Backdoor in D-Link routers enables telnet access
supportannouncement.us.dlink.com
supportannouncement.us.dlink.com
> This ensures that the software is of the highest quality and meets our stringent standards.
We have a hardcoded password...but take the fix at your own risk.
> Certain models of D-Link wireless routers contain an undisclosed factory testing backdoor. Unauthenticated attackers on the local area network can force the device to enable Telnet service by accessing a specific URL and can log in by using the administrator credentials obtained from analyzing the firmware.
Seems very likely that some IOT devices are connected to LANs and can be used for shenanigans which is why you shouldn't trust anything on your LAN and always require encryption/authentication. Having telnet available on a router is beyond stupid and outright malicious.
Do they just hire some rando code monkeys with 0 security audits?
They offer telnet access as a backdoor, so yes...
They’ve been in the biz long enough to know that a security through obscurity back doors don’t hold. And yet this keeps happening.
* codemonkey integrates it with low salary from $state_actor
* codemonkey be happy, manufacturer be happy, state actor be happy - win-win!
For instance: mandate all firmware on home routers be open source. (Either by selling hardware only and give guidance on installing openwrt or disclosing the source to their existing proprietary crap)
Is that a good idea? Is it realistic?
Asus has a couple of Wi-Fi access point/switch/router combos with their own Tomato derived firmware named AsusWRT. It's nice. Because it's GPL, the source is required to be available, and a project for a derivative firmware named Merlin exists. Merlin provides additional features. One can choose to flash this firmware if desired.
If these devices must only accept signed firmware then the above becomes practically impossible and you cannot control the software running on your own device.
Yeah, I can see that. Might be remediated using legislation as well - mandate free access to third parties. The point being that (open) software development can continue maintenance beyond vendor support for the hardware.
But yeah, that would still need some story - and clever thoughts - about authenticity and trustworthiness of the firmware and how to technically enforce them.
Clearer legislation would obviously not kill the hobbyist ecosystem, and possibly improve the branded one. Even if the price of such legislation were to be the loss of grey areas where hacked/unsupported branded products live, it might well be worth paying to cash in the gains. Obviously the devil would be in the details of such legislation, so it's all pure speculation anyway.
Intelligence work is so much easier when one stops reasoning in terms of groups.
No, this is more likely the result of a test or some annoying procedure during development that needed more access than the device would normally provide - I've seen it before, and I think most people who work with embedded systems at least at some point in their career have done something that would be bad if it ended up in production units.
Not saying that it would be a bad thing.
And many won't be paying more, or installing OpenWRT, OpnSense or anything else on their own. I wish more open options were supported from vendors, but they have to lock down and make sure you can't run on frequencies or wattages not allowed in $COUNTRY, less they see massive fines.
I'm using an OpnSense device with a commercial AP myself.. it does cost a bit more, but works great and will be updated beyond what any home router will. Most seem to want a discreet all in one box.
Nothing won, but a lot lost for OpenWRT.
This is only relevant if they have a way of passing institutional knowledge from one 'generation' of developers to another. If churn is high enough and internal processes bad enough it is quite likely that entirely new teams are relearning the same lessons from the same mistakes over and over again every couple of years.
What do HN people tend to run that doesn't give them issues? I'd especially be interested in routers that have good IPv6 support (maybe impossible but still.)
Maybe they don't care to fiddle with a command line, read up on dhcp servers, ipv6 router advertisements, pf configuration and what have you. In such a case, throwing opnsense on some machine, clicking around on three pages and calling it a day isn't that bad.
The experience is close enough to an off-the-shelf router (except for the installation part), all the while getting a much better security situation.
In both cases it is behind a firewall (and NAT, if applicable).
I have it installed on an HP EliteDesk 800G2 SFF that my office was going to throw away. It has an i5-6500, 32 GB RAM, two Samsung 840 EVO SSDs and a 2x10Gb Mellanox card.
Before the Mellanox, it had an intel 4x1Gb, i350 IIRC.
I've run the PC with the intel card connected to a power meter and it was pulling 14-15W while running OPNsense and HomeAssistant, both in dedicated VMs. Some of the dedicated routers may be better than that, but when you factor in the price of the unit, mine isn't too bad, despite the rise in electricity costs here in France.
I don't have any other 10 Gb/s machine to test its max performance, but it could run PF with NAT at 2.5 Gb/s without breaking a sweat.
I'm getting by with a cheap TP-Link for now, but I'm thinking of getting a mini-PC with two NICs and enough oomph to run virtual machines well, and then putting VyOS on a VM. I've always liked the ERPoE's CLI capabilities (which were also a fork of Vyatta). I could probably put much of my former ERPoE config into a VyOS system.
I then looked at their subscription pricing and realized that individuals are not their market, not at all. So, yeah, if I want to run VyOS, I have to put up with rolling releases. :(
https://blog.vyos.io/community-contributors-userbase-and-lts...
They used to have donation options, where in exchange for a regular donation you get LTS releases, (via Patreon and OpenCollective) but both have been decommissioned. I'm not a huge fan of how that was done and how hard it is to find up to date information on that.
Nightlies are pretty stable in my experience, and with the off-device backups, a full recovery will be relatively painless.
Your options are to use the nightlies (perfectly fine IMO), pay a lot for an enterprise LTS, or be a non-profit/education and get LTS for cheap/free.
At some point they changed to doing everything via the 'cloud'. Obviously their customers didn't like that so they gradually backed down.
I want to upgrade my unifi AP so I ask on HN or other forums once in a while. Last answer I got was that you can disable the need for cloud but you still have to sign on somewhere once to be able to disable it.
So I repeat: are you absolutely sure you didn't need to give Ubiquity any info or go through their servers this time?
Because I'd love to get a new access point...
With their "Cloud Gateways" (e.g. UDM Pro, UDR, UX, UCG-Ultra) it used to be difficult if not impossible to get them into a usable state without signing into a UI account, but that is no longer the case since a few years ago.
There are some exceptions, if you wanna use their cameras you lose out on some features if you don't sign into the cloud to activate those, specifically facial recognition stuff.
I switched from consumer to Unifi just because of the better signal.
Unfortunately, even in just this thread there are very mixed answers. One yes you can (and a downvote that probably means the same thing), your 'maybe' and one 'i couldn't'.
And my current AP seems to still be fine...
I guess the 7 pro is the latest and most future proof?
I then factory reset the AP AC HD again, and set it up as a standalone AP using the Android app on a freshly reset Pixel 6 running the latest version of Graphene OS.
Both methods worked fine to setup the AP without any UI accounts involved.
This is available on all APs able to run the current version of the AP firmware, which is literally all the APs released since and including the AP AC Lite (which is from 2014 or thereabouts, they support their devices for a very long period).
7 Pro Max is the current top-end model.
I highly recommend setting up a controller for managing the AP though, even if you don't keep it running 24/7 (you can simply start it on any PC whenever you want to make configuration changes), as when they're in standalone mode a lot of the cool features don't work, you only get one SSID (per radio) and no roaming support for example, whereas when managed by the controller you can have up to 8 SSIDs per radio on the latest APs, you can access telemetry, setup roaming, etc.
I missed the controller... had an old version on an old desktop then downloaded the latest on new machines and it insisted on an UI account back then.
Unifi devices are still pretty good since I haven't needed the controller in years. This new one says I have an AP AC v2.
In this case Unifi is going to make some more money off me next week since i want to try positioning the AP somewhere else (new wire, holes etc).
I do swear there were older versions of the controller (newer than my AP) where I couldn't figure out how to run it without the UI account.
> I don't setup controllers that often
I've only done it twice; once when I installed the AP the first time, and once when I retired the machine with the controller so I needed to install it on a new desktop. Second time is the one where I failed by refusing to make an UI account.
The two other options I can think of is ubiquity and mikrotik.
https://forum.gl-inet.com/t/gl-inet-can-we-trust-them-becaus...
Curious to see HN folks take on them.
At least that's my experience with GL.iNet MT2500A (Brume 2). I happily use their older travel routers though.
That depends on the model.
Their hardware is simple to manage and excellent for the low-ish price though! E.g. the UDM-Pro which is a 10 Gbit capable router for €350, and the UCG-Ultra looks great for budget networks.
Expensive is no panacea, remember eg?:
https://www.rapid7.com/blog/post/2023/10/17/etr-cve-2023-201...
How about another conversation: "Vendors are never trustworthy, so what to do?"
I'm curious for more info like how long it was there.
surely D-Link would be able to pinpoint the code injection and ID the engineer who put in the backdoor (presumably paid by someone)
right?
what happens to that engineer? or are they already long-gone with their $$$
Then customer support will often tell you how they can't support you using your own router (I use my own, I refuse to use theirs and it is currently in bridge mode).
How are the Linksys, d-links, and others actually doing? I would have thought that that market to completely plummet. Which would lead to shortcuts and a lack of proper care.