this post was submitted on 30 May 2024
205 points (98.6% liked)

Technology

59605 readers
3403 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
all 29 comments
sorted by: hot top controversial new old
[–] subtext@lemmy.world 31 points 5 months ago

One day last October, subscribers to an ISP known as Windstream

In case anyone only reads the headline

[–] KaRunChiy@kbin.run 26 points 5 months ago

Oh shit, I use Windstream, this explains a lot about why they were so busy replacing everyones routers down here. I had assumed it was just a defective design since they used all the same units for every network, but it was actually malware, wild

[–] tjr@mbin.xi.ht 24 points 5 months ago (2 children)

the sad thing is this is just routers, think about all of the IoT devices that are compromised due to vendors not caring about patching security issues, just worrying about selling IoT.

[–] SlopppyEngineer@lemmy.world 5 points 5 months ago (1 children)

insecam.org for a quick demo of insecure devices

[–] chiisana@lemmy.chiisana.net 4 points 5 months ago

Shodan also has a lot of fun searches.

[–] BearOfaTime@lemm.ee 3 points 5 months ago

Or having non existent security

[–] Cosmicomical@lemmy.world 13 points 5 months ago

Keep firing tech people, the tech peiple will have to find an hobby

[–] gravitas_deficiency@sh.itjust.works 10 points 5 months ago (1 children)

And that’s why you should run your own router. Preferably using open firmware/OS like ddwrt or pfSense/opnSense.

[–] robotica@lemmy.world 2 points 5 months ago (1 children)

I'm curious, does running open source software somehow exempt you from getting malware?

[–] gravitas_deficiency@sh.itjust.works 12 points 5 months ago (3 children)

Not necessarily, but the odds of getting popped by a heretofore undisclosed backdoor that your ISP didn’t think would be a big deal are eliminated entirely, and you can also do a lot more interesting things with your home infrastructure, if that’s your thing.

[–] cmnybo@discuss.tchncs.de 9 points 5 months ago

You also get regular updates with open source firmware. Many of the ISP provided routers will never see an update.

[–] Max_P@lemmy.max-p.me 5 points 5 months ago

It also doesn't ship with ISP backdoors or ISP remote management crap that can be a big attack vector. Just about every ISP router I've looked at has some hardcoded super admin password or secret unauthenticated paths to access hidden settings.

Custom firmware ships with plain web UI and/or SSH only from the LAN side (or even specific VLAN), so right off the start there isn't a whole lot of potentially exploitable surface. And the community actually cares.

[–] robotica@lemmy.world 1 points 5 months ago* (last edited 5 months ago) (1 children)

Is the recent XZ backdoor (and something that had to do with SSH too) anything to worry about in terms of the probability of there being a backdoor even in open source router software?

Not trying to dissuade anyone here, I love open source software, I'm just wondering how much effort is reasonable to be put into securing your local network (i.e. buying your own router, also installing open source software, or writing your own router software if you don't trust existing solutions) given that not everyone is tech savvy and you get diminishing returns for every additional security measure. And when is the usual point at which you would say "okay, this is secure enough"?

My router is not from an ISP, but it does get frequent firmware updates and I don't use any cloud management features, only local configuration.

I mean, the ISP-provided boxes don’t give you a way to upgrade past that faster than you would on an open distribution. The latter had fixes out within a week, or just weren’t affected. And it’s also way easier to check the deps on open firmware/OSes.