Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

261–270 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#261
post #183

I tell everyone who will listen don't buy consumer networking gear. Buy from Ubiquity or get the enterprise routers/APs from your favorite brand. They are much more likely to be updated and don't really cost much more. Sure, it takes some know how to set up, but they can call me if they take my recommendations.

Eero is a much better alternative for the average person. Solid features, INCREDIBLY easy to setup, nice app, helpful support, etc. Big fan.

They got bought out by Amazon now though, which may worry some people

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#262

Earlier quoted context omitted.

If you want a less touchy solution (not completely plug and play though!) I can't recommend Ubiquiti products enough. I run an EdgeRouter X and Unifi AP at home. Not big enterprise gear but way more enterprisey than whatever you'll find on the shelf at Best Buy. Updates are released regularly and once you get your initial configuration done they just chug along, no random 'internet is down, need to reboot something'…

Cheaper and older alternative is the Ubiquity Unifi Security Gateway + 8 port switch + UAC AP-PRO if you don't want the Edgerouter X cost. Less customizeable but if you're buying an EdgeRouter you know what you want.

Isn't the EdgeRouter X cheaper than the USG?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#263
post #236
post #231

Earlier quoted context omitted.

As soon as warranty/support expires, the device must be free for DRM/reverse-engineering . This will incentivize manufacturers to offer longer support. Edit: Rather they should actually provide the spec, drivers etc

There are a lot of routers using GPL code that have open source firmware available (ddwrt,openwrt,tomato,etc.) I think once support for a device ends it should be mandated that the company release the source code for future development. There is a worrying increase in the amount of IoT devices that will remain forever unpatched due to the (cheap overseas) manufacturers never updating them or ending support for them.

Make that one year before ending support, so there is both time to prepare and incentive to open source early.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#264
post #247

We don’t have cable or a phone line, so I recently bought a D-Link router with a 4G SIM card slot and a massive yearly data plan that corresponds to the approx. amount of data I use yearly at home as a light non-streaming user (400gb at approx. $1 per gb). I’m open to hardware suggestions that are/more open source capable or robust in the first place, but my use case was really niche and the shop(s) had nearly nothin…

Mikrotik has an interesting outdoor LTE router (although I couldn't find anywhere reputable to buy it in the US). You could also get a USB or MiniPCIe modem and put it in whatever Linux box you want.

I would love to build my own that also does proxy server.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#266
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Its been the norm for a long time now. I've always wondered why printer manufacturers could get away with universally exempting themselves from security audits. People just admitted they were bad and said: "don't even look at it wrong or it'll dump all its paper and toner on the floor"

It really does. I had a network connected Xerox printer that would hang until rebooted, only by port scanning it with nmap.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#267
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

This is exactly why I'm done with consumer router devices. Open Source routers are mature and infinitely more secure. https://teklager.se/en/open-source-routers/

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#268
post #139

Earlier quoted context omitted.

The damage from an unpatched router can be pretty far-reaching, especially in cases where it can be exploited over Internet (not sure about this one, but some other D-Link vulnerabilities reportedly could). I find it regrettable that the architecture commonly in use does not make a clear distinction between devices for convenience and for security. It’d be crazy if in our homes the main entrance lock always came as a…

The front door lock is actually a bad example: in single-family houses, the front door is a social and legal signifier more than it is a security device. Smash a window; go around back; use a crowbar: the lock isn't what's keeping you out, it's designating the social expectation that you don't have a right to be there without an invitation and the legal assertion that crossing the threshold violently is a bigger crim…

I’m sure it depends on location, but there is the opportunistic crime—if home owners are away, probe the door to see whether it’s locked, get in and grab something if not. Routers and mass scans are somewhat similar.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#269
post #89
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

Or manufacturers can stop making "smart" devices just so they can fill them with ads and malware, leaving customers exposed to unlimited amount of threats.

It's not like they're just "giving you the choice" either. TV makers have already started completely removing non-smart TVs from their line-ups for instance.

I don't want a smart TV. If I want my TV to be smart, I'll buy a $50-$100 set top box I can upgrade in 2-3 years and is probably significantly more secure. Meanwhile a "smart" TV I will keep for 10+ years, but won't receive updates even for 20% of its lifecycle.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#270

The affected routers may be supported by OpenWRT, a free software wireless router project, or similar projects (dd-wrt, Tomato). Looking the OpenWRT Table of Hardware ( https://openwrt.org/toh/start?dataflt%5BBrand*~%5D=D-Link ), I find: DIR-655: OpenWRT: not listed. DIR-866L: OpenWRT: not listed. dd-wrt: https://wiki.dd-wrt.com/wiki/index.php/D-Link_DIR-868L DIR-652: not listed DHP-1565: Present: https://openwrt.org…

Most DIR-XXX routers are actually Realtek (Lexra), which developers of OpenWRT refuse to support due to the unweildy microarchitecture of the SoC.

Thanks. I thought I'd at least look. Saw some indication that a few of the devices were pretty specifically not supported based on discussions.
Post reply on HN