Live data from Hacker News

BTAgent – CPE backdoor

cryptome.org

1–10 of 19 posts

Re: BTAgent – CPE backdoor

#3
Most of this stuff was published a few months ago and completely debunked - the ip range was just chosen because it isn't routable.

The BTAgent is there to manage the devices - e.g. Updating them. Its possible that some stats are there to improve line quality as well. To me that seems a reasonable tradeoff, and if I wasn't happy with it then it is always possible to use your own piece of CPE.

The other point is that the interface that BTAgent runs on isn't exposed to the internet, it is only available from the management network so someone obtaining the keys for BTAgent would also have to compromise the management network - at which point bt has bigger problems!

Re: BTAgent – CPE backdoor

#4
I was initially interested when I first saw this last year, but it turns out to be complete FUD. See http://www.revk.uk/2013/12/paraniod-ravings.html for the take on the original disclosures from the MD of one of the UK's most technical ISPs (and believe me, he's no fan of BT's).

See also http://www.ispreview.co.uk/index.php/2013/12/confusion-alleg...

In a nutshell, some ISPs will effectively hijack publicly routable ranges for internal use if they know that there's no way those addresses will ever be used for real public services. In this case, a UK ISP is re-using the US DoD's 30.0.0.0/8 network. Anecdotally I've heard the inverse is also true (US ISPs use UK MoD ranges).

Re: BTAgent – CPE backdoor

#6
While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.

Re: BTAgent – CPE backdoor

#7
post #6

While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.

Is it a crime to reverse engineer routers provided by an ISP? (Honest question, I know things like MAC spoofing are illegal, which can be used in the UK to get free cable TV / Internet).

Re: BTAgent – CPE backdoor

#8
post #6

While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.

Do you have a source to back this up?

Re: BTAgent – CPE backdoor

#9

I was initially interested when I first saw this last year, but it turns out to be complete FUD. See http://www.revk.uk/2013/12/paraniod-ravings.html for the take on the original disclosures from the MD of one of the UK's most technical ISPs (and believe me, he's no fan of BT's). See also http://www.ispreview.co.uk/index.php/2013/12/confusion-alleg... In a nutshell, some ISPs will effectively hijack publicly routable…

No matter if he's right or not: it can't hurt to set up an additional firewall. TR-069 is scary enough.

Re: BTAgent – CPE backdoor

#10
post #6

While the pdf from cryptome was initially published almost a year ago the person who reverse engineered the firmware has been visited by the police and then sent a response to cryptome in response to the pdf to clear up some misconceptions.

Is it a crime to reverse engineer routers provided by an ISP? (Honest question, I know things like MAC spoofing are illegal, which can be used in the UK to get free cable TV / Internet).

Not under EU law, but this is the UK we're talking about...
Post reply on HN