Slashdot Mirror


Anonabox Recalls Hundreds of Insecure 'Privacy' Routers

Sparrowvsrevolution writes: It turns out all those critics of the controversial Tor router project Anonabox might have been on to something. Late last month, Anonabox began contacting the first round of customers who bought its tiny, $100 privacy gadget to warn them of serious security flaws in the device, and to offer to ship them a more secure replacement free of charge. While the miniature routers do direct all of a user's Internet traffic over Tor as promised, the company says that its first batch lacked basic password protection, with no way to keep out unwanted users in Wi-Fi range. And worse yet, the faulty Anonaboxes use the hardcoded root password 'admin,' which allows any of those Wi-Fi intruders to completely hijack the device, snooping on or recording all of a user's traffic.

Anonabox's parent company, Sochutel, says that only 350 of the devices lacked that password protection, and that it's fixed the gaping security oversights in newer version of the router.

The initial security criticisms of Anonabox helped to convince Kickstarter to freeze the proejct's $600,000 crowdfunding campaign in October. But Anonabox relaunched on Indiegogo and was later acquired by the tech firm Sochutel. Sochutel claims that the security flaws in the routers developed prior to its acquisition of Anonabox were out of its control, and that it's now hiring outside auditors to check its products' security.

8 of 50 comments (clear)

  1. Translation ... by gstoddart · · Score: 5, Interesting

    Security is hard, and it was more profitable to push crap out the door than actually do what we promised.

    Honestly, TFS makes it sound like someone slapped together something and either naively believed they'd made something secure .. or straight up lied about having made something secure.

    No wifi password and default admin passwords? That's pretty pathetic for something which purports to be a security/privacy tool.

    Sounds like someone wrote the marketing literature before creating the product.

    --
    Lost at C:>. Found at C.
  2. Why? by Lumpy · · Score: 2

    Why not just do a firmware update via the admin web interface?

    Why in the world would you ship them back to have this done?

    --
    Do not look at laser with remaining good eye.
  3. Re:"Out of their control" ....BS by Ignacio · · Score: 3, Insightful

    The real problem is that Sochutel failed to identify their acquisition as snake oil in the first place. It wasn't "security-focused", it was profit-focused from beginning to end.

  4. Analysis by lars_boegild_thomsen · · Score: 5, Informative

    Well, since it wasn't linked in the summary above, I'll do a shameless self-plug here:

    Anonabox Analysis

    And yes - I am the author of that analysis, so if anybody got questions I'll be happy to respond here.

    1. Re:Analysis by lars_boegild_thomsen · · Score: 2

      Yeah, I did consider that one myself :) And, well - I can add the following (and then let everybody make up their own mind).

      1. We did pledge on the Indiegogo campaign

      2. The Anonabox was received on Apr. 1 in UK (the date was funny)

      3. I received it about 2 days ago from UK (I live in Malaysia)

      4. Anonabox mentioned nothing about recalls before I posted the analysis

      5. There _was_ bitching in Indiegogo comments about the lack of WiFi passwords/encryption and there was a mention that if anybody wanted a password he could send the unit back and Anonabox would add one.

      6. To this date the one who ordered the Anonabox have not received any direct mail with a recall (albeit there could be a reason for that in this particular case)

  5. Re:orly? by lars_boegild_thomsen · · Score: 2

    Technically you can't log in to it - every access to the Web gui and/or ssh has been "blocked" (only they forgot IPv6).

    Firmware ripped out is here: Github

  6. Gaping by koan · · Score: 2

    Security holes...

    If they fucked up that bad, over things this simple, I would NEVER use their gear.

    --
    "If any question why we died, Tell them because our fathers lied."
  7. Re:"Out of their control" ....BS by Ignacio · · Score: 2

    So what? There's nothing wrong with making money. There is something wrong with screwing up as badly as Sochutel did.