# Welcome To The Internet of Compromised Things

**URL:** <https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550>\
**Category:** blog\
**Created:** [August 8, 2015, 10:59am UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550 "2015-08-08T10:59:35Z")\
**Posts on this page:** 12\
**Page:** 3

<div class="post-metadata">

**Author:** ![Andrew\_Hoffman](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/andrew_hoffman/32/73100_2.png) [@Andrew\_Hoffman](https://discourse.codinghorror.com/u/Andrew_Hoffman)\
**Post date:** [August 31, 2015, 5:34pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/42 "2015-08-31T17:34:32Z")

</div>

Anyone checked to see if [discourse.codinghorror.com](http://discourse.codinghorror.com) actually encrypts the login page yet?

Cause as of the previous security related blog article, it was still butt-ass naked.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/codinghorror/32/36371_2.png) [@codinghorror](https://discourse.codinghorror.com/u/codinghorror)\
**Post date:** [September 1, 2015, 12:34am UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/43 "2015-09-01T00:34:49Z")

</div>

That’s why I use Google to log in, which goes through https 😉

---

<div class="post-metadata">

**Author:** ![Vignesh\_Iyer](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/v/90ced4/32.png) [@Vignesh\_Iyer](https://discourse.codinghorror.com/u/Vignesh_Iyer)\
**Post date:** [September 12, 2015, 3:33pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/44 "2015-09-12T15:33:47Z")

</div>

Great blog. Inside Your Home and Outside Your Home sections is just want any average internet user would like to know about. Great!

---

<div class="post-metadata">

**Author:** ![Mark\_Brackett](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/m/839c29/32.png) [@Mark\_Brackett](https://discourse.codinghorror.com/u/Mark_Brackett)\
**Post date:** [September 19, 2015, 6:48am UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/45 "2015-09-19T06:48:19Z")

</div>

I’m pretty bummed that I read through that entire cryptostorm article, thinking there was something there because Jeff linked to it. As I was reading, I kept thinking this sounded more and more like a conspiracy theory with almost no actual technical content (just “look - something I don’t understand! Must be malicious!”) but struggled through the entire thing before concluding it’s mostly BS.

A quick Google later confirmed my suspicions that it’s already being well-debunked…or maybe my router is just compromised and that’s what _ **they** want me to think_.

---

<div class="post-metadata">

**Author:** ![Bernardvt](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/b/d07c76/32.png) [@Bernardvt](https://discourse.codinghorror.com/u/Bernardvt)\
**Post date:** [October 13, 2015, 6:40pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/46 "2015-10-13T18:40:16Z")

</div>

This is very true.  
Most do not know what risks they are taking by connecting to an unknown network!  
This compromise in security could easily lead to personal and bank details that can be stolen.  
I never knew one could be attacked by only an infected router alone.

Thank you for all your tips!  
Some of these steps are too difficult for standard users which would mean that they are still vulnerable.

> Never access anything but HTTPS websites.

This should be spread so that everyone can be safe.

---

<div class="post-metadata">

**Author:** ![dequis](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/dequis/32/73709_2.png) [@dequis](https://discourse.codinghorror.com/u/dequis)\
**Post date:** [October 20, 2015, 4:42am UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/47 "2015-10-20T04:42:43Z")

</div>

> [@Mark\_Brackett](#):
>
> I’m pretty bummed that I read through that entire cryptostorm article, thinking there was something there because Jeff linked to it. As I was reading, I kept thinking this sounded more and more like a conspiracy theory with almost no actual technical content (just “look - something I don’t understand! Must be malicious!”) but struggled through the entire thing before concluding it’s mostly BS

Same here. I want my time back 😩

I was already suspecting when it mentioned the OCSP url 404 thing as if it was something significant, and I gave up 3/4ths through, when i saw this:

> [@cryptostorm](#):
>
> And besides… packages are signed! …right? Indeed. While it’s beyond the scope of this report to go into the numerous proven methods for undermining such signing security, here’s a partial list of links

It claims “numerous proven methods” and links a bunch of askubuntu questions with GPG errors from APT, no proofs

That’s when I looked into what kind of organization this thing is, and on the surface it looks like a VPN service with a neat sense of aesthetics, but they also have wacky stuff like a collection of “suspicious looking certificates”, with criteria such as “Subtle typos in the names of companies. Start times that are 1:00:00 exactly. That sort of thing”.

> [@cryptostorm in the fishycerts repo](#):
>
> Sometimes people get mad when they see our fishycert project and research. “It’s not ‘real’ security research,” they might say. Or: “you don’t even know what you’re trying to prove, so how can you be looking for it?” They must have missed science classes in school, with all due respect. This is how real research works

Uhhhhhh… well if they say so.

@codinghorror can you add an edit around that cryptostorm link, warning readers that it’s bullshit? At best, it’s an inconclusive info dump, there’s nothing indicating that messing with DNS or BGP will break HTTPS.

**edit** : [Here, have adam langley telling you that it’s nonsense](https://news.ycombinator.com/item?id=10027424). I didn’t get here through HN but I wish I had seen this comment before.

---

<div class="post-metadata">

**Author:** ![AtKt](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/atkt/32/73713_2.png) [@AtKt](https://discourse.codinghorror.com/u/AtKt)\
**Post date:** [October 24, 2015, 3:32am UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/48 "2015-10-24T03:32:46Z")

</div>

DefCon this year was full of different vulnerabilities on the IoT, including in cars. It was like a playground out there for hackers. Lots of fun, unless you get hacked, I guess.

---

<div class="post-metadata">

**Author:** ![D\_Michelle\_Coffey](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/d_michelle_coffey/32/73781_2.png) [@D\_Michelle\_Coffey](https://discourse.codinghorror.com/u/D_Michelle_Coffey)\
**Post date:** [October 30, 2015, 6:59pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/49 "2015-10-30T18:59:25Z")

</div>

The Netgear Nighthawk is an awesome router and it offers vpn for you to use when away. I generally use my phone’s wifi hotspot when out and about though, because in addition to security, the bandwidth is much better.

---

<div class="post-metadata">

**Author:** ![evanplaice](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/evanplaice/32/73443_2.png) [@evanplaice](https://discourse.codinghorror.com/u/evanplaice)\
**Post date:** [November 1, 2015, 6:22pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/50 "2015-11-01T18:22:26Z")

</div>

Looks like a typical overpriced consumer-level router. Who knows, Asus may have a good offering. It’s just the look of the thing that reminds me of years of Linksys WRT54G hardware upgrades (read downgrades).

Why not try a Ubiquiti? I use a Motorola Modem for DOCSIS, connected to a Ubiquiti Picostation. The little thing is a workhorse and it has all the advanced features I could ever want. I actually purchased it with the intent of loading custom firmware (ie it was replacing my crippled DD-WRT router) but liked the stock capabilities enough that I didn’t bother.

It can be configured to work as SOHO, wireless bridge, and mesh network node. With all the usual advanced networking capabilities. They’re cheap but surprisingly powerful for the cost.

---

<div class="post-metadata">

**Author:** ![AthanSpod](https://discourse-cdn.codinghorror.com/letter_avatar_proxy/v2/letter/a/c4cdca/32.png) [@AthanSpod](https://discourse.codinghorror.com/u/AthanSpod)\
**Post date:** [December 30, 2016, 12:37pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/51 "2016-12-30T12:37:53Z")

</div>

My solution to this is to use a VDSL modem that just passes through the PPP level packets for my Linux server/router/firewall to do the PPPoE part of things. This way I have full control and it’s all my responsibility for keeping it up to date and configuring correctly. No trusting some ‘open’ firmware vendor to not put hardcoded credentials (I’m looking at you OpenELEC, or have they fixed that in later versions?) and to otherwise be on the ball.

So for anyone comfortable with using a custom firmware on a ‘router’ I’d advise going this route instead. WiFi is a separate unit and goes inside the Linux router, preferably on its own sub-net with firewall rules controlling what it can access internally.

And, yeah, I need to get around to setting up a home VPN (for my phone to use when on random WiFi), given I finally have decent (for a home connection) upstream bandwidth.

---

<div class="post-metadata">

**Author:** ![codinghorror](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/codinghorror/32/36371_2.png) [@codinghorror](https://discourse.codinghorror.com/u/codinghorror)\
**Post date:** [July 31, 2018, 8:08am UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/52 "2018-07-31T08:08:54Z")

</div>

Good set of recommendations in [this blog post](https://insights.sei.cmu.edu/sei_blog/2018/07/security-begins-at-the-home-router.html):

> In my earlier [Mirai blog post](https://insights.sei.cmu.edu/sei_blog/2017/03/powered-by-mirai.html), I offered some guidelines that are both practical and achievable in the home router and IoT device market. My hope with the following guidelines is to inspire innovative technical solutions among device vendors and service providers to redesign or update home routers to limit the risk that these devices will end up being used for nefarious purposes:
> 
> 1. Design home routers and IoT devices to operate with read-only filesystems, making run-time installations of malware impractical.
> 2. Disable any packet crafting/spoofing/promiscuous mode on the firmware level to avoid malicious use of network resource on these devices.
> 3. Provide automated updates for firmware with either planned downtime or no downtime to resolve vulnerabilities proactively.
> 
> The purpose of these lightweight, low-cost devices is to transit network data or stream live data (like IP cameras) with little reason for any persistence. In fact, some of the newer home routers do operate within a [chroot](https://en.wikipedia.org/wiki/Chroot) and a read-only file system, making it hard to both exploit these devices and install third-party software for persistence. Even if a would-be attacker learns or guesses an administrative password, malicious code installation performed by VPNFilter and Mirai would not be successful on these devices.

---

<div class="post-metadata">

**Author:** ![RiversideRocks](https://discourse-cdn.codinghorror.com/user_avatar/discourse.codinghorror.com/riversiderocks/32/76823_2.png) [@RiversideRocks](https://discourse.codinghorror.com/u/RiversideRocks)\
**Post date:** [December 17, 2020, 2:10pm UTC](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550/54 "2020-12-17T14:10:52Z")

</div>

With the release of the [Mirai source code](https://www.securityweek.com/hacker-releases-source-code-iot-malware-mirai) and the [rise of the Mozi botnet](https://securityintelligence.com/posts/botnet-attack-mozi-mozied-into-town/), this issue isn’t going away.

[Previous page](https://discourse.codinghorror.com/t/welcome-to-the-internet-of-compromised-things/3550.md?page=2)
