This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…
Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…
D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
111–120 of 306 posts
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#112I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?
One where you can wipe the original firmware and install OpenWRT.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#113Earlier quoted context omitted.
> the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.
It drives prices up in equivalence with subscription pricing over the typical lifespan. (i.e. not obviously better or worse)
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#114I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?
One where you can wipe the original firmware and install OpenWRT.
OpenWRT really is the greatest.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#115Earlier quoted context omitted.
It drives prices up in equivalence with subscription pricing over the typical lifespan. (i.e. not obviously better or worse)
Right. There are differences in incentives and how easy it is to make receiving updates mandatory or the default. But it's reasonable to assume that, however implemented and legislated, everyone ends up--from a financial perspective--having to pay for an ongoing support subscription.
Normal software has an argument towards subscriptions if it's adding features. But routers shouldn't be adding features. Routers should be fixing bugs.
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#116Earlier quoted context omitted.
Xiaomi sells routers in this price range that ship with OpenWrt. The buildroot even has config options for branding! It costs them nothing for the OS. It costs D-Link more to produce their mess.
"But how will we differentiate from the market without our \"value added\" non-standard software?"
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#117I'll think twice before buying D-link again. They've just tarnished their brand irrevocably for me, even though my router is not affected - I had to turn it over and compare version numbers to be certain, and I don't want to have to track exploits and check version numbers to have peace of mind. What manufacturer can I buy next time with a good security record?
Mikrotik or Ubiquiti. My >10yo hardware still receives updates (latest version, not a few backported changes).
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#118This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…
Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…
Nope. Not at all. Most router attacks these days are malicious JavaScript (like in ads and trackers) that send HTTP requests to the router from the user's own web browser (already inside the network). No proximity access is needed
https://arstechnica.com/information-technology/2019/07/websi...
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#119https://www.eweek.com/security/ibm-s-schneier-it-s-time-to-r...
Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
#120This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…
Partly to your point, Buffalo was using DD-WRT for their wireless routers [1]. I have two of them at home, updated to the latest LEDE/OpenWRT. They're mostly fine [2].
Buffalo's support was not great, lagging far behind the latest DD-WRT when they were still providing those updates. As a power-user, I didn't mind since I could switch, but it was not a great showing for vanilla consumer.
Sadly, Buffalo has stopped making them, I suppose the business model didn't survive such a low-margin segment. I definitely appreciate the continued open-source support though!
[1] such as https://www.buffalotech.com/products/airstation-highpower-n3...
[2] I've had to reboot the main one to regain network connectivity a couple times, and it currently loses Wifi settings on power loss. Not great, but not enough to make me switch away yet.