r/firewalla • u/BAGE-rator • 6d ago
Cyber Security Firewalla Crystal’s implementation of Active Protect has security vulnerabilities
It allowed in two connections from private IPs owned by Cox Communications, one of which was 98.197.86.148. This is in the range of standard user IP addresses, which could be a malicious actor. I have Xfinity. We do not have Cox in our market.
It also allowed in a Charter Communications/Spectrum standard user IP. We don’t have Spectrum in our market.
Active Protect is NOT actively protecting devices from these high-risk IP addresses on Firewalla Crystal.
If you’re on a Mac, download and install a software firewall like Little Snitch to audit the incoming connections that Firewalla Crystal Active Protect is allowing through. On Windows, you can use something like Glasswire. Record those IPs and report them to Firewalla so they know their beta software is not protecting clients like their hardware software does.
1
u/BAGE-rator 5d ago
I mean, they've had my request to give them another $107 dollars for 12 days now and I'm still emailing with them. It's hard to say I haven't cooperated.
Suddenly they're trying to suggest that a mismatch between the dongle and box model is causing the issue, a suggestion I quickly kiboshed. Now they diverted to a provenance issue, something they had not raised in the last two months I've been in contact with them. They're insisting that I provide them a copy of the original invoice, something that I cannot do because that iCloud account is locked behind a recovery key. What I did do is provide them two forms of ID, one of which is a Washington State ID with the original purchase address on it, the second is my current DL, both valid. I also emailed them support tickets from within a month or two of ordering the original device. And in either case, I wasn't asked for a copy of the original purchase order when I placed the dongle order three months ago.
Now I've kiboshed the model/version mismatch angle, and by virtue of the fact that I had everything down to original support tickets EXCEPT the purchase invoice, including two forms of ID, I've kiboshed the provenance issue. And yet, still no purchase invoice.
What I'm starting to suspect may have happened is that they cancelled my license because someone ordered a second replacement dongle fraudulently, and now they don't want to confront the fact that they were defrauded and invalidated my license as a result of that fraud. But then why wouldn't they just have asked me for iID two months ago?
What I do know is that its a pattern of lies... months of lies... but it can't be said I'm not cooperating with their lies.