Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

51–60 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#51
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

it's good but the constant use of "super" was a little off-putting, "super curious", "super interesting", "super interested", etc.

Re: Hacking millions of modems and investigating who hacked my modem

#52
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

it's good but the constant use of "super" was a little off-putting, "super curious", "super interesting", "super interested", etc.

Super off-putting, you mean.

Re: Hacking millions of modems and investigating who hacked my modem

#53
post #10
post #6

One of the reasons to not be excited about ISP provided cable modems with WiFi functionality and to have good endpoint/service security on your LAN. (TLS, DNS over TLS at least accross the modem/ISP) I just put it in bridge mode, disable wifi, and all network functionality is served by my own devices. The last modem I rented from ISP, the ISP didn't bother with any firmware updates for ~10 years. It was rock stable b…

Counterpoint: ISP with over 1M customers have the incentives of upgrading their HGW "forever" to reduce Capex. My employer (Free, French ISP also shipping HGW to Italia as Iliad) still upgrade their HGW released in 2011 (though if you have yours dating back from 2011, have it replaced (your oled screen is probably dead ;) to get more recent wifi cards). It runs a modern Linux 6.4. You get modern nifties like airtime…

I'd like the record to show that the upgraded mobile apps are significantly worse than the old ones. The old ones are currently still available to download, for now.

Re: Hacking millions of modems and investigating who hacked my modem

#56
post #54

I see arguments in favour of tr069, but it's the mechanism that BT used to reboot my modem every night at 3am. I hate ISPs.

Unplug it then they can't reboot it :) They probably put it under the guise of load-balancing but that does seem excessive.

Re: Hacking millions of modems and investigating who hacked my modem

#57

Earlier quoted context omitted.

Although expensive, they've always had good fame (and I even had a friend working from them years ago), but something "funny" was going on with their routers some months ago... https://news.ycombinator.com/item?id=40106336

Yeah that's because they used .box as a custom TLD for decades and either didn't get the introduction of .box as a legitimate TLD or failed to secure fritz.box in time. Not the first time this has happened, and likely won't be the last either.

.dev entered the chat

Re: Hacking millions of modems and investigating who hacked my modem

#58
post #2

What a great article. Very easy to follow. The best part was that instead of attacking the messenger and denying any problem, Cox seem to have acted like the very model of responsible security response in this kind of situation. I'd love to read a follow up on what the bug was that intermittently permitted unauthorised access to the APIs. It's the kind of error that could easily be missed by superficial testing or de…

it's good but the constant use of "super" was a little off-putting, "super curious", "super interesting", "super interested", etc.

There were 4 occurrences of the word "super" in an article with more than four thousand words in it, there is no need for "etc." you quoted all the occurrences since "super curious" was used twice.

Re: Hacking millions of modems and investigating who hacked my modem

#59
post #28

> After reporting the vulnerability to Cox, they investigated if the specific vector had ever been maliciously exploited in the past and found no history of abuse Would you trust a thing they say? It seems their whole network is swiss cheese.

if they say not, does that imply another vector that they may or may not know about given the author had already found a compromised device.
Post reply on HN