Someone Has Infected at Least 500,000 Routers All Over the World
motherboard.vice.com
motherboard.vice.com
[1] https://www.justice.gov/opa/pr/justice-department-announces-...
[2] https://en.wikipedia.org/wiki/Fancy_Bear
[3] https://www.engadget.com/2018/05/24/fbi-seizes-domain-russia...
NCCIC released the following analysis last year with more on the topic: https://www.us-cert.gov/sites/default/files/publications/AR-...
Sophos published an article a month ago that warned about this exact scenario: https://nakedsecurity.sophos.com/2018/04/18/russias-grizzly-...
WWIII may not be nukes, but complete economic chaos after banks, hospitals, militaries, and electricity networks are taken down.
Why don't they all auto-update by default for critical vulnerabilities?
Because it costs money for manufacturers to implement and maintain this functionality, and there's (currently) zero benefit to them for doing so and (currently) zero repercussions for doing what they do today after they sell you a device: nothing.
Most of them have many models. Probably many are developed with copy-paste fashion, meaning separate updates and separate testing for each model.
Some quick searching says the average DDOS size at one point in 2017 was measured at ~14Gbps and some larger attacks were peaking at ~120Gbps. Cloudflare's "biggest DDOS ever" was 800Gbps.
Even if we assume a lot of these routers are clustered on specific ISPs or networks and the effective capacity will be less, just on sheer bandwidth we're still well into or above the range of some of the larger DDOS attacks.
Whatever way you look at it, I'm sure 500,000 routers is enough to cause some trouble for most people.
Link to blog: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...
I havent used either, but looking at http://eero.com/ seems to indicate 1) automatic updates and 2) built-in VPN .
That's Ukraine's intelligence sector's way of driving popular "regular Joe" attention to a security interest that they have (by misleading them about the purpose).
What's disappointing is that the VICE article bothers to repeat it.
A state actor isn't going to run the kill command on 500,000 routers to disrupt a soccer match.
The intention of the compromise is for surveillance.
Not nearly as sophisticated as the NSA capabilities - nearly every router in the world (besides the small percentage not produced in the United States) are compromised by the NSA. It's telling how weak the Russian cyber security program is that they need to compromise routers with an active exploit to get some small surveillance capability. It also sounds like the C&C network didn't get a lot of investment, as its design was easy to subvert.
Why they cannot damage few routers? What will stop them? USA and Britain will declare war?
Conspiracy theories?