news.volyx.in

A detailed look at the router provided by my ISP (0x90.psaux.io)

611 points by paddlesteamer · 2388 days ago · 181 comments on HN

Article summary

The author inspects their ISP-provided router, an Huawei HG253s, and discovers an open SSH port. They manage to connect to the router using the SSH port, but find that the interface is highly restricted. The author plans to sniff the communication between the router and the ISP's Auto Configuration Server to potentially upgrade the firmware. The article is the first part of a series, with the goal of taking control of the router from the ISP.

Main themes

  • ISP-provided hardware
  • Router security
  • NAT and routing
  • Network control and freedom
  • Vulnerability reporting
  • Manufacturer and ISP support
  • IPv4 and IPv6
  • Colloquial vs technical definitions of terms like 'router'

What commenters say

  • Some commenters have found vulnerabilities in their ISP-provided hardware, but struggle to report them due to unresponsive manufacturers.
  • Publishing vulnerabilities is seen as the right thing to do, even if it means potential legal repercussions.
  • The definition of a router is debated, with some arguing that a device doing NAT is not a true router.
  • Others argue that the term router has become colloquial and encompasses devices that perform multiple functions, including NAT.
  • Some commenters have successfully replaced their ISP-provided routers with their own hardware, while others are limited by their ISP's policies.
  • The use of NAT is seen as a necessary evil for IPv4, but some argue that it is not a good solution and that IPv6 should be adopted instead.
  • The importance of being able to choose one's own hardware and control one's own network is emphasized.
  • The difficulty of getting support from manufacturers and ISPs is a common theme among commenters.