Earlier quoted context omitted.
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
You can take those routers and use it as a modem only. Then put your own router in front of it.
VPN users unmasked by zero-day vulnerability in Virgin Media routers
11–20 of 97 posts
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#12Earlier quoted context omitted.
You can take those routers and use it as a modem only. Then put your own router in front of it.
Which then burdens you with a double NAT which shouldn't ever be necessary if the industry had their shit together.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#13Security is not their priority.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#14This appears to use API endpoints that are available if the modem is in ISP mode and acting as the Wi-Fi, etc. Does this also affect the router when used in modem mode?
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#15For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.
[0] https://twitter.com/virginmedia/status/1162756227132198914?l...
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#16This appears to use API endpoints that are available if the modem is in ISP mode and acting as the Wi-Fi, etc. Does this also affect the router when used in modem mode?
How is this not prevented by same origin policy etc?
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#17Earlier quoted context omitted.
You can take those routers and use it as a modem only. Then put your own router in front of it.
It's still not really modem-only mode. They do routing in there, mainly for their management layer.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#18Earlier quoted context omitted.
Which then burdens you with a double NAT which shouldn't ever be necessary if the industry had their shit together.
No you don't. In modem mode the VM routers only issue a single IP (the internet facing IP) over DHCP to a single host (your router)
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#19For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.
The same Virgin Media of "Posting it to you is secure, as it's illegal to open someone else's mail." infamy.... [0] [0] https://twitter.com/virginmedia/status/1162756227132198914?l...
Quick! Let's outlaw poverty, violence, theft and coercion, and we're good!
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#20Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…
Here's the list with modems affected by the hardware bug you mentioned: https://www.badmodems.com/