1. Attachments are working again! Check out this thread for more details and to report any other bugs.

PSA: Update your Wi-Fi Routers & Client OS

Discussion in 'Fred's House of Pancakes' started by Prodigyplace, Oct 16, 2017.

  1. Prodigyplace

    Prodigyplace Senior Member

    Joined:
    Nov 1, 2016
    11,696
    11,317
    0
    Location:
    Central Virginia
    Vehicle:
    2017 Prius
    Model:
    Two
  2. Prodigyplace

    Prodigyplace Senior Member

    Joined:
    Nov 1, 2016
    11,696
    11,317
    0
    Location:
    Central Virginia
    Vehicle:
    2017 Prius
    Model:
    Two
    @pilotgrrl please note. I hope your clients are patched.
     
    RCO and pilotgrrl like this.
  3. bhtooefr

    bhtooefr Senior Member

    Joined:
    Apr 4, 2016
    1,396
    1,489
    0
    Location:
    Newark, OH, USA
    Vehicle:
    2016 Prius
    Model:
    Three
    Looks like clients are the higher priority to patch, although routers can have some functionality (largely bridging modes) that will require patching. (My Mikrotik router already received a patch earlier this month, but then that's business-grade hardware.)

    The nasty thing is that a lot of routers and IoT devices are horrendously badly supported and won't get updates.
     
    RCO and pilotgrrl like this.
  4. Mark57

    Mark57 2021 Tesla Model 3 LR AWD

    Joined:
    Aug 14, 2009
    2,945
    2,735
    0
    Location:
    OK
    Vehicle:
    Other Electric Vehicle
    Model:
    N/A
    Sadly, most home users don't remember how to log into their routers, much less upgrade the firmware and why.
     
    RCO and pilotgrrl like this.
  5. Prodigyplace

    Prodigyplace Senior Member

    Joined:
    Nov 1, 2016
    11,696
    11,317
    0
    Location:
    Central Virginia
    Vehicle:
    2017 Prius
    Model:
    Two
    They should definitely upgrade their clients though since this exploit targets the client.
     
    RCO and pilotgrrl like this.
  6. Prodigyplace

    Prodigyplace Senior Member

    Joined:
    Nov 1, 2016
    11,696
    11,317
    0
    Location:
    Central Virginia
    Vehicle:
    2017 Prius
    Model:
    Two
    pilotgrrl likes this.
  7. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,796
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
  8. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,796
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    There are lots of cheap Android devices that probably won't get patched, including mobile broadband devices that are "the only ones certified to work with" certain firewalls and enterprise routers.

    Glad I'm not at work today.

    Posted via the PriusChat mobile app.
     
    Prodigyplace likes this.
  9. Prodigyplace

    Prodigyplace Senior Member

    Joined:
    Nov 1, 2016
    11,696
    11,317
    0
    Location:
    Central Virginia
    Vehicle:
    2017 Prius
    Model:
    Two
    Actually, I see it confirmed that both client and router/Access Point need to be patched to address this vulnerability. :(
     
    pilotgrrl likes this.
  10. bisco

    bisco cookie crumbler

    Joined:
    May 11, 2005
    107,693
    48,945
    0
    Location:
    boston
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    does this apply to comcast supplied wifi routers?
     
  11. Mark57

    Mark57 2021 Tesla Model 3 LR AWD

    Joined:
    Aug 14, 2009
    2,945
    2,735
    0
    Location:
    OK
    Vehicle:
    Other Electric Vehicle
    Model:
    N/A
    It really does not matter who supplies or makes the router. It's about the security protocol WPA2-Personal & WPA2-Enterprise that the router uses as security between itself and the connecting client. If you have or use WPA2-Personal or WPA2-Enterprise then it applies. I don't know of any modern router that this would not apply to.
     
    RCO likes this.
  12. bisco

    bisco cookie crumbler

    Joined:
    May 11, 2005
    107,693
    48,945
    0
    Location:
    boston
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    thanks, how would i find this out, and how concerned should i be, if i do have it?
     
  13. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,796
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    RCO likes this.
  14. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,796
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    Many devices come with default as "WPA2-PSK/WPA-PSK" (or similar) as the authentication type and encryption method.

    Patch whatever you use to connect to the WiFi router and the router itself.

    Posted via the PriusChat mobile app.
     
    Mark57 and bisco like this.
  15. bisco

    bisco cookie crumbler

    Joined:
    May 11, 2005
    107,693
    48,945
    0
    Location:
    boston
    Vehicle:
    2012 Prius Plug-in
    Model:
    Plug-in Base
    thanks, but i would have no idea how do go about that. i suspect 75% of home users are in the same boat.
     
    RCO and Mendel Leisk like this.
  16. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,662
    38,207
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    #16 Mendel Leisk, Oct 16, 2017
    Last edited: Oct 16, 2017
    RCO likes this.
  17. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,662
    38,207
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring
    My son's saying for home user, barring hacker neighbours and drive-by, you should be ok. Also: "If you're doing anything through an https site, like banking etc you're safe". His words, not mine, lol. And that It's coffee shop wifi and the like you'd want to be careful about, till they sort something out.
     
    jerrymildred, RCO and Tideland Prius like this.
  18. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,796
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    Mendel Leisk likes this.
  19. pilotgrrl

    pilotgrrl Senior Member

    Joined:
    Jul 23, 2017
    891
    1,796
    0
    Location:
    Chicagoan in TX
    Vehicle:
    2016 Prius
    Model:
    Three
    RCO likes this.
  20. Mendel Leisk

    Mendel Leisk Senior Member

    Joined:
    Oct 17, 2010
    54,662
    38,207
    80
    Location:
    Greater Vancouver, British Columbia, Canada
    Vehicle:
    2010 Prius
    Model:
    Touring