SharknAT&To: Vulnerabilities in AT&T U-verse modems
nomotion.net
nomotion.net
A VW engineer is likely going to jail over dieselgate.
We have already seen that such insecure internet connected devices can be easily and quickly assembled into a botnet. The operators of such a network can direct the attacks at healthcare institutions, national infrastructure, and other safety critical systems.
At some point, there has to be stricter consequences for companies than simply a fine. C-levels won't start paying attention to security until there's the real possibility that their ass will end up in jail for this kind of insecurity.
What is the crime that "someone" should be charged with?
In the VW case the media reports it was fraud against the government and violation of the Clean Air Act.
To do what you suggest, one first needs an applicable criminal statute. What is it?
(Not implying this is impossible. Only trying to focus the discussion beyond the usual rants.)
Maybe something like certification for electronics is needed and is possible here? Where manufacturers pay for a fairly decent inspection of their work in return for a mark of inspection?
(I don't mean to take a side re this particular crap-storm.)
This article explains it better: https://www.theatlantic.com/business/archive/2016/08/why-are...
In order for this to change, two things need to happen. Things that I think even libertarians would get behind (because of end results).
1) Hold manufacturers of networked consumer devices liable for all damages caused to third parties by their devices (e.g. if they are used in a bother). Reason being that the buyer wilfully choose the device, but a third party did not
2) Create a waiver to this liability if (and only if) the manufacturer includes a standards-compliant, end-user usable firmware upgrade facility AND releases documentation necessary for third parties to build firmware files
Then let the market decide.
Dieselgate is tentatively assessed to have resulted in thousands of human deaths due to air pollution. AT&T modem vulnerabilities have not been assessed similarly.
While I concur with everything else you've said, I encourage selecting a different example with a more evenly-matched fatality rate.
Q: Is fatality rate the only legitimate metric on which to judge prison sentences?
No. Fatality rate is not the sole legitimate metric.
Q: Then why is fatality rate relevant? People are put in prison for all sorts of lesser offences all the time.
It's a "hot-button" metric. Its use inflames emotion and skews human behavior away from rational.
When drawing an analogy between two things, introducing "fatality rate" when not already present muddies the waters of conversation. If done accidentally, this can lead to serious "foot in mouth" scenarios. If done intentionally, it's typically used to encourage fearful decisions instead of careful decisions.
The staggering incompetence responsible up and down the chain for that should have been investigated fully and publicly, and certainly would have been if anyone had been injured/killed.
Update: 4 of 535 members of Congress have computer science degrees.
But how many of the remaining 531 know how computers work?
That's higher than I expected.
A lot of the reason Americans are in this mess is the complete lack of competition in 99+% of the country. /That/ lack of competition comes from a broken investment model. Like roads, water/sewer, and other systems regulated as utilities the physical plant is a natural monopoly; it isn't effective for society or companies to build parallel infrastructures. If the base platform (last mile 'wires') were owned by the community and competition occurred on top of it (like with package delivery) then the context of your comment would make more sense.
It's not necessary for the wires to be owned by the people. They could be owned by a private, highly regulated, capital intensive, infrastructure utility company, that is a legally separate entity from the ISPs who compete to provide your data services.
Private is not necessarily better than community ownership, but may be more politically viable.
But the producer is also regulated and required to include certain safety features because individual consumers are poorly equipped to select cars based on complex safety features. And in any event most consumers are very price sensitive; many people (perhaps most, actually) don't have the luxury of choosing a car based on safety features. seat belts, air bags, crumple zones, ABS, and rear-view cameras have all become mandatory thanks to regulation. (In some cases voluntarily with the understanding that they'd be involuntary if industry didn't cooperate). Collision avoidance systems are already scheduled to be mandatory, again by voluntary agreement.
When it comes to tech, consumers just aren't sophisticated enough to know how to choose products. And the insurance industry doesn't know how to solve that problem, either. It's really only the _commercial_ insurance industry where the insurers work with the policy purchasers to help them select the safest products and procedures. Anyone who has worked in tech support knows that it's a lost cause trying to educate individual consumers.
I hear ya. The flaw is, there isn't enough competition in enough markets. Many rural areas only have one ISP.
https://www.schneier.com/essays/archives/2003/11/liability_c...
Make the liability proportional to the degree to which you've given them the degree to find and fix any issues that might arise. If you give someone FOSS software to solve some particular problem, even a potentially-high-liability problem, you've given them everything they need to both analyze the software for potential issues, and fix them themselves. (Auto manufacturers like FOSS because it means they can always support it themselves if the vendor won't, and they have far longer support lifetimes than many other products.) So disclaiming all liability there seems reasonable, for anything short of intentional malice (e.g. backdoors).
On the other hand, if you give someone a piece of opaque proprietary software, then you're selling them a solution to a problem, and it'd better work because they can't do anything but go to you if it doesn't. They also can't introspect it, and black-box testing only goes so far. So this should increase liability. Even more so if you supply it in an obfuscated form that's difficult to reverse-engineer or test, or if you lock it down to make it irreplaceable.
The same thing would go for changing software yourself, on a high-liability device. If you don't change it, it's not your fault; if you change it, it might be your fault.
I think something like this could apply very well to software. If someone uploads source code to github they haven't sold it to you with any purpose in mind, but commercial sales have functionality promises so they could be held to them.
(Some states allow disclaiming implied warranties, some do not).
> #!/usr/bin/env python
# (c) 2012, Michael DeHaan <michael.dehaan@gmail.com>
# This file is part of Ansible
# Ansible is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation, either version 3 of the License, or (at your option) any later version.
# Ansible is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details. # You should have received a copy of the GNU General Public License # along with Ansible. If not, see <http://www.gnu.org/licenses/>.
###############################
[0]https://github.com/ansible/ansible/blob/devel/bin/ansible
What i'm saying is, if sold by ansible to a consumer, these disclaimers are completely ineffective in a bunch of states.
The UCC (which is what governs these transactions) is model legislation, and provides for a few options that states can choose in various parts. One option allows disclaimer of implied warranty in all transactions. One option allows disclaimer of implied warranty in all transactions except those with consumers. One option disallows disclaimers of implied warranties.
Depending on which option a given state chose, the language you are citing would have different effectiveness.
Thanks for pointing this out. I imagine most people who publish open source software aren't aware of this risk, and will stop when they learn about it.
2. Most folks are aware of this risk when they start companies to sell open source software.
3. Most do not sell the software directly to consumers, and outside of the few states that don't allow disclaiming at all, most states are fine with disclaiming warranties in b2b transactions, just not b2c.
Most don't sell the software directly at all, and those that do are often selling support anyway :)
In summary, there wouldn't be liability for open source developers because there is no business contract. But if you run a website with open source software, you of course would still be liable for anything that happens to your customers' data. So you would probably want to buy that same open source software from someone (e.g. Red Hat), who would also be liable.
One of the worst ideas I've heard lately, and I am genuinely baffled how a person as smart and experienced as Schneier could support it.
The currently widespread practice of trusting sensitive user data to open source code without an audit (either internally or via a third-party, e.g. Red Hat) is horrifying and incredibly negligent.
If your business includes software in any meaningful function, you are making money from it. Any competent lawyer would be able to successfully argue that. Charging money for a license is not the only way, otherwise everybody would just switch to charging for "consultancy service", which coincidentally provides free software license, and avoid any liability.
> You would be free to publish software, open source or not, without incurring liability as long as you don't make money from it.
You as a private person would be. That's my point - that would be the only way to do open source, any corporate support of open source projects would imply full liability, which would be impossible for a product the company gets to revenue from. It would be much harder for a business to justify supporting an open source project when liability costs are added to the equation.
> The currently widespread practice of trusting sensitive user data to open source code without an audit (either internally or via a third-party, e.g. Red Hat) is horrifying
Audits cost money. Tons of money. And they don't guarantee anything - bugs in OpenSSL have not been discovered for years despite thousands of people using the code, poring over it and billions depending on it. There's no magic in "audit" that allows code to be bug-free after it - if there was such a magical procedure people would already be using it, but there's no indication anybody has invented "audit" procedure that allows to eliminate all bugs. Existing flawed procedures are already being used - every company that produces software that I ever heard about uses them - and they are not enough. So what would happen is drastically raising the costs (to the point where having a website would no longer be affordable to an average person) while not significantly improving security.
Any reasonable audit of OpenSSL would have said, "Don't use it."
http://www.cnn.com/2015/05/17/us/fbi-hacker-flight-computer-...
https://arstechnica.com/information-technology/2015/06/airbu...
https://en.wikipedia.org/wiki/Therac-25
https://en.wikipedia.org/wiki/Accidents_and_incidents_involv...
https://en.wikipedia.org/wiki/Mars_Climate_Orbiter#Cause_of_...
Did I make my point clear or do I need to google for another 2 minutes to find a dozen more examples of "aerospace and critical infrastructure projects" with software problems?
In practice, OpenSSL should not be considered secure. At best it can be considered as a way to stop script kiddies.
As others have said, this idea is really bad.
Red Hat will start charging obscene amounts to support the legal side of the license, especially if it is used in eCommerce platforms. What about the wife and husband who want to sell hand-knitted socks online, or small businesses who do less than $250k/year online? Will they be able to afford an alternative to the LAMP stack and fully shield themselves from legal liability and the horde of lawyers who will gladly step into any loophole?
Like many, my servers were affected by Heartbleed. So if I ran OpenSSL and someone found out before I patched it (took me 24h to do so), I could be sued in that window if I hadn't bought the license to Red Hat - oh, and how about all the licenses to all the open source software that depends on it underneath, OpenSSL being one of about a hundred of those projects? Do we license GNU toolchain? What if there are buffer overflow exploits found in various tools?
If mom and pop want to sell hand-knitted socks on the internet I usually recommend them to use a hosted shop solution such as shopify and its ilk. They want to sell socks, not become an expert in hosting a LAMP stack. This is how liability works for brick and mortar stores as well: They're liable if a customer electrocutes himself because some dork attached the wrong wire to the wrong metal part. That's why mom and pop stores in the brick and mortar part of the world usually don't do the electrical installation or any parts that's covered under a builder code. They hire people supposed to be experts in that field to do that work and in in turn, they get to discharge the liability to them. It's about time we treat software the same. If you want to host something, either own up to it or hire someone to do it.
Want a seat at the standards table? Pony up tons of time, plenty of money for travel to cities where meetings are held, and be prepared for the big software consulting firms to crush you anyway with requirements like ISO-<somethingStartingWith9> before you can make a project on github public. Want to contribute to Python? Sure hope you have that degree, plus an engineering certificate from your local/state/national government. Your dues are paid up and you've passed the most recent set of exams, right?
Oh, and let's talk about your toolchain. You can license a certified compiler for $15,000 a seat. Per year.
I can't imagine anything more chilling, other than an outright ban on people writing software.
And good luck knowing what the actual requirements of that standard are; PDFs of ISO standards cost hundreds of dollars.
Step 2 would be the creation of an actual software engineering profession complete with the equivalent of the 'iron ring' and a pledge to go with it. Maybe the ring could be made of ferrite ;)
Step 3 is attaching a figure to compensating victims of breaches over and beyond some credit score bs.
Step 4 would be actual legal liability for service providers and shrink wrap software manufacturers which they could not get you to waive.
Step 5 would be criminal liability for producers of faulty software and especially the management layers above them.
Applied sequentially until it starts to hurt would improve software quality in a hurry and would most likely result in massive retraining of a large number of people now employed as programmers as well as their management.
This is already possible. If you graduate with a B.Eng in Canada you can become a P.Eng with the appropriate training/certification. Many Computer/Software Engineering programs in Canada are B.Eng programs (the alternative is B.Sc though those are less common).
Software/Computer Engineers who graduate with a B.Eng are eligible to receive the iron ring, and many do decide to participate in the Ritual of the Calling of an Engineer.
I think it's much less common to find a P.Eng who is a software or hardware engineer, versus say a Civil or Mechanical Engineer, but the option exists.
I'd be very surprised if Pratt & Whitney Canada didn't have a P.Eng to sign off on their turbofan control software. But Aerospace is different, because it's a highly regulated industry and people's lives can be quickly and obviously at risk due to a mistake.
Self driving vehicles and 'the Internet of Things' are in the same league.
I think the solution would be to find a way to induct an initial group to get the process kick started. The challenge is verifying the training of that initial group as one needs some way other than the current method of working for 4 years under an existing P.Eng.
It already exists in many European countries, and yes in Portugal there is also a ring to go with it.
And although not enforced as the Engineers Association would like it to be, if you are signing projects as <whatever> architect it is advisable to be a registered member.
So if your software is going to affect lives and you feel that you can handle the fall-out in case it does not and you are not certified then you're more than welcome to make that combination work.
(1) their phones given enough charge refuse to call 9/11 as mandated by law at the present anyway
(2) their authentication details are leaked
(3) their operating systems suffer security bugs
At most other levels the damage could easily be contained. Note that even at present they could be sued for any and all of the above, whether such a lawsuit is winnable is beyond my expertise to evaluate but it would certainly be interesting to see the arguments both sides put forth.
So plenty of opportunity to be employed for 'non certified programmers'. Note that almost every big software provider already has a certification program of sorts but at the moment these are just used as either a revenue stream or a way to get people to invest in the eco system.
Just like in other licensed fields like medicine.. no wait, I meant construction... sorry no, I meant a field with fewer consequences.. like hair dressing.. no wait, that doesn't work either.
hmm...
Just like you're free to build a hut in your backyard you are not free to construct a home and then to sell it if it is not up to code. That makes pretty good sense to me.
For simple stuff, like building a deck, you don't need an engineer. For a lot of basic-enough construction projects, you can just buy supplies and hammer them together. It's only where structural or safety issues kick in that you need to have someone sign off and approve your plans, and that makes sense.
Likewise, putting up a brochure-ware Wordpress site, just do it yourself or have some kid do it. But once you start collecting customer/financial/personally-identifying information, you should need to have a professional either do it, or review your code and sign off on it. There's a risk involved, and for too long we just shrug our shoulders and push the risk off onto the consumer, onto Visa, onto whatever.
I am looking forward to when the software world leaves this wild-west phase.
I would say that some sort of negligence laws would be appropriate here, with a defence being that good practice was followed.
Accidents will happen even with the best of intent; but there's a line somewhere.
You might counter: well no one will be willing to be CTO if it involves such personal risk.
I would counter: companies will find a way, through certification or lawyers, of ensuring that their products are secure enough, or they can show sufficient due diligence that they won't end up in jail.
I personally think making execs criminally liable for this kind of insecurity would really force companies to start spending money on ensuring they ship something secure and not a minimum viable product full of holes like this.
Which means CTOs would have huge incentive to conceal such breaches and persecute anybody who would report them. Also, CTOs would require huge money to cover the risks, and probably wide insurance coverage like medical malpractice insurance. Which is five-figure number at least. I wonder which startup could afford that.
> I would counter: companies will find a way, through certification or lawyers, of ensuring that their products are secure enough
They surely can spend money on lawyers writing tricky contracts and acquiring various expensive certifications. As for whether it'd make their software any more secure - this is much more doubtful.
> I personally think making execs criminally liable for this kind of insecurity would really force companies to start spending money on ensuring they ship something secure
That implicitly assumes right now the problem in software being insecure is because not enough money is spent on it, and if software would be more expensive, it would be more secure. This assumption does not seem to be true.
Of course they would. Compensation would go up and the good ones would be readily employed.
The hard part would be to make such liability stick.
If a venture has no reason to exist if cannot produce secure products a culture of building secure products will emerge. It may be that every MBA with a NDA will not be able to afford the competent programmers required, but as they are weeded out we will have fewer less than useless things.
Germany is too scared of hurting their economy in an election year to consider further actions against VW.
My vision for an ideal modem is more like a dumb Ethernet to coax/fiber/etc. adapter, and is otherwise as unobtrusive as possible. Ditto for an ideal ISP: just sell access to the raw, unfiltered Internet, and nothing else.
You'd like Europe then.
You know where we have competing ISPs and this is the standard.
Sources:
https://arstechnica.com/tech-policy/2009/12/comcast-throws-1...
https://www.cnet.com/news/fcc-formally-rules-comcasts-thrott...
The modems, by default, do WiFi, NAT, and have a 4-port switch on the back. The default WLAN name and password is printed on a sticker that's on the modem, they're unique per modem. Same for the admin user. I don't know if they allow SSH and if the SSH password is unique per modem however.
If you ask for the modem to be put into bridge mode, which they will happily do, the WiFi and NAT get disabled and whatever you plug in to the modem gets assigned a real IP address. When I upgraded my service and required a new modem they actually asked if I wanted it in bridge mode. All of this is configured on their side and the modem seems to pull the configuration when you first boot it.
These ISPs exist, but as smaller companies, they often serve a small subset of the population.
As the customer base grows, so does the need for easier management, so eventually, you'll end up in situations like the one described by OP.
It all started when I called to get the admin credentials so that I could open a port. They refused, stating that they use the same PW on all of them so they couldn't provide it to me.
After a day or 2 I found a vulnerability in the WebUI that dumped the password to my browser. Did a shodan scan and found hundreds of these modems connected to the internet. What they said was true, that password worked on the 2-3 I tried just out of curiosity.
I tried reporting my findings to them but they didn't seem to care. So I just changed the password on the one provided to me and let it be.
Now I live elsewhere and use my own purchased modem/firewall/wap. Can't trust ISPs to care about your security.
This is the kicker here:
You SHOULDN'T trust an ISP to care about your security - just like you shouldn't trust a the water company to select which Faucet/Shower head you install in your bathrooms.
Raw pipes to info == raw pipes to water (interesting aside, the Mayans always equated thought as being symbolized by water)
I am paying the water company for pipes to my house, I choose which faucets/shower-heads and use the water is consumed for.
Imagine if the water company charged me a different rate for Kohler Faucets used in the kitchen for washing my dishes, vs a Home Depot Hose used in the garden to water my plants? I pay the water company for the volume of water consumed. I pay the ISP for the bandwidth (volume of data) consumed.
Further, if the ISP is ostensibly providing my security to literally anything, then, by contract, they are assuming some of the risk? If "what we do is for your protection" -- then they assume full/some liability.
The water company provides zero such assurances. A broken pipe/leak/flooding/damage has no affect on the water company, my agreement/bill with them.
Further, the water company isn't injecting "paid supplements" (aside from fluoride, which we can equate to NSA backdoors in this example) into my water supply without my will (ads) -- they don't feed me a % of Gatorade in my water supply because Gatorade has a deal with the main faucet - or fertilizers into the garden hose because of a deal with Monsanto.
Source: My family owns an actual water company.
You'd ask the water company "can't I provide my own connection to the water" and they'd say "No". Then you'd want another water company, but no such company exists because they're a monopoly.
At that point you'd be better off collecting water from your roof and filtering it yourself. The water company is not helping.
Please explain yourself further, if I am missing your point.
Thanks
In reality, water is considered utility but internet is not. Therefore water company can do much less than ISP.
--
WTF state do you live in?
I have my EdgeRouter performing this function currently.
EDIT: Nevermind, I have (bonded) VDSL running through a 5268AC so I don't think I'll be able to do it. If it was "normal" Ethernet it would be possible.
The first you can put the modem in 'DMZ Plus' mode which is the closest you'll get to a bridge mode. This is where you'll lose bandwidth but it's easier to set up.
The second, which I recommend, is to connect your router to the ONT directly, and use their modem as a client on your network. You have to set up some rules to hook up the 802.1X traffic but otherwise the att modem is no longer in the picture. I haven't lost any bandwidth and I can't imagine that att's provided cheapo box would be faster than an EdgeRouter.
Comcast will let you bring your own modem and plug it into the coaxial. I've heard google fiber will let your bring your own stuff.
DMZ plus is much different than setting up an EdgeRouter to forward the authentication to the gateway. You are in much more control of your network if you don't use DMZ plus.
If I had even close to a 1Gb symmetric link I wouldn't care too much if I lost a couple megabits here or there (especially in the name of security or privacy). If I had a 30mbit link that only had 1mbit uplink I'd be upset not to use the whole tube but complaining about 980mbits vs 1000 is just a waste of time.
I'll do some tests myself. To see what the bandwidth lose is once I get an EdgeRouter.
I honestly knew this was going to be a problem when I first port-scanned my residential gateway and saw exposed who-knows-what ports, but for symmetrical 1Gb internet for $79.99 a month what can you do?
[1] https://github.com/ShadwDrgn/eap_proxy/blob/master/eap_proxy...
Though instead of going with the 802.1x proxy approach, it's also possible to spoof the mac address of the RG with your router and swap it in place after 802.1x authentication has occurred. (You have to swap without the link to the ONT going down however, the easiest way to do so being a switch with VLAN support. You put the RG and ONT on one vlan, and then once the connection is up, you swap your router in place of the RG.)
Then you can unplug the RG and put it in your closet (until you have a power outage and have to do it again, which is the main drawback to this approach. However since AT&T provides a UPS for the ONT, if you have a UPS for your router you should be good there too.)
Ugh…why is this even a thing? Like who thought it would be okay to add this "feature" to a modem, let alone at the kernel level where it would be difficult to disable and easier to be compromised?
I don't use its wifi and I have it configured for pass-thru mode. When I got service early this year, I briefly investigated bypassing it entirely. It turns out you need the modem to periodically respond to authentication packets from the AT&T network. But with some ingenuity, you can hang the router off an extra port on your own router and use it only for authentication purposes:
http://www.dslreports.com/forum/r29903721-AT-T-Residential-G...
I eventually decided not to do this because it's somewhat brittle and I didn't otherwise have any issues with the Pace. It's performance is fine.
But, given this disclosure, I'm going to revisit my decison. First, it seems like it's just a matter of time before the Pace has a similar security issue. Second, that kernel module for injecting HTTP advertisements. Just the idea of it bothers me.
Worse, their routers seem to do something to defeat attempts at two-level NAT setups.
I thought one of the network neutrality principles said you couldn't discriminate against compatible network hardware. Too bad Pai is in now.
I have Sonic Fusion, which includes a Pace 5268AC modem which is provided by AT&T U-verse and I cannot replicate the issue.
The title should be "Some AT&T U-verse modems..."
2. Default credentials “caserver” https server NVG599
3. Command Injection “caserver” https server NVG599
4. Information disclosure/hardcoded credentials
5. Firewall bypass no authentication
I want to know what runs on my router, damnit! It's my biggest vulnerability if done wrong and one of the more important security features of the home network if done right.
have you tried the word "hyperbolic" ?
These user-owned modems/routers usually do not encourage SSH access by the user, if they even provide it. Instead they promote a "web interface". Indirect control of the settings. Better than SSH? That is for you to decide.
The "market" seems to love the "web interface". But this often the easiest vector for successful attacks. Less control, and less safety. Is the tradeoff still worth it? That is for you to decide.
https://threatpost.com/vulnerability-disclosed-in-ubquiti-ne...
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advi...
http://www.securityweek.com/worm-infects-many-ubiquiti-devic...
Relying on "Keep up to date with patches" or "Enable updates" as a strategy to improve the safety of a product that was unsafe to begin with is a bit of cognitive dissonance given that its safety was deemed "good enough" for the renter/purchaser at the time of rental/purchase. To achieve a safer product requires not only manufacturers to set new priorities but also consumers as well.
How important is that "web interface"? More important than safety? And why not configure using SSH instead? Whatever the reasons, tradeoffs have consequencesre: safety.