Live data from Hacker News

D-Link patch doesn’t address all bugs listed in their own security advisory

devttys0.com

71–80 of 86 posts

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#71
post #2

I guess this is a reminder that writing secure C is actually really, really hard.

Well, maybe just one "really"

What is really hard is finding decent firmware engineers. Ones who care, and who can write secure code.

Even harder, finding a management chain that values security and that is willing to pay for it, and its continual upkeep (because security is a process, not a feature that you can complete and move on from).

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#72
post #36

Earlier quoted context omitted.

> an even older Linksys WRT54GL That thing has been working for almost ten years (granted it is not an office environment), once with openwrt and now with tomato, while rebooting its little and adorable self every night at 3am automatically so that I don't have to. It's an amazing piece of hardware that makes one say "back in the day".

It was good for its time, but has limited onboard RAM, limited storage, and pretty slow WiFi by modern standards (there are even faster G-band, let alone N). Wouldn't recommend it today, and certainly wouldn't recommend touching Linksys with a ten foot pole. As to stability, I'd describe it has a mixed bag. I owned one for just under five years and had to do fortnightly restarts (which I eventually automated), and we…

Do you have any particular recommendations for new(ish) consumer routers?

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#73
post #67
post #40

Earlier quoted context omitted.

Yes, typically home routers tend to use pretty industry standard chips like Broadcom chips (like the BCM5357 in my home router). D-Link, Linksys, and crew don't usually roll their own SoCs, but just seem to throw off the shelf stuff in there. These chips tend to be SoCs, and while I can't be totally sure that there isn't a weirdo NSA backdoor on it (probably just as likely as any other router, residential or commerci…

ARM? I thought most routers used MIPS. At least several of the ones I've used are.

ARM is taking over from MIPS in the 802.11ac supporting products. MIPS is still around, but is now in the second tier of popularity alongside PPC. The single-core MIPS 24K and 74K that have been so popular just aren't fast enough for doing smart things at DOCSIS 3 speeds. They've also largely switched from NOR flash to NAND flash.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#74

Earlier quoted context omitted.

It was good for its time, but has limited onboard RAM, limited storage, and pretty slow WiFi by modern standards (there are even faster G-band, let alone N). Wouldn't recommend it today, and certainly wouldn't recommend touching Linksys with a ten foot pole. As to stability, I'd describe it has a mixed bag. I owned one for just under five years and had to do fortnightly restarts (which I eventually automated), and we…

Do you have any particular recommendations for new(ish) consumer routers?

I've got 3 Linksys E3000s that seem to be working fine with DD-WRT and Tomato. One's the main router, one's the VPN endpoint(s), and one's a spare.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#75
post #58
post #37

Earlier quoted context omitted.

I have to run the configuration tool in a windows VM because on 10.10 they removed the frameworks it uses to run. I wish they weren't so complacent as to turn my hardware into bricks.

Maybe you just need to reinstall it? I just took a peek at it on my new laptop (which has never had anything but Yosemite installed on it) and it worked fine.

Airport Utility 5.6.1 was the last version that supported some of the older airports. Unfortunately Airport Utility 5.6.1 doesn't work (officially) on anything newer than Snow Leopard, but there's some modified versions floating around that work on 10.9

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#76
post #49

I wonder which vendors have the best firmware.

Are there any left that are owned by semi-reputable big companies? Back when Cisco had Linksys there was some hope that they'd at least look after the vulnerability handling and patching process in a grown up way.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#77
post #76
post #49

I wonder which vendors have the best firmware.

Are there any left that are owned by semi-reputable big companies? Back when Cisco had Linksys there was some hope that they'd at least look after the vulnerability handling and patching process in a grown up way.

The Apple Airport Express is reasonably cheap, has a great range, is easy to configure, and doesn't have a reputation for being insecure.

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#78

Earlier quoted context omitted.

It was good for its time, but has limited onboard RAM, limited storage, and pretty slow WiFi by modern standards (there are even faster G-band, let alone N). Wouldn't recommend it today, and certainly wouldn't recommend touching Linksys with a ten foot pole. As to stability, I'd describe it has a mixed bag. I owned one for just under five years and had to do fortnightly restarts (which I eventually automated), and we…

Do you have any particular recommendations for new(ish) consumer routers?

I buy Asus stuff then flash third party ROMs. Here's a massive list: http://www.dd-wrt.com/wiki/index.php/Supported_Devices

If I was buying something today, it might be the Asus RT-AC66U (since it is a "compromise" between price/performance).

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#79
post #39
post #8

I've just accepted that residential routers are full of assorted orifices (security holes, backdoors & holes in functionality). Then again I'm not hiding anything dubious - if I was I'd install a firewall box asap. (And yes I know the "nothing to hide" slippery slope etc argument)

> I'm not hiding anything dubious - if I was I'd install a firewall box asap. This person does not do online banking, does not have a webcam or mic installed device such as a laptop, and does not have an email account. The only reason I don't have a firewall box behind my residential router is because I don't have money to buy extra hardware.

Email and banking has two factor authentication and runs over SSL so it would have to be a very determined hacker to get to my money.

Its not perfect, but as I'm pretty comfortable with the risk balance. Things like all these android apps containing god knows what make me way more jittery (See google's recent cleanup).

Re: D-Link patch doesn’t address all bugs listed in their own security advisory

#80
post #10

pfsense on a thin client = 40$ OpenWRT on a home router as AP = 30$ Not getting pwned = priceless

What are you running pfSense on for $40?

It's the HP T5735. It's second hand from ebay. I got the fat version that has an extra PCI slot and I put a Realtek gigabit NIC in there. It's fast enough for home use, it does not saturate with my 200 megabit link. I use a TL-WR1043ND as an access point and VLAN-capable switch.
Post reply on HN