For your convenience a copy of my blog entry from here: http://andrewlindley.co.uk/2014/09/30/diary-on-needing-a-sledgehammer/
<p>My disability apportions me a healthy dose of randomness. Accordingly this weekend I had a firtle in my ISP provided broadband home router and the GPL source bundle for it duly downloaded from the manufacturer. There in and amongst the build configuration files was the setup for two backdoor admin logins complete with passwords in clear. A bit of testing proved they were extant in the router as shipped.</p> <p>So in search of what one is supposed to do about such things I consulted the relevant pages at <a href="http://cert.org" title="Computer Emergency Response Team" target="_blank">CERT</a>. 'The vendor' they say. Of course there's no magic high priority contact for security matters when it comes to home routers. Thus after a journey involving an esupport website bug, the manufacturer's 10p/min support line referring me to my ISP, the first call I made to my ISP being disconnected by someone who didn't seem to understand what a security bug is, and another person who evidenced lack of comprehension I finally ended up speaking to a manager in my ISPs helpdesk router section.</p> <p>He expressed patent disinterest and came up with a spurious logic rationalisation for there being no need to fix it. I reached for the sledgehammer of promising publicity if the matter was not pursued. The result was a change of tack and some reassurances in a tone which wasn't exactly convincing. Nor has anyone with a more appropriate technical or security brief at the ISP subsequently contacted me to confim they've received the report and are actioning it. I have, therefore, little confidence that the matter is being dealt with correctly.</p> <p>Better name and shame then, the router is the D-Link DSL-3780 as shipped by Talk Talk who were the ISP I spoke to. Technical details of the vulnerability are available in response to signed GPG email. My fingerprint is AB3F DF36 512E 1EE1 9055 A8C9 62C6 5508 B625 C793. Use the email address at this domain in the key.</p>
