Why release pre-made tools that allow anyone to cause harm? You could still explain the problem without them or show code snippets if you have to.
How to exploit home routers for anonymity
11–20 of 80 posts
Re: How to exploit home routers for anonymity
#12Another reminder to use strong, non-default credentials on something that is the edge of your network. I'm still amazed by how many people drive around leaving their cars unlocked.
Re: How to exploit home routers for anonymity
#13Ah. Great. Anonymity in the identity-theft way.
This is, incidentally, the reason why government-resistant anonymity services need to be legal. If you don't care about stealing credit card numbers or hurting people then you don't care about breaking into some poor sucker's router. But if you're blowing the whistle on some organizational malfeasance, you won't, so you need the likes of Tor.
This is not necessarily an argument against tools like Tor, but it's a tradeoff that I think many Tor supporters are too willing to ignore.
Re: How to exploit home routers for anonymity
#14Re: How to exploit home routers for anonymity
#15The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…
No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.
Re: How to exploit home routers for anonymity
#16The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…
> What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety? No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.
There's a reason things like the Geek Squad are around and can charge as much as they do...
Re: How to exploit home routers for anonymity
#17The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…
Re: How to exploit home routers for anonymity
#18Another reminder to use strong, non-default credentials on something that is the edge of your network. I'm still amazed by how many people drive around leaving their cars unlocked.
I leave my keys in the car sometimes when I'm running errands in my home town. I care a whole lot more about my network security at home than I do my car. It's just a car.
Your network and your car can/will be used by bad guys to do bad things.
You should care.
Re: How to exploit home routers for anonymity
#19This is a good write up Dan. Is there anything as an owner of a home router we can do to protect ourselves?
Re: How to exploit home routers for anonymity
#201. I have a right to read or write public information in an anonymous way.
2. I have a right to prevent you from reading or writing MY private information in an anonymous way, even if the intent is to obtain the right to exercise #1 in the process.
3. Using someone else's infrastructure/compute/power to enable #1 without breaking #2 requires you pay for it. I would also propose my private information is available at a price.
Expecting the right to anonymity by removing the rights of others in the process places an individual in cognitive dissonance. It's not a good place to be.
With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while.