Earlier quoted context omitted.
also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.
How about putting the ISP supplied modem in a DMZ? Then the ISP could admin it all they want but still never touch the LAN.
Hacking millions of modems and investigating who hacked my modem
151–160 of 282 posts
Re: Hacking millions of modems and investigating who hacked my modem
#152Earlier quoted context omitted.
Because even if I remove ethics, I can't find a reason for doing something like that. For me, doing the right thing is beyond all these things, and I don't care about money beyond buying the necessities I need.
> For me, doing the right thing is beyond all these things That...is ethics, no?
Re: Hacking millions of modems and investigating who hacked my modem
#153Earlier quoted context omitted.
> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. He probably should have gone the responsible disclosure route with the modem too. Do you really expect a minimum wage front desk worker to be able to determine what’s a potential major security flaw, and what’s a random idiot who thinks his modem is brok…
I would expect a front-desk worker to be trained to escalate issues within the org, and supported in doing so.
Re: Hacking millions of modems and investigating who hacked my modem
#154What sort of authentication system just lets calls through randomly sometimes... The incompetence!
Re: Hacking millions of modems and investigating who hacked my modem
#155Earlier quoted context omitted.
also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.
Even if you buy your own modem they can push firmware to it (and do). The config file your modem downloads includes a cert that allows the isp to do this. You can flash special firmware (used to be called force ware) to prohibit this.
Re: Hacking millions of modems and investigating who hacked my modem
#156i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.
Re: Hacking millions of modems and investigating who hacked my modem
#157An open question is still: how were the attackers able to grab his HTTP traffic? Some CPEs have a cloud Wireshark-like capability for debugging. I'm not sure if those are even on the Cox production firmware images. Usually there's a set of firmware for production and a set for test (which obviously makes it hard to test for problems in production). I suppose Cox could do a check to see what firmware versions are out…
also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.
You, I and most of the HN crowd may be well capable of maintaining a reasonably secure state of our own hardware and troubleshoot our way through common errors. However, the average internet user isn’t that experienced nor are most people interested in learning those skills.
Re: Hacking millions of modems and investigating who hacked my modem
#158Earlier quoted context omitted.
> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?
> Why? Ethics aside, is everything money? Ethics aside, why not? That's why we have ethics.
Re: Hacking millions of modems and investigating who hacked my modem
#159Earlier quoted context omitted.
Vendors who pay bounties often restrict public disclosure, and the professional value obtained from being able to talk about the research you do may be worth significantly more than the payout
> Vendors who pay bounties often restrict public disclosure, and the professional value obtained from being able to talk about the research you do may be worth significantly more than the payout Professional value that doesn't translate into money, do you mean? How do you categorise that?