Business Wire

CA-M3AAWG

Share
Minimum Home Router Security Recommendations Defined in New Joint LACNOG and M3AAWG Best Practices

New best practices recommendations for ISPs issued by LACNOG and M3 AAWG this month define basic security criteria for home routers and other customer premise equipment (CPE) and are expected to help protect the internet against common attacks, especially DoS attacks arising from the abuse of these devices. The guidelines will strengthen internet service providers’ security efforts by identifying requirements for the hardware devices connected to their networks that are susceptible to exploitation when basic safeguards are ignored.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20190602005010/en/

The best practices document, LACNOG-M3 AAWG Joint Best Current Operational Practices on Minimum Security Requirements for Customer Premises Equipment (CPE) Acquisition, is being translated into multiple languages for use by ISPs worldwide. It was published by the Latin American and Caribbean Network Operators Group and the Messaging, Malware and Mobile Anti-Abuse Group, and is available at www.lacnog.net/docs/lac-bcop-1 and www.m3aawg.org/CPESecurityBP or with current translations at https://www.m3aawg.org/published-documents .

The recommended security settings and functionality are based on industry experience and are essential in deterring Denial of Service (DoS) attacks that make use of vulnerable network infrastructure devices, Internet of Things (IoT) devices, and malware infections. A Table of Requirements is provided to help ISPs customize security recommendations for their networks in a concise format they can provide to CPE manufacturers.

Worldwide Effort to Strengthen Online Protection

The document is currently being translated into Portuguese, Spanish, French, German, and Japanese, with other languages expected to follow. The translated best practices will be useful worldwide as a tool for ISPs to set requirements for secure defaults on the customer premise equipment they will connect to their networks, according to the document’s editor, Lucimara Desiderá, chair of the Latin American and Caribbean Anti-Abuse Working Group (LAC-AAWG) and security analyst at CERT.br (the Brazilian National Computer Emergency Response Team).

“Latin American computer security incident response teams have identified the lack of CPE security as a severe problem in attacks for the past several years. These new best practices will make it easier for ISPs to negotiate with CPE vendors to ensure the equipment they connect to their networks meet minimal security requirements, which will help reduce the number and intensity of attacks on the internet overall, and as a result, the negative impact they cause on ISPs’ operations,” Desiderá said.

The guidelines cover documentation and vendor contact information, software security, remote updates and device management functionality, default configuration preferences, and support policies related to security fixes. Among the recommendations:

  • Passwords should not be hardcoded into the firmware, must be changeable, and vendors should not use the same default password for all devices.
  • There needs to be a mechanism for periodic remote software updates, including a method to verify the authenticity of a downloadable update file.
  • The equipment should be restrictively configured rather than permissively configured.

As an example of the scope of the problem, the Mirai malware responsible for several major website attacks contains a table of more than 60 common factory default user names and passwords it references to log in and infect home security cameras, home routers and other IoT devices. The new guidelines would make the login table ineffective, according to M3 AAWG Chairman of the Board Severin Walker.

Walker said, “M3 AAWG collaboration with LACNOG and its LAC Working Group on this document was a priority, in part, because of our ongoing work with regional network operator and incident response groups to address global threats to secure communications. It was also important because we need to continue evolving our members’ focus on the security of IoT, mobile and other consumer devices in order to help prevent the increasingly larger attacks originating from them.”

The best practices document was developed by LACNOG and M3 AAWG and issued at the LACNIC 31 meeting in the Dominican Republic on May 8. It is based on the expertise of LACNOG's working groups LAC-AAWG and the BCOP Working Group , in cooperation with M3 AAWG members, its Senior Technical Advisors, and the M3 AAWG Technical Committee.

About LACNOG

LACNOG (www.lacnog.net ) is the Latin American and Caribbean Network Operators Group that is structured around a Board, Program Committee, and Working Groups. It provides an environment for network operators and any interested parties to exchange experiences and knowledge through mailing lists, working groups, and annual meetings. LACNOG also promotes local Network Operators Groups (NOGs) and peering forums, the development and adoption of best practices, and technical training activities and tutorials.

About the Messaging, Malware and Mobile Anti-Abuse Working Group (M3AAWG)

The Messaging, Malware and Mobile Anti-Abuse Working Group (M3 AAWG) is where the industry comes together to work against bots, malware, spam, viruses, denial-of-service attacks, and other online exploitation. M3 AAWG (www.m3aawg.org ) members represent more than two billion mailboxes from some of the largest network operators worldwide. It leverages the depth and experience of its global membership to tackle abuse on existing networks and new emerging services through technology, collaboration, and public policy. It also works to educate global policy makers on the technical and operational issues related to online abuse and messaging. Headquartered in San Francisco, Calif., M3 AAWG is driven by market needs and supported by major network operators and messaging providers.

M 3 AAWG Board of Directors and Sponsors:  1 & 1 Internet SE; Adobe Systems Inc.; AT&T Comcast; Endurance International Group; Facebook; Google, Inc.; LinkedIn; Mailchimp; Marketo, Inc.; Microsoft Corp.; Orange; Proofpoint; Rackspace; Return Path, Inc.; SendGrid, Inc.; Vade Secure; Valimail; VeriSign, Inc.; and Verizon Media (Yahoo & AOL).

M 3 AAWG Full Members:  Agora, Inc.; Broadband Security, Inc.; Campaign Monitor; Cisco Systems, Inc.; CloudFlare, Inc.; dotmailer; eDataSource Inc.; ExactTarget, Inc.; IBM; iContact; Internet Initiative Japan (IIJ); Liberty Global; Listrak; Litmus; McAfee; Mimecast; Oracle Marketing Cloud; OVH; Spamhaus; Splio; Symantec; USAA; and Wish.

A complete member list is available at http://www.m3aawg.org/about/roster .

Contact:

Media Contact: Astra Communications Linda Marcus, APR +1-714-974-7973 (U.S. Pacific) LMarcus@astra.cc

Link:

ClickThru

About Business Wire

Business Wire
Business Wire
101 California Street, 20th Floor
CA 94111 San Francisco

http://businesswire.com

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Suzano Reports Record First-Quarter Revenue9.5.2025 02:12:00 CEST | Press release

Suzano, the world’s largest pulp producer, announces its first quarter results for 2025 (1Q25) with record net revenue of R$11.6 billion, up 22% on the same quarter last year (1Q24). The result was driven by the exchange rates, increased pulp sales volumes from the new Ribas do Rio Pardo mill, higher paper volume and prices and the positive contribution from our paperboard mills recently acquired in the U.S. The record revenues occurred despite a series of planned downtimes in the quarter, including production lines of the Três Lagoas Unit, Mucuri Unit, and Aracruz Unit, and the Ribas do Rio Pardo Unit’s first scheduled maintenance downtime. Sales exceeded 3 million tonnes in the quarter, a rise of 12% compared to 1Q24, comprising 2.7 million tonnes of pulp and 390 thousand tonnes of paper, up 10% and 25%, respectively, on the same quarter last year. Adjusted EBITDA totaled R$4.9 billion, a 7% increase over 1Q24. Operating cash generation totaled R$2.6 billion, rising 5% on 1Q24. Net p

Andersen Consulting udvider platformen i Asien og Stillehavsområdet med tilføjelsen af Sertis8.5.2025 23:13:00 CEST | Pressemeddelelse

Andersen Consulting udvider sin dækning i Thailand og Indonesien med sin nyeste medlemsvirksomhed, Sertis, et førende konsulentfirma, der leverer datadrevne AI-løsninger til virksomheder i og uden for Sydøstasien. Dette strategiske skridt styrker Andersen Consultings tilstedeværelse i regionen og styrker organisationens kompetencer inden for AI-området. Sertis blev grundlagt i 2014 af Tee Vachiramon og har specialiseret sig i konsulenttjenester inden for AI og teknologitransformation, herunder udvikling af AI-strategi, tilpassede AI-løsninger, dataanalyse og digital omstilling. Firmaet arbejder med kunder i forskellige sektorer, herunder finans, detailhandel, energi, sundhedspleje og produktion, og sætter dem i stand til at optimere driften, træffe bedre beslutninger og forbedre kundeoplevelsen. "At blive medlem af Andersen Consulting er en milepæl for vores firma, da det giver os mulighed for at trække på en enestående platform med brancheførende løsninger til vores kunder," siger Tee

GC Aesthetics® Strengthens Board of Directors with Strategic Appointments8.5.2025 17:10:00 CEST | Press release

GC Aesthetics® (GCA), a privately-held medical technology company providing aesthetic and reconstruction solutions for global healthcare markets is pleased to announce the appointment of Mr. Luigi Ferrari as Chairman of the Board (non-executive) and Mr. Patrick Lee as Board Director, reinforcing the company’s strategic direction and long-term growth plans. These appointments follow the renewed phase of partnership initiated in early 2024 with Hayfin Capital Management, a longstanding investor in GCA. This collaboration has brought fresh momentum to the company’s commitment to innovation, safety, and global expansion in aesthetic and reconstructive breast surgery. Luigi Ferrari, a seasoned executive and investor with a proven track record in the healthcare sector, brings deep leadership experience, commercial growth expertise and industry insight. From 2012 to 2022 he was CEO of Lima Corporate, a global medical device company in the joint replacement market, acquired then by Enovis Corp

PPG to invest $380 million to buildnew U.S. manufacturing facility in Shelby, N.C. for aerospace coatings and sealants8.5.2025 16:30:00 CEST | Press release

PPG (NYSE: PPG) today announced that it will invest $380 million to build a new aerospace coatings and sealants manufacturing facility in Shelby, N.C. Construction on the 62-acre site, which will initially include manufacturing and warehousing units, is set to commence in October 2025 and is expected to be completed in the first half of 2027. The 198,000-square-foot facility will enable the company to continue meeting the growing demands of the aerospace industry. It will employ more than 110 people and produce the full line of PPG’s aerospace coatings and sealants. The additional capacity of this new plant, combined with nearby transport links that improve supply chain and shipping logistics, will help improve service levels for customers. “PPG’s investment in this new manufacturing facility demonstrates the significant demand growth for our world-class technologies and our continued commitment to serving our aerospace customers,” said Tim Knavish, PPG chairman and chief executive off

WHOOP Unveils WHOOP® 5.0 and WHOOP® MG: Powerful New Devices with Breakthrough Health and Longevity Features8.5.2025 16:00:00 CEST | Press release

Three New Membership Tiers Introduced to Make the Most Advanced Wearable More Accessible and PersonalizedView the WHOOP Launch Announcement here. WHOOP, the human performance company, today introduces WHOOP 5.0 and WHOOP MG — two next-generation wearables designed to unlock a new approach to personal health and longevity. Paired with a redesigned WHOOP experience, the devices offer 14-day battery life in a sleeker, seven percent smaller form - and introduce category-defining features, including Healthspan with WHOOP Age, Heart Screener with on-demand ECG, Blood Pressure Insights, and more. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250508546933/en/ WHOOP Unveils Next Generation WHOOP® 5.0 and WHOOP® MG These innovations arrive at a pivotal moment when ailing health systems cost more and deliver less. WHOOP is advancing a new solution and a better way - one that empowers people to connect their daily decisions to performa

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye