<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Beware the PogoPlug</title>
	<atom:link href="http://robpickering.com/2010/01/beware-the-pogoplug-7/feed" rel="self" type="application/rss+xml" />
	<link>http://robpickering.com/2010/01/beware-the-pogoplug-7</link>
	<description>a rough whimper of insanity</description>
	<lastBuildDate>Thu, 17 May 2012 06:23:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=484</generator>
	<item>
		<title>By: Rob Pickering</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-205</link>
		<dc:creator>Rob Pickering</dc:creator>
		<pubDate>Fri, 02 Sep 2011 20:06:00 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-205</guid>
		<description>The article was written over 18 months ago, a lot has changed since that time.  I also find it odd that you jumped to the conclusion that I don&#039;t understand my network.  The point of the article was one around the security implications of allowing &quot;root&quot; level access with a well-known password to the PogoPlug by default (since fixed, as I pointed out in the article).  Secondly, my issue WAS the firewall, which I admitted to, however, the fact that CloudEngines support (not the developers) just told me to connect it to the Public Internet, wasn&#039;t an appropriate solution, especially in light of the security issue the developers had caused.

I never &quot;pointed fingers at the developers&quot; other than to state that having a well-known, root-level, SSH password, enabled by default, on a consumer device was a bad idea.  They thought so too, after my article, and changed it.

In the comment posted 7 months ago, I pointed out how to get the PogoPlug to work from behind the Astaro Security Gateway.  So, again, not sure where your comment is coming from, as I believe I addressed your concerns either in the original article, or in the comments.</description>
		<content:encoded><![CDATA[<p>The article was written over 18 months ago, a lot has changed since that time.  I also find it odd that you jumped to the conclusion that I don&#8217;t understand my network.  The point of the article was one around the security implications of allowing &#8220;root&#8221; level access with a well-known password to the PogoPlug by default (since fixed, as I pointed out in the article).  Secondly, my issue WAS the firewall, which I admitted to, however, the fact that CloudEngines support (not the developers) just told me to connect it to the Public Internet, wasn&#8217;t an appropriate solution, especially in light of the security issue the developers had caused.</p>
<p>I never &#8220;pointed fingers at the developers&#8221; other than to state that having a well-known, root-level, SSH password, enabled by default, on a consumer device was a bad idea.  They thought so too, after my article, and changed it.</p>
<p>In the comment posted 7 months ago, I pointed out how to get the PogoPlug to work from behind the Astaro Security Gateway.  So, again, not sure where your comment is coming from, as I believe I addressed your concerns either in the original article, or in the comments.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Chimericgamer</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-204</link>
		<dc:creator>Chimericgamer</dc:creator>
		<pubDate>Fri, 02 Sep 2011 19:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-204</guid>
		<description>From what it sounds like you don&#039;t entirely understand either the way your own network security system works, the way the PogoPlug connects (thanks for the great explanation Jed) or both.  Before you point fingers at the developers, ask yourself this:  &quot;Did something I configure make my setup significantly different from that of the common user&quot;.  This in your case was your firewall system.  True, the developers might have asked you to use the device on the public network, but I doubt they would suggest doing so with your data.  With just the device you could troubleshoot your connection, and then apply settings correctly.  From here you could then put the device behind whatever security solution you prefer and attach your data.  Please do your homework before you bite the hand that feeds.</description>
		<content:encoded><![CDATA[<p>From what it sounds like you don&#8217;t entirely understand either the way your own network security system works, the way the PogoPlug connects (thanks for the great explanation Jed) or both.  Before you point fingers at the developers, ask yourself this:  &#8221;Did something I configure make my setup significantly different from that of the common user&#8221;.  This in your case was your firewall system.  True, the developers might have asked you to use the device on the public network, but I doubt they would suggest doing so with your data.  With just the device you could troubleshoot your connection, and then apply settings correctly.  From here you could then put the device behind whatever security solution you prefer and attach your data.  Please do your homework before you bite the hand that feeds.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Pickering</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-186</link>
		<dc:creator>Rob Pickering</dc:creator>
		<pubDate>Tue, 26 Jul 2011 14:34:00 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-186</guid>
		<description>You are correct.  I reflected that in my March 2010 article, found here:  http://robpickering.com/?p=12</description>
		<content:encoded><![CDATA[<p>You are correct.  I reflected that in my March 2010 article, found here:  http://robpickering.com/?p=12</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bob</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-185</link>
		<dc:creator>Bob</dc:creator>
		<pubDate>Tue, 26 Jul 2011 14:09:00 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-185</guid>
		<description>For what it&#039;s worth, I think PogoPlug now ships with SSH access disabled, by default. You&#039;d need to explicitly enable it if you want to SSH into the device.</description>
		<content:encoded><![CDATA[<p>For what it&#8217;s worth, I think PogoPlug now ships with SSH access disabled, by default. You&#8217;d need to explicitly enable it if you want to SSH into the device.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Pickering</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-123</link>
		<dc:creator>Rob Pickering</dc:creator>
		<pubDate>Wed, 02 Feb 2011 23:39:52 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-123</guid>
		<description>&lt;strong&gt;UPDATE:  &lt;/strong&gt;Possible fix for Astaro Gateway Issue - 

A user named Jamy Casteel contacted me and had this advice, &quot;What fixed the whole issue was adding the pogoplug&#039;s IP address to the exclusions list under the Transparent Mode skip list (under web security, http/s)&quot;.  
I also found a post &lt;a href=&quot;http://www.astaro.org/astaro-gateway-products/general-discussion/33995-setup-help-pogoplug-2.html&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt; by @BAlfson that states, &quot;If you have the Astaro using HTTP/S Proxy in &quot;Transparent&quot; mode.  Then you need to put the IP address of the PogoPlug into the &quot;Transparent Mode Skip List&quot; on the Advanced Tab&quot;.

Hopefully, that will help folks.</description>
		<content:encoded><![CDATA[<p><strong>UPDATE:  </strong>Possible fix for Astaro Gateway Issue &#8211; </p>
<p>A user named Jamy Casteel contacted me and had this advice, &#8220;What fixed the whole issue was adding the pogoplug&#8217;s IP address to the exclusions list under the Transparent Mode skip list (under web security, http/s)&#8221;.<br />
I also found a post <a href="http://www.astaro.org/astaro-gateway-products/general-discussion/33995-setup-help-pogoplug-2.html" rel="nofollow">here</a> by @BAlfson that states, &#8220;If you have the Astaro using HTTP/S Proxy in &#8220;Transparent&#8221; mode.  Then you need to put the IP address of the PogoPlug into the &#8220;Transparent Mode Skip List&#8221; on the Advanced Tab&#8221;.</p>
<p>Hopefully, that will help folks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Pickering</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-10</link>
		<dc:creator>Rob Pickering</dc:creator>
		<pubDate>Sun, 31 Jan 2010 06:59:44 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-10</guid>
		<description>&lt;p&gt;Jed,&lt;/p&gt;&lt;p&gt;The purpose of my article was to alert users of the problem and to make them aware of what I perceive to be a serious security flaw.  I do, and will continue to, see the value this type of solution provides to the consumer.  However, it must be done with care, as making things very simple for the end user means the onus to provide security rests with the vendor.&lt;/p&gt;&lt;p&gt;As such, I would be thrilled to work with CloudEngines on this solution and would like to try out the March release of the unit.  Following testing, I will post a follow up article of my findings.  I am also willing to work with CloudEngines on getting the Astaro Home Gateway supported, as it is a very popular end user firewall.&lt;/p&gt;&lt;p&gt;Please use the contact form to provide me an email I can reach you at to discuss further.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Jed,</p>
<p>The purpose of my article was to alert users of the problem and to make them aware of what I perceive to be a serious security flaw.  I do, and will continue to, see the value this type of solution provides to the consumer.  However, it must be done with care, as making things very simple for the end user means the onus to provide security rests with the vendor.</p>
<p>As such, I would be thrilled to work with CloudEngines on this solution and would like to try out the March release of the unit.  Following testing, I will post a follow up article of my findings.  I am also willing to work with CloudEngines on getting the Astaro Home Gateway supported, as it is a very popular end user firewall.</p>
<p>Please use the contact form to provide me an email I can reach you at to discuss further.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jed Putterman</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-9</link>
		<dc:creator>Jed Putterman</dc:creator>
		<pubDate>Sat, 30 Jan 2010 21:33:08 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-9</guid>
		<description>&lt;p&gt;Rob, regarding your 1st and 3rd points, our support should never have told you to open ports, and for this I apologize.  Pogoplug NEVER requires that a port be opened, even with common consumer firewalls running.  Our only requirement is that UDP be enabled on the network and not specifically blocked and outbound TCP requests be allowed.  If a specific brand of firewall is not supported then it needs to be treated as a feature request to support it by our development team, not a request to the end-user to make changes.  &lt;/p&gt;&lt;p&gt;Regarding auto-upgrade - if you change your password, auto upgrade will always continue to work and I have made sure that our support team has this correct information.&lt;/p&gt;&lt;p&gt;If you are up for it, I&#039;ll send you a free unit in March after the release and work with you to get Astaro properly supported.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Rob, regarding your 1st and 3rd points, our support should never have told you to open ports, and for this I apologize.  Pogoplug NEVER requires that a port be opened, even with common consumer firewalls running.  Our only requirement is that UDP be enabled on the network and not specifically blocked and outbound TCP requests be allowed.  If a specific brand of firewall is not supported then it needs to be treated as a feature request to support it by our development team, not a request to the end-user to make changes.  </p>
<p>Regarding auto-upgrade &#8211; if you change your password, auto upgrade will always continue to work and I have made sure that our support team has this correct information.</p>
<p>If you are up for it, I&#8217;ll send you a free unit in March after the release and work with you to get Astaro properly supported.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob Pickering</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-8</link>
		<dc:creator>Rob Pickering</dc:creator>
		<pubDate>Sat, 30 Jan 2010 17:27:11 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-8</guid>
		<description>&lt;p&gt;My response to Jed Putterman at PogoPlug:&lt;/p&gt;&lt;p&gt;1)  Actually it does.  I have the documentation from your own support outlining the ports that MUST BE OPENED to enable BOTH the PogoPlug to register, and the PogoPlug to work.  You&#039;re welcome to also reference ticket numbers:  #3437, #3450, and #3506.  These cases document BOTH that support stated the password could not be changed AND get updates, the ports that MUST be opened for it to work, and the fact that it does not work through an Astaro Home Gateway Firewall (which is not PnP compatible).&lt;/p&gt;&lt;p&gt;2)  Shipping with a &quot;standard&quot; username and password is one thing.  Publishing that username and password on the web AND not providing an easy way for consumers to change that username and password is quite another.  I&#039;m pretty sure most of your users would not be comfortable with SSH, mounting filesystems RW, changing passwords at a command line, and then remounting a filesystem RO.  Comparing yourself to a device that has a web GUI for changing the password isn&#039;t valid.&lt;/p&gt;&lt;p&gt;3)  From your own PogoPlug support on Ticket #3437, &quot;Please note, however, should you do this, automatic firmware updates will not occur.&quot;&lt;/p&gt;&lt;p&gt;4)  This is a false statement, as SSH is enabled BY DEFAULT and accepts connections from ANYWHERE.  So you are relying on the end-user having a firewall to block these connections from the Internet as well as relying on the end-user to have a secure wireless and wired network to prevent these connections.  It&#039;s unacceptable to allow the &#039;root&#039; account to SSH into the device BY DEFAULT.&lt;/p&gt;&lt;p&gt;I&#039;m very happy to hear you are addressing this blatant security hole, I only wish your device would work behind a firewall without having to open ports.  Support for the Astaro Home Gateway firewall would also be appreciated.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>My response to Jed Putterman at PogoPlug:</p>
<p>1)  Actually it does.  I have the documentation from your own support outlining the ports that MUST BE OPENED to enable BOTH the PogoPlug to register, and the PogoPlug to work.  You&#8217;re welcome to also reference ticket numbers:  #3437, #3450, and #3506.  These cases document BOTH that support stated the password could not be changed AND get updates, the ports that MUST be opened for it to work, and the fact that it does not work through an Astaro Home Gateway Firewall (which is not PnP compatible).</p>
<p>2)  Shipping with a &quot;standard&quot; username and password is one thing.  Publishing that username and password on the web AND not providing an easy way for consumers to change that username and password is quite another.  I&#8217;m pretty sure most of your users would not be comfortable with SSH, mounting filesystems RW, changing passwords at a command line, and then remounting a filesystem RO.  Comparing yourself to a device that has a web GUI for changing the password isn&#8217;t valid.</p>
<p>3)  From your own PogoPlug support on Ticket #3437, &quot;Please note, however, should you do this, automatic firmware updates will not occur.&quot;</p>
<p>4)  This is a false statement, as SSH is enabled BY DEFAULT and accepts connections from ANYWHERE.  So you are relying on the end-user having a firewall to block these connections from the Internet as well as relying on the end-user to have a secure wireless and wired network to prevent these connections.  It&#8217;s unacceptable to allow the &#8216;root&#8217; account to SSH into the device BY DEFAULT.</p>
<p>I&#8217;m very happy to hear you are addressing this blatant security hole, I only wish your device would work behind a firewall without having to open ports.  Support for the Astaro Home Gateway firewall would also be appreciated.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jed Putterman</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-7</link>
		<dc:creator>Jed Putterman</dc:creator>
		<pubDate>Sat, 30 Jan 2010 11:33:33 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-7</guid>
		<description>&lt;p&gt;I work at Cloud Engines, the makers of Pogoplug.  First, I appreciate you taking the time to write your thoughts, and your security concerns - we also take security extremely seriously.  We always listen to our users, and address any real security issues or threats with great care and urgency.  I would like to address the concerns you raise in this post, which will hopefully answer the open questions (and issues) raised above.&lt;/p&gt;&lt;p&gt;1.  Pogoplug sits behind your router on your internal network and is safe from outside access by the firewall provided by your router. Pogoplug does NOT require opening any ports or making any changes to your firewall settings.  In fact, we specifically do NOT use UPnP for exactly that reason - your network should never be exposed to the outside.  By not requiring any kind of network changes, opening ports, or port forwarding, Pogoplug is one of the safest remote access solutions on the market.&lt;/p&gt;&lt;p&gt;2.  Many common consumer electronics devices, including the most popular routers, ship with a standard username and password.  They, like us, want your device to be open and available for you to make changes - again, with the knowledge that they are sitting behind your router (or they are your router) and there is no unauthorized external access allowed.&lt;/p&gt;&lt;p&gt;3.  At any point you can change the root password of your Pogoplug.  Your Pogoplug will continue to upgrade automatically as it always has, and in fact will work exactly the same in all regards.&lt;/p&gt;&lt;p&gt;4.  The auto-upgrade check on the Pogoplug uses a secure handshake with the upgrade servers to find out if a new software (firmware) upgrade is available.  The Pogoplug has no ability to upload software to our servers - it can only download the latest firmware, so there is no potential for a trojan style &quot;injection&quot; of malicious software.  In the same regard, Pogoplug never accepts unsolicited requests for data, it only responds to remote access requests from the Pogoplug servers that were initiated by the Pogoplug itself, which further eliminates outside spoof attacks directed at individual Pogoplug devices.&lt;/p&gt;&lt;p&gt;We will add more information to the developer section of our site over the weekend clarifying some of his issues, especially about the fact that it&#039;s fine to change the default password and everything will continue working as always, including auto-upgrades, and that Pogoplug sits behind a router/firewall where there is no direct public access and never opens any ports, don&#039;t use UPnP, ... so publishing the password is a convenience for the owner to keep the device open, rather than a security hole in this environment.  As an aside, in the March release we are adding the ability to disable/enable ssh (default will be disabled) and change the root password from the UI.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I work at Cloud Engines, the makers of Pogoplug.  First, I appreciate you taking the time to write your thoughts, and your security concerns &#8211; we also take security extremely seriously.  We always listen to our users, and address any real security issues or threats with great care and urgency.  I would like to address the concerns you raise in this post, which will hopefully answer the open questions (and issues) raised above.</p>
<p>1.  Pogoplug sits behind your router on your internal network and is safe from outside access by the firewall provided by your router. Pogoplug does NOT require opening any ports or making any changes to your firewall settings.  In fact, we specifically do NOT use UPnP for exactly that reason &#8211; your network should never be exposed to the outside.  By not requiring any kind of network changes, opening ports, or port forwarding, Pogoplug is one of the safest remote access solutions on the market.</p>
<p>2.  Many common consumer electronics devices, including the most popular routers, ship with a standard username and password.  They, like us, want your device to be open and available for you to make changes &#8211; again, with the knowledge that they are sitting behind your router (or they are your router) and there is no unauthorized external access allowed.</p>
<p>3.  At any point you can change the root password of your Pogoplug.  Your Pogoplug will continue to upgrade automatically as it always has, and in fact will work exactly the same in all regards.</p>
<p>4.  The auto-upgrade check on the Pogoplug uses a secure handshake with the upgrade servers to find out if a new software (firmware) upgrade is available.  The Pogoplug has no ability to upload software to our servers &#8211; it can only download the latest firmware, so there is no potential for a trojan style &quot;injection&quot; of malicious software.  In the same regard, Pogoplug never accepts unsolicited requests for data, it only responds to remote access requests from the Pogoplug servers that were initiated by the Pogoplug itself, which further eliminates outside spoof attacks directed at individual Pogoplug devices.</p>
<p>We will add more information to the developer section of our site over the weekend clarifying some of his issues, especially about the fact that it&#8217;s fine to change the default password and everything will continue working as always, including auto-upgrades, and that Pogoplug sits behind a router/firewall where there is no direct public access and never opens any ports, don&#8217;t use UPnP, &#8230; so publishing the password is a convenience for the owner to keep the device open, rather than a security hole in this environment.  As an aside, in the March release we are adding the ability to disable/enable ssh (default will be disabled) and change the root password from the UI.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Staszel</title>
		<link>http://robpickering.com/2010/01/beware-the-pogoplug-7/comment-page-1#comment-6</link>
		<dc:creator>Mike Staszel</dc:creator>
		<pubDate>Sat, 30 Jan 2010 11:05:26 +0000</pubDate>
		<guid isPermaLink="false">http://robpickering.com/2010/01/beware-the-pogoplug/#comment-6</guid>
		<description>&lt;p&gt;You can change the root password and get updates. CliudEngines&#039; API connects to &quot;hbplug&quot; which runs as a root user on the Pogoplug itself. HBPlug, once it knows of new firmware, downloads the upgrade scripts and runs them as root (since the process itself is run by root).&lt;/p&gt;&lt;p&gt;The REAL problem is keeping the API secure. If a hacker were to make the API say &quot;download this trojan firmware&quot; then all Pogoplugs would be destroyed. It&#039;s unlikely but possible.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>You can change the root password and get updates. CliudEngines&#8217; API connects to &quot;hbplug&quot; which runs as a root user on the Pogoplug itself. HBPlug, once it knows of new firmware, downloads the upgrade scripts and runs them as root (since the process itself is run by root).</p>
<p>The REAL problem is keeping the API secure. If a hacker were to make the API say &quot;download this trojan firmware&quot; then all Pogoplugs would be destroyed. It&#8217;s unlikely but possible.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

