Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

251–260 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#251
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…

I’ve often wished I could show an “I know what I’m doing” badge to support to guarantee escalation.

“I’m a three star infosec General, if I’m contacting you it’s not to waste your time.”

Re: Hacking millions of modems and investigating who hacked my modem

#252

Earlier quoted context omitted.

> The author's mistake was not posting somewhere like NANOG or Full-Disclosure with a detailed write-up. This is an organizational equivalent of a code smell. Something is off when support people aren't writing up the anomalies and escalating them. Some of the most serious security issues I've ever had to deal with started with either a sales rep getting a call or a very humble ticket with a level one escalating it u…

"Code smell" as a programming term is often a red herring that causes conflicts within development teams (I've seen this happen too many times), because anyone can call anything they don't like about a coworkers code as a "code smell". Your comment is a "code smell" . See how easy that was? And "code smell" doesn't apply in a similar or metaphorical way towards cable modem support personnel. Those people aren't suppo…

I’ve been in this industry for 15 years and I’ve never had to deal with the code smell situation, in that I don’t use that term and I’ve never interacted with anyone at work who uses that term.

I think after reading this I’ll continue that habit. Putting the phrase “code smell” in a review is like using the dark side of the force: you’re just being an ass

Re: Hacking millions of modems and investigating who hacked my modem

#253
post #135

Earlier quoted context omitted.

> Cox is the largest private broadband provider in the United States, the third-largest cable television provider, and the seventh largest telephone carrier in the country. They have millions of customers and are the most popular ISP in 10 states. That suggested to me that we shouldn't have ISPs that are this big. Cox is clearly a juicy target and a single vulnerability compromises, as an example from the article, ev…

I think the author wrote it up factually. Readers can make their own inferences, but Cox did share with him that the service he exploited was only introduced in 2023. Which suggests the security team did do some investigating. I'm sure* they don't keep raw request logs around for 3+ years. I know what next steps I'd recommend, but even if they undertook those, they're not sharing that in the ticket. (just based on in…

The point is the statementay or may not be accurate. From a journalistic perspective, unless Cox provided evidence or the author was able to otherwise independently verify the claim, it's a claim, not a fact. The comment is a good suggestion.

Re: Hacking millions of modems and investigating who hacked my modem

#254

Earlier quoted context omitted.

> Cox seem to have acted like the very model of responsible security response in this kind of situation It's hard to imagine, but I wish they would have taken advantage of him walking in with the compromised device in the first place. I once stumbled upon a really bad vulnerability in a traditional telco provider, and the amount of work it took to get them to pay attention when only having the front door available wa…

I’ve often wished I could show an “I know what I’m doing” badge to support to guarantee escalation. “I’m a three star infosec General, if I’m contacting you it’s not to waste your time.”

It quickly becomes the Service Animal problem. When no one can or is allowed to verify your infosec credentials, everyone becomes a three star infosec General with a simple purchase from Amazon/Alibaba.

Re: Hacking millions of modems and investigating who hacked my modem

#255

i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

Can the ISP load firmware onto your modem? I'm on Cox in the US (same ISP as in TFA) and you can bring your own modem, but Cox will remotely update the firmware.

Not really as far as I know. Providers in Germany have more or less standardized on Fritz!Box from AVM and the router comes with the admin password available. Updates are then fetched from upstream AVM.

But the key point here is device independence - by law, providers need to give you all information required to establish a connection to them. This allows you to run a Linux or BSD box as a router should you wish to. It somehow makes up for the slow broadband speeds you can get.

*Edit: complaints about slow broadband speeds

Re: Hacking millions of modems and investigating who hacked my modem

#256

Earlier quoted context omitted.

Ethics aside, what is characterful about saying no to money? Should I say no to my salary for character reasons?

There's a difference between doing your job and earning money as a result vs. finding keys to someone's house and selling said keys to the highest bidder.

Yes: ethics.

Re: Hacking millions of modems and investigating who hacked my modem

#257

Earlier quoted context omitted.

How many of those show up in person though?

yeah the false positive problem is huge here. For every legitimate security professional there are probably 10-100 schizos who believe they are “hacked”

I was mentioned in the media once for an unrelated internet protocol vulnerability and I had people contacting me about their "hacked" internet connections.

For a major cable ISP, I can't imagine how many customers walk in to replace their "hacked" boxes on a daily basis.

Re: Hacking millions of modems and investigating who hacked my modem

#258
This reminded me to turn off "privacy settings" to "keep your vehicle in good condition and observe the vehicle's health" on my Volvo XC40 after the mechanics asked me to turn it on yesterday during the yearly maintenance. I don't know if they can change some settings remotely, but I prefer to be cautious

Re: Hacking millions of modems and investigating who hacked my modem

#259

i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

Can the ISP load firmware onto your modem? I'm on Cox in the US (same ISP as in TFA) and you can bring your own modem, but Cox will remotely update the firmware.

No, they can't. They don't have any access at all to your device. But as jeduardo already said, you can fetch updates from the device manufacturer. The mentioned Fritz!Box from AVM has automatic updates and is known for delivering them for a really long time. My 12 year old repeater from that brand is still receiving security updates from time to time.

Re: Hacking millions of modems and investigating who hacked my modem

#260

Earlier quoted context omitted.

For the researcher? Because the vendor has a responsible disclosure program. Because they'd rather know about the bugs. (As for the vendor, I'm sympathetic to the argument that there should be vendor liability under some circumstances.)

In Germany it is common for vendors to acknowledge the security flaw you send to them, but if you want to publish it (and damage their reputation by doing so) they are going to try you in court, and win. Sometimes they even try you in court if you don't publish it (yet)

Regarding Germany and large corporations, and somewhat of a tangent, I remember a decade ago a bunch of hedge funds had tried to sue Porsche, the parent company of VW, for cornering the market for VW’s open interest and cause the mother of all short squeezes.

They tried the case in New York but it got thrown out for lack of jurisdiction. They did try the case in Germany, but Porsche had fittingly cornered the market for the best and biggest law firms. All of the best law firms refused to take the case because it would mean that they’d be essentially blacklisted by the largest companies in Germany for bringing a case against a German company.

It’s taken a decade, but I now see a pattern.

Post reply on HN