7

Discussion topic: Sky Q Hub security update

Reply
This message was authored by MrBaconMaker This message was authored by: MrBaconMaker

Sky Q Hub security update

Hi

 

With the recent disclosure of new wi fi vulnerabilities, do we know when/if the sky q hub will be updated to receive this security patch?

 

Vulnerability here - https://www.fragattacks.com/


Best Answers
This message was authored by mae-3 This message was authored by: mae-3 Answer

Re: Sky Q Hub security update

@MrBaconMaker 

 

The Linux kernel is primarily in the whole OS type of system when it involves client-side/AP wifi vulnerabilities, not server or router and it's with certain wifi adapters. Also, the Sky router has a transparent DNS, so you cannot hijack DNS. I could go on but have read the whole advisory and it doesn't apply to Sky's routers that get firmware patched often.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.

View this Answer within the discussion

Locked

This discussion has been locked

Sorry, you can't reply to this discussion as it's been locked by our Community Managers.

Reply

All Replies

This message was authored by mae-3 This message was authored by: mae-3

Re: Sky Q Hub security update

@MrBaconMaker 

 

The security vulnerabilities primarily impact client devices and most of these have been patched now, Linux systems which the Sky router is written around are not impacted.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
This message was authored by mae-3 This message was authored by: mae-3

Re: Sky Q Hub security update

https://www.theregister.com/2021/05/12/krack_hack_wifi/ 

 

Screenshot 2021-05-12 at 18.15.25.png

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
MrBaconMaker
Topic Author
This message was authored by MrBaconMaker This message was authored by: MrBaconMaker

Re: Sky Q Hub security update

Thanks, I hadn't seen that, I was wondering if they would have been applied to the ISP provided router yet as they tend to be notoriously slow at patching (if at all!)

MrBaconMaker
Topic Author
This message was authored by MrBaconMaker This message was authored by: MrBaconMaker

Re: Sky Q Hub security update

Just reading in more detail, it looks like those were patches to the Linux kernel but that doesn't mean they have yet made it downstream to routers

This message was authored by mae-3 This message was authored by: mae-3 Answer

Re: Sky Q Hub security update

@MrBaconMaker 

 

The Linux kernel is primarily in the whole OS type of system when it involves client-side/AP wifi vulnerabilities, not server or router and it's with certain wifi adapters. Also, the Sky router has a transparent DNS, so you cannot hijack DNS. I could go on but have read the whole advisory and it doesn't apply to Sky's routers that get firmware patched often.

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
MrBaconMaker
Topic Author
This message was authored by MrBaconMaker This message was authored by: MrBaconMaker

Re: Sky Q Hub security update

Thanks, as long as the hubs get frequent updates I'm happy as I'm sure they will get any patches soon.

This message was authored by mae-3 This message was authored by: mae-3

Re: Sky Q Hub security update

https://www.fragattacks.com/#details 

 

Screenshot 2021-05-12 at 18.48.20.png

Because Sky routers use a DNS transparent proxy DNS cannot be poisoned, so it does not impact Sky routers drastically or more accurately it's mitigated!

-------

Zen internet on FTTP (900Mbps down, 100Mbps up). SAT> IP (Apple 4K 2nd gen TV to LG C1 OLED UHD TV/Dolby Atmos Denon AVR, DacMagic Plus for Hi-Res audio), hosting own blog/forum (cluster), OPNsense & Zenarmor L4/L7 NGFW & DPI IDS/IPS, Asus ET12 Pro Tri-Band wifi, Linux, Gamer: Xbox Series X/i7 laptop, round-robin DNS over HTTPS, non-proprietary VoIP HD AMR-WB (G.722.2) and more... Beta tester Apple iOS/watchOS/tvOS/iPadOS/macOS.
Locked

This discussion has been locked

Sorry, you can't reply to this discussion as it's been locked by our Community Managers.

Reply

Was this discussion not helpful?

No problem. Browse or search to find help, or start a new discussion on Community.

Start a new discussion

New Discussion