Live data from Hacker News

Full Disclosure: The Internet Dark Age [pdf]

politaia.org

1–10 of 20 posts

Re: Full Disclosure: The Internet Dark Age [pdf]

#4

Has this research been peer reviewed anywhere?

No big peer review needed - all it takes is a couple of people in GB taking a look at what in blazes their routers are doing.

But to those of us who have heard/known of TR069, we knew that stuff like this would eventually surface...

Re: Full Disclosure: The Internet Dark Age [pdf]

#6

Has this research been peer reviewed anywhere?

No big peer review needed - all it takes is a couple of people in GB taking a look at what in blazes their routers are doing. But to those of us who have heard/known of TR069, we knew that stuff like this would eventually surface...

Small point. The devices called out by the authors are not routers, they are MODEMS which are only installed on Fibre To The Cabinet installations. (These modems are then connected, usually, to an ISP-supplied router such as the BT Home Hub or whatever equivalent your ISP chooses to use.)

Fibre installs are by no means the majority or even the standard in the UK. But obviously the general "don't trust your ISP router if you really think the security services are after you" advice would seem to hold good no matter how you're connected.

Re: Full Disclosure: The Internet Dark Age [pdf]

#8
I just read through the whole document and it felt like someone was narrating a bad infomercial. It takes 30 pages for the document to get into the technical bits and then the research (and mitigation!) methods feel somewhat half-hearted.

1. The "fix" is to log in to the system and manually disable at runtime the VLAN and firewall rules. Nothing is said about making the fixes permanent - as if the authors have never experienced a wedged modem or router. Or had their power go out. (Perhaps they assume everyone has an UPS in place.)

2. The presence of extra VLAN is clear, that's true. I would have wanted to see redacted traffic dumps from a controlled lab network, where the authors actually show that the device attaches to a known VLAN. Right now we have nothing but their inference about egress firewall going up shortly after device boot.

It looks like a real deal. It's just presented in a way that puts me off. I'm waiting for external confirmation and more technical data.

Re: Full Disclosure: The Internet Dark Age [pdf]

#9
post #8

I just read through the whole document and it felt like someone was narrating a bad infomercial. It takes 30 pages for the document to get into the technical bits and then the research (and mitigation!) methods feel somewhat half-hearted. 1. The "fix" is to log in to the system and manually disable at runtime the VLAN and firewall rules. Nothing is said about making the fixes permanent - as if the authors have never…

Good job, I couldn't get past page 15 and all the messiah-complex text before

Re: Full Disclosure: The Internet Dark Age [pdf]

#10

Earlier quoted context omitted.

No big peer review needed - all it takes is a couple of people in GB taking a look at what in blazes their routers are doing. But to those of us who have heard/known of TR069, we knew that stuff like this would eventually surface...

Small point. The devices called out by the authors are not routers, they are MODEMS which are only installed on Fibre To The Cabinet installations. (These modems are then connected, usually, to an ISP-supplied router such as the BT Home Hub or whatever equivalent your ISP chooses to use.) Fibre installs are by no means the majority or even the standard in the UK. But obviously the general "don't trust your ISP router…

This is like that moment in one of those alien movies where the smiley neighbour has something slightly different about him.
Post reply on HN