cybersecurity
31 SujetsBlock incoming connections and ports - ZyXEL EMG2926-Q10A
Greetings, On the Videotron modem ZyXEL EMG2926-Q10A, does anyone know how to block all incoming traffic (from the internet to the modem) and how to lock all ports from incoming connections? When login into the modem via a web browser and the clicking on: Expert Mode > Configuration (left side of the screen) > Security > Firewall > Services > Add firewall rule , I cannot find the option for “incomming” traffic or “outgoing” traffic. There is only the “Source_IP_Address” which I suspect is the way to block the incomming connections to the modem. From my point of view, one would have to list all IP addresses as “source” by stating an IP address range such as 0.0.0.0 to 255.255.255.255. 1) Is that the way to block incoming connections to the router? 2) What is the correct way to type/state an IP address range in the EMG2926-Q10A? Regarding blocking the ports on the modem from incoming connections: 3) is that within: Expert Mode > Configuration > Security > Firewall > Services > Add firewall rule > SourcePortRange that ports 0 to 65535 have to be typed in to prevent people outside the network from scanning/using ports on the modem? Lastly, its not clear if creating a firewall rule (as stated above; “Add a firewall rule”) will create a rule that “allows” or “block” the traffic. 4) Does firewall rules block or allow traffic? Thanks in advance, Regards, B161Vues0like4CommentairesIPv6 et Helix en mode pont / IPv6 & Helix Bridge Mode
Ce sujet est revenu à plusieurs reprises au fil des années, avec des niveaux de résolution variables. Je pense que plusieurs clients — particulièrement ceux d’entre nous qui travaillent dans le domaine des technologies — attendent toujours une réponse claire et officielle de Vidéotron concernant la prise en charge d’IPv6 sur des routeurs et pare-feu gérés par le client. Pour quiconque dépasse une configuration résidentielle de base, la passerelle Helix n’est généralement pas utilisée comme routeur principal ou pare-feu en périphérie du réseau. Plusieurs clients utilisent plutôt des solutions plus avancées comme Unifi Gateway, pfSense, OPNsense, IPFire ou VyOS. Avec IPv4, tout fonctionne très bien lorsque le modem Helix est configuré en mode pont (bridge mode). Par contre, du côté d’IPv6, la situation demeure non résolue. Pendant un certain temps, Vidéotron offrait le 6rd comme solution de contournement, mais plusieurs utilisateurs ont rapporté des résultats inconsistants, ce qui explique peut-être pourquoi cette option a finalement été abandonnée. Nous voilà rendus en 2026, et il ne semble toujours pas y avoir de solution documentée ou officiellement supportée. Pourtant, une solution existe clairement sous une forme ou une autre, puisque la passerelle Helix est capable d’attribuer des adresses IPv6 lorsqu’elle fonctionne en mode routeur. La question est donc simple : pourquoi la configuration requise pour le mode pont n’est-elle pas documentée publiquement? TL;DR En 2026, comment un client utilisant une passerelle Helix en mode pont peut-il configurer IPv6 sur son propre routeur ou pare-feu? ---- This topic has come up several times over the years, with varying degrees of resolution. I think many customers—especially those of us in the tech industry—have been waiting for a clear and official response from Videotron regarding IPv6 support on client-managed border routers and firewalls. For anyone beyond the most basic home setup, the Helix gateway is often not used as the primary border router or firewall. Many customers rely on more advanced solutions such as Unifi Gateway, pfSense, OPNsense, IPFire, or VyOS. With IPv4, this works perfectly fine when the Helix modem is placed in bridge mode. IPv6, however, is still unresolved. There was a period when Videotron offered 6rd as a workaround, but many users reported inconsistent results, which may explain why it was eventually discontinued. Fast-forward to 2026, and there still does not appear to be a documented or supported solution. Yet one clearly exists in some form, since the Helix gateway is capable of provisioning IPv6 when operating in router mode. This raises a simple question: why is the required configuration for bridge mode not publicly documented? TL;DR In 2026, how can a customer using a Helix gateway in bridge mode configure IPv6 on their own firewall/router hardware?174Vues0like2CommentairesWhen will Videotron deploy the November 1, 2025 Android Security Update?
CRITICAL: Network Signaling Issue Preventing Android Security Updates (Re: CVE-2025-48593 & S25/S20 FE) Hello, I am writing to inquire about the planned deployment timeline for the most recent Android Security Bulletin, dated November 1, 2025, and to report a severe, reproducible issue that appears to be preventing prompt security updates for Samsung devices on the Videotron network. My devices' security patch levels are significantly behind, which is unacceptable given the critical nature of the fixes included in monthly updates. I am specifically looking for information regarding the patch that includes the fix for the vulnerability identified as CVE-2025-48593. While the CVE status is currently Reserved on cve.org, its inclusion in the official bulletin emphasizes the need for a prompt update. For reference, the official sources for this update are: Google Android Security Bulletin - November 1, 2025: https://source.android.com/docs/security/bulletin/2025-11-01 CVE Record for CVE-2025-48593: https://www.cve.org/CVERecord?id=CVE-2025-48593 My Observations & Urgent Questions I have two Samsung devices exhibiting the same strange behavior, confirming a likely issue with the Videotron network: Device 1 (Samsung S20 FE): This device is currently stuck on the July 1, 2025 security patch. The industry standard is that the October 1st patch has already been released for this model. Device 2 (Samsung S25 Flagship): This newer, monthly-supported device was also stuck on the July 1, 2025 security patch. It only found and installed the October 1, 2025 patch after I manually removed Videotron as the network carrier in the phone's settings and then added it back. Based on this testing, I have two critical questions for the Videotron team: When is Videotron planning to roll out the November 1, 2025, security patch to its flagship devices? A four-month security gap is a serious security failure, and a clear, confirmed deployment date is required. Is there a known, systemic issue with how Videotron's network is signaling the latest available security patch to Samsung Android devices? Since two separate phones only received the available update after the network connection was forcibly reset (by removing/re-adding the carrier), this strongly suggests that the automatic, over-the-air (OTA) check triggered by the network is failing to register the update's availability. This affects all users who are simply waiting for the update notification. I urge the Videotron technical team to investigate this network-level signaling problem immediately. Thank you for your urgent attention to the security of your customers' devices. Thank you.Résolu194Vues0like1CommentaireTop 7 password managers
Nowadays, having too many accounts and too many passwords to keep track of is a universal problem. As a result, people have adopted a poor habit: using the same password every time to make it easier to remember. Using a password manager is a far better option. The idea is to enter all your identifiers into a highly secure database (think a digital safe). There are two password manager categories: local and cloud based. Local managers Local password managers like KeePassXC and PasswordSafe offer you complete control over your data. They are free, open source, and don’t require an Internet connection. A modern, multiplatform version of KeePass, KeePassXC is recommended for its compatibility with Windows, macOS, and Linux. These tools are ideal for advanced users who want to store their passwords locally, without having to rely on the cloud. Reliability and security of the source code KeePassXC, like KeePass, from which it is derived, is an open-source software. Its source code is accessible publicly, and security experts can audit it. In fact, the KeePass manager for Windows was audited by the European Commission EU-FOSSA project in 2016, and no critical vulnerabilities were detected. This helps guarantee that the source code is exempt of any major faults or backdoors. There are several KeePass clones and derivatives on Windows, Linus, iOS, and Android platforms. Using only official versions, such as KeePassXC, is crucial, as they are actively monitored and regularly updated. This provides better security and greater compatibility. Cloud-based managers Cloud-based password managers keep your password database on the cloud. These managers constitute an interesting compromise between user-friendliness and security. When properly implemented, they are considered safe and offer many benefits: Compatibility with all modern browsers Synchronization of your passwords on all your devices, accessible at all times Possibility of sharing certain passwords with other users (spouse, children, colleagues, etc.) Monitoring of accesses to your account, defining of trusted devices and, occasionally, an emergency contact should an unexpected situation arise Advanced features, such as detection of compromised passwords or dark-web monitoring in the case of certain managers Of all the recommended options, some should, however, be avoided. To avoid: LastPass Although LastPass has long been a key player in the password manager sector, several security incidents that occurred in 2022 have compromised the trust of users and experts alike. Despite efforts to reinforce the security of LastPass, some breaches have had significant repercussions, such as hacking of encrypted data and digital assets. For this reason, we recommend choosing more robust and transparent solutions, like Bitwarden, 1Password, Dashlane, or NordPass. Can the provider access my passwords? The provider cannot read your database, as it is encrypted and unreadable without your master password–whether stored locally or in the cloud. All encryption and decryption operations are carried out locally on your device, and your master password is in no way transmitted to the provider. If the technology is properly implemented according to the best industry-standard encryption and security practices, it is impossible for the provider—and a potential hacker—to decrypt your passwords without your master password. That’s why it’s crucial that you choose a reputable, transparent, and independently audited manager. Essential tips Here are a few habits to adopt to maximize the security of your passwords: Use a long (15-character-or-more), unique master password : A robust master password is the cornerstone of your security. A passphrase: a memorable sequence of at least four words (with or without spaces). A complex password: composed of uppercase and lowercase letters, numbers, and special characters. Enable two-factor authentication (2FA) : This provides added security, even if your password is compromised. Never reuse your passwords : If a password is compromised on one site, all other accounts using the same password are at risk. Keep an eye out for data leaks and change any password that has been compromised : Certain managers automatically alert you if one of your passwords appears in a data leak. Use a reputable, transparent manager : Check the provider’s security audits, confidentiality policy, and reputation. Keep your master password in a safe place : If you lose it, you could lose access to all your passwords. Avoid saving your passwords in your browser : The security offered by specialized managers is far more superior than that of browsers. Comparison charts Here is a comparison chart of the main solutions, to help you choose the one that best suits your needs. Note that some free password managers may limit the number of passwords you can store. We divided the managers into two categories: local solutions, for complete control of your data, and cloud-based solutions, for simplified synching. Comparison of local password managers Manager Cost Platforms Encryption Secure sharing User friendliness KeePassXC $0 Windows, macOS, Linux AES-256 Via third parties Average to good PasswordSafe $0 Windows Blowfish/Twofish Not integrated Basic Comparison of cloud-based password managers Manager Cost Platforms Encryption Secure sharing User friendliness Bitwarden Free to $56/year Windows, macOS, Linux, Android, iOS AES-256 Yes Good 1Password $3.75 – $5.99/month All platforms AES-256 Yes Excellent Dashlane $0 – $10/month All platforms AES-256 Yes Very good NordPass $0 – $4.59/month All platforms XChaCha20 Yes Good Proton Pass $0 – $12.49/month All platforms XChaCha20 Yes Good1,1 kVues0like2Commentaires