Live data from Hacker News

VPNFilter malware infecting 500K devices is worse than was thought

arstechnica.com

41–45 of 45 posts

Re: VPNFilter malware infecting 500K devices is worse than was thought

#41
post #6

How about routers (and IoT devices for that matter) that have a ROM image, with a user intitiated ability to actually obliterate the entire contents of NVRAM and flash? i.e. the firmware (which is made up of various parts, multiple stage bootloader, kernel, initrd, root, NVRAM, maybe proprietary radio firmware and/or baseband files) would be wiped out. The ROM would have a very limited ability to "phone home" only vi…

Sorry to sound like a broken record on this post, but Mikrotik does this. Everything can be flashed. Bootloader and OS. You can even get into a bricked unit via MAC address and their Netinstall utility, and wipe the whole thing with a clean image.

Re: VPNFilter malware infecting 500K devices is worse than was thought

#42
post #32

Earlier quoted context omitted.

Buy a small cheap computer with two ethernet ports and run debian.

And most importantly: keep it updated. About the only thing I would trust without updates is a bsd box. And even that, may eventually fall victim.

which BSD? And how is hardware support these days?

Re: VPNFilter malware infecting 500K devices is worse than was thought

#43
post #32

Earlier quoted context omitted.

Buy a small cheap computer with two ethernet ports and run debian.

And most importantly: keep it updated. About the only thing I would trust without updates is a bsd box. And even that, may eventually fall victim.

Ok, but what if you are very busy and you don't have time for that.

Re: VPNFilter malware infecting 500K devices is worse than was thought

#45

Any suggestions for a good router that is immune from this nonsense?

As in another post, I’d suggest buying any router, taking it apart, identifying the flash chip, find the write-enable line in the data-sheet and MITM that line with a flip switch to block updates at all times.

Ain't nobody got time for that.
Post reply on HN