Live data from Hacker News

How to exploit home routers for anonymity

danmcinerney.org

11–20 of 80 posts

Re: How to exploit home routers for anonymity

#12
post #9

Another reminder to use strong, non-default credentials on something that is the edge of your network. I'm still amazed by how many people drive around leaving their cars unlocked.

I leave my keys in the car sometimes when I'm running errands in my home town. I care a whole lot more about my network security at home than I do my car. It's just a car.

Re: How to exploit home routers for anonymity

#13
post #6

Ah. Great. Anonymity in the identity-theft way.

This is, incidentally, the reason why government-resistant anonymity services need to be legal. If you don't care about stealing credit card numbers or hurting people then you don't care about breaking into some poor sucker's router. But if you're blowing the whistle on some organizational malfeasance, you won't, so you need the likes of Tor.

I think that oversimplifies an important point. Criminals may not CARE about breaking into someone's computer or router, but that doesn't mean they're capable of doing so. Tor significantly lowers the bar for anonymity online, and there is no question in my mind that it enables criminals who wouldn't have the means to mask their identities otherwise.

This is not necessarily an argument against tools like Tor, but it's a tradeoff that I think many Tor supporters are too willing to ignore.

Re: How to exploit home routers for anonymity

#15
post #7

The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…

> What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety?

No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.

Re: How to exploit home routers for anonymity

#16
post #15
post #7

The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…

> What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety? No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.

I think you give way too much credit to the average person. It's easy to lose sight of how scary technical things are to normal people when you're in it day in and day out, but to ask the average person to change something in their router is kind of like asking me to replace a cylinder in my car.

There's a reason things like the Geek Squad are around and can charge as much as they do...

Re: How to exploit home routers for anonymity

#17
post #7

The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…

I often wonder the same thing. Other things that require the same level of expertise typically tell you that you need to do something by actively breaking. I know I need to call my heating and cooling guy because my air conditioning stops working, but nothing breaks to tell you to change your router settings. Technically, it's already broken.

Re: How to exploit home routers for anonymity

#18
post #9

Another reminder to use strong, non-default credentials on something that is the edge of your network. I'm still amazed by how many people drive around leaving their cars unlocked.

I leave my keys in the car sometimes when I'm running errands in my home town. I care a whole lot more about my network security at home than I do my car. It's just a car.

The reason to secure your network is a good reason to secure your car.

Your network and your car can/will be used by bad guys to do bad things.

You should care.

Re: How to exploit home routers for anonymity

#19

This is a good write up Dan. Is there anything as an owner of a home router we can do to protect ourselves?

Make sure your router doesn't allow admin access from the outside. Make sure you have a decent admin password. Disable any built-in cloud/ftp/sharing services that you don't use or need. If you use them, make sure to use good passwords and remove any built-in/default account. Disable UPnP in the router if you don't really need it (and understand the risks).

Re: How to exploit home routers for anonymity

#20
It feels like we need to include anonymity in the Internet Bill of Rights:

1. I have a right to read or write public information in an anonymous way.

2. I have a right to prevent you from reading or writing MY private information in an anonymous way, even if the intent is to obtain the right to exercise #1 in the process.

3. Using someone else's infrastructure/compute/power to enable #1 without breaking #2 requires you pay for it. I would also propose my private information is available at a price.

Expecting the right to anonymity by removing the rights of others in the process places an individual in cognitive dissonance. It's not a good place to be.

With the advent of cryptocurrencies, we're finally in a place someone can pay me to use a portion of my infrastructure for enabling their anonymity. I'm willing to contribute to the cause as long as it's worth my while.

Post reply on HN