4 ms·
Most non-programmers don't give a shit about their router beyond "the wifi must work". Something completely stateless that can't be broken or messed with actual
by Denvercoder9 2y ago
Most non-programmers don't give a shit about their router beyond "the wifi must work". Something completely stateless that can't be broken or messed with actually sounds like something they'd want.
- fiedzia 2y agoFor "wifi to work" you will need updates. Though updating all devices at once is a really dumb policy.
- starttoaster 2y agoWhat about when the router has a security update that is actually useful to stop people from getting owned? Such as to address: https://thehackernews.com/2023/07/critical-mikrotik-routeros.html https://thehackernews.com/2023/07/critical-mikrotik-routeros... Blocking updates seems useful for blocking malicious and helpful updates. I wonder which camp the majority of updates fall into.
- stacktrust 2y agoA physical switch can be locally toggled by the device owner/admin. Some motherboards offer a physical jumper for firmware updates, including x86 PC Engines APU2 coreboot router.
- starttoaster 2y agoSo here's another problem. Going back to the point made earlier in this thread "users don't care much about their routers." The average user opens their router page exceedingly rarely, which is the benefit of automatic updates. I set up my mom's router, and she works in IT (more in project management these days, so she's fallen into being a mostly non-technical user.) And she still texts me every time she needs to get into it to ask me what the password I set up was... once every few years. The downfall of automatic updates is obviously something like the case of the article this discussion is about. But weigh up the costs and benefits, in my opinion, the scale tips more towards automatic updates when you factor in all the critical level vulnerabilities that router OS's have accrued over the years.
- stacktrust 2y agoSome consumer routers (e.g. Amazon eero) have moved to cloud/app config and automatic updates. A read-only partition can bootstrap recovery from cloud, if the main firmware or config is damaged. Some updates are possible with live kernel patching of the memory-resident OS, which can also be used by malware.
- labcomputer 2y agoWell, considering that most home users never update their router's firmware, I'm going to go out on a limb and suggest that the majority of applied updates are malicious. If you did want to go this route, a simple fix would be to have the write enable line gated by a hardware one-shot timer (think like a 555 timer) triggered by a physical button on the front (and the button would also reboot the router). The firmware update sequence would go like: Router prompts user to update using button -> user presses update button -> router reboots to clear malicious software -> when the router comes back up, the write enable gate remains open for $n minutes (and maybe there's a GPIO that can hold the gate open if it is already open) -> router performs software update. The problem is that there's pretty much no way to do this without adding a $1-2 to the BOM, and no manufacturer of (pro|con)sumer routers will do that. Edit: Or do what stacktrust wrote and just have a toggle switch (update/secure).
- starttoaster 2y ago> Well, considering that most home users never update their router's firmware, I'm going to go out on a limb and suggest that the majority of applied updates are malicious. Consumer grade routers often have automatic updates these days.
- internetter 2y agoYeah I have a pretty nice router and inexplicably, random nights, it drops out at 3am for ~3 minutes and then comes back on (and has all the markings of a reboot in terms of the pattern of request failures). I have to assume Synology just decided that nothing's using the internet at 3am
- starttoaster 2y agoI had no idea that Synology did routers too, but I would assume this would be a configurable time somewhere in the settings. But yes, that sounds like automatic updates to me.
- Scoundreller 2y ago
- dymk 2y agoBummer then, SSIDs and WiFi passwords are state.
- q0uaur 2y agoplenty of routers in my country (id go on a limb and say the majority) have both written on a sticker, different password for each device generated when the firmware first gets installed, and people NEVER change it. edit they also come with a QR code you can scan on your phone to connect to the wifi without manually copy the password, so people just put up that qr code somewhere and connecting is easy enough.
- WhyNotHugo 2y agoTo be fair, most people never change these. In any case, you can have a separate storage (you need less than 1KB) for these two things.
- Scoundreller 2y agoI think that’s usually the case: that will be stored in a small 24c or 93c (i2c or SPI) chip that is separate from the firmware that may only handle 1000 flashes and takes a lot longer to flash (often requiring risky and long downtime).
- Denvercoder9 2y agoHalf of my technical friends haven't changed theirs from the factory defaults. None of my non-technical friends have changed them. A non-representative sample of SSIDs I receive in my apartment gives 9 default ones, and 2 custom ones (plus mine).
- deleted 2y ago[deleted]
- hifromwork 2y agoWormable vulnerability in a router is 10x bigger issue in practice than attacks that brick a router. By "in practice" I mean judging by the real world attacks that I know of. Hacked routers are used as residential proxies for criminals, for DDoS attacks, fast flux networks, credential stuffing attacks, and more. Bricking routers is rare (and very loud), that's why it's news on HN. Many router malware families don't even try to be persistent. Even Mirai - arguably the most famous router botnet - is not persistent [1]. In case the device is rebooted, it just gets infected again in a few minutes. It's very important that all network connected devices have an update mechanism, working automatically in the background. [1] At least the original version. After the code leak people were doing all kinds of updates, so there are some variants that try to be persistent in some cases.
- stacktrust 2y ago> In case the device is rebooted, it just gets infected again in a few minutes. Can Suricata detect and block known router botnets?