Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

31–40 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#31
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients?

Frankly he could have just sold the vulnerability to the highest bidder

Re: Hacking millions of modems and investigating who hacked my modem

#34

Holy hell, but how are your laws in the US aligned so doing something like this is okay? In Germany you would get minimum 3 years in jail for this, people got in front of court for way way way way less.

For the researcher? Because the vendor has a responsible disclosure program. Because they'd rather know about the bugs.

(As for the vendor, I'm sympathetic to the argument that there should be vendor liability under some circumstances.)

Re: Hacking millions of modems and investigating who hacked my modem

#35

This is seems like a huge vulnerability, are there any legal repercussion that happens in those situations?

I hope not. Companies would close their responsible disclosure programs as a liability issue. Everything would be less secure because of such legal protections.

Re: Hacking millions of modems and investigating who hacked my modem

#36

Holy hell, but how are your laws in the US aligned so doing something like this is okay? In Germany you would get minimum 3 years in jail for this, people got in front of court for way way way way less.

For the researcher? Because the vendor has a responsible disclosure program. Because they'd rather know about the bugs. (As for the vendor, I'm sympathetic to the argument that there should be vendor liability under some circumstances.)

In Germany it is common for vendors to acknowledge the security flaw you send to them, but if you want to publish it (and damage their reputation by doing so) they are going to try you in court, and win.

Sometimes they even try you in court if you don't publish it (yet)

Re: Hacking millions of modems and investigating who hacked my modem

#38

Earlier quoted context omitted.

FritzBox are also very famous for getting service on lines where other vendors will just crap out. Their chipsets and tunings are top-notch. In addition, the backwards compatibility is amazing. It's 2024, and to my knowledge most of their models still support pulse dialling on the analog telephone frontend.

Although expensive, they've always had good fame (and I even had a friend working from them years ago), but something "funny" was going on with their routers some months ago... https://news.ycombinator.com/item?id=40106336

Yeah that's because they used .box as a custom TLD for decades and either didn't get the introduction of .box as a legitimate TLD or failed to secure fritz.box in time.

Not the first time this has happened, and likely won't be the last either.

Re: Hacking millions of modems and investigating who hacked my modem

#40

Holy hell, but how are your laws in the US aligned so doing something like this is okay? In Germany you would get minimum 3 years in jail for this, people got in front of court for way way way way less.

Cox has a responsible disclosure program: https://www.cox.com/aboutus/policies/cox-security-responsibl....

In my opinion (as a security engineer) the biggest benefit of such programs is not amoral "hackers will always sell exploits to the highest bidder so companies must provide a high bounty for bugs in their software"[1] but "having a responsible disclosure process makes it totally clear that it's ok to report vulnerabilities without being sued".

Looking at the timeline below the post I can't see anything problematic. The author even waited the usual[2] 90 days before disclosure, even though the vulnerability was hotpatched a day after report (congrats to Cox btw). They also shared a draft blog post with them a month ago.

[1]They certainly should, in the ideal world.

[2]A deadline popularized (or even invented) by Google's project zero.

Post reply on HN