15 ms·
Linksys Velop routers send Wi-Fi passwords in plaintext to US servers
- ddggdd 2y agoI never use phone app for router, and always block router calling back home through adguardhome, linksys do 2 every minute, some other brand do every 2 seconds.
- micahdeath 2y agoSo, we should use common (hacked) passwords for our wifi routers. So, my password of 'mickeymouse' is probably compromised. (Password chosen because my young children can spell it from the disney show.)
- bootbloopers 2y agoThis seems like something that would be fairly easy to show proof for using ghidra/binary ninja/ida pro. I wonder why they didn’t provide any disassembly/decompiler output, or other information on the offending binary
- 0cf8612b2e1e 2y agoNo need to worry about Huawei backdoors when domestic infrastructure does such a bang up job on their own. I am sick of reading about these embarrassing security holes in Cisco/Juniper/etc. The internet is an adversarial place. Stop cowboy coding
- ClumsyPilot 2y ago> Stop cowboy coding Why are you giving this company benefit of the doubt - just because it’s western? They haven’t even bothered to comment on the issue, they made no promise to fix it, for all you know they are selling your data to the highest bidder. And to anyone from China too. If a Chinese company does it we are quick to label it stealing, but here we have the authority to regulate, and we go soft, oh no, it’s disorganisation, poor them, they’ve only been in this business for like 40 years or whatever. Maybe we should assume malevolence, just like we do with China.
- fooqux 2y ago> Maybe we should assume malevolence, just like we do with China. I'm fine with assuming ignorance for a brief window. But when the vendor doesn't reply after multiple repeated attempts, and no fix is in sight, it should quickly evolve from ignorance to willful malpractice at the very least.
- 0cf8612b2e1e 2y agoWhere did I give them the benefit of the doubt? I am furious at the network providers ongoing negligence/incompetence. Either they are in bed with the NSA or they just suck at their job. Regardless of the root cause, we all suffer. The mention of Huawei was to point out the humor that the government has banned a company on the potential for subtle back doors. Something like the xz exploit. Yet the domestic vendors put out trivially broken crap on the regular. How many Cisco devices have shipped with hardcoded passwords in the past decade.
- lotsofpulp 2y ago>Why are you giving this company benefit of the doubt - just because it’s western? What does “western” mean? Linksys has been owned by Foxconn since 2018, which is based in Taiwan.
- toast0 2y ago> Stop cowboy coding. Look, I'm a cowboy coder, through and through; but I still know better than to close the barn door after the horse bolted. Information security and software processes aren't that closely related. You can be secure and yolo in production. You can run an extensive change management system and a) push mostly unnecessary cloud services, b) not use reasonable precautions to protect information in transit (and at rest) when sending to cloud services. I picked up some of the Linksys Velop wifi 6 routers recently, because OpenWRT works on them, but I figured I'd try the factory firmware first... Woof, it's bad (but I only used the web interface... I wasn't willing to install the app), I lasted a day. Forming a mesh involves the central node using the default password when accessing the other nodes. I guess that's effective, but felt pretty gross to me.
- thomastjeffery 2y agoMaking this about foreign vs domestic is bullshit. There is no such thing as a friendly vulnerability. Just quit allowing corporations to bake up pointlessly unique proprietary firmware blobs for every single device, and we won't have this problem! It's redundant work anyway.
- anonym29 2y ago"There is no such thing as a friendly vulnerability." is going right up there with "You can't trust code that you did not totally create yourself." in my list of favorite infosec quotes. Thank you!
- deleted 2y ago[deleted]
- ImJamal 2y agoLinksys is owned by a foreign company (Foxconn).
- staplers 2y agoWhen you start digging into outbound dns traffic from consumer routers you can find a baffling amount of data sent. On the order of 50,000-100,000 dns requests a month to their company servers (sometimes hosted in china).
- whalesalad 2y ago[flagged]
- rasengan 2y agoTaking a step back and thinking about this, this vulnerability/bad decision was a result of systemic disorganization. It's not just the developer who wrote said code, as well as the backend developers who receive these outputs, but further, the organization did not have any kind of test/check and balance/security mechanism in place. It's terrible given the router, especially in a world of IoT, may be the device on your network that should be the most secure. Finally, now that it's public how bad the organization at Linksys is, it is trivial for a criminal to pay an employee to purposefully include backdoors. The consumer router scene needs a security focused disruption.
- bastien2 2y agoThere is vendor-side infrastructure to receive the information. This wasn't a lapse in planning/testing. This was intentional. Stop giving corporations the benefit of the doubt.
- caconym_ 2y agoConsumers deserve far better than what they're getting from network gear manufacturers—crap, and grossly overpriced crap. I wish Apple would get back into the game and at least offer some grossly overpriced non-crap.
- 1over137 2y agoYou don’t need Apple as your saviour, there are expensive non crap brands out there. I’ve liked Ruckus for example.
- caconym_ 2y agoI certainly don't need Apple. My primary home router is a virtual machine running on a Proxmox cluster, and my house is serviced by three sub-$30 Netgear wifi 5 access points running OpenWRT with 802.11r fast transition on a wired backhaul. I can't recommend any of that to my non-techy friends or family. I can't recommend Ruckus, either, as it's about an order of magnitude too expensive. Ditto for the other "prosumer" vendors.
- lovethevoid 2y agoEmbarrassing. Not responding for months is actively malicious and should be punished as such, towards the entire company too, not just one throwaway developer to shift blame on to.
- hyperman1 2y agoI'm impressed a consumer test organisation has the technical expertise to detect this. You don't find this by using it as a consumer would. They had to do the effort to hunt for security bugs to notice this.
- c420 2y agoThis isn't limited to their Velop line. While converting my EA7500 to openWRT, I noticed this exact same information being sent as it tried to force me to login via the mylinksys web portal and tried to establish a link with the home server.
- jasonjayr 2y agoVia the TR-69 mechanism, Verizon FiOS routers send your local wifi password to their central management system. The excuse I've heard for this is to "allow support agents to assist users who forgot their passwords" :-/
- ehutch79 2y agoTo be honest, this makes a lot of sense. The time saved in support is probably worth way more that costs of dealing with any security fallout
- PhilipRoman 2y agoFor that I think having a remote "reset password" option is more sensible. It would avoid issues coming from password reuse.
- throwawaynorway 2y ago…and help the customer reconnect all devices on the WiFi?
- SahAssar 2y agoYes. It would be the same as resetting your email password and needing to login again on your devices. If a password is so precious that you share it plaintext with third parties it is a bad usecase for a password.
- arsome 2y agoThe level of effort and obviousness of an email reset is nothing compared to helping someone figure out how to reconfigure every smart device ever made.
- SahAssar 2y agoSo it's a bad usecase for a password, then. Perhaps every router should ship with a preconfigured VLAN for shitty smart home stuff that is a lot more open, or maybe we should stop trying to stick internet into everything ever created.
- idunnoman1222 2y agoThis is pretty light on details, but my guess would be there’s some app that you can use to reconfigure all your Wi-Fi repeaters at once and if you use the app, it erroneously transmit the password which it needs in plain text It’s not clear to me that the router sends the password rather than the app on your phone
- fooqux 2y ago> which it needs in plain text Perhaps this is a typo on your part, in which case, please excuse my strong words here. But passwords should never be transmitted in clear text. Encryption is cheap these days.
- idunnoman1222 2y agoSorry I missed a,
- nottorp 2y agoErroneously? It's an US company. They do it because it's cheaper :) If they were Chinese they would do it because they're spying of course.
- fooqux 2y ago> Despite warning Linksys in November, no effective measures have been taken. November? November?! OK, sure, there are a lot of holidays around then. But I would have expected public disclosure on something like this by end of January at the latest, unless the vendor is actively working / communicating about it.
- jonplackett 2y agoJust reading these comments - is everyone OK with them sending your password to a server, but not with the lack of encryption? I would not expect my password to be sent to the server in the first place.
- e3a8 2y agoSomewhat relevant (from 2013, Google knows every WiFi password in the world): https://www.computerworld.com/article/1496628/android-google-knows-nearly-every-wi-fi-password-in-the-world.html https://www.computerworld.com/article/1496628/android-google...
- deleted 2y ago[deleted]
- miles 2y agoHN discussion at the time (503 points, 302 comments): https://news.ycombinator.com/item?id=6379439 https://news.ycombinator.com/item?id=6379439
- lolinder 2y agoThat discussion is fascinating just for how dramatically the tone on Google has shifted in the past 11 years. Top comment is a defense of Google, top reply to them is more concerned with US laws than with Google's voluntary behavior.
- godzillabrennus 2y agoI know. It is crazy to me as well. Google went from “Do No Evil” to “Do Profit From Evil” and everyone seems okay with the transition.
- ksec 2y agoAnd this was after Steve Jobs started the war on Google and mentioned privacy as a concern during his era. It took the world 15 years and nearly 10 years after his death to understand this. I remember asking people who supported Google before or after their IPO how they make money with your Data. No one cares. I remember pushing for Firefox instead of Chrome in 2009, no one cares. Not even on HN. The sad thing is that those who stood up for privacy got bashed down for so many years and never received an apology. Those who defended Big Tech like Google is safe to use our data never apologised.
- dan-allen 2y agoOf fucking course
- bastien2 2y agoWe've been here before. OE firmware needs to be assumed hostile and either replaced with open source aftermarket firmware, or the device sequestered in a subnet with no internet access.
- fifteen1506 2y agoNobody got time for that. Unified online DB for devices and brands regarding nuisances. Add ads, micropayments and Flattr-like mechanisms for sustainability.
- 0xedd 2y agoMaybe you'd also like a cloud service that ties your shoes? God forbid you should move a muscle.
- pkaye 2y ago> Testaankoop suspects the security issue might stem from third-party software used in the Linksys firmware. What third part software does Linksys use on that router?
- jedisct1 2y agoFirst thing to check before buying a router: if the firmware can be replaced with OpenWRT.
- hindsightbias 2y agoAnd who built the OpenWRT firmware? I bought a gl.inet that comes with OpenWRT but since it's made in China (like every other router) I looked at the OpenWRT blobs and for all I know they're built in China too.
- robertlagrant 2y agoReplaced with.
- gitaarik 2y agoYou can install it yourself, not buy something with it pre-installed
- hsnewman 2y agoSecurity key <> passwords
- blackeyeblitzar 2y agoI’ve really disliked the change in the router industry where the routers have become ‘smart devices’ instead of reliable local networking hardware. This has turned into the same abuse of customers we see from others. For example TP Link uses the same dark patterns in their routers as companies like Roku, where they make updates to the terms of service and force you to accept it in a pop up if you want to use the app. And the app is the ONLY way to access most of the router configuration features, as compared to the old method where routers would let you navigate to a password protected website to configure them. So if you don’t accept the new terms, you can’t control your router that you were able to control all this time. Additionally their app constantly pushes trials of their useless and unwanted services through nudges within the app like red circular badges next to menu items and user interface elements. It wouldn’t surprise me if their terms also let them abuse my privacy and security in the same way as Linksys. But who else do we go to? Every company is doing this. Maybe they just cannot survive without it. It’s probably why we need regulation here (consequences for security breaches, limitations on terms of service abuse, etc).
- rasengan 2y agoI also want to mention that Linksys is owned by Cisco whose hardware probably touches the majority of the internet directly.
- lotsofpulp 2y agoLinksys has not been Cisco since 2013. Right now, Foxconn owns it. Belkin owned it before that. Cisco sells Meraki, which they bought in Dec 2012.
- megous 2y agoVery happy with my own router with my own software (just regular Arch Linux ARM). :) The thing that guards access to and from my internal networks really deserves to not be so turdish. I'd hate to pay $350 for such a betrayal. Some things can apparently only be bought with your own time, when it comes to "but you had to spend cumulative 3 days setting up your custom thing, so it didn't really cost $100" equation that people will throw at you if you tell them that you have built something yourself from relatively cheap components.
- abadpoli 2y agoIs this actually plaintext, or is this plaintext-inside-HTTPS? The article and source material don’t say. It’s pretty normal for passwords to be “plaintext” inside an HTTPS request. That’s how practically every login to a web app works. If it’s not HTTPS, there’s a whole slew of other issues along with putting a plaintext password in the request. If it is HTTPS, then the issue really is just that the password gets sent anywhere rather than staying local. This is a lot more debatable as a practice, but unfortunately is also common for a lot of routers to support their cloud/app management functionalities.
- SahAssar 2y ago> is also common for a lot of routers to support their cloud/app management functionalities Why does the cloud need to know the wifi password to support mgmt functionalities? The only reasons I can think of right now are for more "automatic" setup of a second unit for meshing or if you want a factory reset to have the same password. Both of those cases have better solutions. If it's for setting a new password I don't see why they need the old one, if it's for remote management access using the wifi password as the access credential then that seems both bad (access to my network should not mean access to manage it) and like it can be done a lot better if actually needed (send just a well salted and hashed password).
- iudqnolq 2y agoThis appears to be a cloud password first stetup feature. As in you type your new password into the app, the app sends your password to a cloud API, and then the cloud API instructs the router to change to the new password over a management API. So the password is sent for a specific feature that legitimately wants it. You could have the app connect to a special WiFi network and then communicate directly with an API exposed by the router. That's what my router does. But the experience of using a special-purpose WiFi network is janky on many common devices so I understand not taking that choice.
- GrantMoyer 2y agoYou could send the password through the cloud server pre-hashed, or even better the cloud server could be used to establish an end-to-end encrypted connection from the app to the router.
- TheRealDunkirk 2y agoDoes anyone think that Netgear isn't doing the exact same thing with Orbi? (It's a given that Google is doing it with Eero.) Anyone taking odds on Ubiquiti?
- lotsofpulp 2y agoEero is Amazon.
- tombert 2y agoMy access point is still Ubiquiti, since I haven't found a solution to get WiFi access across my house that works directly with my homebuilt router that I'm sufficiently happy with. I'm sure Ubiquiti is doing the same stuff, behind the scenes. I'm open to suggestions if anyone has them on the best way to avoid this.
- xp84 2y agoIn case you know -- is there a way to get into Ubiquiti without having a drop where I need the secondary AP? Today I use an Eero at the cable modem and a second Eero just mounted on the ceiling upstairs with . I'd like to move to something that isn't locked down the way Eero is (and which has a web UI), but I like the whole 'mesh with a dedicated backhaul on a separate channel' thing. My house is constructed in a way that would make running ethernet upstairs not convenient.
- aspenmayer 2y agoYes, Ubiquiti has AP mesh hardware that uses a dedicated backhaul radio, so you can extend the mesh without needing wired backhaul for mesh points.
- banish-m4 2y agoIt's slow as shit though. I had 5x U6-Mesh after ditching the Google/Nest Wi-Fi garbage. Now, I have U6-Enterprise running on PoE on dedicated copper. There's no substitute for the bandwidth afforded by physical media. FS: U6-Mesh for cheap! ;)
- ftrobro 2y agoDon't most websites send passwords in plaintext for login and rely on the connection being HTTPS for having any security at all? I don't like that, but seems to be very common, so I'm not surprised about the plaintext part of this article. But that the passwords are at all sent to a server, that did surprise me, good to know.
- sofixa 2y agoPlaintext can mean a few things - encrypted in transit using an HTTPS connection means it's no longer plaintext.
- abadpoli 2y agoThe article and source material are light on details here. My guess is that it is using HTTPS, but the researchers saw the plaintext password in the request and assumed “password in plaintext always bad”. If the app isn’t using HTTPS, then the story would be much bigger than just the password being plaintext.
- jhdifdhsak 2y agoso just like unify circa 2017? it was over ssl, but still.
- hpen 2y agoOnly the hacker news crowd is arrogant enough to call them out for check if that password was hTTPS but not for actually giving a fuck about the lack of privacy. SMH hacker news
- HumblyTossed 2y agoI really wish wifi router OEMs would use OpenWRT. They could skin it (ala gli.net) if they wish, but at least use it. It's open. It works. You can still differentiate your product by making it have MOAR ANTENNAS! and continue to add up all the speed numbers to make it look REALLY FAST!!!!
- jofla_net 2y agoMy old Araknis AP was just a reskinned OpenWRT, trudat.
- mouse_ 2y agoI'm really glad OpenWRT does not share a similar fate to Android.
- HumblyTossed 2y agoThe point being that if one has the technical ability, they could just flash stock.
- tombert 2y agoOr if they're worried about GPL stuff from Linux, there's also OpnSense, which works fine and I think is well respected. I'm nerdy enough to have built my own router with OpnSense a few years ago, and it worked like a champ. The only reason I stopped was there was an issue with BSD and a specific Broadcom 10Gbe card that I couldn't work around, so I ended up hacking something together with ClearOS and eventually NixOS.
- VTimofeenko 2y agoAre any parts of your nixos router config available publicly? I also rolled my own and am always on the lookout for inspiration
- tombert 2y agoMy router largely just implemented this tutorial: https://github.com/ghostbuster91/blogposts/blob/a2374f0039f8cdf4faddeaaa0347661ffc2ec7cf/router2023-part2/main.md https://github.com/ghostbuster91/blogposts/blob/a2374f0039f8... ChatGPT was used whenever something I didn't understand came up.
- gwbas1c 2y agoYears ago, I caught some overseas contractors writing passwords to a log file. It wasn't malicious on their part, it was ignorance. (But, that kind of mistake is highly unprofessional and shows a lack of insight from someone who should know better.) I suspect that someone has some debugging flags that do this, and accidentally shipped with the flags set the wrong way.
- kps 2y agoHeck, Apple did that once (CVE-2012-0652).
- meling 2y agoI wish Apple would get back into the WiFi router business again. I trust their privacy/security posture more than most other brands. Sadly they sell Linksys routers as the go to replacement for their previous products.
- 0xedd 2y agoSorry, no one is interested in a device subscription business model. People like to own their hardware.
- stragies 2y agoAs long as * source is available for the boot-loaders, all onboard devices. * Firmware source available for all NPUs, 'offload engines', and other devices in Ethernet data path. * mainline linux kernel supports a fully blob-free bootup (except Wifi/RF) * a jumper enables trustzone access, with complete key management available to the enduser * populated serial UART port header on the inside. (optional) ... Then I don't care who builds it. But I can't image Apple would build such a user-friendly device, that I could just easily install OpenWrt on 5 minutes out the box. Plus they'd probably fleece you.
- bundie 2y agoThis is very bad.
- fifteen1506 2y agoDon't worry, as long as its not a Chinese company we are fine.
- GLORIA90 2y ago[dead]