Live data from Hacker News

200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

badpackets.net

11–20 of 76 posts

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#11
post #10
post #9

Earlier quoted context omitted.

See my post above: APU2 by pcengines. Put debian on it.

It's a great piece of hardware, of which I've used dozens for various purposes. But they draw ~10 times more power than, say, a cheap Linksys wifi router. So if all you're after is a SoHo wifi router, it might not be the best way to go.

They don't. Mine draw under 10W, which is well within range of a Linksys thing.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#12

If you have a currency that can be generated via compute power the incentive structure it creates is to take over as much compute power as you can. Does the incentive structure represent a serious design flaw in the system for widespread adoption?

I would say it's a consequence of computer power becoming commoditized - the flaw might be that using computer power in the past can be 'stored', unlike hijacking someone else's computer and renting it out as server space, there's a point in this kind of crime where one has the profits and got away with it.

I just had this thought and want to get it down, apologies for the rant: I suspect that philosophically, the basic measure of our economy has been units of energy, but it's transitioning to units of power. The 'subscription model' most businesses are transitioning to seems to be an early recognition of that fact. Server space, similarly, isn't really something one can store as easily as gold or gasoline - it's only valuable while in use and degrading whether it's in use or not. Our whole concept of currency may be based on an idea of 'stored' value, analogous to swapping joules, while we should be thinking about 'sources' of value - swapping watts. I think the trouble is that renting (or hijacking) servers is accounting in terms of watts, while currency is accounting in terms of joules. The accounting of the two types of approaches may not be as easily reconcilable as it seems at firs.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#14
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Turris omnia. Open source (both hardware and software), lets you ssh into it directly out of the box (well, after you have set a root password in the gui) They provide regular software updates, and it is imho a good hacker/tinkerer router.

I agree - got one, quite happy with it. But it's targeted for home use, not sure how well it fits into larger networks (small offices). MikroTik seems like a better fit for that, not sure.

One major advantage of Turris Omnia is that CZ.NIC is a non-profit, so they are not as constrained by profitability of this project, and it's a part of a larger strategy (e.g. you may allow reporting statistics back to turris: https://project.turris.cz/en/global-stats/).

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#15
post #10
post #9

Earlier quoted context omitted.

See my post above: APU2 by pcengines. Put debian on it.

It's a great piece of hardware, of which I've used dozens for various purposes. But they draw ~10 times more power than, say, a cheap Linksys wifi router. So if all you're after is a SoHo wifi router, it might not be the best way to go.

That's fair, but I don't know of any SOHO routers I trust, which is what led me to it. It's a tradeoff, but the same tradeoff being made by these mikrotik users.

There is this one the horizon though: https://up-shop.org/up-ai-edge/233-up-net-plus.html

It'd make a fine router in the same vein, no word on power usage though.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#16
post #10

Earlier quoted context omitted.

It's a great piece of hardware, of which I've used dozens for various purposes. But they draw ~10 times more power than, say, a cheap Linksys wifi router. So if all you're after is a SoHo wifi router, it might not be the best way to go.

They don't. Mine draw under 10W, which is well within range of a Linksys thing.

Mine draw around 10W idle, about 15W when active. My Linksys and TP-Link trinkets draw under 2W idle (which I'm guessing is my power meter's minimum value), and not much more when active.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#17
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Germany (or rather DACH) has AVM, a German manufacturer that is making the "Fritz!Box" product line and supplied security updates to all affected routers they ever sold after somebody discovered and exploited a bug in the firmware to remotely call premium numbers via VoIP in various countries.

Their routers were also not affected by the KRACK WPA2 exploit last year.

AVM products cost a lot more than their competitors' but they are really worth their money.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#19
post #16

Earlier quoted context omitted.

They don't. Mine draw under 10W, which is well within range of a Linksys thing.

Mine draw around 10W idle, about 15W when active. My Linksys and TP-Link trinkets draw under 2W idle (which I'm guessing is my power meter's minimum value), and not much more when active.

Power meters generally don't well measuring low loads, 2W sounds like an error.

Re: 200,000+ MikroTik routers worldwide compromised to inject cryptojacking malware

#20
post #5

So ... which SoHo router manufacturer can we actually trust? It seems pretty common in this industry to either not supply security updates, or to only supply them for a very short amount of time.

Turris omnia. Open source (both hardware and software), lets you ssh into it directly out of the box (well, after you have set a root password in the gui) They provide regular software updates, and it is imho a good hacker/tinkerer router.

300€ is about 5 times what I would consider a price to pay for a home router though.
Post reply on HN