11 ms·
The Pumpkin Eclipse
- jslakro 2y agoUseful recommendations from the canadian government https://www.cyber.gc.ca/en/guidance/routers-cyber-security-best-practices-itsap80019 https://www.cyber.gc.ca/en/guidance/routers-cyber-security-b...
- hcfman 2y agoWhich routers are affected ?
- aschla 2y ago"We began an investigation after seeing repeated complaints mentioning specific ActionTec devices, as a massive number of device owners stated that they were not able to access the internet beginning on October 25, 2023. A growing number of users indicated the outage was common to two different gateway models: the ActionTec T3200s and ActionTec T3260s, both displaying a static red light."
- Scoundreller 2y ago“the ActionTec T3200s and ActionTec T3260s, both displaying a static red light.” “This included a drop of ~480k devices associated with Sagemcom, likely the Sagemcom F5380 as both this model and the ActionTec modems were both modems issued by the ISP.”
- prophesi 2y agoAnd which ISP?
- AzN1337c0d3r 2y agoWindstream uses T3200 and T3260.
- prophesi 2y agoAh, was able to find/validate that from a news outlet covering this. Thanks! https://arstechnica.com/security/2024/05/mystery-malware-destroys-600000-routers-from-a-single-isp-during-72-hour-span/ https://arstechnica.com/security/2024/05/mystery-malware-des...
- Scoundreller 2y ago> These reports led us to believe the problem was likely a firmware issue, as most other issues could be resolved through a factory reset. My dream is to intercept the write-enable lines on the flash chips holding these firmwares so I can lock out updates. And schedule a daily reboot for any memory-resident-only crap. That’s what we used to do on, ahem, satellite receivers, 20 years ago and maybe we all need to treat every device attached to the internet as having a similar susceptibility to “electronic counter-measures”. Or at least monitor them for updates and light up a light when an update happens if it was my own equipment and I’d know if it should go off or not.
- iknowstuff 2y ago[flagged]
- whatevaa 2y agoHe just wants to watch the world burn.
- Denvercoder9 2y agoMost non-programmers don't give a shit about their router beyond "the wifi must work". Something completely stateless that can't be broken or messed with actually sounds like something they'd want.
- fiedzia 2y agoFor "wifi to work" you will need updates. Though updating all devices at once is a really dumb policy.
- starttoaster 2y agoWhat about when the router has a security update that is actually useful to stop people from getting owned? Such as to address: https://thehackernews.com/2023/07/critical-mikrotik-routeros.html https://thehackernews.com/2023/07/critical-mikrotik-routeros... Blocking updates seems useful for blocking malicious and helpful updates. I wonder which camp the majority of updates fall into.
- localfirst 2y agothis along with other recent security incidents suggest somebody is rehearsing for massive campaign tied to another geopolitical ambitions.
- waihtis 2y agowell there is a top cyber offensive power whom is de facto at war with the west, hardly surprising
- Crosseye_Jack 2y agoI would say that the rehearsal has long been over. Just before Russian troops entered Ukraine Viasat saw an attack on it's network which among other countries serves Ukraine, which saw updates getting pushed to modems designed to disable those modems. https://en.wikipedia.org/wiki/Viasat_hack https://en.wikipedia.org/wiki/Viasat_hack
- dralley 2y agoSaid geopolitical entities have conducted much larger and more consequential attacks in the past https://www.wired.com/story/notpetya-cyberattack-ukraine-russia-code-crashed-the-world/ https://www.wired.com/story/notpetya-cyberattack-ukraine-rus... https://www.technologyreview.com/2022/05/10/1051973/russia-hack-viasat-satellite-ukraine-invasion/ https://www.technologyreview.com/2022/05/10/1051973/russia-h... It's hard to call this a meaningful rehearsal when previous attacks knocked actual core power and economic infrastructure offline
- sgtaylor5 2y agorelated article from Ars Technica: https://arstechnica.com/security/2024/05/mystery-malware-destroys-600000-routers-from-a-single-isp-during-72-hour-span/ https://arstechnica.com/security/2024/05/mystery-malware-des...
- skilled 2y agoThat doesn’t count as related as it is a rewrite of the original source. Just saying, it adds no details of its own.
- thecosas 2y agoIt does include information which the original article specifically excluded from mentioning: the ISP involved. "Windstream" is mentioned in the first paragraph of the Ars article, while the Lumen post makes references to "a rural ISP" throughout the post.
- jeffbee 2y ago"Router" being used to mean customer premises equipment, it seems.
- TheJoeMan 2y agoHere I was hoping someone was “encouraging” an ISP to upgrade their infra.
- ronnier 2y agoFor a few years now I only buy a small x86 box with dual nics and run OpenWRT. I love it. It's open source, lots of support, good community. It supports wireguard. Latest version allows you to even run docker containers.
- hedora 2y agoI’ve got an old PC Engines board with openbsd on it. It’s been remarkably trouble free for something like 8 years.
- ziml77 2y agoThe PC Engines boards are great for that. I've got mine running OPNSense (FreeBSD) and it's not required any fuss.
- glitchcrab 2y agoAnother very happy PC Engines user here, I've been running pfsense and more lately opnsense on one for over 10 years now. It has never missed a beat.
- rpcope1 2y agoIt's huge shame Pascal basically stopped building those boards since AMD and Intel wouldn't play ball. I'd really like to have something like an APU with 10G connectivity with an x86 processor that was not built and designed in China running open firmware. With PC Engines gone now, I think you're basically out of luck.
- MisterTea 2y agoMy APU2 died few years back and haven't found a decent replacement. Instead I use a Lenovo Thinkstation M720Q off eBay with the PCIe x8 riser and Intel 2 port 10GbE card. You could also fit a 4 port 1Gb card too. The thing idles at 18-19W which is less than the big white rectangular Verizon "trash can" router which idled at 22W and has horrible WiFi (I use a Unifi APLR.)
- londons_explore 2y ago> Lumen identified over 330,000 unique IP addresses that communicated with one of 75 observed C2 nodes How does Black Lotus Labs global telemetry know which IP communicated with which other IP if they have control of neither endpoint? Who/what is keeping traffic logs? If these guys can do it, remind me again how Tor is secure because nobody could possibly be able to follow packets from your machine, through the onion hops, to the exit node where the same packet is available unencrypted...
- hedora 2y agoThis is reasonably standard functionality for backbone routers. They have to parse the TCP headers in hardware anyway, and can track common endpoints with O(1) state. Of course, on the other end of the spectrum, the NSA has tapped into core internet links, is recording everything it possibly can, and is keeping it forever.
- Hikikomori 2y agoYup. Pretty much all ISPs collect sflow/netflow from their devices to be able to debug problems or detect ddos.
- sebzim4500 2y agoIs that actually feasible with their budget? If we are generous and assume there a zettabyte of data a year that they want to store. At consumer prices, you would have to pay $10B per year just buying hard drives yet alone the operational costs/redundancy. The budget for all of the US intelligence services is ~$65B. I think if they wanted to actually do what you are describing it would be the single biggest intelligence expense they have and I don't see how you hide that.
- deleted 2y ago[deleted]
- choilive 2y agoIts not. They don't store the raw IP packet data, instead they store the metadata (this was revealed in a leak a long time ago), like the type in this article (data source and destination, timestamps, size of the data, etc.) the metadata is orders of magnitude less data than the raw packets and likely easily compressible, so I wouldn't be surprised if they keep it all for a decent chunk of time.
- nisa 2y agoArticle is light on the interesting details. How did they came in? Do these routers have open ports and services by default and answer to the Internet in a meaningful way? Couldn't someone grab different firmware versions and compare them? Looks like they are doing what everyone else is doing and using OpenWrt with a vendor SDK: https://forum.openwrt.org/t/openwrt-support-for-actiontec-t3200m/154720 https://forum.openwrt.org/t/openwrt-support-for-actiontec-t3... What's interesting here is speculated the vendor send a malicious/broken update: https://www.reddit.com/r/Windstream/comments/17g9qdu/solid_red_light_on_t3200_modem/ https://www.reddit.com/r/Windstream/comments/17g9qdu/solid_r... So why is there no official statement from the ISP? If it was an attack shouldn't there be an investigation? I'm not familiar with how this is handled in the USA but this looks really strange. Maybe these machines were bot infested and the vendor pushed an update that broke everything? Maybe it's like in the article and it was a coordinated attack maybe involving ransom and everyone got told it's a faulty firmware update, keep calm? which is also kind of bad, as the customer I'd like to know if there security incidents. Has anyone links to firmware images for these devices? Or any more details?
- chrisjj 2y ago> So why is there no official statement from the ISP? If it was an attack shouldn't there be an investigation? We should assume a decision to make no statement was based on the outcome of an investigation. I wonder how much of the replacement cost is insured. I am guessing none. Leaving the ISP at severe risk of, er, business discontinuity. Another good reason for no statement.
- xacky 2y agoReminds me of the CIH virus. It's only a matter of time for ransomware authors to start using firmware blanking as a new technique.
- pragma_x 2y agoFor anyone else that was confused by the headline, this is about the destruction of 600,000 individual (small) routers. Not routers that are worth $600,000 (each or combined).
- steelframe 2y agoFor my home network I've purchased a networking appliance form-factor computer, which is basically a regular old an i3 with VT-x support in a fanless case and 4 2.5GiB NICs. I've installed my favorite stable Linux distro that gets regular automated security updates in both host and a VM, and I've device-mapped 3 of the NICs into that VM. The remaining NIC remains unattached to anything unless I want to SSH in to the host. I'm running UFW and Shorewall in the VM to perform firewall and routing tasks. If I want to tweak anything I just SSH in to that VM. I have a snapshot of the VM disk in case I mess something up so I can trivially roll back to something that I know works. I've purchased a couple of cheaper commercial WiFi access points, and I've placed them in my house with channels set up to minimize interference. Prior to this I've gone through several iterations of network products from the likes of Apple, Google, and ASUS, and they all had issues with performance and reliability. For example infuriating random periods of 3-5 seconds of dropped packets in the middle of Zoom conferences and what not. Since I've rolled my own I've had zero issues, and I have a higher degree of confidence that it's configured securely and is getting relevant security updates. In short, my home network doesn't have a problem unless some significant chunk of the world that's running the same well-known stable Linux distro also has a problem.
- tmoertel 2y agoOut of curiosity, which networking appliance form-factor computer did you purchase?
- steelframe 2y agoIt's a HUNSN RJ36. It came preloaded with pfSense, as many of them do, but I immediately made a full disk backup and then wiped and installed with a Linux distro because, well, "This is Linux. I know this." You're going to find a lot of people who strongly prefer one over the other, and you may find you prefer pfSense over a "do-everything-yourself" Linux distro if you give it a shot. There are also Linux distros that are targeted for network appliances, and setting them up (correctly) can be easier if the distro is built for the task. There are quite a few machines in this category, and what's in stock at any given time tends to rotate relatively quickly. I think the one I bought might still be available, but you will want to check to see if there is something with specs that will work better for your use case.
- Kiboneu 2y agoWell if you backdoor 600k routers and introduce a firmware bug with one of your patches, this is what happens. Can't they just stage their updates? Surely, malware authors and users must be too cool for adopting standard prod practices.
- perlgeek 2y ago> Surely, malware authors and users must be too cool for adopting standard prod practices. Their economic pressures are just different, it's not their own hardware that they're bricking, nor are likely to be held liable for it.
- bostonpete 2y agoWhat is the significance of the article/post title...?
- thamer 2y agoThis attack happened a few days before Halloween 2023 (pumpkins), with a large drop in the number of devices connected to the Internet – like how an eclipse suddenly brings a period of darkness, maybe? This is just my interpretation, I also found it cryptic.
- ajb 2y agoYeah, didn't this have a more comprehensible title a few hours ago?
- its-summertime 2y agoIs the >2x increase in other devices addressed in any form?
- gracebekcy 2y ago[dead]
- mistrial9 2y agodo they say what US ISP was targeted ? these are the routers in people's homes basically?
- skyyler 2y agoIf you do an image search of the impacted devices, they all seem to be Windstream branded. Not sure if that's enough evidence to say it was them... but I don't see another ISP's logo on these things.
- ChrisArchitect 2y ago[dupe] Discussion: https://news.ycombinator.com/item?id=40525130 https://news.ycombinator.com/item?id=40525130
- thimkerbell 2y ago@dang, if there are karma points at HN, you could add some for submitters who improve upon the oft-execrable original clickbait headlines/titles. (Here, I see present verb tense being used for an incident from October of last year.)
- thimkerbell 2y agoYou could also subtract points for submissions whose titles appear to advocate causing harm.
- scrps 2y agoI read the lotus labs blog post they linked and they mentioned no analysis of the actual firmware payload that actually bricked them, is this out there or a sample? I'd be curious to know if it was actually meant to brick or someone f'ed the image and accidentally bricked them trying to be clever. Also if it was a nation state why would you so publically burn your capability bricking residential routers on an ISP that seems to mostly serve rural areas, if they did it for testing that'd be real dumb.
- bitnasty 2y agoWhy would someone build a botnet this complex then brick it?