For all the network engineers, designer, sysadmins that day to day are connecting devices among network branches, this could be a really interesting story to share to any decision maker in any company.
It is a technical article, a small extract.
From this, he looked at its software and operating system, and that’s where he discovered the dark truth: his smart vacuum was a security nightmare and a black hole for his personal data. First of all, it’s Android Debug Bridge, which gives him full root access to the vacuum, wasn’t protected by any kind of password or encryption. The manufacturer added a makeshift security protocol by omitting a crucial file, which caused it to disconnect soon after booting, but Harishankar easily bypassed it. He then discovered that it used Google Cartographer to build a live 3D map of his home.
Should be carefully readed, IMO.
I’m adding a my personal take
If an app is mandatory for configuration, device should not be in any green or blue network
Mostly depends on network structure you’re going to implement.
For any CPE that the provider delivers I always “neuter” it disabling wifi, uPNP, and forwarding only the ports needed for internet access.
Otherwise, some ISPs allows to replace the CPE with your owned device, which sometimes delivers more grunt or functions. It gets more complicated if the contract delivers phone calls (FXS ports to configure) and IPTV/OTT services with multicast.
Anyway, I like to add a ethernet discharge device between router and firewall if the ISP delivers a VDSL connection (copper) rather than actual fiber to the premise. Lightnings are still a thing, they cook hardware like no user can do (most times)
If the only accepted option is keep the CPE delivered… good luck with that?
Italian most prominent ISP TIM delivered crap for 10+ years, now devices are far better, but mostly are ZTE boxes.
I guess I will get a OpenWRT device, hook it up on one of the provider router ethernet ports, and disable the rest of the ethernet ports, wifi and other network related functionalities, and work consider my OpenWRT device as the primary device to start fiddling with network (ethernet and WiFi) segmentation, firewall and all other goodies. Basically virtually bricking the ISP router on the LAN side except for 1 ethernet port → OpenWRT and 1 FXS port → Phone only.
New interesting story about “strangers in your home”.
Thanks to an italian media company (which did not delivered source, so I’d give them the same treatment) I’m now aware than some android-powered projects like Magcubic HY300 Pro+ have some “nasty addons” embedded into the firmware
From the github page, the TL:DR from the author
The Problem: Numerous cheap Android projectors (potentially brands like Magcubic, Hotack, etc., utilizing the Allwinner H713 chip), currently sold in massive quantities on Amazon, eBay, and AliExpress, are infected with malware straight from the factory (Supply Chain Attack, similar to the “BADBOX” cases).
The Mechanism: A seemingly harmless system app (“StoreOS”) acts as a disguised dropper. It completely silently downloads a Stage-2-Dropper named “SilentSDK” in the background and installs it with maximum system privileges, which in turn installs a modular, plugin-based, architechture aware RAT & possibly phishing framework.
The Danger: The malware establishes a C2 connection to China (api.pixelpioneerss.com), extracts sensitive device IDs, and can download and execute arbitrary additional malicious code with root privileges at any time (chmod 777). Additionally, the devices feature open root backdoors.
Immediate Mitigation: The C2 domains (especially *.aodintech.com, api.pixelpioneerss.com, sta.smartinnovate.net) must be blocked at the network level. Affected users can only disable the malicious apps manually via ADB, as they are deeply embedded in the system.
The underliyng then rebranded device seems to be a Nonete HY260Pro, which could make consider all the branding entities more like subject rather than object of the scam/intrusion, however… this helps some rule of thumbs for network admins:
have in place multiple networks and don’t test devices into the most important/critical one
have in place a way to monitor and block unwanted connections
cheap devices are nice, but sometimes they can lead to a lot of issues, which might be pricer than the price advantage
I wish NethSecurity would be available for ARM devices for home usage. I know @mark_nl has working images, but that’s not for me to fiddle on that level.