Live data from Hacker News

Netgear 0-day vulnerability analysis and exploit

blog.grimm-co.com

61–70 of 102 posts

Re: Netgear 0-day vulnerability analysis and exploit

#61
post #30

I've used Apple routers for many years, but since they've been discontinued I wonder what I'll do when I need to replace them. All the major alternatives seem to have crap software that requires frequent reboots and has security issues. Can anyone recommend an awesome wireless router that works great off the shelf? I don't want to have to learn how to flash it with DD-WRT.

In my experience, the biggest gain is from separating the router from the wireless AP. It lets you choose among more affordable, purpose built and higher performance devices.

Specifically I would recommend the TP-Link EAP line as a wireless AP (the $50 EAP225v3 is very good). Extremely simple to configure. Routers that perform well require configuration unfortunately, especially economical ones like the Microtik ($50). It lacks out of the box settings for port forwarding and hairpin NAT, though it has the simplest secure VPN setup I have ever seen. The only router that competes with its performance (ie can route gigabit Internet at full speed) with easy config is the Cisco RV340, which costs $220 and is 3 years old.

Apple discontinued its wireless routers because they were bad. Apple routers run an ancient and naturally no longer patched version of NetBSD. They have terrible wireless performance on the worst Broadcom chipset with awful quirks. They mix with non Broadcom wireless devices extremely poorly (typically Atheros is the high performance pick). They are extremely slow, not at all suitable for gigabit Internet. If you update the port forwarding they must restart, and take down your internet. However, they are basically purpose built for correct macOS and iPhone multi-AP WiFi hand-off. There are things they do that not even enterprise hardware does right or may ever do right, simply because Apple does not document the magic that makes it possible. Or because Apple uses such bad chipsets with so many quirks, that only those quirks all working together do things go right. If I were you, I’d eBay away your 7 year old Airport Express to some greater fool, and use that surprisingly large amount of money to buy good stuff.

Anyway, most people shove their wireless AP into a bookshelf, taking at least 30% of their internet bill worth of performance and lighting it on fire. People use mesh networking wireless, like the Eero, something so abjectly bad it boggles the mind, because they’d rather spend $300 once to only use 50% of their internet’s monthly value than $10 once on Ethernet cable to get 100% of it. Sometimes they buy Ubiquiti hardware, which is ancient and overpriced at this point, and wind up paying for some internet configuration license that makes no sense. I really pity the people paying a monthly fee for mesh wireless configuration. This stuff is extremely marketing driven, it is in reality just the same exact commodities (two possible wireless chipsets and Linux) remixed into whatever crap Google thinks will convince people to let them gather home networking telemetry.

But configuring a Microtik is not easy. So there you go.

Re: Netgear 0-day vulnerability analysis and exploit

#63
post #23
post #6

The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…

The best thing about setting up Google wifi routers for your relatives is you can set yourself up as the manager of them, and manage them with the Google Wifi app from anywhere. So before Uncle Bob calls you about the wifi you'd already have got the notification that his cable service is down again.

Sorry to be "that guy", but how about not giving an advertisement company access to all your network traffic (while paying them for the privilege)...

Almost every router supports some form of remote management (or just put TeamViewer on their machine). Most also support dynamic DNS so you can set up a ping check for the "its down" notification.

Re: Netgear 0-day vulnerability analysis and exploit

#65
post #63
post #23

Earlier quoted context omitted.

The best thing about setting up Google wifi routers for your relatives is you can set yourself up as the manager of them, and manage them with the Google Wifi app from anywhere. So before Uncle Bob calls you about the wifi you'd already have got the notification that his cable service is down again.

Sorry to be "that guy", but how about not giving an advertisement company access to all your network traffic (while paying them for the privilege)... Almost every router supports some form of remote management (or just put TeamViewer on their machine). Most also support dynamic DNS so you can set up a ping check for the "its down" notification.

Sorry to say that you are "that guy" and your comment, in addition to adding nothing to this conversation, also detracts from HN generally and contributes to the perception that it is an unserious place haunted by the deranged and irrational.

"Google Wifi and Nest Wifi devices do not track the websites you visit or collect the content of any traffic on your network."

Re: Netgear 0-day vulnerability analysis and exploit

#66
post #30

I've used Apple routers for many years, but since they've been discontinued I wonder what I'll do when I need to replace them. All the major alternatives seem to have crap software that requires frequent reboots and has security issues. Can anyone recommend an awesome wireless router that works great off the shelf? I don't want to have to learn how to flash it with DD-WRT.

I used to have apple gear, replaced it with a edgerouter for a while but that was too much of a bother. Now I got a amplifi HD which is more or less a apple experience in a good way.

Re: Netgear 0-day vulnerability analysis and exploit

#67

I am sick of having to assume my network hardware is trivially compromised. What will it take for me to be able to purchase a microkernel driven router/access-point with audited drivers (or Rust based)? I would settle for mediocre performance (ie no gigabit) if I could have some strong security guarantees. Can I setup Redox or seL4 as home network hardware at this point? Or would the pain threshold still be quite hig…

The tough part in my opinion is the access point. You either have to: - Put a wireless card in the router, but a lot of them are crap (limited features, not dual band, require closed firmware, not compatible with *BSD...) - Buy an access point appliance, but most of them are as secure as the Netgear devices of the fine article.

> - Buy an access point appliance, but most of them are as secure as the Netgear devices of the fine article.

1. The AP isn't directly exposed to inbound traffic from the internet.

2. You can put the AP's management interface on a VLAN without internet access and/or use firewall rules to the same effect.

I'm way less worried about the security posture of my AP than my internet-facing router.

Re: Netgear 0-day vulnerability analysis and exploit

#68

Earlier quoted context omitted.

Maybe better than typical SOHO, but I have been disappointed with Mikrotik stuff as well.

My RB3011 has been pretty much rock solid for me. If you don't mind me asking - what kinds of issues have you run into?

Wireless performance isn't great (20$ clunky china routers are usually faster), SXTsq that always slowed down horribly after few weeks of uptime, hAP Lite firmware that died (had to be reflashed from netboot, config gone), many software problems with SXT LTE6 (stopped working after upgrade, still broken after downgrade, mysteriously after hour of flashing various versions it suddenly started working again. Incoming voice call to modem SIM card just breaks connection, and it never fixes itself automatically, you need to manually down/up interface. I now fear touching anything in this installation at all).

Re: Netgear 0-day vulnerability analysis and exploit

#69
post #63
post #23

Earlier quoted context omitted.

The best thing about setting up Google wifi routers for your relatives is you can set yourself up as the manager of them, and manage them with the Google Wifi app from anywhere. So before Uncle Bob calls you about the wifi you'd already have got the notification that his cable service is down again.

Sorry to be "that guy", but how about not giving an advertisement company access to all your network traffic (while paying them for the privilege)... Almost every router supports some form of remote management (or just put TeamViewer on their machine). Most also support dynamic DNS so you can set up a ping check for the "its down" notification.

The fact that I've paid them for the hardware gives me more confidence that I'm not the product. Ironically, the fact that I can get TeamViewer for free and use it to get remote access others' computers makes it feel like a higher threat attack vector for me.

Before I bought the Google mesh wifi, I already had android, chrome, project Fi, and Google's DNS (router level) at various levels of my request stack. That's not even counting search, gmail, and calendar. If Google are playing shady games with my network traffic, whatever marginal gain they get from having software on my router is negligible. Especially compared to the awful PR backlash they'd get once somebody hooks some monitoring gear up to their hardware and exposes it.

Re: Netgear 0-day vulnerability analysis and exploit

#70
post #6

The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade. About a year ago, I tried to update the firmware on my Netgear router. It was the exact model from the article, the R7000. I assumed "new update" for router firmware would involve some critical security updates, and maybe some stability f…

> The worst part is this isn't even just going to affect folks that would never think to update their router firmware. The firmware they do push out is frequently a massive downgrade.

I worked there a bit over 10 years ago, so things may have changed, but honestly I wouldn't expect them to change all that much. For that kind of hardware (SOHO stuff), Netgear didn't have any software developers in-house. It was all outsourced to dev shops in Asia. The software was usually whatever generic thing the dev house had built, with customization for branding and enabling/disabling features Netgear wanted or didn't want. Occasionally they would pay to add features that didn't exist.

Netgear usually didn't get source code, and would only get changelogs for new releases (which weren't all that detailed). There were often many regressions, and all bug testing and feature verification was black-box. When something was wrong, it was often a fight to get the dev house to prioritize it, especially if they didn't think it was a critical bug (declaring a bug a shipping showstopper was usually effective, but you can't cry wolf all the time, and that only works for pre-release products, not updates).

I imagine things are better now; at the very least I expect these developers to have at least a little more awareness of common security issues and how to avoid them (definitely was not the case in the 00s), but I assume it's still a mixed bag. On the plus side, most of the current-gen hardware is beefy enough to run Linux, which a lot more developers are familiar with (IIRC a lot of the stuff back then was running vxWorks), which hopefully makes it easier to hire better developers.

If you want high-quality software on your networking gear, go with a company that you know is actually a software company, and not an outsourced hw/sw company. Products that are based on OpenWRT or Tomato or something like that are probably safer, assuming they haven't broken it with their customizations... but don't expect updates to new major releases. Having said that, I still buy Netgear switches and other stuff that's internal to my network and are generally relatively "dumb". They're usually pretty reliable and reasonably priced.

Post reply on HN