Unpatched routers being used to build vast proxy army, spy on networks
arstechnica.com
arstechnica.com
What are the most interesting network analysis tools I should look into? I'm talking more about high-level visualisations. For example, I'd be interested in keeping a list of every device that's ever connected to my network, and maybe get alerts upon detecting it. Or map requests/connections in real-time/historically on a globe in HTML5. Just some fun stuff to actually get a sense of what's going on in my network.
Any recommendations?
Basically you want a fast machine with a good switch, running something like OpenWRT. You may also want to play around with OPNsense [2] in a VM.
Just curious where to start in this exercise.
I guess you can gain some confidence that it isn't compromised, but can never be sure.
About edit being done by the ISP, once you fix on a not all powerful adversary (not the NSA), it's easy to get some machine it couldn't have tainted.
For this specific issue? It only affects Mikrotik routers, and the vulnerability has been patched. So if you aren't using Mikrotik, or if you are and have the latest firmware, you're good.
I think you vastly overestimate how much technical knowledge non-technical people have. A huge swath of non-technical people that use computers won't even know which component the router is, let alone know how to log into the UI and check the firmware.
It's easy for us to point the finger and say people need to invest in their own personal understanding of this stuff. To some extent I agree but I also want my CPA to spend his free time learning more about the tax code and my finances, not patching his router. Overall computer security needs a reset. For all the complaints of "walled gardens" and "lock in" etc... most folks' iPhone is the closest they'll ever get to a secure computer. That's a shame.
In hopefully unrelated story, my Mikrotik and/or my ISP has been acting up in the past hour; I've lost the ability to resolve many .com domains for ~30 minutes, even though I have Google's NS configured set up as the first two on the router. Manual queries (Mikrotik: resolve somedomain.com server 8.8.8.8 / Local: nslookup - 8.8.8.8) resolved correctly; it's just defaults that couldn't. Sad to admit this, but I have no clue what's going on -.-
Apparently, ISP's NS stopped resolving a lot of .com domains, and it must have poisoned my router's cache. After disabling DNS peering (to avoid ISP's NS injecting itself) and flushing cache, the problem seems to be resolved.
Also significantly less effective.
It’s nice for devices/cases where you cannot have an adblocker in your browser. It is unnecessary otherwise.
- Nice for TVs and other devices where you can't control the apps
- Or even in phones or tablets, if you don't have root access , you can block lots of ads in browser or even in apps
- Also, you can reduce the quantity of CPU used by ad blockers on your devices (again, essentially, phones and tablets).
- Also nice for visitors in your network ;)
I ended up installing Docker on my laptop, grabbing the Pi-Hole container, and configuring my laptop to use the docker container as the DNS server.
So far this has worked very well. Wherever I go, I have pihole running in the background. I can access the web interface and do everything I could do on the rasp pi-hole, without the extra hardware. It does take a minute or two to start up in the background after logging in though.
"What makes Plume different from my traditional Wi-Fi router or extender?
Single router Wi-Fi systems can give you the speed you need as long as you’re close enough to the router. Wi-Fi extenders or repeaters can improve coverage, but are often complicated, unreliable, and degrade performance. Plume is a cloud coordinated Wi-Fi system that replaces your current router and gives you stable and consistent Wi-Fi coverage and speed in every room within your home using blazing fast tri-band SuperPods coupled with auto-channel hop technology."
If I understand this word salad correctly, it's a router which uses a cloud service to auto-configure itself.
Mmm. Love some word salad with mesh dressing.
In the end, it's just hardware with some online configurator which will most likely render the whole system unusable if the online service shuts down.
Great for anyone that doesn't stop to think for a minute how dumb this idea is.
If you really need a mesh (you probably don't), there are other solutions. If you know at least a little about home networking and WiFi, just setup a Unifi system and be done with it.
The newer story @ Ars has some updated stats and thoughts: https://arstechnica.com/features/2018/06/exclusive-plumes-ne...
Part of the improvement is the hardware. The latency improvement is awesome, for example. But part of it seems to legitimately be the optimization that their software is doing re: signal strength, which backhaul to use, auto updates, the level of customer support, and other stuff.
I don't know how it compares, but it seems it may be better than people were initially thinking.
Things like OLE can be said in retrospect wasn't a good idea security wise. Autorun kept delivering for more than a decade. Perhaps GDI could do with a security model. That sort of things makes it unnecessarily difficult to secure the system.
The reason we don't hear about Windows router botnets is because nobody bothers building those boxes in the first place. You put your Windows box behind a small Linux box in order to connect it to the Internet, not the other way around.
Processors themselves are insecure. There is no hope this war can be won.
In the past, security focused on multiple users of the same machine. Users should be safeguarded from each other. Applications are installed system wide by a knowledgeable sysadmin and can be trusted.
But this threat model was completely dated. Today, most machines have 1 user. But the applications are either cheaply written with no respect for other applications, or are actively harming the user by stealing his data, and the average user is his own sysadmin but really doesn't want to do the job or knows how. Additionally, DRM means the machine tries to defend itself from its owner, preferring multinationals instead.
The windows XP and standard unix security model defend against the old threat model. Android, iPhone and Vista + defend against the new model.