Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

141–150 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#141
post #137

Feds take aim at potent VPNFilter malware allegedly unleashed by Russia. [..] to counter Russian-engineered malware that has infected hundreds of thousands devices. I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't kno…

Makes you wonder how much is protected sources and methods. One good mole (digital or human, really) would make technical analysis a secondary consideration.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#142

Earlier quoted context omitted.

A lot of these routers contain tons of oss libraries. Would it then depend on which component caused the bug? It‘s a rabbit hole.

No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…

> If the vendor simply used open source libraries, then it needs to review and take responsibility for the code,

I can imagine a lot of licensing hassle here. Worked for Technicolor in Edegem, not on routers / STBs but know the challenges. There are tons of libraries used by virtually every device in the field that no company will touch b/c of licensing hell.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#143
post #137

Feds take aim at potent VPNFilter malware allegedly unleashed by Russia. [..] to counter Russian-engineered malware that has infected hundreds of thousands devices. I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't kno…

Another article mentioned an rc4 implementation that had been tied to a previous Russian State sponsored cyber attack. (Sorry, am mobile, don't have the link).

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#144
post #120

Earlier quoted context omitted.

No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…

You need to bundle mandatory, sizable insurance as a requirement for getting the license to sell/not selling illegally (i.e., treat the device as illegal as an insurance provider who is not licensed to sell insurance, not as an unlicensed medical doctor). The insurance would make the vendor fix his shit. And he can't just chicken out. Make some way for sufficiently large companies to self-insure, or they will be mad.…

At the end of the day, the end consumer will pay.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#145
post #119

Earlier quoted context omitted.

> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…

I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…

I've been shipping production software for years... I think you've misread my post if you think I said that every bug should lead to a lawsuit. It's right in the first part of my first post that we should not be holding every product equally liable for every bug.

There is a line somewhere, and beyond that line is negligence. A developer exposing a potential vulnerability in an internal service that does not handle sensitive information is clearly not across that line, a company that creates routers that constantly have serious holes, that handle sensitive information, seems clearly on the other side.

Deciding exactly where that line exists is obviously complex.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#146
post #60

Earlier quoted context omitted.

Not true. Product liability lawsuits have been around for ages. It's just that the tech industry has been able to escape them, by and large. I think one of the greater injustices in business was Microsoft's avoidance of a lawsuit from their spate of windows malware from roughly 2003-2010. They just sat on their hands and let for-profit A/V companies and nonprofit volunteers secure their platform, while consumers lost…

> after being rooted by 4 lines of JavaScript Could you provide any sort of source for this extraordinary claim of yours?

I'm not sure what the OP was referring to, but off the top of my head there was a security vulnerability in Windows disclosed last year which seems to fit that description[1][2].

[1] https://twitter.com/natashenka/status/861748397409058816

[2] https://bugs.chromium.org/p/project-zero/issues/detail?id=12...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#147
post #114

Earlier quoted context omitted.

802.11g actual max throughput is 22Mbps, assuming you don’t live in an apartment.

It's usually 802.11ac EDIT: oops, thanks

I think you may have misread something: he's stating that the WRT54GL router which was recommended a few comments above, only supports up to 802.11g.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#148
post #137

Feds take aim at potent VPNFilter malware allegedly unleashed by Russia. [..] to counter Russian-engineered malware that has infected hundreds of thousands devices. I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't kno…

Another article mentioned an rc4 implementation that had been tied to a previous Russian State sponsored cyber attack. (Sorry, am mobile, don't have the link).

You are right. The not-quite-RC4 implementation is mentioned in the Talos post, and it is originating from BlackEnergy. Talos is referencing a US-CERT report of APT28/29[0], which links an F-Secure whitepaper on APTs using "crimeware"[1]:

BlackEnergy is a toolkit that has been used for years by various criminal outfits. In the summer of 2014, we noted that certain samples of BlackEnergy malware began targeting Ukranian government organizations for information harvesting. These samples were identified as being the work of one group, referred to in this document as “Quedagh”, which has a history of targeting political organizations.

The only way I see how anybody could conclude from "APT uses a black market toolkit" to "Anybody using this toolkit is that APT" is: clickbait.

[0] https://www.us-cert.gov/sites/default/files/publications/AR-...

[1] https://www.f-secure.com/documents/996508/1030745/blackenerg...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#149
post #127

Consumer routers should be self-updating, along the lines of the CoreOS Update Philosophy: https://coreos.com/why/#updates

All connected devices should be similar. IoT included.

Absolutely. How many smartphones, Smart TVs, old routers, etc, are out there running insecure software? A shit ton.

This is insane.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#150
post #121

Earlier quoted context omitted.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

When you use free software, you are tied by its license which says:

15. Disclaimer of Warranty.

THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 16. Limitation of Liability.

IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

Post reply on HN