Asus lawsuit puts entire industry on notice over shoddy router security
arstechnica.com
arstechnica.com
Pretty much what we've all been saying here.
Do we really care? I made this post couple of days back.
https://news.ycombinator.com/item?id=11149716
I posted the same to reddit also. I was down voted heavily.
Anyway, I want to ask this.
How did we get here? How did the whole tech crowd okayed the use of perpetually connected devices with cameras (on both sides!) and microphones to allow operating them without notifying the user.
I mean, did no one ask, why is there no indicator light on this camera (or mic) on my net connected phone that I take with me to the most private of places?
So what about forcing these gadget makers to add notification that cannot be bypassed in software to alert users when camera or mic is active? Let them add them in all the new devices.
Also, pickup your phone right now and stick a piece of tape on that camera (both of them). Will you do that? Naa...you won't, because that is too 'inconvenient' to remove it when you have to take a picture..
So yes. We deserve everything that we get!
Consumer choice is not all it's cracked up to be. The process for getting surveillance out of phones is like getting lead out of the water: functioning accountable regulation.
(Cameras are less relevant when the phone is in my pocket; it's the microphone that is more of concern.)
We're in a bad Nash Equilibrium, increasing security costs money, but it's only really beneficial if everyone does it at once.
So did early car manufacturers etc etc.
Personally I think if everything had been thoroughly regulated from the start a lot of the innovations we are all benefiting from today wouldn't have happened or would have taken far longer time.
So I am not against regulations, but I can understand why waiting a bit and thinking very carefully before implementing regulation might be smart.
That said, while hard to use, that tractor's hand crank automatically disconnected well enough once the engine got started. Then again my father, born in the early '30s, grew up using them.
Hell, I was born 30 years later, and they still existed on tractors, fork lifts, and other, assorted engines.
There are a couple 'safety rules' when using a hand crank on a gasoline engine:
1) Always grip the crank with the thumb wrapped below with the fingers. So, all your fingers on ONE side of the crank, instead of four fingers on one side, and the thumb on the other
2) NEVER push the crank down the right side of the rotation.
3) If the hand crank binds when inserted through the starting crank bushing and into the crank ratchet, don't crank start the car. Too much bind will prevent the crank from releasing from the ratchet.
The AR-15/M16/M4 which follows that family (M1 and '50s M14) lacks that "feature", replacing the lost functionality with a separate forward bolt assist. In other major rifles of that general era, the AK-47 etc. and SIG SG 55x and I think it's 510 predecessor reciprocates, this in fact goes back to the original Nazi StG 44 "storm rifle", the FAL and G3 don't.
Auto-retraction was a thing by the mid 1970s.
Look, I understand why you would want such a thing and I don't believe that your desire is wrong. However, the method you propose I don't think would work the way you expect in the final analysis.
If you really want to do something in this area: why not work to create a consumer products security organization. Yes, it wouldn't have force of law, but you could certify products which manufacturers could use as a valuable distinguishing characteristic in the marketplace. Yes, all of that requires good marketing, etc. and not everyone would pay attention... but that may be better than the use of government force.
Virtually all of it if you use frameworks like xposed and xprivacy to protect yourself.
IMO the people who lead the corporation that released the product should be held personally liable but I realize that's an unfavorable opinion. Otherwise the government ends up footing the bill, which means WE foot the bill, and we're back to being in an unfair situation.
It kind of sucks that my first requirement for buying a router is that I must be able to immediately, and easily, flash a new firmware on to it. It doesn't matter whose makes them, you are going to be receiving absolute shit for an OS, save for maybe a few prestige models of some of the better brands.
I liked the TP-Link Archer C7s because they were easy to flash and came with some pretty nice hardware for the price. Their products have been badly vulnerable, and now they're locking out alternative firmware. So even when you find a brand/model you like, that may not last.
Also, there's no engineering society that censures its members and creates standards or certifications for quality or security, and it doesn't look like engineers are too interested in that.
Medical malpractice or unethical behavior are also fuzzy lines, but at least there's a medical association that draws some kind of line, determines standards for membership, and censures its members for malpractice or bad behavior, thereby also improving its public image as a trustworthy institution.
TP-Link has already fallen victim to this.
You can take openwrt, ddwrt, tomato and padavan from my cold dead hands.
Consumer networking hardware needs to be secure out of the box, and automatically keep itself updated without any end-user intervention.
Installing alternate firmware should be an option, but it shouldn't be necessary.
Yep. New hardware is shipped first with proprietary drivers, then shitty open-source code dumps. When the hardware vendors don't participate in the open-source process, it takes the community quite a lot of time to clean things up enough to be merged upstream. Usually by the time that happens the vendors will have secretly changed all the guts of the model with completely incompatible hardware at least once.
Just requiring a new model number for new hardware would get rid of most of the confusion. If the router and chipset vendors would actually maintain their operating systems as flavors of current OpenWRT instead of 5+ year old private branches, most of the problems wouldn't exist in the first place.
Then you should be teaching them, much like how I've taught friends and family to reformat and reinstall the OS on any prebuilt device before actually using it.
The only way things will get better for everyone is if we, the ones who know how, try our hardest to educate the ones who don't. If we remain complacent and want others to solve our problems for us, we're implicitly giving up our freedoms to the governments and corporations who are more than willing to take control of more and more aspects of our lives. Asking for "secure out of the box" will make them interpret it to mean secured against their owners. It certainly won't be easy, but that doesn't mean we should give up.
It's like asking everyone to change their car's oil. Sure, it's easy enough to learn to do and will save you money, but some folks would just rather pay somebody else to deal with the problem. Both options are valid.
We need both integrity protection for firmware and user control of the signing keys.
Try Tomato for a friendlier newbie environment. Google your router to see what alternate firmwares are available for it and never buy a new router unless you know one of the alternatives is available for it because most factory firmware is full of holes.
Powerful and flexible, yes. Newbie or casual-user friendly, no.
If Tomato is not enough, then DD-WRT, but Tomato being more stripped down becomes more newbie friendly by default.
They've all got web interfaces that present a status summary upon log-in and have pages for configuring different categories of settings (WAN, WiFi, port forwarding, etc.). Unless you think Tomato's default color scheme makes it vastly more usable, you'll have to point to something specific.
(And while it's been a while since I last used DD-WRT, my experience was that it had a multitude of options that were non-functional or incorrectly documented, so I'll need some pretty strong convincing that it's got any advantage over OpenWRT.)
I used Tomato (various flavours, including this one) for a long time until finally succumbing to OpenWRT.
The web interface is lacking compared to Tomato, but in return you get a recent LTS kernel built with the latest GNU toolchain and a superb package manager + collection.
OpenWRTs CLI config system is very slick, the web interface just doesn't yet hook into all possible settings (which may vary between devices).
I hope the pieces and supply chain are not locked up to the point that there is no way around.
Lets face it, the manufacturer are not that interested in supporting the operating system of your device after a few years. Device manufacturers profit from selling you new devices not maintaining old devices. Throwing a perfect working hardware device just because it has outdated software is bad for the environment and not good when we have global warming. Do we want to have a Wall-E kind of future scenario of the working junk we consume and throw to consume to throw?
This is of course not only consumer routers, all devices that run embedded software that the manufacturer stops caring for are in danger of getting hacked. If they can be hacked they will be hacked - hackers law.
Why does consumer devices have to be that different from a PC? A PC can load any operating system you like on including good open source operating systems.
This is also the same for cell phones, there are lots of Android devices with older releases that are not security updated.
Make it trivially easy to install open source firmware and the security problem gets solved by the people who know more what they're doing.