Monday, July 24, 2006
D-Link security vulnerability -- are you affected?
First, there's the scary headline, that wireless routers from D-Link have a security hole that could allow someone to take them over and do bad things to your network.
It also seems bad that security firm eEye first told D-Link about the problem in February and it's only now been fixed. That's way too slow a response time. (See the link for a list of affected products).
Get past the headlines, though, and it turns out that the problem doesn't apply to strangers coming in over the Internet. It's only a problem if you have someone malicious on your local network. That's easy to have happen on a wireless network, since anyone within range can connect, but it changes the odds.
Are you safe if you've locked down your network so random people can't connect? Nobody's giving enough detail to tell. If you're a coffee shop, you certainly need to worry.
D-Link has updates on their website which you can download and use to reprogram your D-Link device to patch the problem. Good luck finding out where on the website those updates live. I would have given you a link if I'd been able to find them.
|
It also seems bad that security firm eEye first told D-Link about the problem in February and it's only now been fixed. That's way too slow a response time. (See the link for a list of affected products).
Get past the headlines, though, and it turns out that the problem doesn't apply to strangers coming in over the Internet. It's only a problem if you have someone malicious on your local network. That's easy to have happen on a wireless network, since anyone within range can connect, but it changes the odds.
Are you safe if you've locked down your network so random people can't connect? Nobody's giving enough detail to tell. If you're a coffee shop, you certainly need to worry.
D-Link has updates on their website which you can download and use to reprogram your D-Link device to patch the problem. Good luck finding out where on the website those updates live. I would have given you a link if I'd been able to find them.