this post was submitted on 09 Jul 2024
642 points (99.7% liked)

Technology

59174 readers
3700 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS
 

During installation, the router sent several data packets to an Amazon server in the US. These packets contained the configured SSID name and password in clear text, as well as some identification tokens for this network within a broader database and an access token for a user session that could potentially enable a MITM attack.

Linksys has refused to acknowledge/respond to the issue.

you are viewing a single comment's thread
view the rest of the comments
[–] [email protected] 10 points 4 months ago* (last edited 4 months ago) (12 children)

What does this mean, that the use plain HTTP or some other protocol? I can't see details.

[–] [email protected] 76 points 4 months ago (9 children)

Two important points raised:

  • Why is Linksys sending your Wifi details, as well as your private password, outside of your home
  • If they're doing it, why are they sending your critically important private information unencrypted onto the public internet

The answer to the first one may be semi-legit as these are mesh products. As in, the other nodes in the mesh will need this information, and it appears that Linksys has decided to store your security data in AWS for the other mesh nodes to retrieve it when you're setting it up. I'd sure as hell like to know this before the product does this. Further, I'd much prefer to simply attached to each mesh node myself to input the secured credentials instead of sending them outside to the internet.

There's not excuse for Linksys sending the creds unencrypted onto the internet.

[–] [email protected] 2 points 4 months ago (1 children)

Even then, the other nodes would only need the hash of the password, not the password itself.

[–] [email protected] 2 points 4 months ago

That depends entirely on the auth system, but you can use a separate credential to retrieve the password (using something like a PAKE algorithm)

load more comments (7 replies)
load more comments (9 replies)