Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


RunningMan

8955 posts

Uber Geek


#214760 27-May-2017 07:29
Send private message

Article here

 

Essentially discussing remote admin and/or TR-069 access to your router by your ISP.


Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic
 1 | 2 | 3 | 4 | 5 | 6
Linux
11419 posts

Uber Geek

Trusted
Lifetime subscriber

  #1789005 27-May-2017 07:40
Send private message

Yes to provide remote support

Linux



l43a2
1779 posts

Uber Geek

ID Verified
Trusted

  #1789009 27-May-2017 08:00
Send private message

i thought the whole article was a great piece of comedy. Some of the examples of how staff could setup Wireless Networks and go to clients houses and steal their files was amazing.






Behodar
10504 posts

Uber Geek

Trusted
Lifetime subscriber

  #1789015 27-May-2017 08:44
Send private message

Wait, wait, wait, you mean that my property-of-Chorus centrally-managed ONT "modem" is centrally-managed? Whatever shall I do?!




kiwiharry
1030 posts

Uber Geek

ID Verified
Subscriber

  #1789017 27-May-2017 08:54
Send private message

Although the article doesn't state which modem it was, on my Vodafone HG659 modem there is a Remote Management tab and it looks like it allows me to disable it.

The so called "Opt-out" feature already built in?

Or maybe we should all go and claim for $300 reimbursement of hardware before it's too late.




If you can't laugh at yourself then you probably shouldn't laugh at others.


tdgeek
29746 posts

Uber Geek

Trusted
Lifetime subscriber

  #1789022 27-May-2017 09:03
Send private message

kiwiharry: Although the article doesn't state which modem it was, on my Vodafone HG659 modem there is a Remote Management tab and it looks like it allows me to disable it.

The so called "Opt-out" feature already built in?

Or maybe we should all go and claim for $300 reimbursement of hardware before it's too late.

 

Or be comfortable for the RSP to send their own support out at a cost. Cost? No way!!!  


Goosey
2829 posts

Uber Geek

Subscriber

  #1789026 27-May-2017 09:06
Send private message

This will make some less technically minded people think they should go and buy a dlink or netgear off the shelf because they dont want their ISP having access and in the process just simply open up themselfs to the world in the process because they have no idea about locking it down as such. 


sbiddle
30853 posts

Uber Geek

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #1789031 27-May-2017 09:12
Send private message

The story was very poorly written and IMHO will do nothing but spread FUD and increase support calls and costs to an RSP. If you're a security "expert" and have just discovered TR-069 I don't think you should be proclaiming yourself to be an expert.

 

Much of what's written about TR-069 on the Internet is also without basis - yes there have been documented security risks over the years from poorly deployed solutions but that's because of the way they've been deployed.

 

If you're a large ISP remote management of CPE is essential, particularly if you're offering voice services over it.

 

 

 

 

 

 


 
 
 

Free kids accounts - trade shares and funds (NZ, US) with Sharesies (affiliate link).
jamesrt
1609 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1789032 27-May-2017 09:13
Send private message

Maybe this should be on the other suitable thread


<removes tongue from cheek>

sbiddle
30853 posts

Uber Geek

Retired Mod
Trusted
Biddle Corp
Lifetime subscriber

  #1789034 27-May-2017 09:24
Send private message

There are other issues such as people giving their CPE away that's provisioned with voice details that are legitimate issues of auto provisioned hardware but not mentioned. We've seen numerous posts from people over the years as a result of this, both from Vodafone and Snap/2degrees users.

 

 

 

 


antoniosk
2358 posts

Uber Geek

ID Verified
Trusted
Lifetime subscriber

  #1789038 27-May-2017 09:32
Send private message

A few years ago BT's Homehub product was nobbled - https://www.theregister.co.uk/2007/10/22/home_hub_vuln_plugged/ - because of reasons, but it did give an example of how not paying attention to the details can lead to compromised security and opportunity for nuisance.

 

 

 

Without knowing the specifics of what risk there is - beyond the obvious 'we can remote in and do stuff' - I'm not sure what the right answer is.

 

 

 

I guess the alternative is to go back to the world where ISP's provided NO support for the equipment they were supplying, and left the customer to do it themselves.

 

 

 

As long as the isp's are confident no one else can log in via the remote access path, and have 100% confidence in the hardware - HG659 I'm looking at you - to not 'accidentally' let someone through....





________

 

Antoniosk


noroad
949 posts

Ultimate Geek

Trusted

  #1789040 27-May-2017 09:39
Send private message

sbiddle:

 

The story was very poorly written and IMHO will do nothing but spread FUD and increase support calls and costs to an RSP. If you're a security "expert" and have just discovered TR-069 I don't think you should be proclaiming yourself to be an expert.

 

 

 

 

 

Yep, this self proclaimed "expert" clearly knows zero about the telecommunications industry. TR69 is not new and certainly not a bad thing unless its been very poorly implemented.


mdf

mdf
3513 posts

Uber Geek

Trusted

  #1789043 27-May-2017 09:46
Send private message

FFS. Just once I'd like to see a tech article that didn't involve someone belly aching about something. How about "ISPs invest millions to ensure that the digital divide doesn't leave anyone behind"? We're living in the goddam future and all the press can do is go barking at every passing car from a "security expert" that is using a $50 ISP supplied router.

If you can't trust your ISP, you've got much bigger problems than hypothetical "rogue employees" creating additional wifi access points. Your *life* flows through their pipes before it even hits your modem.

DarthKermit
5346 posts

Uber Geek

Trusted

  #1789051 27-May-2017 10:02
Send private message

Why is anyone surprised? This is the kind of gutter journalism they stoop to all the time now. undecided


robcreid
243 posts

Master Geek


  #1789058 27-May-2017 10:23
Send private message

noroad:

 

sbiddle:

 

The story was very poorly written and IMHO will do nothing but spread FUD and increase support calls and costs to an RSP. If you're a security "expert" and have just discovered TR-069 I don't think you should be proclaiming yourself to be an expert.

 

 

Yep, this self proclaimed "expert" clearly knows zero about the telecommunications industry. TR69 is not new and certainly not a bad thing unless its been very poorly implemented.

 

But he "has experience working on IT security with intelligence agencies". He is clearly too busy to be reading a modem manual.

 

I suspect this all started as way to get a free modem.


michaelmurfy
meow
13243 posts

Uber Geek

Moderator
ID Verified
Trusted
Lifetime subscriber

  #1789060 27-May-2017 10:27
Send private message

What the actual fu..

 

Shame this "security expert" was not named for his discovery of TR069. Wonder if he used my router guide?





Michael Murphy | https://murfy.nz
Referral Links: Quic Broadband (use R122101E7CV7Q for free setup)

Are you happy with what you get from Geekzone? Please consider supporting us by subscribing.
Opinions are my own and not the views of my employer.


 1 | 2 | 3 | 4 | 5 | 6
Filter this topic showing only the reply marked as answer View this topic in a long page with up to 500 replies per page Create new topic





News and reviews »

Air New Zealand Starts AI adoption with OpenAI
Posted 24-Jul-2025 16:00


eero Pro 7 Review
Posted 23-Jul-2025 12:07


BeeStation Plus Review
Posted 21-Jul-2025 14:21


eero Unveils New Wi-Fi 7 Products in New Zealand
Posted 21-Jul-2025 00:01


WiZ Introduces HDMI Sync Box and other Light Devices
Posted 20-Jul-2025 17:32


RedShield Enhances DDoS and Bot Attack Protection
Posted 20-Jul-2025 17:26


Seagate Ships 30TB Drives
Posted 17-Jul-2025 11:24


Oclean AirPump A10 Water Flosser Review
Posted 13-Jul-2025 11:05


Samsung Galaxy Z Fold7: Raising the Bar for Smartphones
Posted 10-Jul-2025 02:01


Samsung Galaxy Z Flip7 Brings New Edge-To-Edge FlexWindow
Posted 10-Jul-2025 02:01


Epson Launches New AM-C550Z WorkForce Enterprise printer
Posted 9-Jul-2025 18:22


Samsung Releases Smart Monitor M9
Posted 9-Jul-2025 17:46


Nearly Half of Older Kiwis Still Write their Passwords on Paper
Posted 9-Jul-2025 08:42


D-Link 4G+ Cat6 Wi-Fi 6 DWR-933M Mobile Hotspot Review
Posted 1-Jul-2025 11:34


Oppo A5 Series Launches With New Levels of Durability
Posted 30-Jun-2025 10:15









Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.