Live data from Hacker News

VPN users unmasked by zero-day vulnerability in Virgin Media routers

portswigger.net

1–10 of 97 posts

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#2
Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures.

ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets, yet they still to this day sell devices with them. They don't care about fixing things - they care about selling things.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#3
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#4
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

You can take those routers and use it as a modem only. Then put your own router in front of it.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#6
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

(I bought my DOCSIS 3.whatever cable modem to use with Cox Cablevision myself at Best Buy after deciding which one I thought would be the best.)

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#7

Earlier quoted context omitted.

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

You can take those routers and use it as a modem only. Then put your own router in front of it.

It's still not really modem-only mode. They do routing in there, mainly for their management layer.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#8
post #2

Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…

Correct, but in this case, it sounds like you didn't need to use the ISP router as your VPN gateway.

If I understand the DNS rebinding attack reference correctly, you could be running the VPN software on your desktop/laptop and still have your IP revealed by your ISP router.

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#9

Earlier quoted context omitted.

You can take those routers and use it as a modem only. Then put your own router in front of it.

It's still not really modem-only mode. They do routing in there, mainly for their management layer.

But that's fine right? If your ISP wants to send you bad packets having your own equipment isn't going to stop them either

Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers

#10
post #6

Earlier quoted context omitted.

I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)

(I bought my DOCSIS 3.whatever cable modem to use with Cox Cablevision myself at Best Buy after deciding which one I thought would be the best.)

Bestbuy likes to push the $300 modems. They do carry a $69 one on the bottom shelf, if it's stocked.
Post reply on HN