Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

161–170 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#161

What sucks about this situation is when your ISP forces you to use their modem or router. For example, I have AT&T fiber and it does some kind of 802.1X authentication with certificates to connect to their network. If they didn't do this, I could just plug any arbitrary device into the ONT. There are/were workarounds to this but I don't want to go through all those hoops to get online. Instead, I ended up disabling e…

It was mentioned by a sibling, but there are ways to connect without using one of AT&T's gateway devices. Different methods are catalogued on https://pon.wiki/

Re: Hacking millions of modems and investigating who hacked my modem

#162
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…

> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all.

They were presented with some random person who wanted to get a new modern on their rental but also keep the old one, for free. They had no way of knowing if they were an actual security professional.

Re: Hacking millions of modems and investigating who hacked my modem

#163

Earlier quoted context omitted.

also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.

I get the perspective, but I also like the fact that ISPs do take over some of the admin burden associated with running a piece of equipment like a router. You, I and most of the HN crowd may be well capable of maintaining a reasonably secure state of our own hardware and troubleshoot our way through common errors. However, the average internet user isn’t that experienced nor are most people interested in learning th…

I have a feeling the OP ... has the skills to manage his router :)

but point well taken in general.

Re: Hacking millions of modems and investigating who hacked my modem

#164

Earlier quoted context omitted.

also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.

Even if you buy your own modem they can push firmware to it (and do). The config file your modem downloads includes a cert that allows the isp to do this. You can flash special firmware (used to be called force ware) to prohibit this.

You're assuming DOCSIS. I'm on FTTP, where the demarcation point is a cat5 cable to my equipment. Granted, there could be chicanery on the optical terminal, but that still doesn't provide my ISP visibility into my internal network.

Re: Hacking millions of modems and investigating who hacked my modem

#165
post #149

Earlier quoted context omitted.

> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…

>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…

How many of those show up in person though?

Re: Hacking millions of modems and investigating who hacked my modem

#166
post #146

Earlier quoted context omitted.

> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. He probably should have gone the responsible disclosure route with the modem too. Do you really expect a minimum wage front desk worker to be able to determine what’s a potential major security flaw, and what’s a random idiot who thinks his modem is brok…

I would expect a front-desk worker to be trained to escalate issues within the org, and supported in doing so.

Have you ever worked as a front-line support agent? I'm guessing not. I have many years ago, and for an ISP too. If I bought an Amazon share back then for every time a customer called support because they were "hacked", I'd not be posting here during a boring meeting because I'd own my own private island.

The two best conversations I can recall were when we changed a customer's email address about a half dozen times over a year because "hackers were getting in and sending them emails" (internal customer note: stop signing up for porn sites), and a customer's computer could barely browse the web because they were running about 5 software firewalls because they were "under surveillance by the NSA" (internal customer note: schizophrenia).

The expected value of processing requests like this any way other than patting the reporter on their head and assuring them the company will research it, then sending them along their way with a new device while chucking the old one in the "reflash" pile isn't just zero, it's sharply negative.

The author's mistake was not posting somewhere like NANOG or Full-Disclosure with a detailed write-up. The right circles would've seen it, the detailed write-up would've revealed that the author wasn't an idiot or paranoid, and the popped device might've been researched.

Re: Hacking millions of modems and investigating who hacked my modem

#167
post #149

Earlier quoted context omitted.

>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…

How many of those show up in person though?

Just the craziest, wrongest ones

Re: Hacking millions of modems and investigating who hacked my modem

#169

Earlier quoted context omitted.

also, yet another reason I don't trust (and don't use) any ISP provided equipment. Remote administration from my ISP? No thank you.

How about putting the ISP supplied modem in a DMZ? Then the ISP could admin it all they want but still never touch the LAN.

That's pretty much the way to go. Keep the ISP modem, but connect it to your own router/firewall and connect your devices to your hardware and not the ISP modem.

Re: Hacking millions of modems and investigating who hacked my modem

#170

Earlier quoted context omitted.

> For me, doing the right thing is beyond all these things That...is ethics, no?

Ethics and character, yes, and an attitude towards life that doesn't regard money as the deeper meaning of everything.

Ethics aside, what is characterful about saying no to money? Should I say no to my salary for character reasons?
Post reply on HN