Earlier quoted context omitted.
A lot of these routers contain tons of oss libraries. Would it then depend on which component caused the bug? It‘s a rabbit hole.
No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…
FBI tells router users to reboot now to kill malware infecting 500k devices
161–170 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#162Earlier quoted context omitted.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
This is going to be really, really hard without turning into a mess. Software is complex, and bad software even more so, and an integrated hardware/software system is even worse. Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. And even assuming we have a definition of 'infrastructure software' and a wa…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#163Earlier quoted context omitted.
Is there no laws w.r.t. negligence that can be used to punish negligent actors? If a door manufacturer is negligent in their construction of the door and someone gets robbed as a result, in violation of how they expected their door to work, is there nothing currently in the law that could help them?
Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent.
So you consider well-known and well-understood design limitations to be comparable to unknown defects?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#164Earlier quoted context omitted.
People in an adversarial relationship with the government they live under would definitely be that segment of the population, yes.
So, 100% of the US population, based on: - the continued militarization of police - classifying 66% of houses as constitution-free border crossings - holding citizens for years without charges or trial - a for-profit prison system that engages in de facto forced labor - criminalizing mental health issues and withholding psychiatric care from insured people. For the record, these things have all been going on for mult…
You're going many steps beyond simple exaggeration and pushing into extreme hyperbolic territory.
> classifying 66% of houses as constitution-free border crossings
You're inventing that, such a thing has not been classified by the US Government. If the government - local, state or federal - wants to search your residence in NYC or Los Angeles, they still need a warrant or equivalent court approval. If you were right, that wouldn't be the case.
> holding citizens for years without charges or trial
Show me the specific figures you have on how many times that has occurred in relation to the total number of people that have been arrested over a relevant time frame. It's extraordinarily rare in fact. Using events with very few instances to argue a premise of widespread occurrence, is an immense logic fail.
> a for-profit prison system that engages in de facto forced labor
The government prison complex (the supposedly non-profit oriented mass incarceration machine) is and has been dramatically worse. Over 95% of all people that have been put into prison in the last 40 years, during the war on drugs and mass incarceration phase, have gone into government prisons. During the epic Reagan and Clinton prison boom, the private prison industry had a single digit share of the prison inmates.
And now the incarceration rate is rapidly declining and has been for a decade. We're also pursuing the end of mass incarceration policies, with wide bi-partisan support. And we're also pursuing the end of the war on drugs, via legalization and decriminalization policies all over the US. If I were to use your argumentation approach, that means the expansion of private prisons is causing all of those things and is a good thing: as the private prisons have expanded their market share the last decade, all of those good things have finally started to happen.
> criminalizing mental health issues and withholding psychiatric care from insured people
What share of the population has suffered from the criminalization of which mental health issues? How many insured people are being kept from psychiatric care? Being vague doesn't support your topline premise, it detracts from it.
You've made an extraordinary claim and you didn't support it with much of anything.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#165Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#166Earlier quoted context omitted.
This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.
When you use free software, you are tied by its license which says: 15. Disclaimer of Warranty. THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#167Just calling out the good guys at Microtik. They patched their router a year before being notified by Cisco.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#168Earlier quoted context omitted.
I've read three articles about this today (this one included), and they all specified the same Mikrotik models: - Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072
You're right, I just got down to the bottom of the article and those models are listed there. I don't recall what article I read a day or two ago, but I don't believe it mentioned the specific models.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#169Earlier quoted context omitted.
damn, enterprise I used to work at uses mikrotik for critical services...
So critical that they'd leave the web interface running on public IPs without firewalling? If not then they're probably safe.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#170Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.