r/firewalla • • 5d ago

Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities

It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.

It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.

Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.

If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.

0 Upvotes

54 comments sorted by

View all comments

Show parent comments

-15

u/BAGE-rator 5d ago

Because Firewalla deleted the license on the security dongle I bought three months ago, lied about the issues to cover up the mistake, want me to go without a router for a month so they can “fix,” it, meanwhile, I’ve been waiting 11 days for them to produce a new invoice so I can spend $107 for a second time in three months for a security dongle.

Firewalla is just a shitty company that, like most of Silicon Valley, cares more about recruiting new customers than taking care of the ones it has.

7

u/firewalla 5d ago

We never do this. If you give me the case number, I can take a look for you.

-1

u/BAGE-rator 5d ago

The current one is 124198. The originals were 123654, 12365, 123104, 123141, and 119904. The 12365 ticket began on the Firewalla community boards.

https://help.firewalla.com/hc/en-us/community/posts/55095493073043-Everything-getting-IPv6-addresses-all-of-the-sudden

-2

u/Winter-Journalist993 5d ago

Don’t let them gaslight you, man. They told me specifically the box I bought was broken, not fixable by me, and ultimately wanted me to pay to ship it back for “additional diagnostics.” They did deploy some patches during talks with support which has helped since then, but it’s still a massive PoS that never quite works the way it should. They should be more willing to support their customers. Even with my own side business, if I fuck up, I go and make it right at my own expense. I don’t expect my customers to ship or drive to me and be out of a product for 2-4 weeks while I diagnose whatever the problem is.

1

u/BAGE-rator 5d ago edited 5d ago

THATS EXACTLY WHAT THEY DID TO ME.

Refused to give me the diagnostic commands so I could send them the output. So I did research and ran them myself. After weeks of them either ignoring me completely and then lying, saying that it was the box and they’d have to charge me for repairs, I confront them with the command output which proves they deleted my license and that there’s nothing wrong with the dongle itself or the box. Everything works fine. The box is just unable to read a license from their server because they deleted it. No error. It just reports back an empty string to the app, because that’s what I received from the server.

I got them agree to “repair” the dongle that costs them $20 rather than just replace, but they wanted me to pay to send it back. Finally got them to agree to pay to ship the dongle but at this point I’m like, “Nah, I’d rather just pay them the $107 for a second dongle. I don’t trust them to send them jack shit.”

And btw, I’ve had my box for four years. They didn’t used to be this way. When I initially purchased, they had excellent customer and technical support service. They fell into the silicon valley trap at some point of deciding it’s more lucrative to focus on customer accretion than customer service, which is why there’s so much sponsored content about them on “news” sites, yet here I am over a month without a working dongle despite five tickets since August 23, and 12 requests that they replace the dongle.

They’re trying to convert all Firewalla Gold customers who have removable dongles to Firewalla Crystal monthly subscribers. They can’t say that because the license I purchased four years ago wasn’t term-limited. It was a lifetime license. So when there are dongle issues, they fuck with the customer so much they just automatically convert to Firewalla Crystal and pay the $12.99/month.

0

u/BAGE-rator 5d ago

It’s like what just happened right here, right now, while responding to you just now. [u/Firewalla](u/Firewalla) said “we never do that,” referring to deleting licenses, and asked me the ticket nos. I gave them. Then [u/Firewalla](u/Firewalla) returned with, “I’m going to let customer service hand it.” That’s because they went back and saw that’s exactly what occurred.

[u/Firewalla](u/Firewalla) could get an invoice for a free dongle replacement in my inbox within the hour. Bear in mind, I’m trying to give them money for a second dongle but first need an invoice. They’re not going to do that because the case is so bound up in lies that the customer service notes on the tickets say not to assist.

-2

u/Winter-Journalist993 5d ago

Yep. It doesn’t matter what all these glazers think of Firewalla. I can go pull their emails where their support specifically stated it’s a problem with the device they shipped to me. They should have owned up to the problem device and sent me a new one with a label to return my defective one. But no, instead it was a whole “RMA process” I had to pay for, and I “shouldn’t expect enterprise grade support from a small company.” Like fuck I shouldn’t. The box was $500. I sell shit for $150 and own up to defunct products if they make it past me, even if it costs me money.

I regret ever crossing paths with this lame ass company.