Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

151–160 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#151

Earlier quoted context omitted.

also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.

How about putting the ISP supplied modem in a DMZ? Then the ISP could admin it all they want but still never touch the LAN.

So open it up to anyone? DMZ is an open target, not what you want to be doing.

Re: Hacking millions of modems and investigating who hacked my modem

#152

Earlier quoted context omitted.

Because even if I remove ethics, I can't find a reason for doing something like that. For me, doing the right thing is beyond all these things, and I don't care about money beyond buying the necessities I need.

> For me, doing the right thing is beyond all these things That...is ethics, no?

Ethics and character, yes, and an attitude towards life that doesn't regard money as the deeper meaning of everything.

Re: Hacking millions of modems and investigating who hacked my modem

#153
post #146

Earlier quoted context omitted.

> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. He probably should have gone the responsible disclosure route with the modem too. Do you really expect a minimum wage front desk worker to be able to determine what’s a potential major security flaw, and what’s a random idiot who thinks his modem is brok…

I would expect a front-desk worker to be trained to escalate issues within the org, and supported in doing so.

[deleted]

Re: Hacking millions of modems and investigating who hacked my modem

#154

What sort of authentication system just lets calls through randomly sometimes... The incompetence!

It's happened with both of the G.hn powerline devices I've used; presumably they are all reskinned versions of the silicon vendor's firmware. You can send commands (including changing encryption keys and updating firmware) and sometimes they just go through.

Re: Hacking millions of modems and investigating who hacked my modem

#155

Earlier quoted context omitted.

also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.

Even if you buy your own modem they can push firmware to it (and do). The config file your modem downloads includes a cert that allows the isp to do this. You can flash special firmware (used to be called force ware) to prohibit this.

Is it safe enough to buy a separate router and put the ISP modem on the "internet" side of it?

Re: Hacking millions of modems and investigating who hacked my modem

#156

i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

Can the ISP load firmware onto your modem? I'm on Cox in the US (same ISP as in TFA) and you can bring your own modem, but Cox will remotely update the firmware.

Re: Hacking millions of modems and investigating who hacked my modem

#157
post #122

An open question is still: how were the attackers able to grab his HTTP traffic? Some CPEs have a cloud Wireshark-like capability for debugging. I'm not sure if those are even on the Cox production firmware images. Usually there's a set of firmware for production and a set for test (which obviously makes it hard to test for problems in production). I suppose Cox could do a check to see what firmware versions are out…

also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.

I get the perspective, but I also like the fact that ISPs do take over some of the admin burden associated with running a piece of equipment like a router.

You, I and most of the HN crowd may be well capable of maintaining a reasonably secure state of our own hardware and troubleshoot our way through common errors. However, the average internet user isn’t that experienced nor are most people interested in learning those skills.

Re: Hacking millions of modems and investigating who hacked my modem

#158

Earlier quoted context omitted.

> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?

> Why? Ethics aside, is everything money? Ethics aside, why not? That's why we have ethics.

Ethics aside, there are many thing that move people, and it's not always money. For instance, selling the vulnerability means the author wouldn't have been able to tell their story.

Re: Hacking millions of modems and investigating who hacked my modem

#159
post #102

Earlier quoted context omitted.

Vendors who pay bounties often restrict public disclosure, and the professional value obtained from being able to talk about the research you do may be worth significantly more than the payout

> Vendors who pay bounties often restrict public disclosure, and the professional value obtained from being able to talk about the research you do may be worth significantly more than the payout Professional value that doesn't translate into money, do you mean? How do you categorise that?

I take the "professional value" to mean essentially putting it on your resume, gaining publicity by blogging about it, getting conference organizers to let you give a talk about it, etc., all of which may ultimately increase the money you can earn doing computer security.
Post reply on HN