Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
stackdiary.com
stackdiary.com
I would not expect my password to be sent to the server in the first place.
I remember asking people who supported Google before or after their IPO how they make money with your Data. No one cares. I remember pushing for Firefox instead of Chrome in 2009, no one cares. Not even on HN.
The sad thing is that those who stood up for privacy got bashed down for so many years and never received an apology. Those who defended Big Tech like Google is safe to use our data never apologised.
People do care, they are just sort of powerless to do anything.
Try the following exercises:
- try not to use google docs at work
- try to block google sites from your phone
- try to pay for things on the internet without accessing google/recaptcha/etc
it is both too big and too small of a problem for most people to deal with.
I know most technical people have done these sorts of things, but it is sort of like being your own sysadmin/security researcher. It's probably easier to run your own mail server in comparison.
BTW, I don't live under a rock, I do online banking from the PC and have pretty much given up telling my lawyer and doctor not to use Whatsapp to send and receive sensitive documents, then keep them in their unencrypted phones, but that doesn't prevent me to be worried by how easy it has become to obtain personal data about someone for those who can.
… but apple sells ads too therefore every option is equally bad!
It’s funny to see people admit with the AI stuff that apple is getting it right, introducing privacy-protecting approaches and services, etc, yet refuse to admit that the same perspective and approaches have informed all their services for a long time. In the day to day, there is no legitimate debate that Apple Maps is vastly more privacy preserving than google maps, etc. People use some weird purity test where because App Store ads exist suddenly apple is the same as a literal adtech company.
A new AirPort Extreme with an M Series I would be all over that though.
Yes.
It also doesn't help that said device vendor has been trying to destroy computing freedom while sabotaging open standards left and right.
> It’s funny to see people admit with the AI stuff that apple is getting it right, introducing privacy-protecting approaches and services, etc, yet refuse to admit that the same perspective and approaches have informed all their services for a long time.
It's funny that different people on the Internet express different and sometimes conflicting opinions?
Audits are but a means to try champion that trust. And, indeed by no means a silver bullet at that.
Yes but, depending on how the ecosystem is built, the amount of trust needed can be smaller or greater. Reality isn't black or white, we also have shades and colors.
They have some fascinating papers about it, if I recall.
What has happened to some password managers though is that they don't store the metadata encrypted (like username, website name, etc.) so that leaks have revealed which sites you use but I don't think any decent password manager has leaked passwords without a client being hacked, right?
After that point, the outcomes are not my problem. It is less work to do it this way.
The most you can expect from PR damage like this is that maybe an update goes out faster that fixes the problem (or at least hides it better). Nobody is afraid of bad PR. The most hated companies in the US are also massively wealthy and successful. If people refused to by routers from companies that pulled shit like this, nobody could buy a router. You can enter pretty much any major brand of wireless router into google next to words like "hardcoded" "backdoor" and "plaintext" and get results going back decades.
Next step is trawling procurement records for public purchasers of their products, and prompting their return.
No, it's probably devs not even caring about it (or not caring enough to push back on deadlines). It's surprising what people will do if they aren't forced to do the right thing (passwords checked to version control, proprietary code pasted in Stackoverflow) and so on.
You must live in an unbelievably beautiful world to consider that comment to be "hate speech".
I wonder what term you would use to refer to actual vile racist speech? And how you would differentiate between them when you use the term so freely?
Not Wi-Fi routers, but I don’t see why those developers wouldn’t be able to slowly churn through Jira tickets for a router software.
SSID = [google] agrees to the following ToS.
psword = use of this password confers in perpetuity, unlimited use of any and all google products and services with no cost or liability, as the owner of the password sees fit
That said, I haven't considered Linksys routers to be fit for purpose at all for years now anyway.
Either way, not connecting your TV to wifi isn't an excuse for the behavior. Good for you, but that doesn't justify their actions or make anybody who is not up to date with what kind of spying happens any less of a victim. It shouldn't happen even if you are able to get around them. You should be able to use wifi AND not be spied on. Full stop.
https://web.archive.org/web/20210912135232/https://forum.dev...
Anyway while I would not call the original accusation of the TV using any open WIFI automatically out of the question this experiment provides little evidence of that. It's hardly unthinkable that your neighbor or someone using their TV just clicked OK on some prompts to make them go away and thereby selecting the first network in the list. It's also not unthinkable that your neighbor wanted to use some functionality that requires an internet connection to setup and just didn't pay attention to the WIFI network selection.
Also, it could connect to an open WiFi without telling the user since it wouldn't need any input to enter credentials. It is becoming a lot harder to remain offline, at least with TVs.
I’m skeptical of this. Why would my Apple TV cheerfully proxy my TV’s request to send packets to the Internet?
And hell, I can't even find any evidence that there's TVs that support HEC.
The real problem is cars, IoT Devices. Do you drive a vehicle newer than model year ~2015? That thing is sending all kinds of telemetry to OEM manufacturer and their entire supply line of OEM suppliers. That data is firstly used to audit and evaluate functions in the vehicle for future iterations....but then that data is sold as many times as they can to research firms, advertisers, gov't planning boards etc.
Taking ownership of the vehicle is you signing away any investigation or litigation rights, or even access to those data/data systems.
I think THIS is where data privacy awareness needs to be pivoted to, Geolocating "iot" devices like vehicle CPU that no one, not even service techs can ever access.
No, I don't, for that exact reason. Some things are important enough for me to go to the effort to find a way to mitigate the security threat they pose. Other things, like relatively modern cars and IoT devices that I can't control, aren't important enough to do that. Instead, I just don't use them.
But if that day comes, I'll figure out how to disable the radio. If that's not possible, then I'll stop owning a car.
The US, for example, allows one to build a kit car totally by ones-self, and the waitlist for VIN certification is fairly short. If you want to shortcut the VIN certification you can build a car on a car that has at least 30% of the original frame in tact and piggy-back onto that VIN number with proper certification. If that frame is older than the mid 70s, go hog-wild; you can operate it with a coal engine if you want to.
If you're a 'dedicated individual' that is concerned with having a modern car that is engineered well for safety's sake, then go buy a kit from the hundreds of companies that do nothing but engineering work.
If you're afraid that there will be electrification mandates, no worries -- there are hundreds of startups focused on the conversion of existing ICEs into EVs.
What I'm trying to say : a world locked down to prevent all forms of vehicular autonomy is a lot different than the one we exist in today; it's not something easily predictable to assume when that will end, given the many different venues one can explore to express vehicular autonomy and individualistic choice.
Auto OEMs as a rule have more "data points" for inference than any other hardware platform/software integration. IE; actions you take in the car and the info gleamed from those actions ar more valuable to marketers than data from your cell phone. None of this needs a gps signal, there are dozens of speed,time,weight,weather,delta, sensors..
Ford for example can brag that it, more than any other manufacturer on the planet, knows exactly how often you go to gas station X from location Y, if you get gas, and where you go after. They can tell where you look, how much you weigh, your common routine, even your contacts PID. You type of "personality" can be determined trivially (IE buying/travel habits).
Your vehicle is 100 percent complicent in building a marketing/safety profile for you. Is this^ even "bad"? I think so. But I am not an expert and have yet to have an issue with it in my life.
While I do still encourage people to do this as any security is better than no security, it is worth noting that you can entirely bypass things like a DNS block (i.e. pihole). For example, your browser probably does. Idk where it is in Chrome, but in Firefox you can go to Settings > Privacy & Security[0] and down at the bottom is "Enable DNS over HTTPS using:". Which, in general, I'd also encourage people to use. Cloudflare suggests this feature is available in Brace, Chrome, Edge, and Firefox[1]
So I'm saying there's an extra step to be aware of because if you rely on only DNS to perform the blocking, then it may not catch everything because there might just be a host file with the IPs manually specified. Which isn't unlikely.
I think the bigger problem is the complexity of all of this and how we're all being spied on unknowingly and in unexpected ways (you might know that you're being spied on in some ways but I'm willing to bet there's also ways you don't know). It's pervasive, invasive, and quite difficult to escape for even technologically adept people. And we shouldn't have a society where people are victims of things just because they do not have domain expertise in that subject matter. No one is a domain expert in all domains and it would be ludicrous to suggest one could be in even several of the critical ones.
[0] or about:preferences#privacy
[1] https://developers.cloudflare.com/1.1.1.1/encryption/dns-ove...
I'm waiting for more of the post-2015 models to hit the secondary markets before the legal system sorts this out. When someone buys a used car for cash from a independent dealership, I seriously doubt they have sufficiently signed off on such data collection.
That is most likely what _Linksys_ did.
Please! Lets not just accept this poor state of security and somehow try to be apologetic for this issue. The BAR IS SO LOW .. Do not send unencrypted PII over the internet. And bonus points for not sharing someone's WiFi password with a third party. A third party in the US. We can probably assume that some three letter US government agency has intercepted all these requests.
The bar is really low. This is basic stuff. Zero need to be nice to Linksys.
At least with Comcast it seems like they have the ability to modify and (I assume) see this stuff in plain text. Who thought that was acceptable from a security standpoint I will never understand.
The idea that your LAN is a security boundary is out of date by decades.
Famous last words.
> The idea that your LAN is a security boundary is out of date by decades.
I'm sure there are plenty of device and software vendors that haven't gotten the news. And exploits exist - no reason to carelessly discard a defensive layer just because it isn't 100% perfect.
It's included in GrapheneOS, so you can backup things like WiFi passwords to a local NextCloud server.
I work on SPR @ https://www.supernetworks.org/,w e keep data self hosted, instead of a database in someone else's cloud.
We need a privacy bill of rights. It’s time! The GDPR shows the way, and we can even improve on it with hindsight.
We’ll never get ahead of the data harvesting and exploitation of that data without it and all of this becomes quite an acute problem when we add low cost cognitive digital intelligences to the equation.
Take a poll and see how many iPhone users are here. Now realize the remainder are on some OEM Android! 50/50 I am the only one to reply to you running GrapheneOS. People WANT it to be this way, because any other way is too much work. It's how oligarchy arises!
I am not being hyperbolic, y'alls bitlocker codes are going to Microsoft soon if not already with 24H2.
Being into technology on a tech hacking [orange] subreddit does not put one into the same group as the tradecraft-savvy.
:-/
If a password is so precious that you share it plaintext with third parties it is a bad usecase for a password.
Treating the network as untrusted is good but as long as some people are paying for service, traffic and bandwidth there are reasons to not allow anything to use your network. And there is also a legal question of liability if someone is not quite above board from your IP.
I've had calls lasting over an hour helping customers configure their email on their phone and computer.
I learned not to laugh when people called "the internet" either "that e-thingy", "mozarella foxfire" or "googlé charome".
I dealt with explaining to people why IE6 did not understand SNI when we decided to give all our customers websites HTTPS.
Just saying that I've been in that and seen that.
But, that’s why I run my own router for internet access. It’s my router and I can control what it does. If it goes down, then that’s on me. And I’m okay with that. Would I necessarily want the same setup for my parents? Probably not…
Those who are security conscious enough to have concerns about their LAN security do not buy "internet + routers + desktop support as a service" by renting the endpoint equipment -- they buy just the internet connectivity and furnish equipment they can control and trust.
If you buy the equipment from Verizon, I will bet you a significant amount of money that it still sends your passwords to them [on edit: with exactly zero disclosure that's detectable to 99.99 percent of users]. In fact, I'll bet you Verizon treats customer-owned equipment exactly like rented equipment except in billing. But anyway.
> The people who would trust the ISP-owned device likely have already typed that wi-fi password into things like $99 smart TVs which probably transmit their wifi password, location, and microphone data directly to China. Verizon having the wifi password is not cause for concern here.
You park your car in bad neighborhoods. Had I not stolen your car, somebody else would have done it.
Also I feel like if you are concerned about forgetting your wifi password you'd probably just keep the one that's written on the device (and which is probably quite a bit more secure than the password you'd come up with yourself).
That's my experience with ISPs in SF. It's clear that many people don't buy Internet access. They buy "WiFi" which is that Xfinity integrated service. The components don't matter.
But I've assisted people who's mental model is simply "Verizon put this box in my home and now I have internet". Who panic when a site doesn't load, and will call the first person they think is responsible for the problem. (typically, the company that gave them internet). Or more commonly nowadays, "my phone is my internet connection" -- and the only thing they think they have the power to do is to wave the phone in the air to find 'more bars'.
I suppose it makes sense from Verizon's (or any ISPs) perspective, and honesty, if you understand how all this works, then you understand how to trivially eliminate the issue, and then of course, you know when and when not to call Verizon with problems. (Of course, it'd be awful nice if they offered 'Shibboleet' [1] service for folks who do undertsand when the problem is between the site and the router.) HOWEVER, it'd be nice if they were more upfront with the disclosure of this password sharing ...
Iirc it was something small like $5 or $15 a month... I really only did it for the better hardware and software.
I went in and the unlimited plan was about $15 less per month using their modem/router than my own (which I already had), plus the router was free (I'm not paying a monthly equipment "rental" fee).
One annoyance was that their router didn't allow spaces in the WiFi password, so I had to reconfigure all my devices.
I could set up the router in bridge mode where it acts like a dumb modem and continue to use my own router, but I have not bothered with that.
They also force you to share your cable/wifi connection with other Xfinity users who are near you. Buying your own router and modem is a much better deal.
So, $100 or pay $10/mo forever, and over the past 5 years that $10 would be $600, or $500 saved by buying my own modem.
That is, as long as I stay on top of it. Every 3 months like clockwork, they "forget" that I'm not renting their equipment and start billing me for it. I have to call them up and remind them.
EDIT: also, if your ISP has a mobile app from which you can change any password on ISP provided devices, then most likely it goes around in plain text (inside TCP/TLS packets, at least).
It makes me feel happy about my longstanding habit of not using routers supplied by ISPs, though.
But who else do we go to? Every company is doing this. Maybe they just cannot survive without it. It’s probably why we need regulation here (consequences for security breaches, limitations on terms of service abuse, etc).
It’s pretty normal for passwords to be “plaintext” inside an HTTPS request. That’s how practically every login to a web app works. If it’s not HTTPS, there’s a whole slew of other issues along with putting a plaintext password in the request.
If it is HTTPS, then the issue really is just that the password gets sent anywhere rather than staying local. This is a lot more debatable as a practice, but unfortunately is also common for a lot of routers to support their cloud/app management functionalities.
Why does the cloud need to know the wifi password to support mgmt functionalities? The only reasons I can think of right now are for more "automatic" setup of a second unit for meshing or if you want a factory reset to have the same password. Both of those cases have better solutions.
If it's for setting a new password I don't see why they need the old one, if it's for remote management access using the wifi password as the access credential then that seems both bad (access to my network should not mean access to manage it) and like it can be done a lot better if actually needed (send just a well salted and hashed password).
So the password is sent for a specific feature that legitimately wants it.
You could have the app connect to a special WiFi network and then communicate directly with an API exposed by the router. That's what my router does. But the experience of using a special-purpose WiFi network is janky on many common devices so I understand not taking that choice.
Yea, this is my hunch as well as to why this works this way. Consumers are easily confused, and asking them to disconnect from their currently working internet connect and connect to a router that hasn’t yet been set up (and might not be able to provide an internet connection) can get confusing. I know I’ve been in this situation before where I’ve been connected to a special-purpose network without internet connect, need to look up some instructions online, but then remember I can’t because I’m not connected to the internet…
But this router has to have an internet connection for this flow to work, right? Otherwise how can the router get the password from the cloud service?
What is needed is the device-to-router connection to work securely but by sending the wifi credentials plaintext that is not secure, so not sure what is won here.
It’d be possible to have some sane defaults in there to make it work, but I wouldn’t count on them to be 100% out in the field of who-knows-what-crazy-settings-this-consumer-has.
> sending the wifi credentials plaintext that is not secure
If the connection between the app, router, and cloud server are all HTTPS, then it’s probably more secure to do it that way than it would be to send it over an unconfigured, insecure WiFi network (which typically uses HTTP or unsigned certificates for the management interface).
I'm just trying to ask: What is the scenario where the best (in both security and user-friendliness) solution is to send the wifi password in plaintext?
My phone did have that API, and I subjectively still found the experience janky. But that's just my opinion.
I'm nerdy enough to have built my own router with OpnSense a few years ago, and it worked like a champ. The only reason I stopped was there was an issue with BSD and a specific Broadcom 10Gbe card that I couldn't work around, so I ended up hacking something together with ClearOS and eventually NixOS.
ChatGPT was used whenever something I didn't understand came up.
Two years ago or so, my office mate and I pulled out an old AirPort Extreme when our Fritz!Box broke. Not only did it still work very well, it was still pretty competitive as an 802.11ac router.
https://www.gl-inet.com/support/firmware-versions/
https://github.com/gl-inet/openwrt
And it's straightforward to install stock OpenWRT using OpenWRT's sysupgrade method:
It's just not the upstream OpenWRT. Instead, it would be an ancient version of OpenWRT with an ancient Linux kernel (hint hint).
Guessed why? Yeah, the same story as Android. Hardware vendors (those actually designing wireless chips, like Qualcomm and Mediatek) based their official SDK on an ancient version of OpenWRT and piled on tons of non-upstream-able patches to implement drivers.
November? November?! OK, sure, there are a lot of holidays around then. But I would have expected public disclosure on something like this by end of January at the latest, unless the vendor is actively working / communicating about it.
* source is available for the boot-loaders, all onboard devices.
* Firmware source available for all NPUs, 'offload engines', and other devices in Ethernet data path.
* mainline linux kernel supports a fully blob-free bootup (except Wifi/RF)
* a jumper enables trustzone access, with complete key management available to the enduser
* populated serial UART port header on the inside. (optional)
... Then I don't care who builds it. But I can't image Apple would build such a user-friendly device, that I could just easily install OpenWrt on 5 minutes out the box. Plus they'd probably fleece you.
I can't recommend any of that to my non-techy friends or family. I can't recommend Ruckus, either, as it's about an order of magnitude too expensive. Ditto for the other "prosumer" vendors.
Unified online DB for devices and brands regarding nuisances.
Add ads, micropayments and Flattr-like mechanisms for sustainability.
It's not just the developer who wrote said code, as well as the backend developers who receive these outputs, but further, the organization did not have any kind of test/check and balance/security mechanism in place.
It's terrible given the router, especially in a world of IoT, may be the device on your network that should be the most secure.
Finally, now that it's public how bad the organization at Linksys is, it is trivial for a criminal to pay an employee to purposefully include backdoors.
The consumer router scene needs a security focused disruption.
Stop giving corporations the benefit of the doubt.
Some things can apparently only be bought with your own time, when it comes to "but you had to spend cumulative 3 days setting up your custom thing, so it didn't really cost $100" equation that people will throw at you if you tell them that you have built something yourself from relatively cheap components.
I'm open to suggestions if anyone has them on the best way to avoid this.
FS: U6-Mesh for cheap! ;)
I suspect that someone has some debugging flags that do this, and accidentally shipped with the flags set the wrong way.
What third part software does Linksys use on that router?
If the app isn’t using HTTPS, then the story would be much bigger than just the password being plaintext.
I wonder why they didn’t provide any disassembly/decompiler output, or other information on the offending binary
It’s not clear to me that the router sends the password rather than the app on your phone
Perhaps this is a typo on your part, in which case, please excuse my strong words here. But passwords should never be transmitted in clear text. Encryption is cheap these days.
If they were Chinese they would do it because they're spying of course.
Cisco sells Meraki, which they bought in Dec 2012.
it was over ssl, but still.
I am sick of reading about these embarrassing security holes in Cisco/Juniper/etc. The internet is an adversarial place. Stop cowboy coding
Why are you giving this company benefit of the doubt - just because it’s western? They haven’t even bothered to comment on the issue, they made no promise to fix it, for all you know they are selling your data to the highest bidder. And to anyone from China too.
If a Chinese company does it we are quick to label it stealing, but here we have the authority to regulate, and we go soft, oh no, it’s disorganisation, poor them, they’ve only been in this business for like 40 years or whatever.
Maybe we should assume malevolence, just like we do with China.
I'm fine with assuming ignorance for a brief window. But when the vendor doesn't reply after multiple repeated attempts, and no fix is in sight, it should quickly evolve from ignorance to willful malpractice at the very least.
The mention of Huawei was to point out the humor that the government has banned a company on the potential for subtle back doors. Something like the xz exploit. Yet the domestic vendors put out trivially broken crap on the regular. How many Cisco devices have shipped with hardcoded passwords in the past decade.
What does “western” mean? Linksys has been owned by Foxconn since 2018, which is based in Taiwan.
Look, I'm a cowboy coder, through and through; but I still know better than to close the barn door after the horse bolted.
Information security and software processes aren't that closely related. You can be secure and yolo in production. You can run an extensive change management system and a) push mostly unnecessary cloud services, b) not use reasonable precautions to protect information in transit (and at rest) when sending to cloud services.
I picked up some of the Linksys Velop wifi 6 routers recently, because OpenWRT works on them, but I figured I'd try the factory firmware first... Woof, it's bad (but I only used the web interface... I wasn't willing to install the app), I lasted a day.
Forming a mesh involves the central node using the default password when accessing the other nodes. I guess that's effective, but felt pretty gross to me.
Just quit allowing corporations to bake up pointlessly unique proprietary firmware blobs for every single device, and we won't have this problem! It's redundant work anyway.