3 ms·
OK, and (1) how are you supposed to trust that the manufacturer won't get hacked one day (or whatever) and the IP address won't change to something external/mal
by wfunction 9y ago
OK, and (1) how are you supposed to trust that the manufacturer won't get hacked one day (or whatever) and the IP address won't change to something external/malicious? (2) what if I don't have an internet connection and don't have a DNS server on the gateway that can reply to such a query?
- lmm 9y ago1) If you trust them to write secure router firmware you can trust them to keep their HTTPS certificates safe - the former is a lot easer than the latter. 2) Router intercepts all DNS requests and responds with its own IP, responds to HTTP calls with HTTP 428, like already happens and like OSes already deal with appropriately.
- wfunction 9y ago> (1) If you trust them to write secure router firmware you can trust them to keep their HTTPS certificates safe wha? uhm, no. Just because I trust you to do something correctly once that doesn't mean I trust you to keep something else safe for all eternity. > 2) Router intercepts all DNS requests and responds with its own IP Actually, what if I have multiple of these routers in (say) a chain? I have to go physically find the one I need so I can connect an Ethernet cable to it and bypass all the others? I can't just connect to the one I want directly by its IP address?
- lmm 9y ago> Actually, what if I have multiple of these routers in (say) a chain? I have to go physically find the one I need so I can connect an Ethernet cable to it and bypass all the others? I can't just connect to the one I want directly by its IP address? Ah, I misunderstood, thought you were talking about a "captive portal"-type use case. If you're talking about having the router host some config interface like any other webserver then I'd say like any other webserver it should be able to generate its own certificate and CSR for a hostname you configure it with, and you submit that to your internal CA, or directly to let's encrypt or similar provider.
- wfunction 9y agoEr, what "internal CA" are you even talking about? Like imagine my grandma gets Comcast, her internet is not working, and I tell her to go to 10.0.0.1 to see if it shows anything. Suddenly she's supposed to get an HTTPS error warning her there's an MITM attack? Or am I supposed to tell her to install a root cert in her machine and every other machine she might connect in the future? Or heck, what if I'm just connecting to my damn scanner in my network? Or what if it's a guest trying to do that? "Sorry auntie, you'll have to install my self-signed cert as a root cert before you can use my scanner's web interface to scan your pic"?
- lmm 9y agoIf your router or scanner is to be accessible over the network then it needs its own name and it needs to be able to certify that that's its name. Anything else is just too dangerous. A user expects addresses they enter into the browser to mean the same thing on any connection; having a few "magic" addresses that go one place on one network and another place on another network is a recipe for users getting hacked. For the consumer use case, maybe the router gets a unique default address in the manufacturer's namespace (router12345.linksys.com) and ships with a certificate for that name and that name printed on the box, just like we do for the admin password. Since it's a router it's probably running the DNS for your network (at least in the consumer use case) so it can route requests for itself correctly. For scanners or similar, the router would need to update its DNS when the scanner joins the router's network - a lot of routers already do this within the local domain based on DHCP registrations, so this ought to be simple if it's not already done. Crucially this part isn't security-critical - if you try to print a confidential document on your network printer while you're on your neighbour's wifi, the worst their router can do is not route you, because an evil endpoint won't have your printer's certificate.
- wfunction 9y ago> If your router or scanner is to be accessible over the network then it needs its own name and it needs to be able to certify that that's its name. Anything else is just too dangerous. A user expects addresses they enter into the browser to mean the same thing on any connection; having a few "magic" addresses that go one place on one network and another place on another network is a recipe for users getting hacked. ...a recipe for users getting hacked? on a home network? by whom exactly? my family? The router is already firewalling the entire network against the internet. Can you describe the exact attack scenario you're imagining?
- gcp 9y agoCan't the router reply to the DNS request itself with 192.168.1.1? The public DNS record is needed to verify the DV cert, not to do the actual lookup.