|
|
Log in / Subscribe / Register

Tips to Secure Your Network in the Wake of KRACK (Linux.com)

Konstantin Ryabitsev argues on Linux.com that WiFi security is only a part of the problem. "Wi-Fi is merely the first link in a long chain of communication happening over channels that we should not trust. If I were to guess, the Wi-Fi router you’re using has probably not received a security update since the day it got put together. Worse, it probably came with default or easily guessable administrative credentials that were never changed. Unless you set up and configured that router yourself and you can remember the last time you updated its firmware, you should assume that it is now controlled by someone else and cannot be trusted."

to post comments

Tips to Secure Your Network in the Wake of KRACK (Linux.com)

Posted Oct 18, 2017 20:26 UTC (Wed) by Wol (subscriber, #4433) [Link]

One *obvious* security feature (which I have seen but seems to have been deleted from recent routers) is that I had an ISP router that, amazingly, was sensibly configured!

The admin interface, while poorly secured password-wise, was firewalled. It could only be accessed via one of the cat-5 ports. In other words, you couldn't use a wi-fi laptop, and you couldn't come in remotely.

Of course, now most people only have laptops or phones, and modern laptops (the smaller ones especially) seem to have done away with ethernet ports. Certainly our 10" netbook doesn't have one. Oops.

Cheers,
Wol

Tips to Secure Your Network in the Wake of KRACK (Linux.com)

Posted Oct 18, 2017 22:17 UTC (Wed) by tialaramex (subscriber, #21167) [Link] (3 responses)

My impression is that a lot of home users have WiFi integrated with their CPE. So from their perspective they buy "WiFi" the same way they buy their Internet access except that it's not subject to a quota (the Internet access might not have a formal quota but it usually has some sort of "abuse prevention" type limits)

In this case the other aspects of the CPE are of course managed by the service provider, why wouldn't they likewise ensure security updates, set a reasonable access policy and so on?

Obviously if you hand roll everything, bought all your own equipment, then the problem is yours, but that's not most users. I think a big UK ISP said that their IPv6 rollout (which basically was a firmware update to their custom CPE) hit about 95% of customers. And the 5% who didn't benefit has to include everybody who had been with that ISP for so long their equipment was obsolete and didn't have IPv6 upgrades, as well as everybody who had purchased their own alternative. So we're talking a small minority here.

Tips to Secure Your Network in the Wake of KRACK (Linux.com)

Posted Oct 19, 2017 0:04 UTC (Thu) by Cyberax (✭ supporter ✭, #52523) [Link] (2 responses)

All cable modems can be updated remotely, it’s a part of the DOCSIS standard.

Tips to Secure Your Network in the Wake of KRACK (Linux.com)

Posted Oct 19, 2017 16:26 UTC (Thu) by Wol (subscriber, #4433) [Link] (1 responses)

The thing is, why would an ISP or phone provider update your cable modem? To provide a security fix? Where's the incentive to do that?

But to provide a new service/feature - especially something like IPv6 which will massively *reduce* their tech support hassle - well the incentive is obvious!

Follow the money - security updates have no value.

Cheers,
Wol

Tips to Secure Your Network in the Wake of KRACK (Linux.com)

Posted Oct 20, 2017 12:28 UTC (Fri) by hkario (subscriber, #94864) [Link]

> Where's the incentive to do that?

so as not have your whole IP space marked as spam source, including business customers?

while there are ISPs that store their abuse@isp.net email on the /dev/null device, it's not universal

And while it may be my biased European perspective, I've seen DOCSIS modems being updated and restarted remotely multiple times.


Copyright © 2017, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds