| ▲ | cyberpunk 10 hours ago | |||||||||||||||||||||||||||||||||||||||||||
That's really impressive finger pointing. If the vendor can't even secure their update server; how long do you think it would be until some RCE on these 100k un-patchable routers gets exploited? The only people to blame for this is the vendor, and they failed on multiple levels here. It's not hard to sign a firmware, or even just fetch checksums from a different site than you serve the files from... | ||||||||||||||||||||||||||||||||||||||||||||
| ▲ | kachapopopow 9 hours ago | parent [-] | |||||||||||||||||||||||||||||||||||||||||||
the problem is that these laws just make the problem bigger - instead of having to compromise 100 thousand routers they can just compromise a single update server from a vendor that doesn't care about security. the fallout is some companies losing their revenue: https://status.neoprotect.net/ and other headaches for people all over the world | ||||||||||||||||||||||||||||||||||||||||||||
| ||||||||||||||||||||||||||||||||||||||||||||