able to purchase a microkernel driven router/access-point with audited drivers (or Rust based)? I would settle for mediocre performance (ie no gigabit) if I could have some strong security guarantees. Can I setup Redox or seL4 as home network hardware at this point? Or would the pain threshold still be quite hig…

The tough part in my opinion is the access point. You either have to:

- Put a wireless card in the router, but a lot of them are crap (limited features, not dual band, require closed firmware, not compatible with *BSD...)

- Buy an access point appliance, but most of them are as secure as the Netgear devices of the fine article.

Re: Netgear 0-day vulnerability analysis and exploit

#53

Earlier quoted context omitted.

That's not a workable solution for the vast majority of the population.

Sadly not. You generally have to be very technically inclined to use something like Mikrotik (which is what I'm using) and even the Ubiquiti stuff isn't as easy to use as it could be.

Maybe better than typical SOHO, but I have been disappointed with Mikrotik stuff as well.

Re: Netgear 0-day vulnerability analysis and exploit

#54
post #30

I've used Apple routers for many years, but since they've been discontinued I wonder what I'll do when I need to replace them. All the major alternatives seem to have crap software that requires frequent reboots and has security issues. Can anyone recommend an awesome wireless router that works great off the shelf? I don't want to have to learn how to flash it with DD-WRT.

Eero

I almost went full Unifi, got lazy and got Eero. So far everything has been fantastic. It's not perfect but it works and delivered on its promise. Speed is fast, it's not Wifi 6 but neither are any of my devices. Paid full price too, not a shill here.

Re: Netgear 0-day vulnerability analysis and exploit

#55

I am sick of having to assume my network hardware is trivially compromised. What will it take for me to be able to purchase a microkernel driven router/access-point with audited drivers (or Rust based)? I would settle for mediocre performance (ie no gigabit) if I could have some strong security guarantees. Can I setup Redox or seL4 as home network hardware at this point? Or would the pain threshold still be quite hig…

> I am sick of having to assume my network hardware is trivially compromised. I don't have the gateway my ISP gave me on my LAN for this reason. I do have to laugh a little bit about people who use a VPN to hide requests (DNS? Because most of the web is HTTPS, now) from their ISP when their ISP has a device on their network .

Even personally owned hardware has its risks from today's ISPs. DOCSIS standards require every off the shelf cable modem to basically have giant "management" back doors for the ISPs. They can remotely install firmware updates to your modem that you own for "your safety" and there's not much you can do about it.

Re: Netgear 0-day vulnerability analysis and exploit

#56

Earlier quoted context omitted.

Sadly not. You generally have to be very technically inclined to use something like Mikrotik (which is what I'm using) and even the Ubiquiti stuff isn't as easy to use as it could be.

Maybe better than typical SOHO, but I have been disappointed with Mikrotik stuff as well.

My RB3011 has been pretty much rock solid for me. If you don't mind me asking - what kinds of issues have you run into?

Re: Netgear 0-day vulnerability analysis and exploit

#57
post #23

Earlier quoted context omitted.

The best thing about setting up Google wifi routers for your relatives is you can set yourself up as the manager of them, and manage them with the Google Wifi app from anywhere. So before Uncle Bob calls you about the wifi you'd already have got the notification that his cable service is down again.

I've had a pretty disappointing run with those Google Wifi routers... It started with the lack of ability to have an open guest wifi... Like - it's for my guests, I want anyone to be able to connect, and I don't want to be faffing with passwords or guests having to ask me... I have to name my network "My House - Password Is password" Then every month it seemed to do some kind of update and disconnect wifi devices...…

Google Wifi just released a new version in June 2020. The one before that was October 2019, and June 2019 before that. That's only 2 updates per year. How disruptive is that?

Re: Netgear 0-day vulnerability analysis and exploit

#58

Earlier quoted context omitted.

Eero

I almost went full Unifi, got lazy and got Eero. So far everything has been fantastic. It's not perfect but it works and delivered on its promise. Speed is fast, it's not Wifi 6 but neither are any of my devices. Paid full price too, not a shill here.

Ubiquiti has a consumer/prosumer brand called Amplifi now. It's got the ease of something like Eero but the decade of experience of Unifi. (They also already have a WiFi 6 mesh router at the top of the line on the prosumer side.)

Re: Netgear 0-day vulnerability analysis and exploit

#59

Earlier quoted context omitted.

That's not a workable solution for the vast majority of the population.

Sadly not. You generally have to be very technically inclined to use something like Mikrotik (which is what I'm using) and even the Ubiquiti stuff isn't as easy to use as it could be.

Ubiquiti has a consumer/prosumer brand now called Amplifi. I set it up at my parents' and it was a breeze. It's adapted well to some strange network situations they had. (A long story but they moved in to a place with an ancient audio LAN wired through the home and we explored various configurations of detaching portions of the audio LAN for WiFi backhaul.)

Re: Netgear 0-day vulnerability analysis and exploit

#60
post #6

The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…

Another brand i vouch for is AVM, their routers are all over Germany and they're reliable workhorses for years... Maybe, just maybe, someone should start a list with vendors that put out shitty software on their devices, never deliver firmware updates and have stupid exploits...

> Maybe, just maybe, someone should start a list with vendors that put out shitty software on their devices, never deliver firmware updates and have stupid exploits...

I don't disagree, but perhaps it would be better to list the vendors that push bad software and whose hardware doesn't let you run a better firmware. After all, if the hardware is decent and can run OpenWRT or such, who cares how bad the stock firmware is?

Post reply on HN