Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

151–160 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#151
post #121

Earlier quoted context omitted.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

From the GPL:

   This program is distributed in the hope that it will be useful,
    but WITHOUT ANY WARRANTY; without even the implied warranty of
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
    GNU General Public License for more details.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#152
post #121

Earlier quoted context omitted.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

If you install someone's free plastic brake pads, you're at fault for whatever happens - and if someone offers to give you something for free and you agree, they don't have to follow through. If you buy them, there's an implied contract that you will receive them. In that implied contract, our society has also inserted "and they won't kill you." The idea that every time a dollar changes hands an implied contract is m…

That's not how liability works at all. That's an idealistic interpretation of the law that has never actually existed.

It does not matter if you charge for your service or product, nor how much you charge, you can still be found criminally negligent or reckless if it kills people and your actions played an important role. There are very few exceptions to that.

In civil terms it's far more straight forward: if your free brakes kill people, you will be sued for it (almost guaranteed). From there they will attempt to prove that you were negligent regarding the quality of the free brakes you created.

You give away thousands of free chicken sandwiches, that without your knowledge happen to contain bacteria that causes food poisoning and ends up killing several people. You did a very poor, careless job at food prep (similar to the dangerously manufactured brakes). You're almost guaranteed to be pursued criminally and civilly for the deaths.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#153
post #150
post #121

Earlier quoted context omitted.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

When you use free software, you are tied by its license which says: 15. Disclaimer of Warranty. THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY…

Sure and so does most nonfree software.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#154

What's a good affordable router well supported by Tomato/OpenWRT, these days? (put differently: 2018's version of the Linksys WRT54G :) From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its…

Just search for WRT54GL on Amazon. It's selling for $34.99, which is pretty affordable. N.B. the WRT54G doesn't work with Tomato.

At least get a WRT841N, they are like 15$+sales tax, unless you get the wrong vendor. Less if you find refurb's or buy bulk. They are the main workhorse for our local mesh network, with WRT1043 devices handling encrypted uplinks due to the lack of speed with chacha/poly running on the former (think under 10Mbit/s). Don't worry, they do handle advanced mesh routing algorithms at line rate, e.g. 2x2 mimo 802.11n and 100BASE-T (4+1 ports). E.g., they handle mesh domains of about a thousand nodes before one needs to split, and mostly due to L2 traffic starting to hog the slower links (it's an L2 mesh).

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#155

Earlier quoted context omitted.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

Carmakers will not be liable if I break your brakes. Why should your router manufacturer be liable if I break your router? Clearly in both cases the company failed to manufacture a secure enough product.

One difference: you can repair your brakes, or replace them, without having to get a new car. Most routers do not have updates available after the first one or two patches, and you can't even install your own OS on most. Your only options are: live with it, or buy a complete new router.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#156

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

Considering the nation state initiating this shit is barely being punished, it seems absolutely premature to even start down this avenue.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#157
post #97

Earlier quoted context omitted.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

This is going to be really, really hard without turning into a mess. Software is complex, and bad software even more so, and an integrated hardware/software system is even worse. Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. And even assuming we have a definition of 'infrastructure software' and a wa…

> Software is complex, and bad software even more so, and an integrated hardware/software system is even worse.

You nailed the problem here, though you don't seem to realize it. Yes, software is very complex. Maybe it should be made simpler instead of buggier.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#158
post #56
post #46

Earlier quoted context omitted.

Cloud Key, USG, Switch 8 POE, and two AP-Lites. The UniFi console makes management easy compared to the edge router UI. I also have one of those but it’s just sitting right now.

I'd be wary of any Ubiquiti network kit. I only trust their APs. The ERL for example is an awful router - it has had a firmware issue for years now where it causes persistent packet loss due to reordering incoming packets. I discovered these problems in my own testing, and there is a giant thread on the forums about it which I helped kick off. The ER-X is the only thing that seems to work properly. Their switches are…

How large do you want the switch to be? Where I am, if I download something form google drive, I get _major_ bufferbloat on the downstream, I suspect because everthing except the last PHY link to my laptop (on a LAN port) handles at least 1Gbit, but the switch is still a little old-ish and won't do more than fast Ethernet. Please, for god's sake, either drop packets or use fq-codel or something similar, but don't use a large-ish, blind fifo that only listens to his expelicit QOS settings. I wan't my mosh session to be responsive even if there is a large _inbound_ filetransfer. (note that this is textbook bufferbloat, just in the reverse direction from the usual residential situation)

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#159

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

I don't think they should be fined, but they should be required to fix security vulnerabilities. Default passwords are a vulnerability, and defective by design is not an excuse... My Netgear router came with a secure unique password printed on a card, an internal-only admin panel, and UPnP disabled by default. It's not hard.

Yeah admin panels should never hit the internet unless you truly know wth you're doing in which case you can figure out what to do to put it online anyway.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#160
post #97

Earlier quoted context omitted.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

This is going to be really, really hard without turning into a mess. Software is complex, and bad software even more so, and an integrated hardware/software system is even worse. Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. And even assuming we have a definition of 'infrastructure software' and a wa…

Perhaps a “UL Labs” type of solution for software, so that if your software and organization are certified according to the current standard, then your liabilities would be reduced?

And yes, organizations and versions of software would have to be recertified on a regular basis.

You would want software versions to be able to be certified quickly and through an automated process, but there is already some best practice in this space — it’s just unevenly distributed.

Post reply on HN