Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

101–110 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#101

Earlier quoted context omitted.

> Why? Ethics aside, is everything money? Ethics aside, why not? That's why we have ethics.

Because even if I remove ethics, I can't find a reason for doing something like that. For me, doing the right thing is beyond all these things, and I don't care about money beyond buying the necessities I need.

> I can't find a reason for doing something like that.

Money often starts out as necessity or one of it's close cousins. If I were 1) 8k miles away from my target, 2) in a region with more internet access than employment prospects and 3) needed to eat, I can see a path to profitable disclosure.

> For me, doing the right thing is beyond all these things,

This can be a luxury. After a year or 3 of kids in and out of hunger, what's right can get reframed.

> and I don't care about money beyond buying the necessities I need.

Getting beyond that is the thing.

Re: Hacking millions of modems and investigating who hacked my modem

#102

Earlier quoted context omitted.

> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?

> Why? Ethics aside, is everything money? Ethics aside, why not? That's why we have ethics.

Vendors who pay bounties often restrict public disclosure, and the professional value obtained from being able to talk about the research you do may be worth significantly more than the payout

Re: Hacking millions of modems and investigating who hacked my modem

#103

Earlier quoted context omitted.

because money grants wishes, and having more money means you get more of your wishes granted.

That doesn't make me interested. I don't get all excited about the things money can buy. Edit: As I noted elsewhere, necessities are something else.

May I suggest a decade of red state hunger-level poverty? My kids and I did it. Three years out of it, I get excited paying utilities on time.

Re: Hacking millions of modems and investigating who hacked my modem

#104

Holy hell, but how are your laws in the US aligned so doing something like this is okay? In Germany you would get minimum 3 years in jail for this, people got in front of court for way way way way less.

Germany is an outlier, not the norm, when it comes to security research

Re: Hacking millions of modems and investigating who hacked my modem

#106
Great article, but unfortunately a determined threat actor would just go to the source and get a remote job as a Cox technician to gain access to millions of routers to add to their botnet. A real solution by the ISP would be to implement a software (or, preferably, hardware) setting that prevents remote access by default unless explicitly enabled by the customer. That approach would slow a social engineering campaign and limit the scope of a hack like this.

Re: Hacking millions of modems and investigating who hacked my modem

#107

Earlier quoted context omitted.

> ...can't pay someone that found a bug impacting all their clients?...he could have just sold the vulnerability to the highest bidder This attitude is why "independent security researchers" offering to present unsolicited findings to companies in exchange for payment feels exactly like extortion.

At the same time, Cox is a commercial entity that makes money by providing services. Cyberattacks make them lose money, so it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those. We're not talking about a grandma losing her wallet with 50 bucks in it and not giving money to the guy that found it and gave her back.

>it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those.

Yes, Cox has that choice. But, what you're describing is the definition of extortion. The fact that it's easy for people to get away with it does not make it ethical.

Re: Hacking millions of modems and investigating who hacked my modem

#109

Earlier quoted context omitted.

> ...can't pay someone that found a bug impacting all their clients?...he could have just sold the vulnerability to the highest bidder This attitude is why "independent security researchers" offering to present unsolicited findings to companies in exchange for payment feels exactly like extortion.

while beg bounty people can be annoying, you have to remember that people aren't obligated to sit down and find free bugs for any company (especially not a big one) - why would i sit down and look at some code for free for some giant corp when i could go to the beach instead?

No, they aren't obligated. So, if there's no bug bounty program in place, then they should either go to the beach or be willing to find bugs for the public good.

The idea that the company owes them anything for their unsolicited work is misguided. And, if they present the bugs for money under the implicit threat of selling the information to people who would harm the company, then it's extortion.

Post reply on HN