Live data from Hacker News

How to exploit home routers for anonymity

danmcinerney.org

51–60 of 80 posts

Re: How to exploit home routers for anonymity

#51
post #49

Earlier quoted context omitted.

Could you "enable anonymity" at very low bandwidth ... say ... the equivalent of 9600 baud? What a fantastic idea. This seems worth pursuing. It should be possible to configure a modern browser to work with low bandwidth: HTML/CSS/JS would load, but images and other media wouldn't. Is there any reason why HN, Reddit, Twitter, webmail, and other services like IRC wouldn't be usable under those conditions? It seems lik…

I would love to see someone try to use HN at 9600 bps. That's bits per second, so 9600 / 8 = 1200 characters per second, roughly.

I used all of those things - irc, the web (gopher), etc., at 9600 baud for years. Wasn't a problem.

Also, you don't really need to configure a browser - just use lynx, which will ignore most of the bandwidth hungry aspects of a site.

Re: How to exploit home routers for anonymity

#52

Probably worth pointing out that one should remain aware of their local laws when carrying out such activities as the ones outlined in this HOW TO. Because you're blindly hitting hosts and attempting logins, you don't know whose infrastructure you're probing. If you accidentally knock on the wrong door, the simple act of attempting a log in can cause issues for you (legal and otherwise). I'm trying to avoid sounding…

When I read the announcement, I got the feeling that what he's doing isn't so much leveraging other people's routers as providing the owners of those routers with plausible deniability.

Legal and IMO worthy of much praise.

Re: How to exploit home routers for anonymity

#53
post #21

This is a good write up Dan. Is there anything as an owner of a home router we can do to protect ourselves?

I'm no expert but I imagine it's a combination of keeping your router's firmware up-to-date, using a properly configured firewall, and using a strong password for your router login.

You'd think, but most consumer equipment is abandonware and the firmware isn't updated once a newer model is out.

Re: How to exploit home routers for anonymity

#54
post #50

Earlier quoted context omitted.

I love this impression that if you're connecting from , laws don't apply. I'd wager nobody that's ever actually lived anywhere in 3rd world bandies it about. True, you're less likely to actually be convicted , but the months/years waiting for trail is guaranteed to be worse than your actual sentence elsewhere, if not fatal.

The parent specifically mentioned Nigeria. Africa is not a country, and his comment may not apply to say, South Africa or Morocco. You're the one generalizing about 3rd world countries, not him. If you think LLE or even the FBI is going to open the diplomatic channels necessary to pursue someone in Nigeria over access to a consumer-grade router, you're kidding yourself. For all practical purposes, these laws do not i…

Unless that consumer grade router is running a bank of a nuclear power plant.

There are very few places outside the reach of US law enforcement. Especially if they bother to get Interpol involved.

Re: How to exploit home routers for anonymity

#55
post #7

The opening paragraph asserts that simply not publishing ("censoring") such concrete, recipe-like exploits of the deficiencies of our shared infrastructure "won't make practices like those outlined [in the article] disappear"[2]. I am reminded of Steve Kemp's 2014 post »Secure your rsync shares, please«[0], relating how he abandoned a project employing zmap[1] upon discovering numerous openly accessible rsync shares…

As usual there's actually one effective way: Education.

You could also try scaring people about the end of the Internet, their money stolen and their pets kidnapped if they don't secure their router, but that would still be education.

Re: How to exploit home routers for anonymity

#56
post #30

Stuff like this is why I built my own router (I recommend the ALIX series http://pcengines.ch/alix.htm ). High quality hardware and you don't have to worry about the software because you control all of it. Right down to the BIOS if you want to.

How would you verify on demand that the BIOS isn't compromised?

I don't know about "on demand" but PCEngines will give the source for the BIOS and has an older version posted to the site. http://pcengines.ch/tinybios.htm

Re: How to exploit home routers for anonymity

#57
post #15

Earlier quoted context omitted.

> What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety? No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.

I think you give way too much credit to the average person. It's easy to lose sight of how scary technical things are to normal people when you're in it day in and day out, but to ask the average person to change something in their router is kind of like asking me to replace a cylinder in my car. There's a reason things like the Geek Squad are around and can charge as much as they do...

If a random stranger can remotely hack your router, I wouldn't be confident that any settings change will secure it. The router is garbage and needs to be replaced, which is easily within the understanding of an average person.

Re: How to exploit home routers for anonymity

#58
post #56

Earlier quoted context omitted.

How would you verify on demand that the BIOS isn't compromised?

I don't know about "on demand" but PCEngines will give the source for the BIOS and has an older version posted to the site. http://pcengines.ch/tinybios.htm

What I mean is, how would we verify the BIOS firmware matches what that source code should produce? If it's possible for us to make our own builds (i.e. there's no cryptographic signing for the BIOS binaries) then an adversary can insert a backdoor into the source code, make their own build, and then remotely flash your hardware with it. Or does flashing the hardware require some kind of manual operation, like holding down a button for 30 seconds?

Re: How to exploit home routers for anonymity

#59
post #54
post #50

Earlier quoted context omitted.

The parent specifically mentioned Nigeria. Africa is not a country, and his comment may not apply to say, South Africa or Morocco. You're the one generalizing about 3rd world countries, not him. If you think LLE or even the FBI is going to open the diplomatic channels necessary to pursue someone in Nigeria over access to a consumer-grade router, you're kidding yourself. For all practical purposes, these laws do not i…

Unless that consumer grade router is running a bank of a nuclear power plant. There are very few places outside the reach of US law enforcement. Especially if they bother to get Interpol involved.

I am now imagining wardriving to a nuclear power plant parking lot in order to score free wifi off their NetGear.

Re: How to exploit home routers for anonymity

#60
The nice thing about this is that you don’t have to wonder whether or not your VPN provider is saving logs or not, you are in control of that.

If you take over a single router, a provider does indeed have logs of both the inbound you used to reach the router, and the outbound traffic you create from it. Simple timing logging will show its you and if its "their" router, they'll (at least theoretically) be able to decrypt your traffic too. (And that's assuming it wasn't a great big tasty honey-pot to begin with, pooh-bear)

If you must do this, bounce between a few... and if you must do this, just use tor already.

Post reply on HN