4 ms·
This is classic security overreaction, when talking about home routers. Just to be clear if this is an issue for you, make sure you do not connect to any wifi y
by sensiblesec 4y ago
This is classic security overreaction, when talking about home routers.
Just to be clear if this is an issue for you, make sure you do not connect to any wifi you have not hardened yourself beforehand!
Also articles on the page fail to show any practical implications and what does happen instead on what can happen. Don't get me wrong having your router used for DDoS and C2 is not great but it has 0 practical implications for you. The summaries on the page also omit that most of the nasty sounding issues are directly mitigated by using HTTPS.
Delivering malware will have an affect but none of these articles actually mention such cases (other than it can be done) and how prevalent this is compared to other malware delivery methods. I'd say it is safe to assume it isn't.
Also notice most of the recommendations have nothing to do with the these threats. That can be summed up to update your router and change password.
- YPPH 4y agoI tend to agree. And in terms of being used for DDoS attacks etc., that's really an issue that needs to be addressed by ISPs, who supply routers to the vast majority of non-technical home users. ISPs should be setting appropriate defaults, setting unique passwords, and issuing automatic firmware updates over the air.
- sensiblesec 4y agoAgree. I see an argument about C2 and DDoS from a public good perspective but it is misguided to think this will be addressed by individuals
- nonameiguess 4y agoYou can possibly get your entire house blocked and/or banned by services, servers, and networks that notice your public IP seems to be part of a botnet. That said, I'd be skeptical and want to see real data if this guy is claiming your router is more likely to be infected and become part of a botnet than your other networked devices.
- sensiblesec 4y agooperative word is can again. I'd doubt that this happens on large scale (we would see/hear more because of the sizes of botnets). also when it does happen, removing it from bans will probably cost you less work then applying the hardening in the first place...
- staticassertion 4y agoYeah, router compromise was way worse a decade ago when no one used HTTPS. These days it's obviously not great but you're not really in danger so much as you can be inconvenienced. That said, it would be nice if router security wasn't absolute shit and those devs actually gave two shits about it, but I could say that about so many things.