Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

161–170 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#161

Earlier quoted context omitted.

A lot of these routers contain tons of oss libraries. Would it then depend on which component caused the bug? It‘s a rabbit hole.

No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…

It would also incentivize vendors to fund critical FLOSS with direct development support on safety-critical functionality.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#162
post #97

Earlier quoted context omitted.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

This is going to be really, really hard without turning into a mess. Software is complex, and bad software even more so, and an integrated hardware/software system is even worse. Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. And even assuming we have a definition of 'infrastructure software' and a wa…

Given the above, consider the future of semi-autonomous and fully-autonomous vehicles.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#163
post #87

Earlier quoted context omitted.

Is there no laws w.r.t. negligence that can be used to punish negligent actors? If a door manufacturer is negligent in their construction of the door and someone gets robbed as a result, in violation of how they expected their door to work, is there nothing currently in the law that could help them?

Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent.

> Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent.

So you consider well-known and well-understood design limitations to be comparable to unknown defects?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#164
post #91

Earlier quoted context omitted.

People in an adversarial relationship with the government they live under would definitely be that segment of the population, yes.

So, 100% of the US population, based on: - the continued militarization of police - classifying 66% of houses as constitution-free border crossings - holding citizens for years without charges or trial - a for-profit prison system that engages in de facto forced labor - criminalizing mental health issues and withholding psychiatric care from insured people. For the record, these things have all been going on for mult…

> 100% of the US population [has an adversarial relationship with the government]

You're going many steps beyond simple exaggeration and pushing into extreme hyperbolic territory.

> classifying 66% of houses as constitution-free border crossings

You're inventing that, such a thing has not been classified by the US Government. If the government - local, state or federal - wants to search your residence in NYC or Los Angeles, they still need a warrant or equivalent court approval. If you were right, that wouldn't be the case.

> holding citizens for years without charges or trial

Show me the specific figures you have on how many times that has occurred in relation to the total number of people that have been arrested over a relevant time frame. It's extraordinarily rare in fact. Using events with very few instances to argue a premise of widespread occurrence, is an immense logic fail.

> a for-profit prison system that engages in de facto forced labor

The government prison complex (the supposedly non-profit oriented mass incarceration machine) is and has been dramatically worse. Over 95% of all people that have been put into prison in the last 40 years, during the war on drugs and mass incarceration phase, have gone into government prisons. During the epic Reagan and Clinton prison boom, the private prison industry had a single digit share of the prison inmates.

And now the incarceration rate is rapidly declining and has been for a decade. We're also pursuing the end of mass incarceration policies, with wide bi-partisan support. And we're also pursuing the end of the war on drugs, via legalization and decriminalization policies all over the US. If I were to use your argumentation approach, that means the expansion of private prisons is causing all of those things and is a good thing: as the private prisons have expanded their market share the last decade, all of those good things have finally started to happen.

> criminalizing mental health issues and withholding psychiatric care from insured people

What share of the population has suffered from the criminalization of which mental health issues? How many insured people are being kept from psychiatric care? Being vague doesn't support your topline premise, it detracts from it.

You've made an extraordinary claim and you didn't support it with much of anything.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#166
post #150
post #121

Earlier quoted context omitted.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

When you use free software, you are tied by its license which says: 15. Disclaimer of Warranty. THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY…

Written by a Fortran IV lawyer.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#167

Just calling out the good guys at Microtik. They patched their router a year before being notified by Cisco.

As a Mikrotik devote, I love the active development and patches being pushed for their Packages and RouterBoard. If anyone maintains a Mikrotik router and/or switches and hasn't heard about the vulnerability and actively patched their systems, then they're completely at fault and putting themselves and possibly they're companies at risk.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#168

Earlier quoted context omitted.

I've read three articles about this today (this one included), and they all specified the same Mikrotik models: - Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072

You're right, I just got down to the bottom of the article and those models are listed there. I don't recall what article I read a day or two ago, but I don't believe it mentioned the specific models.

As GP says, MT boxes all run the same software. The latest release (6.42.3) dated May 24 has suspiciously few bugfixes listed in the changelog. Probably worth updating on the basis the vulnerability fix is in there too.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#169

Earlier quoted context omitted.

damn, enterprise I used to work at uses mikrotik for critical services...

So critical that they'd leave the web interface running on public IPs without firewalling? If not then they're probably safe.

Is it known that the vulnerability is in the web UI? I ask because the CERT report advised to disable/ACL web UI but it didn't (afaik) say that this was the attach vector. They might have just thrown that in as sound general advice.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#170

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

There shouldn't be liability for bugs; there should be liability for negligence. If you ship network-aware code you are negligent if you don't take reasonable steps to prevent bugs and have a reasonable process to patch bugs.
Post reply on HN