Live data from Hacker News

D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

threatpost.com

51–60 of 306 posts

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#51
post #43

This is the new normal, folks. Consumer technology is manufactured for six to twelve months, but live in our homes for three to five years. Today's manufacturers cannot afford to update software for hardware devices they have already moved on from. Changing that requires a significant upheaval in their business models. This applies to every "connected device:" printers, cell phones, home routers, refrigerators, therm…

For D-Link this is the normal, normal and has been for years. Check out VU#924307 which they never fixed. It could be triggered either by an attacker or just in the normal course of using the router:

https://www.kb.cert.org/vuls/id/924307/

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#53
post #20

Earlier quoted context omitted.

If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. It doesn't matter if it's a Prius or a Ferrari. These vendors are selling defective devices and it is fixable via software patch. Just because they stopped selling them doesn't mean they shouldn't have to fix it.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

In an hospital, someone could die from a hacked device.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#54
post #53

Earlier quoted context omitted.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

In an hospital, someone could die from a hacked device.

I should really, really hope hospitals are not using routers like these.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#55
post #22

What is the best wifi-router out now for home hackers? I'd like to do a pi-hole type setup but without the pi-hole and I also need a stronger wifi signal than on the box my ISP gives me.

I'd suggest to avoid dealing with wifi routers as much as possible, they are not worth the time, and instead separate wifi and routing. Doing all the dhcp, dns/pi-holing, nat, firewalling on a PC-based router and using a wifi router behind it only for wifi.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#56
post #38

Earlier quoted context omitted.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

It's not just "one unpatched router". It could be millions. Or millions or billions or IOT devices in the future that are unpatched. That does have the potential to create some damage if anyone takes control of them. Maybe even kill some people, if say they DDoS the V2I network for self-driving cars in the future, or a hospital network over which remote surgeries are performed, etc. I feel like this argument that "yo…

Without agreeing with this point it's a perfectly reasonable one to make. Why is it dead? Seems to be quite a bit of this sort of thing of late, new ML tools?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#57

For national security sake all routers should be required to support open firmwares.

Not exactly what you’re asking for, and it has its own problems [0], but the US military has a “trusted foundry program” [1] for sourcing chips. [0] https://semiengineering.com/a-crisis-in-dods-trusted-foundry... [1] https://en.m.wikipedia.org/wiki/Trusted_Foundry_Program

Being open source at the chip level, while an admirable goal isn't really required for open source firmware. Most router firmware is linux, that runs on either ARM or MIPS based SoCs. Opening up that code is more than enough to fix any security flaws like these.

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#58

Earlier quoted context omitted.

If you want a less touchy solution (not completely plug and play though!) I can't recommend Ubiquiti products enough. I run an EdgeRouter X and Unifi AP at home. Not big enterprise gear but way more enterprisey than whatever you'll find on the shelf at Best Buy. Updates are released regularly and once you get your initial configuration done they just chug along, no random 'internet is down, need to reboot something'…

Cheaper and older alternative is the Ubiquity Unifi Security Gateway + 8 port switch + UAC AP-PRO if you don't want the Edgerouter X cost. Less customizeable but if you're buying an EdgeRouter you know what you want.

how does power consumption compare with a setup like this vs some consumer all-in-one thing?

Re: D-Link Home Routers Open to Remote Takeover Will Remain Unpatched

#60
post #38

Earlier quoted context omitted.

> If a car spontaneously combusts we hold the auto manufacturable liable for correcting that defect. This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.

It's not just "one unpatched router". It could be millions. Or millions or billions or IOT devices in the future that are unpatched. That does have the potential to create some damage if anyone takes control of them. Maybe even kill some people, if say they DDoS the V2I network for self-driving cars in the future, or a hospital network over which remote surgeries are performed, etc. I feel like this argument that "yo…

It's not "you get what you pay for", even the most expensive consumer routers are out of support 2 years later.
Post reply on HN