Hi
I think you should untie (unlink) device ID from DDNS domains.
After some simple search I found this DDNS domains:
https://pastebin.com/raw/xxxxxxxxxxxxxxx(will self destruct after two weeks)
Hi
I think you should untie (unlink) device ID from DDNS domains.
After some simple search I found this DDNS domains:
https://pastebin.com/raw/xxxxxxxxxxxxxxx(will self destruct after two weeks)
I beg you, stop posting those "security" reports, they are all nonsense.
(This isn't an official warning, just my 2 cents as somebody working in IT for years)
Of course, you can enumerate all DDNS domains. That's by design of DDNS and is the same for MyFritz (Germany) for example. You can even enumerate most other domains due to SSL cert logs, for example.
Enumeration of domains isn't a security flaw, it's just how DDNS works. If people enable DDNS, then it's precisely what they want - they want a public endpoint showing their WAN IP.
The only thing I would like is if you disable GLDDNS via your routers GUI it should clean the DDNS domain entry on the DDNS DNS as well.
Edit
For example is it pretty easy to find routers connected to the internet and access on WAN enabled: https://www.shodan.io/search?query="gl.inet"
I know that. I meant that it tied to device ID. I mean make device ID separate from DDNS domain.
Now xxxxxxx.glddns.com = device ID
I mean make xxxxxxx.glddns.com and yyyyyyyyas device ID
I was able to contact support team (I will NOT provide information from which address and when) asking to provide MAC using this info and I was able to locate random person (physically, using BSSID location databases)
It’s not about security, it is about privacy. Hide device ID.
None of these are issues.
There is no difference between using xxxxxxx or yyyyyyyyy.
BSSID will be randomized.