Earlier quoted context omitted.
Cloud Key, USG, Switch 8 POE, and two AP-Lites. The UniFi console makes management easy compared to the edge router UI. I also have one of those but it’s just sitting right now.
I'd be wary of any Ubiquiti network kit. I only trust their APs. The ERL for example is an awful router - it has had a firmware issue for years now where it causes persistent packet loss due to reordering incoming packets. I discovered these problems in my own testing, and there is a giant thread on the forums about it which I helped kick off. The ER-X is the only thing that seems to work properly. Their switches are…
FBI tells router users to reboot now to kill malware infecting 500k devices
131–140 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#132Earlier quoted context omitted.
> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.
This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.
I'm not sure I agree that making the vendors liable in case of vulnerabilities is the right way. It should probably suffice to require vendors to define a guaranteed product support period, where they are obliged to provide security patches, and then hold them liable if they fail that.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#133Earlier quoted context omitted.
> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.
This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#134Earlier quoted context omitted.
> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…
I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…
In programming, you have true and false, and generally things fall into one or the other category with no human input.
In law, you have concepts like "reasonable", and a whole lot of human input, by design.
So my expectation would be that if software vendors were to be held responsible for bugs in their products, the standard they would be expected to adhere to would be "reasonable expectation of proper functioning", with humans intepreting what "reasonable" means.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#135Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#136Earlier quoted context omitted.
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#137[..] to counter Russian-engineered malware that has infected hundreds of thousands devices.
I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't know that), and that it shares code with the BlackEnergy bot builder toolkit[1], which apparently can be bought on the black market for a decade already.
Neither of the original articles [2,3] mention Russia or any of the Russian APTs, so I'm genuinly interested in better attribution data.
[0] https://amp.thedailybeast.com/exclusive-fbi-seizes-control-o...
[1] https://community.rsa.com/thread/186012
[2] https://blog.talosintelligence.com/2018/05/VPNFilter.html
[3] https://www.symantec.com/blogs/threat-intelligence/vpnfilter...
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#138Earlier quoted context omitted.
No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…
If they were liable there is no profit margin. These products will never exist.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#139Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#140Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.
So when these devices reboot, the FBI is now going to have control of ~500,000 home routers? That's, uh, "reassuring".
In one case they went to court to get an OK from a judge to use the malware and seized domain(s) to then activity remove it from people's computers. They asked a judge because while they can seize a botnet, actually altering people's computers might be seen as bad so it seems they went about it the right way.
If they were going to be all evil I doubt they'd be talking about rebooting routers and such ;)