Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

111–120 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#111
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

You can use Javascript in an ad to make the browser connect to the internal IP address, which often is something like 192.168.1.1 and then once you’re in you can add the device to a botnet and sell its bandwidth or reroute its traffic.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#112
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

One where you can wipe the original firmware and install OpenWRT.

Or AsusWRT! I'm pretty happy with my RT-AC3200.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#113
post #78
post #72

Earlier quoted context omitted.

> the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.

It drives prices up in equivalence with subscription pricing over the typical lifespan. (i.e. not obviously better or worse)

Right. There are differences in incentives and how easy it is to make receiving updates mandatory or the default. But it's reasonable to assume that, however implemented and legislated, everyone ends up--from a financial perspective--having to pay for an ongoing support subscription.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#114
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

One where you can wipe the original firmware and install OpenWRT.

There may be other answers here, but this is really the only guaranteed one.

OpenWRT really is the greatest.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#115
post #113
post #78

Earlier quoted context omitted.

It drives prices up in equivalence with subscription pricing over the typical lifespan. (i.e. not obviously better or worse)

Right. There are differences in incentives and how easy it is to make receiving updates mandatory or the default. But it's reasonable to assume that, however implemented and legislated, everyone ends up--from a financial perspective--having to pay for an ongoing support subscription.

Can you explain to me how a subscription, for which only subscribers get fixes, is not a perverse incentive to ship broken software?

Normal software has an argument towards subscriptions if it's adding features. But routers shouldn't be adding features. Routers should be fixing bugs.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#116

Earlier quoted context omitted.

Xiaomi sells routers in this price range that ship with OpenWrt. The buildroot even has config options for branding! It costs them nothing for the OS. It costs D-Link more to produce their mess.

"But how will we differentiate from the market without our \"value added\" non-standard software?"

The same way Dell and HP do with a Windows PC. The OpenWrt buildroot can help them do that too! ;-)

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#117
post #106
post #95

I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?

Mikrotik or Ubiquiti. My >10yo hardware still receives updates (latest version, not a few backported changes).

This. I just decommissioned 5 x AP and 2 x backhaul radios this summer from Ubiquiti at a remote site I manage. These were all purchased and installed in 2011. I replaced them all with newer equivalents, not because they weren't working or weren't receiving updates - but because I'm 4 hours from the site and told the owner they've gotten their ROI and needed to preemptively replace. This happens to be my in-laws place and I don't want to deal with replacing some outdoor radios in the middle of a Midwestern winter. I sold all the gear as a package for about $150 and the buyer was well aware of the age and the fact that 3 of the devices had been outside that entire time. I commend Ubiquiti on the commitment to their line of products and the updates all devices that were in service continue to receive.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#118
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

>Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet.

Nope. Not at all. Most router attacks these days are malicious JavaScript (like in ads and trackers) that send HTTP requests to the router from the user's own web browser (already inside the network). No proximity access is needed

https://arstechnica.com/information-technology/2019/07/websi...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#119
Schneier has recently argued that there is a missing market for IOT security in the sense that devices manufacturers have no incentive to patch impose external costs on society, and that this might be hard to fix without regulation.

https://www.eweek.com/security/ibm-s-schneier-it-s-time-to-r...

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#120
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

> Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves?

Partly to your point, Buffalo was using DD-WRT for their wireless routers [1]. I have two of them at home, updated to the latest LEDE/OpenWRT. They're mostly fine [2].

Buffalo's support was not great, lagging far behind the latest DD-WRT when they were still providing those updates. As a power-user, I didn't mind since I could switch, but it was not a great showing for vanilla consumer.

Sadly, Buffalo has stopped making them, I suppose the business model didn't survive such a low-margin segment. I definitely appreciate the continued open-source support though!

[1] such as https://www.buffalotech.com/products/airstation-highpower-n3...

[2] I've had to reboot the main one to regain network connectivity a couple times, and it currently loses Wifi settings on power loss. Not great, but not enough to make me switch away yet.

Post reply on HN