Live data from Hacker News

Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

derekabdine.com

11–20 of 36 posts

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#11
post #10
post #9

Earlier quoted context omitted.

how are the users going to manage the router without it? they just need to do it securely and better ways to auto update.

By inverting the direction of control, such that the network device initiates connections to canonical addresses to receive their initial configurations.

By canonical addresses are you referring to dns that can be spoofed or IP addresses that can be rerouted?

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#12
post #10
post #9

Earlier quoted context omitted.

how are the users going to manage the router without it? they just need to do it securely and better ways to auto update.

By inverting the direction of control, such that the network device initiates connections to canonical addresses to receive their initial configurations.

A nice idea in theory, I'd love to manage networks devices using some open standard. However, I can already see what would happen if this were to become reality:

"You wish to configure your router? For your safety, you can only configure our VaporWare™ SecuRouter with our dedicated Windows 11 or phone app. Do note that any ad or tracking blockers might interfere with our super privacy preserving app (trust us, really!).

only Android, iOS, and Windows 11 are supported. App does not work without Internet connectivity. Android devices require Google Play services. Jailbreak and root access will trigger our SecuRouter Secure Data Protection mechanism and disable access from your IP address. Privacy agreements and terms and conditions apply. Product may not be sold in areas covered by the GDPR."

In fact, I've had to deal with routers that required me to log in through the ISP website rather than locally because of "security".

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#13
post #10

Earlier quoted context omitted.

By inverting the direction of control, such that the network device initiates connections to canonical addresses to receive their initial configurations.

A nice idea in theory, I'd love to manage networks devices using some open standard. However, I can already see what would happen if this were to become reality: "You wish to configure your router? For your safety, you can only configure our VaporWare™ SecuRouter with our dedicated Windows 11 or phone app . Do note that any ad or tracking blockers might interfere with our super privacy preserving app (trust us, reall…

You can make up whatever fallacious slippery slope arguments you care to invent, but such routers already exist and they are the best, most secure routers you can buy.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#14
post #13

Earlier quoted context omitted.

A nice idea in theory, I'd love to manage networks devices using some open standard. However, I can already see what would happen if this were to become reality: "You wish to configure your router? For your safety, you can only configure our VaporWare™ SecuRouter with our dedicated Windows 11 or phone app . Do note that any ad or tracking blockers might interfere with our super privacy preserving app (trust us, reall…

You can make up whatever fallacious slippery slope arguments you care to invent, but such routers already exist and they are the best, most secure routers you can buy.

Those routers you can get now are only for dumb residential nonces, and routers for anything heavier duty then that all have at least a console connection available, even if they have a cloud management component.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#15
post #8
post #2

Monolithic network appliances, computers, endpoints, etc are fundamentally designed without a security-first posture. There's nothing conceptually wrong with a modem that also contains a NAT firewall/router/switch/(WAP). But in practice, even examining the hardware architecture of a consumer-grade router reveals fundamental design flaws in terms of the monolithic nature of the hardware architecture. Thus, using separ…

>from scratch You do realize that this is already a red flag, right? In 99% cases the decision to start from scratch when you already have something well established is a mistake.

SOP: Build "from scratch" as a superset on the existing legacy.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#16
post #13

Earlier quoted context omitted.

A nice idea in theory, I'd love to manage networks devices using some open standard. However, I can already see what would happen if this were to become reality: "You wish to configure your router? For your safety, you can only configure our VaporWare™ SecuRouter with our dedicated Windows 11 or phone app . Do note that any ad or tracking blockers might interfere with our super privacy preserving app (trust us, reall…

You can make up whatever fallacious slippery slope arguments you care to invent, but such routers already exist and they are the best, most secure routers you can buy.

May I ask what are those routers?

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#18
I read this and _instantly_ wonder if it's viable for certificate extraction to bypass the god-awful NAT system in AT&T's equipment, a-la pfatt: https://github.com/MonkWho/pfatt

Edit: Ah yes, this is covered in the section "Obtaining the certificate via reboot & exploitation"

Sadly my hardware appears to be patched.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#19
post #9
post #5

Routers should not contain http servers, nor any other connection-oriented server that can accept. Just stop doing this.

how are the users going to manage the router without it? they just need to do it securely and better ways to auto update.

A serial port? Or perhaps these days, a USB one.

Re: Arris / Arris-variant DSL/Fiber router critical vulnerability exposure

#20
post #18

I read this and _instantly_ wonder if it's viable for certificate extraction to bypass the god-awful NAT system in AT&T's equipment, a-la pfatt: https://github.com/MonkWho/pfatt Edit: Ah yes, this is covered in the section "Obtaining the certificate via reboot & exploitation" Sadly my hardware appears to be patched.

You can downgrade the firmware and extract the certs: https://www.dupuis.xyz/bgw210-700-root-and-certs/

However, AT&T added another layer of authentication in mid-2021 that precludes the use of third-party hardware. I don't think that part has been cracked yet.

Post reply on HN