VPN users unmasked by zero-day vulnerability in Virgin Media routers
61–70 of 97 posts
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#62So all the while, for almost two years, Virgin didn't do squat about this. Gives me flashbacks to some of our disclosure interactions with PayPal and others. Wonder why issues like this are so common - do they just de-prioritize vulnerabilities reported by researchers to death?
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#63I almost admire how mediocre they are - they do just enough to keep people on their service and because they've done the work of laying cable to all the houses in an area, there's little incentive for OpenReach to lay fibre in those areas.
I live in London and I can get Gigabit from VM (although only download, their upload is a pathetic 50Mb/s) so OpenReach has just left this area on crappy old copper phone lines and my alternative is It sucks and I hate it and I have absolutely no choice in the matter. Thanks capitalism! ;)
Edit: Fun fact, VM is owned by Liberty Global, who have thus far rolled out IPv6 on their other ISPs using DS-Lite (where you get a routable v6 address, but your v4 address is behind Carrier Grade NAT). I saw this and decided to switch to VM's business service so I could get a static v4 address.... turns out they just connect normally over the residential network and then do a GRE tunnel to the other side of the country for the static addressing, and their crappy router will just randomly stop routing packets over the GRE tunnel after a couple of weeks, requiring a reset of the router.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#64Nobody should use ISP provided equipment for anything security sensitive, ever. ISPs don't care about security at all, aside from "security" as a sales term, and aside from when they're getting a bad name because of egregious failures. ARRIS shouldn't be given a year embargo, either. They're the same company who've known since 2016 about hardware issues which cannot be corrected in software in the Intel PUMA chipsets…
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
Although as of a few weeks ago, WOW has announced bandwidth caps, so I have to rescind my former glowing recommendation. Le sigh.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#65For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.
This reignites my recurring question: Don't (at least some) password rules just shrink the problem space?
Having no rules means you have a maximum search space. However, a general audience means that the top X% (lets say 70 to be arbitrary) are going to be in a very small search space... An English word with maybe some numbers substituted in for a letter or two.
OTOH, having password rules means that you eliminate the smallest areas of the search space, so every password resides in a restricted version of the larger space. Fewer possible passwords, but all at a larger complexity to guess.
Then, there are password rules like "no special characters" or "maximum length of 10 characters" which are fantastically stupid and lazy, and only serve to make brute forcing them that much easier.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#66For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.
This reignites my recurring question: Don't (at least some) password rules just shrink the problem space?
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#67Earlier quoted context omitted.
This reignites my recurring question: Don't (at least some) password rules just shrink the problem space?
Yes and no. Having no rules means you have a maximum search space. However, a general audience means that the top X% (lets say 70 to be arbitrary) are going to be in a very small search space... An English word with maybe some numbers substituted in for a letter or two. OTOH, having password rules means that you eliminate the smallest areas of the search space, so every password resides in a restricted version of the…
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#68Earlier quoted context omitted.
(I bought my DOCSIS 3.whatever cable modem to use with Cox Cablevision myself at Best Buy after deciding which one I thought would be the best.)
In the UK, Virgin Media (The biggest cable provider, I think there maybe a couple of minor regional cable providers still dotted around the country) are the largest cable provider after buying up the smaller regional companies (My regional provider was brought up by Telewest). Long story short, their was tons of regional providers, they were brought up by one of two players which basically devided the country into be…
Five months later I sent it off for recycling because i'd heard nothing. Two months after that they asked for it back and then charged me £80 for not having it anymore.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#69Earlier quoted context omitted.
I think generally you don't get a choice when it comes to DOCSIS equipment. You can't just connect up your own (or at least no to Virgin Media's network)
I brought my own modem to WideOpenWest, and it wasn't even on the compatibility list. Just gave them the MAC, and a few moments later I had DHCP. Been solid for 9 years now. Although as of a few weeks ago, WOW has announced bandwidth caps, so I have to rescind my former glowing recommendation. Le sigh.
Re: VPN users unmasked by zero-day vulnerability in Virgin Media routers
#70For context. This is Virgin Media which demands your passwords (including e-mail passwords) must be no longer than 10 characters, must begin with a letter, not a number and cannot include any special characters. Security is not their priority.
The same Virgin Media of "Posting it to you is secure, as it's illegal to open someone else's mail." infamy.... [0] [0] https://twitter.com/virginmedia/status/1162756227132198914?l...