SHA1 sunset will block millions from encrypted net, Facebook warns
arstechnica.com
arstechnica.com
Linksys have no firmware update for this device. Looks like dd-wrt (or another alternative) is the way to fly.
A wrt54g doesn't have gigabit ethernet, doesn't support 802.11N or AC.. The last one I used topped out at 50mbit on a single connection.
Those things were good for a while, but unless the rest of your hardware is from 2008, you probably owe it to yourself to upgrade.
Oh, and the folks who own the system itself would have absolutely no idea of what any of the items in your second sentence mean, or what they'd matter to them (if the features mattered at all to them, which they in fact don't). There's no GigE on the property. If they had a Web-only system they'd probably be ahead of the game (less shit to go wrong), and wireless bands supported work fine with devices connecting to it.
Point is, there's a piece of perfectly _suitable_ and _usable_ hardware that's running just fine at the job for which it was originally intended, but the manufacturer's abandoned it.
Something I strongly suspect we'll be seeing rather more of in the coming age of the Internet of Broken Things That Spy on You.
But, say you've sold me: what's a decent replacement. And a Free-Software based ROM to put on it (I'd like to put extensive blocklisting on the gateway device itself).
Fortunately most[1] wrt54g devices are re-flashable, so if the slow lan speeds and poor wifi support are not a problem, you can get another few years out of it.
> But, say you've sold me: what's a decent replacement. And a Free-Software based ROM to put on it (I'd like to put extensive blocklisting on the gateway device itself).
At home I use a pair of an edge router lite and a random TP link AC router in AP mode (basically, DHCP server disabled). You can't really buy a decent AC access point, it's much more cost effective to buy a router and put it in AP mode. A Unifi UAP‑AC might be nice, but it's 3x the cost the tp-link was.
I haven't bothered re-flashing the TP-link, but I made sure I could when I bought it. The edge router lite will probably end up running something like openbsd or pfsense in a few years.
[1] a few ran vxworks with flash too small to support linux
You say this like GigE is required in every situation that might need a router. It really comes across like "that guy" who talks down at the (e.g.) Prius owner because they aren't driving a turbo-charged V8 (as if every person driving a car should be required to have one).
Couldn't you just have logged in with another browser or an older browser?
(Also, how exactly does this work if you are not one of the tech literate?)
"Gladly the router was open to dd-wrt"
On a fun note not sure if you remember the old "Get Netscape Now!" icons that were at the bottom of nearly every 90's webpage which, to your point, was as if someone visited your site and would actually pause to download and install a new browser (over dialup no less) if it didn't render correctly. [1]
How often do I have to replace stuff that I own?
My car is 25 years old (gasp) and reliable, though not designed for current emissions standards, my laptop is 8 years old and works great, though it can only run so many app-that-is-browser programs, my phone is 4 years old and works, and my router is 5 years old and still kicking, and my table saw is 10 years old and works great.
I'd like to not have to replace my biggest, most expensive tools in my life every couple years, just because someone else has and thinks I should too.
Your 25-year-old car probably emits a lot more harmful substances into the air than recent cars do, so someone could argue that you are actually harming others by continuing to drive it.
Similarly, one could argue that your use of computing devices that only support outdated cryptography is harmful to other people, because it makes it difficult for everyone else to upgrade to more secure algorithms. You might not be directly forcing anyone else to make any particular choice, but your choice contributes to the perpetuation of an insecure ecosystem, just like your car contributes to air pollution in your neighborhood.
I just would like to figure out how to use something for its actual lifetime.
c'est la vie
In the case of routers, using dd-wrt instead of some proprietary firmware that doesn't even do the job properly would be a good start.
If anything, the former opposes the latter.
Luckily with phones the support cycles seem finally to get longer, just like they have gotten with computers.
I'm not sad that my tools from years ago aren't as good as the ones today. That's inevitable. I'm sad that many of them are useful but artificially rendered useless by decisions.
For example, I had no complaints about my phone's battery life, security, or performance in 2011, my phone hasn't changed, and I use it for the same tasks. The same goes for the other items I listed.
My point is that routers don't (for some unknown reason) typically ship with automatic self-updates. The company could just as easily ship a firmware upgrade to fix your SSL issue (why is the burden on you the owner to switch to dd-wrt?) But if that doesn't happen, should the fact that some router companies refuse to upgrade to the latest standard stop us from encrypting the web?
I think no. And I think having to upgrade my router for that cause is an okay tradeoff.
Maybe I have a different standard for a bank then a blog, or a router config page. Or maybe I don't. You don't have to choose for me, not in this case.
I was legitimately curious how old OP's router was in addition to my statement. 5 years is a bit meh, but if you've got a router that doesn't support past 108.11b/g, then it's time to upgrade. Sorry.
Yes it is a chicken and the egg problem (and, I guess, evolutionary offshoots with no genetic future...), and this is exactly the kind of thing that is inconvenient about it. The decision was that it was worth the pain to be rid of SHA1 once and for all (just look at all the CA objections in the various threads about this to see the very strong objections to sunsetting SHA1 in the next year instead of five+ years from now).
It's not at all clear to me that this prevents the internet from getting more secure.
It means people can keep using their insecure clients instead of being forced to upgrade to something secure.
Their proposal doesn't actually stop SHA-1 attacks. If an attacker can forge a SHA-1 cert, they can set up a MitM in which the victim talks exclusively to the attacker's server. Facebook's servers won't be contacted, so the downgrade-proof logic on Facebook's servers won't even be executed. The attacker's server will present only the forged SHA-1 certificate, which web browsers will accept in the name of backwards compatibility. Long-term, browsers will stop accepting SHA-1 certificates, but this is not scheduled to happen until 2017.
> It's not at all clear to me that this prevents the internet from getting more secure.
Two ways this prevents the Internet from getting more secure:
1. Their proposal would make it possible to obtain SHA-1 certificates past December 31, 2015, which means there's more time for an attacker to exploit a collision to forge a cert. It's important to understand that exploiting a SHA-1 collision requires a certificate authority to issue you a certificate, so if no one is able to find a SHA-1 collision in the next 19 days, the Internet will be safe from SHA-1 collisions in 2016 even if browsers continue to accept SHA-1 certificates until 2017. Allowing continued SHA-1 issuance removes this safety net.
2. It sends the message to companies that deadlines can be ignored because they'll be pushed back at the last minute. This will make it difficult to deprecate insecure practices in the future.
I agree about the political part of the issue, but on the other hand, the SHA-1 deprecation is one of the most proactive things the CA/Browser Forum has done. Having it go not quite perfectly is still a vast improvement from reactively deprecating things only when they are fully insecure.
b) may help prevent collision attacks, but I have a hard time viewing a) (requiring downgrade-proof cert switching) as anything but security theater.
Edit: it's not even clear to me that b) is an integral part of Facebook's proposal. Their blog post says (emphasis added): "Such verification can be automated or manual, and appropriate measures can be put in place to reduce the risk of a collision attack. Those protections could include requiring LV applicants to have already passed OV or EV verification" [https://www.facebook.com/notes/alex-stamos/the-sha-1-sunset/...] CloudFlare's blog post [https://blog.cloudflare.com/sha-1-deprecation-no-browser-lef...] doesn't mention it at all.
Alas, we already more or less live in this world. If old standards were burned down without remorse more regularly, I'd think we'd see many things done differently. "But think of the pacemaker in the children's hospital" has unfortunately been the order of the day for quite some time.
Of course there will still be heaps of SHA-1 out there from private roots, but at least the rest of the world can move forward.
SHA1 isn't great, but it is certainly better than plaintext communications.
[1] http://thenextweb.com/facebook/2014/01/29/facebook-passes-1-...
P.S. that's basically the state of SMTP encryption, which is quite sad.
I should be clear that SHA1 shouldn't be used for cryptographic purposes that require high amount of trust, but for your average everyday FB status updates it is probably fine when coupled with other protections.
So, probably not a popular opinion, but screw em. Maybe when they buy a replacement device they will ask "Will this thing be obsolete in a year like the last one or will it actually get software updates?" "Will I be able to install a different ROM on this or is the bootloader locked?
The number quoted of $70K to crack SHA1 indicates that it is non-trivial to hack. Which means adversaries could break the encryption, but could only afford to attack a small number of people. Which means that SHA1 is effective for a large majority.
No, because an attacker could forge a single CA certificate that could then be used to sign certificates for an unlimited number of websites. This is what the MD5 attack did: https://www.win.tue.nl/hashclash/rogue-ca/