
Minimum Home Router Security Recommendations Defined in New Joint LACNOG and M3AAWG Best Practices
New best practices recommendations for ISPs issued by LACNOG and M3AAWG this month define basic security criteria for home routers and other customer premise equipment (CPE) and are expected to help protect the internet against common attacks, especially DoS attacks arising from the abuse of these devices. The guidelines will strengthen internet service providers’ security efforts by identifying requirements for the hardware devices connected to their networks that are susceptible to exploitation when basic safeguards are ignored.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20190602005010/en/
The best practices document, LACNOG-M3AAWG Joint Best Current Operational Practices on Minimum Security Requirements for Customer Premises Equipment (CPE) Acquisition, is being translated into multiple languages for use by ISPs worldwide. It was published by the Latin American and Caribbean Network Operators Group and the Messaging, Malware and Mobile Anti-Abuse Group, and is available at www.lacnog.net/docs/lac-bcop-1 and www.m3aawg.org/CPESecurityBP or with current translations at https://www.m3aawg.org/published-documents.
The recommended security settings and functionality are based on industry experience and are essential in deterring Denial of Service (DoS) attacks that make use of vulnerable network infrastructure devices, Internet of Things (IoT) devices, and malware infections. A Table of Requirements is provided to help ISPs customize security recommendations for their networks in a concise format they can provide to CPE manufacturers.
Worldwide Effort to Strengthen Online Protection
The document is currently being translated into Portuguese, Spanish, French, German, and Japanese, with other languages expected to follow. The translated best practices will be useful worldwide as a tool for ISPs to set requirements for secure defaults on the customer premise equipment they will connect to their networks, according to the document’s editor, Lucimara Desiderá, chair of the Latin American and Caribbean Anti-Abuse Working Group (LAC-AAWG) and security analyst at CERT.br (the Brazilian National Computer Emergency Response Team).
“Latin American computer security incident response teams have identified the lack of CPE security as a severe problem in attacks for the past several years. These new best practices will make it easier for ISPs to negotiate with CPE vendors to ensure the equipment they connect to their networks meet minimal security requirements, which will help reduce the number and intensity of attacks on the internet overall, and as a result, the negative impact they cause on ISPs’ operations,” Desiderá said.
The guidelines cover documentation and vendor contact information, software security, remote updates and device management functionality, default configuration preferences, and support policies related to security fixes. Among the recommendations:
- Passwords should not be hardcoded into the firmware, must be changeable, and vendors should not use the same default password for all devices.
- There needs to be a mechanism for periodic remote software updates, including a method to verify the authenticity of a downloadable update file.
- The equipment should be restrictively configured rather than permissively configured.
As an example of the scope of the problem, the Mirai malware responsible for several major website attacks contains a table of more than 60 common factory default user names and passwords it references to log in and infect home security cameras, home routers and other IoT devices. The new guidelines would make the login table ineffective, according to M3AAWG Chairman of the Board Severin Walker.
Walker said, “M3AAWG collaboration with LACNOG and its LAC Working Group on this document was a priority, in part, because of our ongoing work with regional network operator and incident response groups to address global threats to secure communications. It was also important because we need to continue evolving our members’ focus on the security of IoT, mobile and other consumer devices in order to help prevent the increasingly larger attacks originating from them.”
The best practices document was developed by LACNOG and M3AAWG and issued at the LACNIC 31 meeting in the Dominican Republic on May 8. It is based on the expertise of LACNOG's working groups LAC-AAWG and the BCOP Working Group, in cooperation with M3AAWG members, its Senior Technical Advisors, and the M3AAWG Technical Committee.
About LACNOG
LACNOG (www.lacnog.net) is the Latin American and Caribbean Network Operators Group that is structured around a Board, Program Committee, and Working Groups. It provides an environment for network operators and any interested parties to exchange experiences and knowledge through mailing lists, working groups, and annual meetings. LACNOG also promotes local Network Operators Groups (NOGs) and peering forums, the development and adoption of best practices, and technical training activities and tutorials.
About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)
The Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks, and other online exploitation. M3AAWG (www.m3aawg.org) members represent more than two billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration, and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3AAWG is driven by market needs and supported by major network operators and messaging providers.
M 3 AAWG Board of Directors and Sponsors: 1 & 1 Internet SE; Adobe Systems Inc.; AT&T Comcast; Endurance International Group; Facebook; Google, Inc.; LinkedIn; Mailchimp; Marketo, Inc.; Microsoft Corp.; Orange; Proofpoint; Rackspace; Return Path, Inc.; SendGrid, Inc.; Vade Secure; Valimail; VeriSign, Inc.; and Verizon Media (Yahoo & AOL).
M 3 AAWG Full Members: Agora, Inc.; Broadband Security, Inc.; Campaign Monitor; Cisco Systems, Inc.; CloudFlare, Inc.; dotmailer; eDataSource Inc.; ExactTarget, Inc.; IBM; iContact; Internet Initiative Japan (IIJ); Liberty Global; Listrak; Litmus; McAfee; Mimecast; Oracle Marketing Cloud; OVH; Spamhaus; Splio; Symantec; USAA; and Wish.
A complete member list is available at http://www.m3aawg.org/about/roster.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20190602005010/en/
Contact information
Media Contact:
Astra Communications
Linda Marcus, APR
+1-714-974-7973
(U.S. Pacific)
LMarcus@astra.cc
About Business Wire
(c) 2018 Business Wire, Inc., All rights reserved.
Business Wire, a Berkshire Hathaway company, is the global leader in multiplatform press release distribution.
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
H.I.G. Capital Announces the Sale of DGS S.p.A.11.6.2024 12:00:00 CEST | Press release
H.I.G. Capital (“H.I.G.”), a leading global alternative investment firm with $62 billion of capital under management, is pleased to announce that an affiliate has signed a definitive agreement to sell its portfolio company, DGS S.p.A. (“DGS” or the “Group”), a leading firm in the Italian Information Technology market, to DGS Co-Founders and management team in partnership with ICG, a global alternative asset manager. Since its inception in 1997, DGShas supported blue-chip customers in the design, integration, and maintenance of complex IT systems, with a specialization in digital transformation and cybersecurity services. The Group currently has over 1,900 employees, revenues of approximately €300 million, and maintains a group of highly loyal clientele. During H.I.G.’s ownership, DGS has tripled in size and consolidated its position as a leading Italian firm in cybersecurity services and digital transformation. DGS offers its clients sophisticated and proprietary digital transformation
Evertas Names Nick Selby Head of European Underwriting11.6.2024 12:00:00 CEST | Press release
Evertas, the world’s first crypto insurance company, has named Nick Selby as its new Head of European Underwriting. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240611141887/en/ Nick Selby, Executive Vice President and Head of European Underwriting at Evertas (Photo: Business Wire) Selby, an accomplished information and physical security professional, brings two decades of expertise in public and private sector information security, physical security, and complex incident handling, as well as seven years of experience leading teams securing billions of dollars in cryptoassets. Previously, his roles included VP of the Software Assurance Practice at Trail of Bits, Chief Security Officer at Paxos Trust Company, and Director of Cyber Intelligence and Investigations at the NYPD Intelligence Bureau. “Nick is an extremely valuable addition to our European team,” said Evertas CEO and Co-Founder J. Gdanski. “His public and private
Owlet utvider globalt fotavtrykk med lanseringen av medisinsk-sertifisert Dream Sock™ i Storbritannia og over hele Europa11.6.2024 11:00:00 CEST | Pressemelding
Owlet, Inc. («Owlet» or the «Company») (NYSE:OWLT), pioneren innen smart spedbarnsovervåking, kunngjør i dag den britiske og europeiske lanseringen av Dream Sock. Dette er en smart babymonitor med levende helseavlesninger og varsler for friske spedbarn mellom 0-18 måneder og 2,5-13,6 kg. Dette innovative medisinske utstyret gir foreldre helse og viktig informasjon i sanntid, noe som gir uovertruffen trygghet. Denne pressemeldingen inneholder multimedia. Se hele pressemeldingen her: https://www.businesswire.com/news/home/20240611820341/no/ (Photo: Business Wire) «Vi er svært stolte over å lansere Dream Sock til omsorgspersoner over hele Storbritannia og Europa og gi millioner av foreldre mer trygghet mens babyen sover,» sa Kurt Workman, Owlets administrerende direktør og medgründer. «Dream Sock er nå et globalt produkt som er anerkjent som medisinsk nøyaktig og trygt, etter å ha gjennomgått regulatoriske autorisasjoner og sertifiseringer innenfor flere geografier. I dag er misjonen vår
V-Nova Surpasses 1000 Patent Milestone in Media Technology Innovation11.6.2024 10:00:00 CEST | Press release
V-Nova, a leading provider of data compression solutions, video compression technology, XR technology, AI acceleration and parallel processing for a multitude of industries including media and entertainment, today announced its milestone achievement of 1000 active technology patents. This accomplishment underscores V-Nova’s dedication to research and development and its commitment to protecting its intellectual property globally. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240611724561/en/ V-Nova’s patent portfolio spans more than 50 different jurisdictions. Including over 400 patents in Europe, over 200 in the Americas, over 100 in the United States specifically, and over 200 in Asia. V-Nova forged new directions in data processing to enhance digital experiences, maximize efficiency, reduce costs, and increase sustainability. The company leads the way with key international data compression standards for the video indust
Alipay+ Reveals Top Scorer Trophy Design for UEFA EURO 2024™11.6.2024 09:24:00 CEST | Press release
Alipay+, a suite of cross-border mobile payment and digitalization technology solutions operated by Ant International and an Official Partner of UEFA EURO 2024™, today revealed the trophy that will be awarded to the most prolific marksman at the UEFA EURO 2024™ finale on July 14 in Berlin, Germany. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20240610328619/en/ The UEFA Top Scorer Trophy presented by Alipay+ is unveiled for UEFA EURO 2024™ (Photo: Business Wire) Sculpted in the shape of the Chinese character “支” (pronounced zhi, and meaning payment as well as support), the trophy reflects Alipay+’s dedication to supporting consumers to enjoy seamless payment and a broad choice of deals using their preferred payment methods while traveling abroad. The character also resembles the fleeting moment of a barefooted striker poised to shoot, evoking the original beauty and power of football – a game that united people across the wo