news.volyx.in

Hacking millions of modems and investigating who hacked my modem (samcurry.net)

838 points by albinowax_ · 802 days ago · 271 comments on HN

Article summary

The article describes a personal experience of the author, whose home network traffic was being intercepted and replayed by an unknown IP address. The author investigated and found that the IP address was associated with phishing websites and a potential command and control server. The author's modem was likely compromised, and after replacing it, the issue stopped. The author later investigated the Cox Business portal and found potential vulnerabilities in the API, which could have been used to compromise the modem.

Main themes

  • Modem hacking
  • API vulnerabilities
  • Bug bounty programs
  • Cybersecurity
  • Extortion vs. responsible disclosure
  • Ethics in security research

What commenters say

  • Companies should offer bug bounty programs to incentivize responsible disclosure of vulnerabilities, rather than risking them being sold to malicious actors.
  • The absence of a bug bounty program does not obligate a company to pay for unsolicited security research, and demanding payment can be seen as extortion.
  • Paying bug bounties is a drop in the ocean for large companies and can be a worthwhile investment in security, but others argue that it's not the company's responsibility to pay for unsolicited work.
  • Some argue that selling vulnerabilities to the highest bidder is not extortion if the company does not provide incentives for responsible disclosure, while others see it as a morally questionable practice.
  • The definition of extortion should not depend on the size of the company or its ability to pay, but rather on the presence of a threat or coercion.
  • Ethics and character play a significant role in security research, and some researchers prioritize doing the right thing over personal financial gain, while others see it as a luxury that not everyone can afford.
  • The line between responsible disclosure and extortion can be blurry, and different people have different opinions on what constitutes ethical behavior in security research.