Flutterby™! : Watching TR-069

Next unread comment / Catchup all unread comments User Account Info | Logout | XML/Pilot/etc versions | Long version (with comments) | Weblog archives | Site Map | | Browse Topics

Watching TR-069

2020-01-10 17:27:55.742339+00 by Dan Lyke 0 comments

There's this technology called TR-069, which your ISP likely uses to be able to look at the configuration information on your home router, especially if you rent or lease your router. They do this for debugging purposes, it's tremendously useful to help figure out what your issues are.

It's always bugged me a little bit, and I've always thought that one should consider networks behind TR-069 enabled routers as essentially public WiFi, with all of the same security concerns and precautions you'd use if you were going to use those same computers and services in your local coffee shop.

To be fair, this probably isn't so much about mass attacks, criminals casting wide nets to catch open security holes have many other juicy targets to attempt that with, as it is about someone interested in a specific target. But in general if you've got a network that has unencrypted traffic, where devices trust each other, you probably want another firewall behind your ISP's router.

And this is particularly annoying if you're trying to set up a network behind crappy CPEs like the Pace modems that don't do ISPv6 very well, and don't have a pass-thru mode...

Anyway, code is at https://github.com/mhils/tr069

The paper is at Watching the Weak Link into Your Home: An Inspection and Monitoring Toolkit for TR-069

[ related topics: Interactive Drama broadband Model Building Woodworking ]

comments in ascending chronological order (reverse):

Add your own comment:

(If anyone ever actually uses Webmention/indie-action to post here, please email me)




Format with:

(You should probably use "Text" mode: URLs will be mostly recognized and linked, _underscore quoted_ text is looked up in a glossary, _underscore quoted_ (http://xyz.pdq) becomes a link, without the link in the parenthesis it becomes a <cite> tag. All <cite>ed text will point to the Flutterby knowledge base. Two enters (ie: a blank line) gets you a new paragraph, special treatment for paragraphs that are manually indented or start with "#" (as in "#include" or "#!/usr/bin/perl"), "/* " or ">" (as in a quoted message) or look like lists, or within a paragraph you can use a number of HTML tags:

p, img, br, hr, a, sub, sup, tt, i, b, h1, h2, h3, h4, h5, h6, cite, em, strong, code, samp, kbd, pre, blockquote, address, ol, dl, ul, dt, dd, li, dir, menu, table, tr, td, th

Comment policy

We will not edit your comments. However, we may delete your comments, or cause them to be hidden behind another link, if we feel they detract from the conversation. Commercial plugs are fine, if they are relevant to the conversation, and if you don't try to pretend to be a consumer. Annoying endorsements will be deleted if you're lucky, if you're not a whole bunch of people smarter and more articulate than you will ridicule you, and we will leave such ridicule in place.


Flutterby™ is a trademark claimed by

Dan Lyke
for the web publications at www.flutterby.com and www.flutterby.net.