Live data from Hacker News

How to exploit home routers for anonymity

danmcinerney.org

71–80 of 80 posts

Re: How to exploit home routers for anonymity

#71
post #9

Another reminder to use strong, non-default credentials on something that is the edge of your network. I'm still amazed by how many people drive around leaving their cars unlocked.

I leave my keys in the car sometimes when I'm running errands in my home town. I care a whole lot more about my network security at home than I do my car. It's just a car.

In my country, it's illegal to leave the keys in your car when you're not in it (a child could get in it to play and hurt themselves or others)

Re: How to exploit home routers for anonymity

#73
post #51
post #49

Earlier quoted context omitted.

I would love to see someone try to use HN at 9600 bps. That's bits per second, so 9600 / 8 = 1200 characters per second, roughly.

I used all of those things - irc, the web (gopher), etc., at 9600 baud for years. Wasn't a problem. Also, you don't really need to configure a browser - just use lynx, which will ignore most of the bandwidth hungry aspects of a site.

When we used the Internet at slow speeds or in batch mode we had people being cautious with bandwidth. Usenet had the informal McQ limit for signatures, which led to newsgroups like alt.fan.warlord to mock people with big or ugly sigs.

The text on the current top story (the Wright Brothers article) is about 11kbytes. That doesn't include any html or css or anything else. That would make a page load at over ten seconds just for the text.

The point isn't that it can not be done, but that people would not tolerate it unless they had a real need.

Re: How to exploit home routers for anonymity

#74
post #34

Earlier quoted context omitted.

The Bill of Rights already explicitly says it isn't the List of Rights.

The intent of it is a framework, right? i.e. it's not inclusive of all rights, just ones that are currently applicable and a template of intent for future ones.

The answer is in the assumption that powers are enumerated and rights are not. That's why the BoR contains that disclaimer.

Re: How to exploit home routers for anonymity

#75
post #51
post #49

Earlier quoted context omitted.

I would love to see someone try to use HN at 9600 bps. That's bits per second, so 9600 / 8 = 1200 characters per second, roughly.

I used all of those things - irc, the web (gopher), etc., at 9600 baud for years. Wasn't a problem. Also, you don't really need to configure a browser - just use lynx, which will ignore most of the bandwidth hungry aspects of a site.

I regularly use links (as opposed to lynx) to access text heavy sites; nice, clean, distraction-free reading.

Re: How to exploit home routers for anonymity

#76

Earlier quoted context omitted.

This is, incidentally, the reason why government-resistant anonymity services need to be legal. If you don't care about stealing credit card numbers or hurting people then you don't care about breaking into some poor sucker's router. But if you're blowing the whistle on some organizational malfeasance, you won't, so you need the likes of Tor.

I think that oversimplifies an important point. Criminals may not CARE about breaking into someone's computer or router, but that doesn't mean they're capable of doing so. Tor significantly lowers the bar for anonymity online, and there is no question in my mind that it enables criminals who wouldn't have the means to mask their identities otherwise. This is not necessarily an argument against tools like Tor, but it'…

> Criminals may not CARE about breaking into someone's computer or router, but that doesn't mean they're capable of doing so.

The problem with this line of reasoning is that it covers such a small number of people. The only people your argument covers are serious criminals who a) are too stupid to be able to download a simple tool to exploit routers with unpatched vulnerabilities from last year and yet b) are still competent enough to use Tor without doing anything that would reveal their identity.

And that also excludes the most serious criminals because the set of people who can break into the computers of large organizations to commit crimes is essentially a superset of the set of people who can break into an unpatched consumer-level router.

Re: How to exploit home routers for anonymity

#77

Earlier quoted context omitted.

I think you give way too much credit to the average person. It's easy to lose sight of how scary technical things are to normal people when you're in it day in and day out, but to ask the average person to change something in their router is kind of like asking me to replace a cylinder in my car. There's a reason things like the Geek Squad are around and can charge as much as they do...

I agree with Oxdeadbeefbabe; you are complementing your own 'technical' (computer-related) ability, and overstating the task of configuring a router. Also, not to be pedantic, 'to replace a cylinder' hardly describes a task that can be undertaken on a motor. The variance in technical ability of the 'average person' nowadays is pretty wide. There are still pop-up clicking grandmothers on IE7 out there, but there are a…

It is relatively easy to change a cylinder on a horizontally opposed air-cooled VW motor (think '60s beetle) or the Lycoming/Continental engines popular in light aircraft.

Re: How to exploit home routers for anonymity

#78

Earlier quoted context omitted.

While I don't disagree with you, at least in the UK, possession in a cache and in some circumstances, transmission of child abuse images is a strict liability offence, meaning intent doesn't come into it - I suspect it's the same in many jurisdictions. It's a ridiculous position, but it's still the reality for many.

Are there any actual cases where someone was found guilty just for operating a computer/router/whatever that relayed information? What is a piece of legislation says and what is actually "law" is often not the same, as the courts can interpret it however they want.

There are a couple that stick in the back of my head, but I can't remember the names - I'll try and dig them out when I get home next week!

Re: How to exploit home routers for anonymity

#79
post #57

Earlier quoted context omitted.

I think you give way too much credit to the average person. It's easy to lose sight of how scary technical things are to normal people when you're in it day in and day out, but to ask the average person to change something in their router is kind of like asking me to replace a cylinder in my car. There's a reason things like the Geek Squad are around and can charge as much as they do...

If a random stranger can remotely hack your router, I wouldn't be confident that any settings change will secure it. The router is garbage and needs to be replaced, which is easily within the understanding of an average person.

That view is a bit naive. If the problem with a router is that the router is shipped by default with a known back-door or with insecure settings, that does not mean that "the router is garbage". It points to a deplorable lack of wisdom on the part of the vendor, but does not necessarily imply that the only solution is the pay for a replacement.

Re: How to exploit home routers for anonymity

#80
post #15

Earlier quoted context omitted.

> What can be done? Are we reduced to just securing our friends' and families' infrastructure, all the while standing by idly while others outside of our direct sphere of influence suffer the consequences of naïvety? No. We can write articles similar to this one which, instead of clearly explaining step-by-step procedures for exploiting weaknesses, clearly explain step-by-step procedures for REPAIRING weaknesses.

I think you give way too much credit to the average person. It's easy to lose sight of how scary technical things are to normal people when you're in it day in and day out, but to ask the average person to change something in their router is kind of like asking me to replace a cylinder in my car. There's a reason things like the Geek Squad are around and can charge as much as they do...

Writing simple instructions about how to configure the router safely will not produce a ready-made solution for EVERYONE, but it will certainly help for SOME PEOPLE. And the question was whether anything could be done to assist those "outside of our direct sphere of influence" (i.e. not friends and family). This clearly would help.
Post reply on HN