Live data from Hacker News

Security Begins at the Home Router

insights.sei.cmu.edu

171–177 of 177 posts

Re: Security Begins at the Home Router

#171

Earlier quoted context omitted.

Similar concerns, I recently used Google Express for a purchase, it worked fine, and then I deleted it. My Google account is my main email, and every new Google service is another opportunity for my whole account to get irreversibly banned. Using Google with their famous lack of customer service to make purchases that I could conceivably need to put a chargeback on felt uncomfortably risky. Tie my home internet conne…

Agree on lack of support. I have an account that is blocked. I forgot the password since it was always logged in. When I try to recover the password, it asks me a bunch of questions that I am pretty sure I am answering correctly. At the end it just tells me that the account cannot be recovered... even if I had the second factor authenticator still working and I punched in the right code. I searched high and low onlin…

To be honest, if someone doesn’t know my password, doesn’t have my 2-factor code, and can’t answer the security questions, I don’t want them to be able to call up customer service and social engineer an account takeover. I don’t think there’s any amount of proof that I could provide but an adversary targeting me couldnt’t fake to convince a call center employee.

What I’m more worried about is their “You violated the TOS. We can’t tell you how you violated the TOS. We can’t unban your account.” If you don’t know someone at Google, you’re out of luck.

Re: Security Begins at the Home Router

#172
post #167
post #157

Earlier quoted context omitted.

That’s the only reason? And the fact that it’s exclusively online?

If you have to create pw you want use one time and tell it to someone over the phone or use it for "Guest WiFi" network, I don't see why I got downvoted. It is not like I am going to use it for my main email account.

I get it but OTOH just search for “XKCD password generator” and there’s like twenty offline options…

Re: Security Begins at the Home Router

#173
post #49

Earlier quoted context omitted.

Solid firmwares like OpenWRT run on a lot of routers already. It should be possible to have some amount of regular updates, if not automatic.

Do you realize that OpenWrt is not very secure and DD-Wrt is even worse?

With a current kernel and updated userland? the no-password root ssh after flashing is vulnerable to others in your local network yes, keep it offline until pubkey-only auth is configured. To save against dropbear exploits, bind ssh to the internal-ethernet interface and if installed, access uhttpd/LuCI only via this tunnel. Other than that it seems equal to other default distribution installs. Apparmor/selinux steps up ubuntus/fedoras game yes, I don't know how much of this has been a concern yet in OpenWrt, a recent talk touches shortly on it. It seems to be a clean, easy-to-configure distribution that is alive and well after the remerge that just got a recent stable-release. Secondary vectors like package-system are a factor. But despite being reliant on the vendor, it buildable by the end-user. I applaud their efforts.

Re: Security Begins at the Home Router

#174
post #172
post #167

Earlier quoted context omitted.

If you have to create pw you want use one time and tell it to someone over the phone or use it for "Guest WiFi" network, I don't see why I got downvoted. It is not like I am going to use it for my main email account.

I get it but OTOH just search for “XKCD password generator” and there’s like twenty offline options…

Oh yes, XKCD style passwords are even better to spell out over the phone.

Re: Security Begins at the Home Router

#175
post #164

Earlier quoted context omitted.

I don't know why technical people bother with anything else these days, TBH. You don't even need a separate server for it: just use a separate network card in an existing machine. And even if one decides to buy a separate machine, it's still much cheaper than a router with comparable capabilities. And the existing router can often be reused as a dumb access point. It's a no-brainer.

> You don't even need a separate server for it: just use a separate network card in an existing machine. Because you want internal network to keep working when you do server maintenance.

Just do it at the same time you do the router upgrade. Updates are released every couple of weeks. You don't have to install all of them, and not all of them require a reboot, but you could totally do it was I describe. I do have a separate machine for the router (the machine also runs the Kubernetes master), but that's more due to how my house is wired, not because I need it.

Re: Security Begins at the Home Router

#176
post #35

I agree with Steven Gibson. The biggest defense we can have on this is autoupdating routers. At a minimum, just restart at some fixed time after an update is downloaded. More fancy would be dynamically calculating a low usage day and time to restart. But this would also involve the router manufacturer keeping it up-to-date as well. Which gets me thinking... Does a SOHO (or any) device exist that effectively runs two…

If you start making my router autoupdate and autoreboot like Windows does you will alienate a very large number of customers. Instead: stop making shit routers.

It could and likely would be configurable. The problem is the people who plug the router in with the default password and forget about it.

This would solve that while leaving it configurable for technical users.

Re: Security Begins at the Home Router

#177

Earlier quoted context omitted.

I would have said that too based on our RT-AC68U right up until I read this post and thought "time to update that router" and when I did so, for the first time in many updates I was presented with a license agreement allowing ASUS to send basically every bit of data to a 3rd party (Trend Micro) for features I didn't ask for. I should have captured it but the data they described was basically every bit of data you can…

Is this the case with Merlin's firmware too or just the OEM FW?

I don't know what Merlin's firmware is, but it's completely stock with stock updates.
Post reply on HN