4 ms·
What about when the router has a security update that is actually useful to stop people from getting owned? Such as to address: https://thehackernews.com/2023/0
by starttoaster 2y ago
What about when the router has a security update that is actually useful to stop people from getting owned? Such as to address: https://thehackernews.com/2023/07/critical-mikrotik-routeros.html https://thehackernews.com/2023/07/critical-mikrotik-routeros...
Blocking updates seems useful for blocking malicious and helpful updates. I wonder which camp the majority of updates fall into.
- stacktrust 2y agoA physical switch can be locally toggled by the device owner/admin. Some motherboards offer a physical jumper for firmware updates, including x86 PC Engines APU2 coreboot router.
- starttoaster 2y agoSo here's another problem. Going back to the point made earlier in this thread "users don't care much about their routers." The average user opens their router page exceedingly rarely, which is the benefit of automatic updates. I set up my mom's router, and she works in IT (more in project management these days, so she's fallen into being a mostly non-technical user.) And she still texts me every time she needs to get into it to ask me what the password I set up was... once every few years. The downfall of automatic updates is obviously something like the case of the article this discussion is about. But weigh up the costs and benefits, in my opinion, the scale tips more towards automatic updates when you factor in all the critical level vulnerabilities that router OS's have accrued over the years.
- stacktrust 2y agoSome consumer routers (e.g. Amazon eero) have moved to cloud/app config and automatic updates. A read-only partition can bootstrap recovery from cloud, if the main firmware or config is damaged. Some updates are possible with live kernel patching of the memory-resident OS, which can also be used by malware.
- labcomputer 2y agoWell, considering that most home users never update their router's firmware, I'm going to go out on a limb and suggest that the majority of applied updates are malicious. If you did want to go this route, a simple fix would be to have the write enable line gated by a hardware one-shot timer (think like a 555 timer) triggered by a physical button on the front (and the button would also reboot the router). The firmware update sequence would go like: Router prompts user to update using button -> user presses update button -> router reboots to clear malicious software -> when the router comes back up, the write enable gate remains open for $n minutes (and maybe there's a GPIO that can hold the gate open if it is already open) -> router performs software update. The problem is that there's pretty much no way to do this without adding a $1-2 to the BOM, and no manufacturer of (pro|con)sumer routers will do that. Edit: Or do what stacktrust wrote and just have a toggle switch (update/secure).
- starttoaster 2y ago> Well, considering that most home users never update their router's firmware, I'm going to go out on a limb and suggest that the majority of applied updates are malicious. Consumer grade routers often have automatic updates these days.
- internetter 2y agoYeah I have a pretty nice router and inexplicably, random nights, it drops out at 3am for ~3 minutes and then comes back on (and has all the markings of a reboot in terms of the pattern of request failures). I have to assume Synology just decided that nothing's using the internet at 3am
- starttoaster 2y agoI had no idea that Synology did routers too, but I would assume this would be a configurable time somewhere in the settings. But yes, that sounds like automatic updates to me.
- Scoundreller 2y ago