VPN users unmasked by zero-day vulnerability in Virgin Media routers
1–10 of 97 posts
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#2ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets, yet they still to this day sell devices with them. They don't care about fixing things - they care about selling things.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#3Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#4Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#5Does this also affect the router when used in modem mode?
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#6Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#7Earlier quoted context omitted.
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
You can take those routers and use it as a modem only. Then put your own router in front of it.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#8Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…
If I understand the DNS rebinding attack reference correctly, you could be running the VPN software on your desktop/laptop and still have your IP revealed by your ISP router.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#9Earlier quoted context omitted.
You can take those routers and use it as a modem only. Then put your own router in front of it.
It's still not really modem-only mode. They do routing in there, mainly for their management layer.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#10Earlier quoted context omitted.
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
(I bought my DOCSIS 3.whatever cable modem to use with Cox Cablevision myself at Best Buy after deciding which one I thought would be the best.)