For your convenience a copy of my blog entry from here:

http://andrewlindley.co.uk/2014/09/30/diary-on-needing-a-sledgehammer/

<p>My disability apportions me a healthy dose of
randomness. Accordingly this weekend I had a firtle in my ISP provided
broadband home router and the GPL source bundle for it duly downloaded
from the manufacturer.  There in and amongst the build configuration
files was the setup for two backdoor admin logins complete with
passwords in clear.  A bit of testing proved they were extant in the
router as shipped.</p>

<p>So in search of what one is supposed to do about such things I
consulted the relevant pages at <a href="http://cert.org";
title="Computer Emergency Response Team" target="_blank">CERT</a>.
'The vendor' they say.  Of course there's no magic high priority
contact for security matters when it comes to home routers.  Thus
after a journey involving an esupport website bug, the manufacturer's
10p/min support line referring me to my ISP, the first call I made to
my ISP being disconnected by someone who didn't seem to understand
what a security bug is, and another person who evidenced lack of
comprehension I finally ended up speaking to a manager in my ISPs
helpdesk router section.</p>

<p>He expressed patent disinterest and came up with a spurious logic
rationalisation for there being no need to fix it. I reached for the
sledgehammer of promising publicity if the matter was not pursued.
The result was a change of tack and some reassurances in a tone which
wasn't exactly convincing.  Nor has anyone with a more appropriate
technical or security brief at the ISP subsequently contacted me to
confim they've received the report and are actioning it. I have,
therefore, little confidence that the matter is being dealt with
correctly.</p>

<p>Better name and shame then, the router is the D-Link DSL-3780 as
shipped by Talk Talk who were the ISP I spoke to.  Technical details
of the vulnerability are available in response to signed GPG email.
My fingerprint is AB3F DF36 512E 1EE1 9055 A8C9 62C6 5508 B625
C793. Use the email address at this domain in the key.</p>

Reply via email to