Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

171–180 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#171

Earlier quoted context omitted.

Even if you buy your own modem they can push firmware to it (and do). The config file your modem downloads includes a cert that allows the isp to do this. You can flash special firmware (used to be called force ware) to prohibit this.

Is it safe enough to buy a separate router and put the ISP modem on the "internet" side of it?

I think the attack described in the article is still possible in this setting, where the modem is in the middle of your unencrypted http traffic. This is true of any equipment belonging to the isp

However, I would assume no unencrypted traffic is safe anyway, and the modem would indeed not have access to your internal network.

Re: Hacking millions of modems and investigating who hacked my modem

#172
post #146

Earlier quoted context omitted.

> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…

> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. He probably should have gone the responsible disclosure route with the modem too. Do you really expect a minimum wage front desk worker to be able to determine what’s a potential major security flaw, and what’s a random idiot who thinks his modem is brok…

> He probably should have gone the responsible disclosure route with the modem too

I think he was probably keen to get back on the Internet to be fair.

Re: Hacking millions of modems and investigating who hacked my modem

#173
post #146

Earlier quoted context omitted.

> Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. He probably should have gone the responsible disclosure route with the modem too. Do you really expect a minimum wage front desk worker to be able to determine what’s a potential major security flaw, and what’s a random idiot who thinks his modem is brok…

I would expect a front-desk worker to be trained to escalate issues within the org, and supported in doing so.

We really need to work on this definition of "expect". It's expected from them to have such training but we know that in practice that is not what happens. So we "expect" they to be trained, but what we "expect" will happen in practice is very different.

Re: Hacking millions of modems and investigating who hacked my modem

#174

Earlier quoted context omitted.

> it's only fair for them to financially award people that responsibly inform them of vulnerabilities instead of easily and anonymously selling those. Yes, Cox has that choice . But, what you're describing is the definition of extortion. The fact that it's easy for people to get away with it does not make it ethical.

It's not the definition of extortion. If I walk past a business and notice the locks on their windows are rusted and I happen to be a lock guy and say hey, I noticed your locks are fucked, I'd be happy to consult for you and show you how and why they are broken, that's just doing business. Extortion is telling them, hey, your locks are fucked and I'm telling everyone unless you pay me. It requires a threat.

Great response, entirely agree.

Re: Hacking millions of modems and investigating who hacked my modem

#175
post #66

Earlier quoted context omitted.

this is why everything gets logged to an S3 bucket under an AWS account that has only write permissions and three people are required to break into the account that can do anything else with that bucket. I don't know if that's what Cox has, but that's how it's architect it to be able to claim there's no history of abuse.

That's how it should be architected, but the article shows that Cox's network gives no thought to security so it's unlikely how it is architected. Even if the Cox answer is correct to the best of their knowledge, we can't rule out that attackers are inside the network wiping out their logs.

You’re right, except I’d say that Cox gave some thought so security, but not enough. Which is in some ways even more dangerous than ignoring security entirely.

Re: Hacking millions of modems and investigating who hacked my modem

#177

No payout?

It can be inferred that the author is satisfied with that aspect of the transaction by their willingness to list things that they still felt unresolved at the end.

They either were paid and think it's nobody's business or weren't and have no ideological reason for making a stink. For what it's worth, I sympathize with people who feel shafted for their work by large companies, but think it is a little silly to go looking for it.

Re: Hacking millions of modems and investigating who hacked my modem

#178

Earlier quoted context omitted.

Just the craziest, wrongest ones

+1 to this. Dealt with the same in consumer PC repair.

This was my experience too.

Some people truly believe the computer is hacked every time there is behaviour they didn't expect. Only the craziest, least capable ones show up to scream at you like you caused the whole thing.

Re: Hacking millions of modems and investigating who hacked my modem

#179

i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

FWIW, you can use your own modem and router with Cox internet, but most people don't because the provided modem is free and most people don't care to spend money on their own.

Re: Hacking millions of modems and investigating who hacked my modem

#180
post #138

What sucks about this situation is when your ISP forces you to use their modem or router. For example, I have AT&T fiber and it does some kind of 802.1X authentication with certificates to connect to their network. If they didn't do this, I could just plug any arbitrary device into the ONT. There are/were workarounds to this but I don't want to go through all those hoops to get online. Instead, I ended up disabling e…

If you have the att fiber with the ONT separate from the modem, it's really easy to bypass 802.1X. Plug an unmanaged switch in between the modem and the ONT; let the modem auth; disconnect the modem. You'll likely need to do that again if the ONT reboots, but at least for me, ATT a UPS for the ONT, so reboot frequency should be low. Personally, I built up a rube goldberg of software and hardware with bypass nics so i…

That's a good idea, I do have an extra UPS/switch I can use for this. In the past when I was a bachelor and had more free time, I used to run my own FreeBSD server with pf and other services running in jails. Now that I am settled down, I just want to make things as idiot proof as possible in case there is an Internet issue at home and another family member needs to fix it.

The XGS-PON workaround that DannyBee looks promising though:

https://pon.wiki/guides/masquerade-as-the-att-inc-bgw320-500...

I probably could pay to upgrade my speed to 2Gbps and then downgrade it back to 1Gbps and keep the XGS-PON.

Post reply on HN