Live data from Hacker News

D-Link patch doesn’t address all bugs listed in their own security advisory

devttys0.com

21–30 of 86 posts

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#23

I inherited an office with a D-Link router being used that kept misbehaving. I tried upgrading the firmware as a last resort, since DDWRT and the others don't work on it. Digging around I found a thread where customers were wondering what happened to bridge mode and why it had been removed. An obdurate admin informs everyone that D-Link decided it wasn't needed as a feature, so they removed it. The admin is very coar…

I had that router. To be clear, when they "removed bridging" they "removed, via adding a CSS 'display:none;' block to the radio button", and the workaround was inspecting the HTML and removing the CSS.

NOT that you should have to, by any means whatsoever.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#25
post #17
post #10

pfsense on a thin client = 40$ OpenWRT on a home router as AP = 30$ Not getting pwned = priceless

The problem is that mom and pop can't possibly be expected to do this. They are trusting that the device they buy or the device their ISP provides, is secure.

Indeed, but I don't think ariendj was talking to mom or pop.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#27

I inherited an office with a D-Link router being used that kept misbehaving. I tried upgrading the firmware as a last resort, since DDWRT and the others don't work on it. Digging around I found a thread where customers were wondering what happened to bridge mode and why it had been removed. An obdurate admin informs everyone that D-Link decided it wasn't needed as a feature, so they removed it. The admin is very coar…

TCP did that with their smart bulbs. They removed the local web interface in a silent update, bricking the bulbs for a lot of users. It's really bad manners, and I wish they would at least have options to re-add the missing features. It ultimately just alienates customers.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#28
I was in a dev team for a network security appliance. It is really sad they way they treat vulnerabilities and security advisories. There were very few people who know what the actual vulnerability was.The vulnerability would be listed as one of the last items in a release checklist. Gets assigned to a guy who has no clue whatsoever. The guy fixing the issue would google a patch. apply it. has no way of testing it comprehensively. He will run a basic test case. He will make up a report with a lot of security jargon for the managers and advisory team. And the next release would list the vulnerability as fixed.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#29
post #10

pfsense on a thin client = 40$ OpenWRT on a home router as AP = 30$ Not getting pwned = priceless

What are you running pfSense on for $40?

I think that he means per month in electricity costs. ;)

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#30

Things like this make me so happy to have things like DDWRT, OpenWRT, et al.

Why would you still be comfortable using an incompetent company's hardware , even if you fixed the software issue? Does anyone do meticulous teardowns of routers, much less documenting what silicon is present?

The OpenWRT wiki pages for the routers usually has some detailed info about the hardware. That won't tell you about hardware problems they might have that they didn't investigate but you can usually find photos of the boards to see what's there. [1][2][3]

[1] http://wiki.openwrt.org/toh/tp-link/tl-mr3040#photos_v10 [2] http://wiki.openwrt.org/toh/linksys/wrt610n#opening_the_case [3] http://wiki.openwrt.org/toh/netgear/wndr3700#photos

Post reply on HN