Live data from Hacker News

Hacking millions of modems and investigating who hacked my modem

samcurry.net

91–100 of 282 posts

Re: Hacking millions of modems and investigating who hacked my modem

#91
Observation: The root of this problem is NOT because Cox's engineering practices lacked a comprehensive enough security review process to find and fix security vulnerabilities prior to them being discovered post deployment ("hindsight is always 20/20" as they say), but rather because there was (and still is) an Information Asymmetry between Cox and Cox's customers, i.e., in terms of complete knowledge of how Cox's devices actually work under the hood...

Although, in fairness to Cox, this Information Asymmetry -- also exists between most companies that produce tech consumer goods and most tech consumers (i.e., is it really a big deal if most other big tech companies engage in the same practices?), with the occasional exception of the truly rare, completely transparent, 100% Open Source Hardware, 100% Open Source Software company...

https://en.wikipedia.org/wiki/Information_asymmetry

Anyway, a very interesting article!

Re: Hacking millions of modems and investigating who hacked my modem

#92

What sucks about this situation is when your ISP forces you to use their modem or router. For example, I have AT&T fiber and it does some kind of 802.1X authentication with certificates to connect to their network. If they didn't do this, I could just plug any arbitrary device into the ONT. There are/were workarounds to this but I don't want to go through all those hoops to get online. Instead, I ended up disabling e…

Fwiw: the hoops are automated these days if you are on xgspon.

It's "plug in sfp+, upload firmware using web interface, enter equipment serial number"

You can even skip step 2 depending on the sfp stick you use.

The 802.1x state is not actually verified server side. The standard says modems should not pass traffic when 802.1x is required but not done. Most do anyway or can be changed to do so. AT&T side does not verify, and always passes traffic. That is what is happening under the covers.

Re: Hacking millions of modems and investigating who hacked my modem

#93
Great read, and fantastic investigation. Also nice to see a story of some big corp not going nuclear on a security researcher.

I can't say for certain, and the OP if they're here I'd love for you to validate this - but I'm not convinced requests to the local admin interface on these Nokia routers is properly authenticated. I know this because I recently was provisioned with one and found there were certain settings I could not change as a regular admin, and I was refused the super admin account by the ISP. turns out you could just inspector hack the page to undisable the fields and change the fields yourself, and the API would happily accept them.

if this is the case, and an application can be running inside your network, it wouldn't be hard to compromise the router that way, but seems awfully specific!

Re: Hacking millions of modems and investigating who hacked my modem

#94
post #31

Earlier quoted context omitted.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder

> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?

> Why? Ethics aside, is everything money?

Ethics aside, why not? That's why we have ethics.

Re: Hacking millions of modems and investigating who hacked my modem

#95

Earlier quoted context omitted.

> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?

> Why? Ethics aside, is everything money? Ethics aside, why not? That's why we have ethics.

Because even if I remove ethics, I can't find a reason for doing something like that.

For me, doing the right thing is beyond all these things, and I don't care about money beyond buying the necessities I need.

Re: Hacking millions of modems and investigating who hacked my modem

#96

i'm really glad that i can use my own modem. In germany every ISP is by law required to accept self brought modems. They can't force you to use their often shitty hardware. My current modem/router is up for 3 months without a single interruption to my connection.

I use the ISP's modem (separating my own choices from having to worry about upgrades to DOCSIS and the like), but then hang my own router off of it. For that matter I have multiple routers inside the cable router for various tiers. With secure DNS and almost universal TLS, and then the firewall that are the internal private networks, the threat profile is negligible.

Re: Hacking millions of modems and investigating who hacked my modem

#97

Earlier quoted context omitted.

> Frankly he could have just sold the vulnerability to the highest bidder Why? Ethics aside, is everything money?

because money grants wishes, and having more money means you get more of your wishes granted.

That doesn't make me interested. I don't get all excited about the things money can buy.

Edit: As I noted elsewhere, necessities are something else.

Re: Hacking millions of modems and investigating who hacked my modem

#99
post #31

Earlier quoted context omitted.

I assumed they offered a bounty for bug disclosure? You mean to tell me that an internet provider with 11 billion in revenue can't pay someone that found a bug impacting all their clients? Frankly he could have just sold the vulnerability to the highest bidder

> ...can't pay someone that found a bug impacting all their clients?...he could have just sold the vulnerability to the highest bidder This attitude is why "independent security researchers" offering to present unsolicited findings to companies in exchange for payment feels exactly like extortion.

while beg bounty people can be annoying, you have to remember that people aren't obligated to sit down and find free bugs for any company (especially not a big one) - why would i sit down and look at some code for free for some giant corp when i could go to the beach instead?

Re: Hacking millions of modems and investigating who hacked my modem

#100

Earlier quoted context omitted.

because money grants wishes, and having more money means you get more of your wishes granted.

That doesn't make me interested. I don't get all excited about the things money can buy. Edit: As I noted elsewhere, necessities are something else.

I would love to have the money (42k EUR) to buy Scewo, which is an advanced self balancing stair climbing wheelchair. Sadly enough, I doubt I will ever be able to.
Post reply on HN