4 ms·
How can I verify some malicious code is actually present on my router? What does this code do? Could the FBI put their own malicious code on the router, via thi
by kfrzcode 8y ago
How can I verify some malicious code is actually present on my router? What does this code do? Could the FBI put their own malicious code on the router, via this supposed exploit? Why should I trust the FBI?
Excuse my ignorance but I'm not not going to ask these types of questions.
EDIT: After reading a bit - it seems the control is somehow "transferred" to the FBI rather than the malicious actor - any other external agent controlling my software and hardware should be considered a malicious actor from a defensive standpoint, right?
Also, I don't buy the "FBI is better" argument, because I'm a skeptic.
EDIT 2: Moved the 'Why should I trust the FBI?' question to the end of my opening paragraph because I just want to know more about how a layman should approach verification of this vulnerability other than just "trust the powers that be"
- archgoon 8y agoWhy do you need to trust the FBI? This is a notification of a potential compromise of your security, you can ignore them if you want. "The FBI is advising users of consumer-grade routers and network-attached storage devices to reboot them as soon as possible"
- kfrzcode 8y agoI'm honestly far from a network expert or even engineer - but it seems if there's a vuln that the bad-actor had control over, then the ping-home domain of that vuln is controlled by the FBI, then the FBI is telling me to reboot my router, there is a non-negligible possibility that the FBI has an interest in using that vuln in their favor. Granted I don't know many specifics here but that's why I'm employing the elenctic method.
- badlucklottery 8y ago>Why should I trust the FBI? Because this is their job. And you'll probably need to reboot your router anyway in the near future so why now do it now just in case? >Could the FBI put their own malicious code on the router, via this supposed exploit? Sure. So could space aliens.
- kfrzcode 8y agoI don't think the FBI Special Agent job description is one line of "make humans trust you" - I believe it's closer to "protect the country from foreign and domestic threats," and I think just because the FBI tells me to jump doesn't mean I should jump... Your second point is not clear to me. Space aliens aren't an extant authority on our planet (afaik)
- badlucklottery 8y ago>I think just because the FBI tells me to jump doesn't mean I should jump You can find independent corroboration of this this malware with little effort. And if your gear is compromised, it's most likely doing something you don't want. So "jumping" is the smart move here unless you just want to be contrary. The second point is: if you're assuming a conspiracy based on zero evidence, why not go big?
- ggm 8y agoExplain how the FBI would leverage an advantage by telling you to reboot. Explain in a way, which doesn't depend on an unprovable. The best I can come up with is a false sense of security, which given they actually expect you to also patch and upgrade and proffer advice to patch and upgrade, is a bit weak. Basically, I cannot construct a scenario where there is a significant, could-not-be-found-by-white-hat reason they'd do this, to secure some advantage. I.E. Occams razor works for you, in this case.
- kfrzcode 8y agoI suppose I just don't know what exploits could be implanted -- are there forms of rootkits that can go undetected? Or have all of these infected firmware been reverse engineered and the exploit in question cataloged? According to ArsTech in this article (https://arstechnica.com/information-technology/2018/05/hackers-infect-500000-consumer-routers-all-over-the-world-with-malware/ https://arstechnica.com/information-technology/2018/05/hacke...) the VPNFilter exploit can survive a reboot - so how can a simple reboot disinfect if the only delta is the owner of [one of] the second stage callback IP addresses? I haven't seen any mechanics explained that would actually disinfect the router. I appreciate your response with actual critical thinking tips and not just flippancy - I don't know where else to have these types of discussions.
- ggm 8y agoThe attack had three components: infection, sign-in with an initiator head-end, and then second/third stage download. As I understand it, from reading around: The FBI took over an "initiator" headend which bootstraps a simpler infection into the actual threat/attack code. The low level infection can't be removed simply, that demands new code from the maker or an OpenWRT type source. The FBI took over the domain namer behind a service which acts as the sign-in site. The attack mode code is not in your firmware, it has to be re-downloaded. If you block the initiator login, you aren't "clean" but you cannot complete download of attack code to mount the DDOS If you reboot, the low level infection tries to sign in, and is blocked, and so can't get the second/third stage downloads.
- 8y ago
- reaperducer 8y ago> Why should I trust the FBI? So don't. No one is forcing you to reboot your router. No one who cares about this issue cares about your personal Jason Bourne fantasies. Reboot. Don't reboot. For the rest of the world, your decision makes zero difference. because skeptic It's just like English. Close enough.
- kfrzcode 8y agoI'm just trying to learn through discussion - I thought that HN would be a good place to do it, and that may be my mistake. I'm an interpersonal learner and admittedly ignorant on this topic. I have no personal fantasies; I want to understand the truth and that's my only motive.