Earlier quoted context omitted.
>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…
How many of those show up in person though?
Hacking millions of modems and investigating who hacked my modem
221–230 of 282 posts
Re: Hacking millions of modems and investigating who hacked my modem
#222Earlier quoted context omitted.
That's why I'm not an AT&T customer. Spectrum lets me bring my own hardware, and they're the only other option in my area, so Spectrum gets my business. Plain and simple. Unfortunately, not everyone has the palatable solution that I have.
Spectrum remote manages your hardware even if you bring your own modem. This nearly entirely consists of deploying firmware updates once a decade, but they can also command other things like modem reboots.
Re: Hacking millions of modems and investigating who hacked my modem
#223Earlier quoted context omitted.
Its HTTP not HTTPS, anyone or anything on the wire could see the request
That's the part I didn't get. The author said there was no other possibility except the modem, but why? It seems like quite a leap. I would have first suspected a compromised router on the internet. Is it possible that changing the modem caused new routes to be used which appeared to fix the problem?
Re: Hacking millions of modems and investigating who hacked my modem
#224Did they * pay* him? He kind of saved them, tipped them off to a complete compromise of their security infrastructure which was not trivial to discover. Looks like he got nothing in return for "doing the right thing". How insulting is that? What is their perception of someone walking in to their offices with this essential information? I guarantee his self image and their perception are very different. They see an ov…
Re: Hacking millions of modems and investigating who hacked my modem
#225[flagged]
Re: Hacking millions of modems and investigating who hacked my modem
#226Earlier quoted context omitted.
>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…
How many of those show up in person though?
Re: Hacking millions of modems and investigating who hacked my modem
#227Earlier quoted context omitted.
> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…
>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…
Re: Hacking millions of modems and investigating who hacked my modem
#228Earlier quoted context omitted.
> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…
>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…
If you dropped this in my lap, and I'm pretty savvy for a layman, I wouldn't know how to get past my single channel. I think it would require convincing the gatekeeper.
Re: Hacking millions of modems and investigating who hacked my modem
#229Earlier quoted context omitted.
Spectrum remote manages your hardware even if you bring your own modem. This nearly entirely consists of deploying firmware updates once a decade, but they can also command other things like modem reboots.
If it's your own hardware, what's stopping you from closing the port they connect to?
Re: Hacking millions of modems and investigating who hacked my modem
#230Earlier quoted context omitted.
>Cox's support organization was presented with a compromised device being handed to them by an infosec professional, and they couldn't handle it effectively at all. I can't really blame them. The number of customers able to qualify that a device has actually been hacked is nearly zero. But do you know how many naive users out there that will call/visit because they think they've been hacked? It's unfortunately larger…
I work for a support org for a traditional telco. We have "contacts" but they're effectively middlemen. If you dropped this in my lap, and I'm pretty savvy for a layman, I wouldn't know how to get past my single channel. I think it would require convincing the gatekeeper.
Especially because both of the ISPs we supported insisted on using a lot of dodgy CPE.