Feds take aim at potent VPNFilter malware allegedly unleashed by Russia. [..] to counter Russian-engineered malware that has infected hundreds of thousands devices. I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't kno…
FBI tells router users to reboot now to kill malware infecting 500k devices
141–150 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#142Earlier quoted context omitted.
A lot of these routers contain tons of oss libraries. Would it then depend on which component caused the bug? It‘s a rabbit hole.
No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…
I can imagine a lot of licensing hassle here. Worked for Technicolor in Edegem, not on routers / STBs but know the challenges. There are tons of libraries used by virtually every device in the field that no company will touch b/c of licensing hell.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#143Feds take aim at potent VPNFilter malware allegedly unleashed by Russia. [..] to counter Russian-engineered malware that has infected hundreds of thousands devices. I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't kno…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#144Earlier quoted context omitted.
No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…
You need to bundle mandatory, sizable insurance as a requirement for getting the license to sell/not selling illegally (i.e., treat the device as illegal as an insurance provider who is not licensed to sell insurance, not as an unlicensed medical doctor). The insurance would make the vendor fix his shit. And he can't just chicken out. Make some way for sufficiently large companies to self-insure, or they will be mad.…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#145Earlier quoted context omitted.
> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…
I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…
There is a line somewhere, and beyond that line is negligence. A developer exposing a potential vulnerability in an internal service that does not handle sensitive information is clearly not across that line, a company that creates routers that constantly have serious holes, that handle sensitive information, seems clearly on the other side.
Deciding exactly where that line exists is obviously complex.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#146Earlier quoted context omitted.
Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost…
> after being rooted by 4 lines of JavaScript Could you provide any sort of source for this extraordinary claim of yours?
[1] https://twitter.com/natashenka/status/861748397409058816
[2] https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#147Earlier quoted context omitted.
802.11g actual max throughput is 22Mbps, assuming you don’t live in an apartment.
It's usually 802.11ac EDIT: oops, thanks
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#148Feds take aim at potent VPNFilter malware allegedly unleashed by Russia. [..] to counter Russian-engineered malware that has infected hundreds of thousands devices. I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't kno…
Another article mentioned an rc4 implementation that had been tied to a previous Russian State sponsored cyber attack. (Sorry, am mobile, don't have the link).
BlackEnergy is a toolkit that has been used for years by various criminal outfits. In the summer of 2014, we noted that certain samples of BlackEnergy malware began targeting Ukranian government organizations for information harvesting. These samples were identified as being the work of one group, referred to in this document as “Quedagh”, which has a history of targeting political organizations.
The only way I see how anybody could conclude from "APT uses a black market toolkit" to "Anybody using this toolkit is that APT" is: clickbait.
[0] https://www.us-cert.gov/sites/default/files/publications/AR-...
[1] https://www.f-secure.com/documents/996508/1030745/blackenerg...
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#149Consumer routers should be self-updating, along the lines of the CoreOS Update Philosophy: https://coreos.com/why/#updates
All connected devices should be similar. IoT included.
This is insane.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#150Earlier quoted context omitted.
> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.
This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.