D-Link Home Routers Open to Remote Takeover Will Remain Unpatched
threatpost.com
threatpost.com
This applies to every "connected device:" printers, cell phones, home routers, refrigerators, thermostats -- you name it. Michael DeGusta did a great infographic demonstrating this for Android phones in 2011 [1, 2]. Sadly, this hasn't materially changed in the eight years since. Just this year, Google added new terms to the Android license requiring security patches, but even then only for "popular devices." [3] Imagine those dynamics in the secondary and tertiary markets of printers and refrigerators.
As an industry, we've been to this rodeo before. The advancements we've made in operating system and core applications security over the last 20 years have more about patching speed and agility than shipping fewer bugs. However, those areas have backing and control from Apple and Microsoft, managing the end to end ecosystem. There is not a similarly equipped manufacturer of embedded operating systems with the scale to provide post-sale/post-deployment patching infrastructure.
Since this is Hacker News, I'll point out the enormous opportunity to anyone who can address that problem. Can you provide an "enterprise class embedded OS" to device manufacturers and address post-deployment updates? Can you provide infrastructure device manufacturers can use to manage post-deployment updates themselves? Do you have a better approach to it? There's a burgeoning multi-billion dollar market waiting for a few leaders to take it over.
1 - https://theunderstatement.com/post/11982112928/android-orpha...
2 - img link is broken in his post, the graphic itself: http://media.theunderstatement.com/016a_android_orphans.png
3 - https://www.theverge.com/2018/10/24/18019356/android-securit...
Of course, in reality, this CVE seems almost un-exploitable in the wild, anyway. How will an exploiter get to the login page in the first place? They'd have to know your network password and be in your physical vicinity, or your ISP would have to send traffic to your router's login page from the Internet.
So they'd have to physically drive around looking for these three specific D-Link routers.
And then what would they get out of a successful exploit? Access to your network's traffic and unprotected file shares (most people don't even have any file shares), and even that level of access will be rather useless for getting important information like bank credentials (protected by HTTPS).
Am I wrong about any of this?
A lot of non-technical people use old Android phones, old printers, etc, and never experience any serious security breach. Some of them do experience a security breach, but it's far more likely to happen in a social exploit (phishing, whaling, etc) or institutional breach (your reused password being breached from a database hack of a popular website). In a lot of ways, ignorance is bliss.
Nope. Not at all. Most router attacks these days are malicious JavaScript (like in ads and trackers) that send HTTP requests to the router from the user's own web browser (already inside the network). No proximity access is needed
https://arstechnica.com/information-technology/2019/07/websi...
This is one of the reasons my internal network is not 192.168.1.1/24 and the router is not 192.168.1.1.
Do you also disable WebRTC on all clients on your network? An attacker (or script) may be foiled by your non-standard gateway network, but your work in obfuscating the router is wasted if they can get at your client IP address.
> The attacks work when routers use weak administrative passwords and are vulnerable to CSRF attacks.
Which implies that a cross site request is being made. So e.g. you put a hidden form in a netf1ix.com page whose action is at some URL on the router. The user ends up accidentally posting data to that URL which is not affected by CORS and same-origin.
You cannot shift a Gresham's Law race-to-the-bottom dynamic by insisting on consumer (or producer) willpower. You've got to enforce a floor.
In other consumer (and industrial) products, this has tended to happen through the combined mechanisms of strict liability, certification, and independent inspection (in specific cases).
Where manufacturers, or as seems more likely given the industry concentration around sales points, retailers, are liable for the consequences of unfit-for-purpose devices and services, a reasonable set of minimum requirements (including life-of-product and update requirements) can be specified, then you might see a shift to some mix of time-of-sale plus subscription service pricing and payment models.
More likely you'll see devices bundled with services (which sometimes happens), though preferably in a far more user-friendly basis than is presently the case (e.g., cable service set-top boxes).
There's actually a long history of leased-equipment business in the IT sector, most notably as pioneered by IBM in the 1950s and 1960s.
Edit: Rather they should actually provide the spec, drivers etc
There is a worrying increase in the amount of IoT devices that will remain forever unpatched due to the (cheap overseas) manufacturers never updating them or ending support for them.
Not sure that is what we want to go back to.
But the hardware itself was robust and reliable.
Fake commercial on Saturday Night Season 2 Episode 1.
(It wasn't called Saturday Night Live until later.)
Independent inventor convicted and gaoled by AT&T for "misdemeanor attachment", the crime of attaching non-AT&T equipment to AT&T's phone network.
https://en.wikipedia.org/wiki/Walter_L._Shaw
More on this in the first bit of "The Inventor and the Thief" on Snap Judgement:
https://www.wnycstudios.org/podcasts/snapjudgment/episodes/l...
I can see why consumers and consumer advocate groups don’t like this.
Meaning, all of those sets performed more or less (in some cases less, specifically in certain special service applications) identically to a 2500/500, and at least one of those was a 2500 in a mouse shaped box.
Touch-Tone was actually a value add for the telco because it reduced register holding times in crossbar switches, and could reduce the amount of common control hardware needed, yet they still charged more for it (and the service too)
(Also, I think you mean trimline not streamline)
If we alternatively enforce a floor on security updates for user-purchased routers, let’s say we require security updates for the physical lifespan of the device (10 years?), they will be baked into the price of the device in some way, and I’m not sure the majority of home router customers who essentially look to spend around $20-40 will be willing to bear that cost.
An example of that in action would be purchasing a business SKU laptop compared to a consumer one, and taking a look at the length of driver support.
Many small businesses not only have unprotected file shares, and have remote admin turned on so that their IT person can administer the router remotely (as silly as it is). I saw this so many times when I worked in IT. People make all sorts of assumptions about LAN privacy when setting up their network and devices.
Ok, I’m willing. Where do I sign up?
Which manufactures are offering this service for residential grade equipment?
I guess 2FA might block them, but if it were a typed in code you could still get it.
It's not like they're just "giving you the choice" either. TV makers have already started completely removing non-smart TVs from their line-ups for instance.
I don't want a smart TV. If I want my TV to be smart, I'll buy a $50-$100 set top box I can upgrade in 2-3 years and is probably significantly more secure. Meanwhile a "smart" TV I will keep for 10+ years, but won't receive updates even for 20% of its lifecycle.
Ubiquiti has a number of CVEs and has addressed them in a timely manner, IMHO. If you’re buying the cheapest product then expect the cheapest support. My UniFi stuff is easy to manage and upgrade. I can set a number of auto updates I can’t do with other vendors.
Originally I had a DLink gaming router, but as soon as that router went out of support I switched to Apple networking gear, thinking Apple would do an excellent job with support. Also, 802.11AC wasn't supported on my Dlink router.
Then I read an article about Ubiquiti networking equipment on ArsTechnica a few years ago and thought about getting that for a forever home.
The thing that sealed my home network upgrade was Apple discontinuing their networking equipment. I figured (at the time) that Apple would abandon support for their devices. I remembered the Ars article from 4 years ago, and took the plunge on a cloud key, access point, USG, and Unifi Switch. Is this overkill or a 1 bedroom apt or 2 bedroom condo? Yes. However, having the piece of mind that the hardware I bought has continuous software upgrades and excellent customer support via their forums is outstanding.
Sure, their hardware ends up in residential deployments more often than perhaps any other kind of enterprise computer stuff, but if you're not willing to call them "enterprise", I'm going to insist they be practically alone in their own category of "pro-sumer but actually professional-consumer, and not the yuppie garbage that you usually call pro-sumer that's just the normal consumer crap but priced at 4x with a slick black plastic case."
I agree with GP in that the spectrum you are suggesting ("you get what you pay for" actually looks more like this:
<cheap garbage> ----------- <expensive garbage> ----[huge $$$ gap]----- <enterprise stuff for price-insensitive corporations who value brand and risk-aversion more than actual specs>
Which I would reify into the realm of, for example, computer hardware, as follows:
<a $100 best buy laptop with Windows> --------- <a $4000 alienware desktop with windows> --------------- <a $40000 Dell server with out-of-band management and ECC ram and HSM's and dual power supplies and actual RAID controllers and so on>
The best buy laptop and the alienware desktop are going to have the same issues with regards to control and privacy, and you need to make a huge jump to get to anything remotely respecting you.
It's a different market segment that doesn't refute GP's point.
Ubuntu is already doing this: https://ubuntu.com/internet-of-things
For Linux distributions, security updates and maintenance are a solved problem. Ubuntu adds to this a read-only filesystem with atomic updates for embedded devices, vendor-only apps and app stores, and so forth.
Disclosure: I work for Canonical, but not in this particular area.
Speaking for myself, I find it frustrating that Ubuntu's solutions aren't more widely known and recognised. As far as I know, our community is very aware of the issues involved in this space and there is no other solution that solves the "IoT maintenance" problem properly.
Not completely true. For example, just something I discovered recently is that some e-book readers have very long lifespan if you look inside and ignore the battery. There's not even an electrolytic or tantalum capacitors there. Really nothing that will expire.
If you don't kill it mechanically, these will survive for 10 years+ just fine. Even the internal memory holding the OS and your data is easily replaceable (uSD card, and no other memory that can get corrupted). Indeed you can easily upgrade your $150 2GB e-book reader to 32GiB for $6, with a much faster uSD card. Or even replace the OS completely. ;)
The only thing that makes these devices' lives limited is the battery and the cheap noname uSD card. They even make it so that display is easily replaceable, no glue or anything.
What I hate is lack of commitment to free software. Manufacturer will just dump incomplete old kernel code on github once, without a source code to also GPLed bootloader, after years of nagging from users, and calls it a compliance with GPL.
They don't even bother with mainline Linux support, that would make it so that anyone could use their device for whatever creative prupose and it would get automatic longterm software support for free, even after they would not want to bother anymore to support it.
It's not even a cost thing, I just reverse engineered one such device and it now runs Linux 5.4-rc2 and all HW works, including an eink display driver. It took about 2 weeks of occasional work. Instead the manufacturer probably spent huge amount of time hacking together some old kernel and messy SoC vendor drivers, so that the OS at least holds together for their purposes.
It's probably just some culture thing of not giving a fuck about anything but themselves. And there's a huge amout of waste as a result. At least some people sell these devices if they are just locking up/hanging (sure sign of uSD card data corruption) on eBay. But many will probably just throw it out. Such shame.
So yeah, some tech is indeed solid, but manufacturer will gladly mess all the benefits up on the software side, for no real reason, at least to me.
But I hope people will buy second-hand or broken + replacement display instead of supporting the company and buying new, if they want to play with it. They don't really deserve any support for abusing the free work of others and violating the GPL license.
How about Microsoft’s Azure Sphere Linux/cloud product with “10-year lifetime” support?
> Azure Sphere will feature a turnkey cloud security service that guards every Azure Sphere device, including the ability to update and upgrade this security protection for a 10-year lifetime of the device.
https://blogs.microsoft.com/blog/2018/04/16/using-intelligen...
Samples: https://github.com/Azure/azure-sphere-samples
Pricing, with support through July 2031: https://azure.microsoft.com/en-ca/pricing/details/azure-sphe...
Yes. At least for routers, the topic of the article, OpenWRT is that OS. Any manufacturer can make it work on their router very cheaply. Any customer can install and upgrade it indefinitely.
And yet my over 10 year old PC still gets the latest updates. Manufacturers have brought this on themselves, by locking and closing their devices, and insisting on proprietary solutions when open alternatives exist, or could exist.
Partly to your point, Buffalo was using DD-WRT for their wireless routers [1]. I have two of them at home, updated to the latest LEDE/OpenWRT. They're mostly fine [2].
Buffalo's support was not great, lagging far behind the latest DD-WRT when they were still providing those updates. As a power-user, I didn't mind since I could switch, but it was not a great showing for vanilla consumer.
Sadly, Buffalo has stopped making them, I suppose the business model didn't survive such a low-margin segment. I definitely appreciate the continued open-source support though!
[1] such as https://www.buffalotech.com/products/airstation-highpower-n3...
[2] I've had to reboot the main one to regain network connectivity a couple times, and it currently loses Wifi settings on power loss. Not great, but not enough to make me switch away yet.
https://openwrt.org/toh/linksys/wrt_ac_series
Their support for the first models in the beginning was a little spotty, but I think they are great systems now
I have a wrt54g that's 10+ years old running at my grandma's house...and running dd-wrt because no one making APs 10 years ago, and even now, was that good at security and stability.
What's telling is that the hardware is the part that still works, and I bet part of it is that software fixes are easier than hardware, so you can get away with lower quality software.
However - I have to ask - have you upgraded her dd-wrt?
I know. Yuck. But the only other real possibility is to legislate that such updates be made available for N years as part of the purchase conditions.
I am unclear why this is not the preferential solution here. "Don't sell lemons" is a societal good.
Phones should have some level of modularity and repairability, so they can last a multiple of their present service life. (Think smaller scale standards like in desktop PCs.)
However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein?
There is an idea of harm to the ecosystem/society with unpatched IoT and other network devices though. So perhaps a heavy-handed approach is justifiable.
> However, how would you feel about legislation that required five years of dealer service to be included with every automobile sale? Or other products in a similar vein?
This analogy doesn't work for me; software bugs are defects, they aren't something getting old and falling apart. I think that a defect in an automobile should be repaired at manufacturer expense whether it's a year old or twenty.
The economics of providing 5 years of defensive patching on a $100 device simply does not work.
Support costs increase as fragmentation does, it things sold at a reasonable price and without dozens of variations it would be more feasible to maintain longer supported life cycles - but these companies have no incentive to think beyond the next quarter’s earnings call.
Not yet.
(i.e. not obviously better or worse)
Frankly I think the better option might actually be the reverse: a mandatory payout to every customer for every nontrivial security defect. Not sure how you'd adjudicate it, so it's pie-in-the-sky, but take it out of the realm of the class-action lawsuit and see how serious these manufacturers become about correctness.
Businesses fear only the big stick; it should be swung on the consumer's behalf.
Normal software has an argument towards subscriptions if it's adding features. But routers shouldn't be adding features. Routers should be fixing bugs.
Companies do buy subscriptions for older software even though they may only be getting security fixes at this point.
That said, I do think bundling longer-term updates into the cost is better insofar as it means buyers don't get a choice to just use the unpatched software. But it does mean that companies can cut costs by just not patching software at all or for a short period (as today).
Sure. Hence the use of a very big stick.
The lack of restraint on bad actors is a societal problem, not an economic one.
What would be better is to require that the firmware be replaceable with something like DD-WRT or OpenWRT. One of the biggest issues with hardware like this is that the original manufacturer goes out of business and yet millions of people still have their devices.
You can't require updates from a company that no longer exists, but that's not really a problem if their hardware can run the latest versions of half a dozen different open source router firmwares.
What should be happening is that the FCC / international communications bodies should be directly funding a project like OpenWRT and using regulation to compel device manufacturers seeking approval by the bureau to submit their requests contingent to providing device specific hardware enablement upstream and to default-ship their devices with this common OS. Then those certification costs fund the ongoing operating system project.
If a company then wanted to implement a new feature to push their hardware, they could... by submitting it upstream.
There have been so many billions of developer hours wasted in the pursuit of profit by reinventing every single damn wheel a trillion times over its disgusting to think about and governments should be recognizing this flaw in US-IP-driven software business models and work to correct it.
The exact opposite is what actually happened. In late 2016, the FCC specifically banned owner-based firmware upgrades[0]. It was ostensibly due to RF configuration, it could also be seen as a concession to the manufacturers.
0 - https://hackaday.com/2016/02/26/fcc-locks-down-router-firmwa...
"Use open source" would make the situation appreciably better, because it would mean not accepting any closed-source or out of tree drivers that lock you in to particular kernel versions and non-standard management APIs. Once those problems are out of the way, frequently rebasing the web interface on current upstream OpenWRT is pretty straightforward.
There is already vxWorks, they don't have to start from scratch and they're already widely used in the industry. (There are others as well).
Anyway: The devices in question are running some Linux with a custom web interface on top. Patching this specific flaw is just about having one engineer add a few lines to the webif git, trigger a rebuild, flash to a qemu VM (could happen automatically) and test if the interface still works. If that's the case (which is likely), put the firmware as "unsupported"/"alpha" on the company FTP.
This assumes they have proper tooling (e.g. tagged git, automatic&deterministic build server, an efficient test environment,...). If they don't have, they probably wouldn't buy it (or, maybe they would?).
Automatic post-deployment are only the end of the chain, and for cheap embedded consumer systems there are good reasons against it: "My router didn't react, so I powercycled it" is problematic if it was just applying an update (resilience against this costs money, which is tight). And then your 1st level support has to explain your grandma how to use tftp to flash the firmware via the bootloader (this is bad for 1st level support suicide rates). Did I mention all the crap should be cheap? What good is a well maintained IoShit device if it costs 4$ more than the poorly maintained competition? Chances are high you won't sell enough to sustain your company - unless you go into a premium segment and just charge twice as much as the competition, which might still be problematic (consumer expectations change a lot with price - cheap and vs. expensive and nice).
Also, at the other end of the embedded spectrum: Industrial embedded systems should probably only be updated if really necessary, e.g. if something is broken due to bad firmware. Downtime is really expensive for huge manufacturing plants, especially if unscheduled (in addition to the machine[s] not producing value, your 500 workers a fiddling their thumbs), so you want to reduce the number of opportunities for this to happen.
There's no market for this. The market is for $50 device. Android Phones, nearly flagship, that sell for $500-700 get at best two years updates. People want $50 router that they can throw away when it stops working.
I have a $350 router. I have had it for 3 years by now. It is a tiny passively cooled industrial PC that fits into a VESA mount with an Intel Celeron, 128Gb SSD and 2x wifi modules. Why two? Because i want a guest network to be separate from the real network and i want crap-wifi speaking devices to be isolated via VLAN etc. It is running Debian and even techies marvel at the speed, functionality and all the goodies. They want to know where they can get it... Until they hear that it was $350 at which point they go "I was thinking i would pay about $80". A dinner for two in a Puero Rican chicken shack with a couple of beers will be $35!
Android Oreo: https://www.androidauthority.com/android-oreo-fastest-manufa...
Android Pie: https://www.androidauthority.com/android-pie-fastest-manufac...
Then they put out this weird update: https://www.androidauthority.com/counterpoint-android-update...
Well, they could (D-link has millions), but they won't because it would eat into their obscene profits.
What is this statement based on? None of your links show any kind of unit economics that support the assertion that providing critical security patches for a defined support window is infeasible for manufactures and their business models.
This is a choice that they make. Yes, having a legacy support team is going to cost a bit of money, but not a ridiculous amount. Maybe instead of having a ridiculous number of barely-differentiated SKUs, they could lighten the support burden a bit by making a smaller number of solid well-supported models.
Edit: also, basing the models on a common platform would help too. I assume they generally do this already, but if not...
They don't, because they save a few dollars by re-bidding each product. So each company is shipping a random assortment of Broadcom, Marvell, and Qualcomm reference designs, all running incompatible software stacks.
How... what... c'mon! You're totally right [1], and even within similar model numbers (e.g. the DIR-300 B-series uses Ralink chips, but the DIR-330 uses Broadcom). Yeesh.
Well... I guess I'll just keep on picking devices supported by OpenWRT and not rely on vendor firmware at all. Yuck.
[1] https://openwrt.org/toh/start?dataflt%5BBrand*~%5D=d-link
If no one addresses this problem, regulations will be imposed.
I would expect a consumer router to run without problem for not less than 10 years: they should update it to work. Now they shouldn't have to add support for the next protocol or feature, but if it isn't secure that is different and should be fixed. All it takes is a lawyer.
Note that you don't have to have the affected router, just prove that an affected router is attacking you. I think there are people in IT who are able to prove this latter one so all that is left is bring it to your lawyers to get dlink to pay your costs from the attack.
That's not a realistic expectation. Nobody is selling consumer devices with a 10-year support lifecycle.
An original iPad isn't even 10 years old and is many years past being able to run an iOS version that receives security updates. A 10 year old MacBook Pro is a few years beyond having a supported OS with security updates. Cisco, with a support contract on actual Enterprise gear, offers up to 5 years from the end-of-sale date and do not actually promise to provide security updates for that whole period.
To expect a $50 junk router to provide an industry-leading support lifecycle is absurd.
However consumer goods must be fit for purpose for a reasonable time. The case of the insecure router after 5-10 years was probably not brought to court, but I hope the court would agree that it isn't fit for purpose if insecure..
If you are really interested, you can read on the law here (my jurisdiction is Quebec, Canada) : https://www.opc.gouv.qc.ca/en/consumer/good-service/goods/sm...
Fortunately, we don't have to care what manufacturers think is absurd or not; it's been decided for them.
Well, the legal answer is 10-years for a no-charge repair [0].
If D-Link routers start burning down homes I'm sure the Consumer Product Safety Commission will take an interest, but if it's more than a few years old the recommendation will likely be to throw it out and buy a replacement.
In your case I'd imagine these are multi million dollar machines vs a $30 bottom line home router.
> get dlink to pay your costs
What happens when the company is gone?
(wakes up from dream)
crap.
You always kind of get what you pay for. If you pay an annual maintenance, then you can expect regular and secure updates, otherwise you are buying the product as is at time of purchase.
Then again, I buy stuff that can be flashed with OpenWRT ...
This is a bit of a spurious comparison. Nobody is dying from an unpatched router. Why should a company be on the hook for a device, particularly if it's out of warranty? If you expect more than that, you need to be buying something with a contract stating you're going to get more than that.
I find it regrettable that the architecture commonly in use does not make a clear distinction between devices for convenience and for security.
It’d be crazy if in our homes the main entrance lock always came as an afterthought in the package of all the inside doors, and we didn’t have an obvious way to replace it separately on our own.
This case is more like a golf cart being sold as a car: it's technically usable for that, but lacking any sort of safety or weather protection.
Not just financial damage, the owners of defective routers can be targets of criminal lawsuits if their connections are used as proxies for attacks, death threats, bank fraud, etc.
That does have the potential to create some damage if anyone takes control of them. Maybe even kill some people, if say they DDoS the V2I network for self-driving cars in the future, or a hospital network over which remote surgeries are performed, etc.
I feel like this argument that "you get what you pay for" is pretty lazy. Usually, or ideally, consumer regulations are about setting standards and raising the bar.
So that means that if there were strong laws for stuff like this, then the minimum router price may become $70 instead of $50 - but everyone would be reasonably protected for the large majority a device's lifecycle (only a small portion of the customers should be affected by leftover bugs when support ends, like say <5%, as others will have moved on to new products by then).
There are arbitrary and discretionary licenses that have been created in response so prior issues.
Licensing/certification regimes allow for almost any expansion of the role of government to those licensed, including capital requirements to resolve an issue.
So first you would need a license, determine the scope of the license, who needs it, and the consequences of operating without one.
Good luck
This is false equivalence. A car is not $/£/E/50 piece of hardware.
You know, like tons of other safety-relevant products. Anything you plug into the wall, or put gas in, or has enough torque to hurt someone ends up going through safety checks.... except software.
Let's unpack this:
You get what you pay for... yet you also say that OpenWRT solves this problem and is available free of charge.
If you pay for a support contract, you get support right up to the point where the company decides to stop that support. If you have a contract worded the right way, you might be able to take the company to court over it, but if the company's willing to settle, you end up with some go-away money and an insecure router nobody's supporting. Does the money pay for next week's massive outage due to someone taking over your routers?
Finally, the product as it was at time of purchase was a product fit to be sold, without major defects. In other industries, that's a standard companies are held to: If a ball joint goes out completely after 10,000 miles, Ford's kinda on the hook for that, neh? They can't say that you have the car you purchased because the car you purchased was driveable and not sitting on the side of the road.
And we already have a system put in place to assess. It's called CVEs. If you exist, you should be on the hook to fix.
It's called 'Being Responsible'. And corporations have a strong tendency to not want to be. That's why we need the 'stick'.
Often times when defective products are sold there is some responsibility for some time to correct or notify people. Cars, child seats, and many other things fall into that.
The defective devices that get updates or notifications are often safety related. Yet, safety and security are not talked about much with regard to technology. Maybe it's time to start doing that.
https://battlepenguin.com/tech/using-the-banana-pi-bpi-r1-as...
but then I learned the hardware itself could fail into an insecure state, and there was no way to deal with it in software:
https://battlepenguin.com/tech/banana-pi-bpi-r1-fails-into-a...
I'd expect cheap mass-produced routers to be around $15 - $25, like an immersion blender.. I don't quite understand why cheap ones are still $40-$60.
An edgerouter X is $50 for instance, but doesn't have wifi and lacks serious routing features. It is considered a very low end router compared to more expensive stuff from Juniper or Cisco. (even an entry grade router/firewall like an SRX300 will run you back atleast 4x the price of the edgerouter.)
One thing these $50 routers lack besides proper software is stability. Most consumer networking equipment has an abysmal track record in terms of reliability.
And once again, we're all reminded of the divide between people who know how to do things like this and people who don't, and how the people who do know have an advantage in life.
Edit: another link: https://nordvpn.com/tutorials/dd-wrt/flashrouters-privacy-ap... .
What manufacturer can I buy next time with a good security record?
OpenWRT really is the greatest.
DIR-655: OpenWRT: not listed.
DIR-866L: OpenWRT: not listed. dd-wrt: https://wiki.dd-wrt.com/wiki/index.php/D-Link_DIR-868L
DIR-652: not listed
DHP-1565: Present: https://openwrt.org/toh/d-link/dhp-1565
Buying well-supported hardware and flashing with OpenWRT (or similar) is strongly recommended.
OpenWRT: https://www.openwrt.org/
Tomato: http://www.polarcloud.com/tomato
dd-wrt: https://dd-wrt.com
OK, let's say I am someone who actually knows "end-of-lifed" is a thing, and a thing you don't want...
How would I check to see if a certain router was end-of-lifed before buying it?
If I can figure that out, and I know it's not end-of-lifed, is there any way for me to see how much time is left in it's life before it's end-of-lifed, how would I check to make sure a router I was buying woudln't become end-of-lifed tomorrow, or next week, but has, say, a year or two of supported life left at least.
Obviously, what D-Link is counting on is that most customers won't know that this is even a thing, wont' know what questions to ask, won't realize their router is end-of-lifed, won't realize their router is vulnerable, won't realize it if their router gets hacked, and it wont' effect their likelyhood of buying another D-link router or telling others to. It's not that they think this kind of support is going to be considered acceptable to their customers -- it's that they think their customers won't even be able to figure out what kind of support or security they are getting, mostly won't even realize this is even a question to ask.
And they're probably right.
You should be able to Google "$MODEL_NUMBER support", although D-Link's Web site is pretty bad and doesn't say tha the product is EOL (although since the last firmware update is from 2013 you could guess).
https://www.eweek.com/security/ibm-s-schneier-it-s-time-to-r...
https://techerati.com/news-hub/canonical-releases-ubuntu-cor...
A few posts mentioned installing a different (open source) firmware. But, both OpenWrt and DD-Wrt aren't compatible. Am I missing another option?
As an aside, can anyone recommend a wifi router that runs either OpenWrt or DD-Wrt well, for $100-$150?
https://www.amazon.com/Linksys-AC1900-Source-Wireless-WRT190...
FCC requires home router manufacturers to prevent users from modifying transmit settings (primarily to prevent interference with weather systems - which 5G is also going to mess with). While the router manufacturers themselves might not provide features to modify the parameters, allowing third-party open source firmware opens them upto liability, because third-party firmware -- almost all of which are open source, can provide users with features that allow changing the transmit parameters. This is because the radio operation is controlled by the OS (most of these have linux on them), and the parameters are to be included in the same firmware blob as the OS.
FCC is not the problem here either. FCC saw the quick-fix that some manufacturers took, like TP-Link, which is to block any third-party firmware. So they required TP-Link to reverse their decision to prevent installation of third-party firmware. Then what's the solution?
The best way to prevent allowing consumers to change the transmit settings, while allowing open source firmware meant for the rest of the board (where all of the security issues arise), will require having different flash chips - one for most of the firmware, and a separate on for the storage radio parameters. This route is what Linksys is taking.
Personally, I doubt this is a good enough solution. Board designs today use a single SoC that does everything. So I'm not sure how they think storing the transmit settings on a different flash chip will prevent the firmware from using different parameters. Any design that is more complex than the two flash chip solution will require a lot of reworking of designs, because most board designs basically consist of a few components: the SoC, the flash and RAM. Nothing else.
Apart from the re-working of existing designs, there's another problem. The problem is the BOM constraints router makers face, since they are always in a race to the bottom price-wise. Adding additional chips, introduces cost and complexity, which they don't want to go through.
The enforcement comes down to this: If you transmit in an obnoxious way and you annoy someone, you get squashed. If you kill someone, you get squashed harder. That doesn't bring the dead back to life, but sending someone to prison for killing someone else with an axe doesn't bring the dead back to life, either.
Clearly not, the person that knowingly modified it to do something illegal is at fault. Preventing anyone from modifying anything is a backwards response to the real problem: the guy that wants to do the illegal thing.
Zero, as long as the person:
(1) Knew it was loaded
(2) Voluntarily accepted to receive the gun.
In this analogy the gun going off broke a law. So you voluntarily handed somebody a loaded gun - who then committed a crime with that gun.
Obviously context matter - but you can bet the police will be asking why you gave that gun to them.
Example: https://hackaday.com/2019/09/05/esp8266-and-esp32-wifi-hacke... what if Espressif dropped support for these a while ago? You couldn't securely use these in some scenarios without reverse-engineering the binary blobs and patching the flaws. And I can't imagine how many of IoT devices out there use that chip or a derivative.
[0] https://semiengineering.com/a-crisis-in-dods-trusted-foundry...
Own (key word) an old RPG that won't run because the publisher decided the servers were no longer profitable?
RPG gets opened sourced.
Have a John Deer remote operated tractor that John Deer won't fix a bug that allows attackers to operate remotely?
John Deer's tractor software gets open sourced.
No support? No legal IP protection.
All the code's there - you just don't have the right to change it!
Full access to the device you own, signing keys and all.
I’m open to hardware suggestions that are/more open source capable or robust in the first place, but my use case was really niche and the shop(s) had nearly nothing suitable except this one model.
Combine that with 2 UniFi APs, multiple SSIDs each landing on separate VLANs, all converging on the router VM as separate "interfaces", so you can very selectively do policy-based routing per MAC address, and whitelist/blacklist IoT devices from accessing the Internet or specific sites. It gives you a huge amount of control that is very hard to do otherwise.
It has been great...I'm definitely never going back to a crappy commercial router ever again.
At least if there was a security issue OpenWRT couldn't patch, I have the source code to do so myself.
And I haven't bought D-Link kit in a very long time. Their record on a variety of things (reliability, support, ...) means you get better value (in the low-mid market segment at least) from the Chinese vendors e.g. TP-Link.
[1] https://www.tomsguide.com/news/d-link-wont-fix-serious-secur...
First released in 2011, EOL in 2018. Can't say I blame 'em, EOL is EOL, but it's also the new planned obsolescence. (Better buy a new router every 7 years or the hackerman'll get ya!)
Assuming 192.168.1.1 is your router, you can craft a webpage on the public internet to exploit that IP address, without javascript.
With js, it's trivial.. But you have to deal with CORS being set up. Question then becomes - is CORS set up right? If not, pwn3d.
Of course, the underlying problem here is that users depend on vendors for patching, and their incentives are misaligned. Free software like DD-WRT removes that dependency and thus the incentive misalignment problem. To the extent that educational, legal, and technical measures prevent users from exercising the freedoms of free software in practice, these problems will get worse and worse
Am I correct that this allows administrator access to the router, but requires connecting to the router's network (either via having the WiFi password or having physical access)?
IIRC, the DIR-655 is also stuck on WPA2, which was broken, so the WiFi password doesn't offer any protection either. In which case, anyone within range of the access point could access the admin panel.
On one hand, this sucks because aside from these vulnerabilities, the DIR-655 works fine. On the other hand, I think I bought it over a decade ago.
See this for a crash course in an entire Unifi setup, https://www.youtube.com/watch?v=f_-iuY_xxFY
I personally run pi-hole on a pi, use an edgerouter x and unifi aps for the house.
Seperating routing from providing wireless makes things far more flexible, not to mention you usually get two seperate devices which are far better at doing their sperate jobs compared to an all in one solution.
If you want to level that up, use Proxmox with pfSense VM and any other junk you want to throw on it.
Many QoL things that a consumer level router + TomatoUSB firmware does for you are either difficult to set properly set up (NAT reflection) or are not available at all (per-IP traffic accounting).
https://www.techrepublic.com/article/unpatched-vulnerability...
I'm more of an app developer that does DevOps stuff when I have to. Is this something I can get done in a day or so? Is a Raspberry Pi enough, or do I need something more powerful?
The primary motivation for that one is that native wireguard (UDP) is blocked by several wireless networks I use on the move. So on those networks I have to use a shitty OpenVPN configuration over tcp port 443. OpenVPN on Android is buggy and prone to crash all the god damn time. Now, at home at least, I don't have to suffer it.
The device I use has a metal case, is fanless/noiseless, the size of an AP, has 4 gigabit ports, 4 x86-64 Bay Trail cores, 8GB of RAM, runs standard Linux, and cost me like $150. Honestly I'm done with plastic off-the-shelf crap.
I recently switched from OpenBSD to Linux and it was mostly painless. nftables is almost as usable as pf.
If you get a decent WiFi card you can just use hostapd and manage your wireless networks on the gateway; slicing it up however you want without needing vlan capable switches on your network.
I have unbound DNS and iptables to intercept all DNS requests destin for the internet, so I can block some ads. I null route the DoH servers and some hostile countries. Works great.
dnsmasq (caching) + stubby for me
i don't know what the answer is to this simply because of all the variables i consider, especially the emergence of drones. how will this be secured to a degree that few can interfere with package deliveries, the abuse of surveillance and what space around a property is actually protected. as example you can drive by in a vehicle collect AP information and the average geek can obtain access so it will be with drones.
if you really want to get interesting, think about the things drones can do, such as compromise crime scenes with planted evidence.
If you're looking to be more careful in the future, I suggest only buying routers with OpenWRT support.
I wonder if there's any company that's trying to encourage people to upgrade their routers often.
Having sorted this out, let me clearly state that the only ethical solution is to brick these devices offline.
And there you go: https://news.ycombinator.com/item?id=21195759