logoalt Hacker News

kachapopopowyesterday at 7:41 PM3 repliesview on HN

fun fact, part of the reason this botnet exists is because europe required the ability to install security updates unattended that you cannot disable and they compromised one of the servers that had the capability to push these updates compromising hundreds of thousands of routers.


Replies

cyberpunkyesterday at 8:19 PM

That's really impressive finger pointing.

If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited?

The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from...

show 1 reply
alphagertoday at 12:11 AM

That's just not true. I'm in Europe and all of my routers allow me to disable unattended updates and most don't enable it by default.

show 1 reply
Razenganyesterday at 8:10 PM

Wait when was this?? Did it fly under the news??

show 1 reply