this post was submitted on 09 Jul 2024
641 points (99.7% liked)

Technology

59219 readers
3145 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

you are viewing a single comment's thread
view the rest of the comments
[–] 0x0@programming.dev 4 points 4 months ago (2 children)

You do know that enterprise doesn't make you safer, right? Consumer gets hit by botnets, enterprise gets hit by higher level attacks.

[–] cyberpunk007@lemmy.ca 4 points 4 months ago (1 children)

I don't get your point. This isn't an attack, this is a cheap consumer company doing what they do best and stealing your personal information because $ and other crap. If this happened in enterprise they'd be in so much shit with laws. Cisco, juniper, Aruba, etc are not going to be shipping off your passwords because that liability is going to be a big problem.

Enterprise level stuff also charge top dollar and don't need to sell your data to make more money.

If enterprise level stuff we're doing this intentionally they'd be out of business. This would not fly with SOC and other security designations.

Additionally just because a consumer uses enterprise gear, that does not make them a larger target. I'm not Microsoft. No state attacker is going to want my worthless data.

[–] 0x0@programming.dev 1 points 4 months ago (1 children)

Additionally just because a consumer uses enterprise gear, that does not make them a larger target.

It'll make them a target of attacks targeting that class of gear.

[–] cyberpunk007@lemmy.ca 3 points 4 months ago

Most threat actors are looking at who owns what IP space and checking the IPs of that, or what other public info they can find (website address etc). Not chasing after someone with a consumer internet IP. There is just not the same incentive.

[–] PenisWenisGenius@lemmynsfw.com 1 points 4 months ago* (last edited 4 months ago)

They specifically didn't say they're using enterprise. Diy open source solutions such as a ddwrt router for example doesn't exactly fit in the "consumer" nor the "enterprise" category.