Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

301–306 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#301
post #299

Earlier quoted context omitted.

In my jurisdiction, consumer device must have "reasonable lifetime" by law. This lifetime of course is not to be determined by the manufacturer, but by the courts in the event of a disagreement. Ten years is bit long, but it's not absurd to think (i.e. reasonable) it should work ten years after the time of purchase even if the technology becomes obsolete.

Nobody would sell consumer electronics in your jurisdiction if they thought it were a remote possibility that courts would endorse "Purchase date + 10 years" or even "First sale date + 10 years" for software updates . An original iPad isn't even 10 years old and is many years past being able to run an iOS version that receives security updates. A 10 year old MacBook Pro is a few years beyond having a supported OS wit…

Handheld devices cannot be reasonably expected to last 10 years.

However consumer goods must be fit for purpose for a reasonable time. The case of the insecure router after 5-10 years was probably not brought to court, but I hope the court would agree that it isn't fit for purpose if insecure..

If you are really interested, you can read on the law here (my jurisdiction is Quebec, Canada) : https://www.opc.gouv.qc.ca/en/consumer/good-service/goods/sm...

Fortunately, we don't have to care what manufacturers think is absurd or not; it's been decided for them.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#302
the more i think about it the more i notice that a lot of 'security' is actually used to verify or 'add value' to the data that gets mined meaning 'verified' traffic holds more value than non verified traffic so that might explain a reason why security protocols on routers and other common devices are not as secure as they could be. you could note that this is also a form of 'security against you' meaning a 'proof' for a court.

i don't know what the answer is to this simply because of all the variables i consider, especially the emergence of drones. how will this be secured to a degree that few can interfere with package deliveries, the abuse of surveillance and what space around a property is actually protected. as example you can drive by in a vehicle collect AP information and the average geek can obtain access so it will be with drones.

if you really want to get interesting, think about the things drones can do, such as compromise crime scenes with planted evidence.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#303
post #89

Earlier quoted context omitted.

Until consumers are willing to spend on subscription services to keep devices up-to-date, new hardware is the de facto method of paying for software development work. Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send t…

Until consumers are willing to spend on subscription services... You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor. In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases). Where manufacturers, or as…

And most consumers probably lease their routers through their ISP as modem/WiFi router combos, which essentially remain supported and updated by the ISP.

If we alternatively enforce a floor on security updates for user-purchased routers, let’s say we require security updates for the physical lifespan of the device (10 years?), they will be baked into the price of the device in some way, and I’m not sure the majority of home router customers who essentially look to spend around $20-40 will be willing to bear that cost.

An example of that in action would be purchasing a business SKU laptop compared to a consumer one, and taking a look at the length of driver support.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#304

Earlier quoted context omitted.

Because the hardware didn't do much of anything!

Contrast Minitel, a videotext online system provided by the French government phone monopoly Postes, Télégraphes et Téléphones in 1980. https://en.wikipedia.org/wiki/Minitel

[deleted]

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#305
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

The killer app would be a portable, secure (say, seL4), extremely fast-booting OS that handles hardware and tasks asynchronously. Right now, I'm dealing with a Xfinity->Cisco->Pegatron router that reboots spontaneously 15x/day, the web interface takes 2 minutes to load a PHP page and it takes 2-3 minutes to reboot. This is unacceptable since software doesn't have to behave like this... we can and must do better.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#306
post #212

Earlier quoted context omitted.

Can this model be used as a VPN server routing through your home ISP connection?

I think this router+dd-wrt supports it though I haven't personally used vpn on it. Here is the link that implies it supports it: https://www.myopenrouter.com/articles/r6300r6300v2-guides-ho... . Some general information about the router is at: https://wiki.dd-wrt.com/wiki/index.php/Netgear_R6300v2 . Edit: another link: https://nordvpn.com/tutorials/dd-wrt/flashrouters-privacy-ap... .

Thanks for the links.
Post reply on HN