Live data from Hacker News

Linksys CherryBlossom Advisory

linksys.com

1–10 of 46 posts

Re: Linksys CherryBlossom Advisory

#2
I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself.

I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected.

Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

Re: Linksys CherryBlossom Advisory

#4

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

If the security of your router is of concern to you I would recommend setting up your own FreeBSD+pfSense router.

Another option is to setup a vpn server that all your devices connect to to access the internet. In that scenario it won't matter if your router is compromised because all traffic flowing through would be encrypted.

Re: Linksys CherryBlossom Advisory

#5

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

i'm not saying it's happened here, but i'd imagine with router firmware (because it's not too large) it'd be pretty cheap to have a copy of the factory firmware and settings in a physically read only storage of some kind

Re: Linksys CherryBlossom Advisory

#6

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

Yeah, I'd think it would take a reflash to get rid of the compromise, since the compromise is implemented by means of firmware replacement to begin with.

Probably your cheapest bet on the supported device list (ca. p27 of the PDF on Wikileaks) would be a WRT54G v5. The GL models have some support as well, but last I checked they had a relatively high used value, presumably for their hackability - the G models are much more limited.

Re: Linksys CherryBlossom Advisory

#8

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

> Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

To be clear, the main "vulnerability" is just ability to get physical access and re-flash the devices with a custom firmware which allows the access to the target network. The best defense would be locking down the router physically and setting a strong password for the admin portal.

Re: Linksys CherryBlossom Advisory

#9

I wonder if a factory reset is enough in all cases - the source for the factory reset has to be on the device itself. I haven't played with it much, but there are ways to persist after a reset on Android, I'd assume the same is possible here. Very happy to be corrected. Anyone know what the cheapest Linksys I could buy is, and whether these vulnerabilities have been released publicly?

i'm not saying it's happened here, but i'd imagine with router firmware (because it's not too large) it'd be pretty cheap to have a copy of the factory firmware and settings in a physically read only storage of some kind

You're correct in some cases. My last "consumer" router was a TP Link Archer D9 and doing a factory reset only restored the last flashed version of the firmware - so that partition was writeable during updates at least.

Re: Linksys CherryBlossom Advisory

#10
> If users believe their router firmware may have been compromised, Linksys recommends that users download the latest available firmware from http://www.linksys.com/support/ and update your router.

Is there a hardware feature that makes the firmware boot secure in a way that prevents the firmware from interfering with the update? Such as croning itself to reinstall the compromise when you're not looking? Or lying that it updated?

Post reply on HN