“News Alert: Irish Broadband Routers Totally Secure”

October 9th, 2007
Irish Broadband routers totally secure

After all the coverage that Eircom got over their security problems, Irish Broadband have attempted to capitalise on the situation with this press release: “Irish Broadband routers are totally secure”. I don’t know whether they are trying to lure any confused/misguided Eircom customers to switch providers, or whether this is an attempt to console their existing customers, but this is an irresponsible message to send at a time when the public has finally begun to take note of internet security.

This line in particular is rotten to the core:

This password, being set by the customer, is not derived from the serial number of the modem or the network name and is therefore completely secure.

Ignoring the 58,700 results that I get in Google for “crack wpa”, even if the encryption method is somehow 100% unbreakable, just ask Paypal what happens when you allow the user to pick his own password.

When Eircom responded to their security issue last week, their reply was responsible and honest (for the most part). They qualified their statements with the standard disclaimer known to every first year computer science student and network technician: “it is widely recognised in the industry that no wireless access can be deemed 100% secure”, noting that through policy and advice to customers, they are making an effort to minimise the potential vulnerability. This is the textbook response.

Eircom gave their customers a false sense of security because some programmer made a genuine mistake (and he would have got away with it if it weren’t for those pesky kids). Irish Broadband are doing the same thing - unnecessarily allowing their customers to overestimate their security - but what is their excuse? Either they’re completely ignorant, or they’re blatantly lying.

3 Responses to ““News Alert: Irish Broadband Routers Totally Secure””

  1. Damien Mulley » Blog Archive » Fluffy Links - Thursday October 11th 2007 Says:

    [...] Irish Broadband are just asking to be hacked. [...]

  2. Branedy Says:

    This is like a ‘Kick Me’ sign on their backsides.

  3. Dave Devery Says:

    I admire your stance on this topic. Great blog

Leave a Reply

I am from Cork, Ireland. A fan of the Big Lebowski, Mac OS X, Linux, Cork hurling, Munster rugby, Irish football. Interests include QuakeWorld, Python (lately Django), network security, web applications and technology in general.

Leave a comment if you come across something that interests you. My contact details are here. Alternatively, you can connect on LinkedIn or Twitter.