Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

121–130 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#121

Earlier quoted context omitted.

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable?

This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#122

Asus is not affected by this but it I still updated the firmware because it was affected by multiple other vulnerabilities... I wonder if computing we'll become secure before I die...

It's an arms race at this point -- exploits are weapons.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#123
post #75
post #51

Earlier quoted context omitted.

Most of these devices are insecure not because the attackers are hyper-sophisticated, but because the software is rushed and a second-thought to the hardware. There is no one (in power) at these companies that cares about crafting quality software. They just care about crafting the bare minimum to make their devices work. I wager that "security" is something fairly far from their mind when they craft this software, w…

It's even worse: most of these companies don't even write the software for the low end consumer hardware. They just license it from a third party, usually in Asia, and pay them to turn features on or off and skin the UI for their branding. It's no surprise that routers from competing manufacturers are vulnerable, since it's all the same under the hood. The companies that sell the finished product have zero insight in…

But there's open source software for this. Why don't they just use that?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#124
post #96

Earlier quoted context omitted.

Is this sarcastic? Locks get picked and doors smashed by burglars multiple times a day.

Architects and civil engineers are held liable. I would imagine we would use a similar system, as someone with no idea how that system works.

The homeowner's insurance regulates the locks and doorframes to be used for external doors, maybe differentiation more or less.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#125
post #51

Earlier quoted context omitted.

No tool manufacturer is responsible for the outcomes of their tools (except the particular function they intended as a warantee)

Most of these devices are insecure not because the attackers are hyper-sophisticated, but because the software is rushed and a second-thought to the hardware. There is no one (in power) at these companies that cares about crafting quality software. They just care about crafting the bare minimum to make their devices work. I wager that "security" is something fairly far from their mind when they craft this software, w…

My router has the password saved in the page source ...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#126

Earlier quoted context omitted.

A lot of these routers contain tons of oss libraries. Would it then depend on which component caused the bug? It‘s a rabbit hole.

No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…

If they were liable there is no profit margin. These products will never exist.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#129
post #127

Consumer routers should be self-updating, along the lines of the CoreOS Update Philosophy: https://coreos.com/why/#updates

Which business or consumer routers can be configured for auto-updates where the vendor limits updates to security fixes only?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#130

Earlier quoted context omitted.

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

Carmakers will not be liable if I break your brakes.

Why should your router manufacturer be liable if I break your router?

Clearly in both cases the company failed to manufacture a secure enough product.

Post reply on HN