The antidote to this could be a hardware switch, i.e. the option to completely disable wireless connectivity if the customer wishes so - in a way that is tamper-proof. But I haven't seen products that implement this so far.
A switch is not enough to prevent millions of devices from being part of a botnet if the consumers don’t see the advantage of switching it off (“why would I”). There needs to be significant motivation (fines for participating in DoS attacks) or a different default.
I just found out that I may be able to sell my 2yo car to a dealer despite still paying it up - something to do with the demand for secondhand cars being so high these days and I can get more than I owe... I digress!
Anyway, I don't really need a car but it's handy so I'm looking at a 20 year old Grand Cherokee (or possibly a Cherokee). The main reason is that it has almost no tech in it. Nothing that can serve me ads. Nothing that can track me. Nothing that can be used against me. Nothing that can be hacked. Nothing that can be remotely accessed by the manufacturer. It only contains things that make it go (and stop)!
My phone will be getting replaced with... probably the most basic thing I can get since I barely use it too.
Anyway, just wanted to chuck in my $0.02
DEATH TO SPAMMERS
if i was to pick two books to recommend to all HN, it would be those. ive read everything suarez has written and theyre all greaf, but the technopolitical daemon and freedom and superlative.
And the other two obviously aren't going to keel over unless you come up with like five of such botnets. They're pretty much the largest possible targets who are still gonna report that they felt something. Which sounds precisely like advertisement to me.
The only security connotation of this is that some guys got a botnet and they flex on Krebs to have him advertise the fact—pretty much like he's supposed to, per his job description.
It makes me a little sad each time I see people promoting his site.
source?
Heh, that's grand.
That seems to nean something though: the trend of hosting not just information but computation more local to its destination like CDNs did for information.
I don't know what IoT means other than shit that shouldn't be networked (let alone computational) is networked.
I guess I will be doing some research on MicroTik vulnerabilities and try to find out if these are just misconfigured devices that got owned or if I should hold off on the switch!
Edit: also this checker, when you get the device online: https://radar.qrator.net/
Unclear how old your firmware is, but it seems that the vulnerability was patched years ago. Check anyway.
That seems to be countered in the article mentioning that the majority of devices are running firmware that’s relatively recent (one release from the latest).
They don't all come with it configured this way by default, and it's definitely something to be aware of.
The hAP AC^2, for example, has a button that rotates through 3 default configs. One of those configs is NAT home router/firewall, one of them is just router, and one of them is completely empty. At least, that's how I remember it working.
My thought was the same but yup you never know. From the outside my attack surface is very low, just a couple port forwards to a VPN/SSH server. It’s the non-obvious exploits that worry me (overflow in packet header parsing or borderline magic like that), but perhaps I’ve been watching too many movies :)
I will make sure my config is as solid as I can reasonably make it before connecting it to the world, I guess outside of that there’s not a whole lot I can do anyway.
Most recent experience with Netgear Orbi Mesh system and Nest Wifi (or is it Google Wifi v2)
There are nearly no customization, hardening that can be made.
I can appreciate that a presentation is needed for average home user, but there should be a technical tweak away layer available.