Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

71–80 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#71

Earlier quoted context omitted.

For the researcher? Because the vendor has a responsible disclosure program. Because they'd rather know about the bugs. (As for the vendor, I'm sympathetic to the argument that there should be vendor liability under some circumstances.)

In Germany it is common for vendors to acknowledge the security flaw you send to them, but if you want to publish it (and damage their reputation by doing so) they are going to try you in court, and win. Sometimes they even try you in court if you don't publish it (yet)

This seems like awful law. Is there any movement to rectify the situation?

Re: Hacking millions of modems and investigating who hacked my modem

#72
post #31

Earlier quoted context omitted.

agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder

They do not:

> Cox does not offer a bounty program or provide compensation in exchange for security vulnerability submissions.

https://www.cox.com/aboutus/policies/cox-security-responsibl...

Re: Hacking millions of modems and investigating who hacked my modem

#73
post #31

Earlier quoted context omitted.

agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder

>...can't pay someone that found a bug impacting all their clients?...he could have just sold the vulnerability to the highest bidder

This attitude is why "independent security researchers" offering to present unsolicited findings to companies in exchange for payment feels exactly like extortion.

Re: Hacking millions of modems and investigating who hacked my modem

#74
post #31

Earlier quoted context omitted.

agreed, lets hope they dont bloody sue him into the ground for "hacking" Its stuff like this that company's should REWARD people for finding.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder

> Frankly he could have just sold the vulnerability to the highest bidder

Why? Ethics aside, is everything money?

Re: Hacking millions of modems and investigating who hacked my modem

#75
post #28

> After reporting the vulnerability to Cox, they investigated if the specific vector had ever been maliciously exploited in the past and found no history of abuse Would you trust a thing they say? It seems their whole network is swiss cheese.

You can't just refuse to participate, especially if you're the one who started the whole conversation. At some point you say "this is what i have and it's better than before."

Re: Hacking millions of modems and investigating who hacked my modem

#76
i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

Re: Hacking millions of modems and investigating who hacked my modem

#77
post #31

Earlier quoted context omitted.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder

> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?

because money grants wishes, and having more money means you get more of your wishes granted.

Re: Hacking millions of modems and investigating who hacked my modem

#78
> One of the things I'll never understand was why the attacker was replaying my traffic? They were clearly in my network and could access everything without being detected, why replay all the HTTP requests? So odd.

Did you determine if POSTs were replayed? As in, logging into accounts and sending payment info and account info?

Re: Hacking millions of modems and investigating who hacked my modem

#79

What sort of authentication system just lets calls through randomly sometimes... The incompetence!

In my experience this can be caused by a loadbalancer, for example not being able to route (properly) to servers in the pool or a difference in configuration/patch-level between them.
Post reply on HN