Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

211–220 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#211
post #207

Earlier quoted context omitted.

I suppose I just don't know what exploits could be implanted -- are there forms of rootkits that can go undetected? Or have all of these infected firmware been reverse engineered and the exploit in question cataloged? According to ArsTech in this article ( https://arstechnica.com/information-technology/2018/05/hacke... ) the VPNFilter exploit can survive a reboot - so how can a simple reboot disinfect if the only del…

The attack had three components: infection, sign-in with an initiator head-end, and then second/third stage download. As I understand it, from reading around: The FBI took over an "initiator" headend which bootstraps a simpler infection into the actual threat/attack code. The low level infection can't be removed simply, that demands new code from the maker or an OpenWRT type source. The FBI took over the domain namer…

Ok, so it's kind of like burning a line in a forest fire - the fire is still fire, but it's controlled and used in such a way that it should stop the bigger blaze from crossing said line?

Thanks for this insightful response. I know a lot of readers would just tell me to do my own research but this was really enlightening.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#212

Earlier quoted context omitted.

As a Mikrotik devote, I love the active development and patches being pushed for their Packages and RouterBoard. If anyone maintains a Mikrotik router and/or switches and hasn't heard about the vulnerability and actively patched their systems, then they're completely at fault and putting themselves and possibly they're companies at risk.

Honest question: how's their GPL compliance these days?

Some info here: https://forum.lede-project.org/t/mikrotik-gpl-source/6750/12

Which led to this repo: https://github.com/robimarko/routeros-GPL

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#213
post #119

Earlier quoted context omitted.

I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…

I've been shipping production software for years... I think you've misread my post if you think I said that every bug should lead to a lawsuit. It's right in the first part of my first post that we should not be holding every product equally liable for every bug. There is a line somewhere , and beyond that line is negligence. A developer exposing a potential vulnerability in an internal service that does not handle s…

>>>> - What happens if that library is openssl and almost all webservers on the internet are vulnerable?

>>> Everyone deploying it is liable.

> I've been shipping production software for years...

Have you ever shipped software which depends on openssl? If not, then pretend that you have. Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for because you deployed something using openssl?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#214
post #207

Earlier quoted context omitted.

The attack had three components: infection, sign-in with an initiator head-end, and then second/third stage download. As I understand it, from reading around: The FBI took over an "initiator" headend which bootstraps a simpler infection into the actual threat/attack code. The low level infection can't be removed simply, that demands new code from the maker or an OpenWRT type source. The FBI took over the domain namer…

Ok, so it's kind of like burning a line in a forest fire - the fire is still fire, but it's controlled and used in such a way that it should stop the bigger blaze from crossing said line? Thanks for this insightful response. I know a lot of readers would just tell me to do my own research but this was really enlightening.

Nah.. I don't like that metaphor. I think I like this one better.

Back in the day, cable TV was crypted, and people had to have cable TV decoder cards with a key to fit a slot in the receiver. So, in the UK, somebody worked out how to decode the keypair, and you could buy a keycard in the pub for like GBP50, instead of paying the cable company GBP100/mo. But the cards, they have a fixed life. They don't last forever, you have to keep coming back for more.

The real fix is obviously to fix the crypto, but there are a million receivers out there. Nobody has time to go round each one. So what the cops did, is find where the faked out keycards are being printed and shut down the print house, so imagine... if you then get the city electric company to power cycle every house, when its receiver reboots, it needs a new keycard, but they can't get one any more, 'cept from the cable company. Fixed? No, but you cut the problem off at the knees.

Oh wait: we all wanted those sweet stolen keycards. I gotta think of a better metaphor :-)

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#215

Earlier quoted context omitted.

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

> Yeah, definitely. Especially for infrastructure.

The problem is that this is entirely useless.

There are basically two classes of software company.

The first is the likes of Google or Mozilla. They, as a rule, do the right thing. All humans make mistakes but the mistakes are understandable and there isn't really much we can expect to incentivize them to do that they aren't already doing.

The second is Fly By Night IoT Device Corporation. They make garbage, it has a million vulnerabilities, but they're judgment proof. If you sue them they just file for bankruptcy. Many of them don't even exist within your jurisdiction and the ones that do are likely to have gone out of business by the time you get around to filing a lawsuit. You might as well pass a law imposing liability on raccoons for spilling garbage.

There is a much better solution to all of this. Fund a government agency to search for vulnerabilities in popular products and report the vulnerabilities to the developers. Then remove products from the market that have had known unpatched vulnerabilities for more than a limited amount of time, and require updates to be offered to any product sold in the past X number of years.

Because it's a lot easier to get a company to spend $5000 in developer time to fix their garbage than to get them not to avoid a twelve billion dollar lawsuit by filing for bankruptcy -- which only leaves all their customers in the lurch with hardware that will then never be patched.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#216

Earlier quoted context omitted.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

> Yeah, definitely. Especially for infrastructure. The problem is that this is entirely useless. There are basically two classes of software company. The first is the likes of Google or Mozilla. They, as a rule, do the right thing. All humans make mistakes but the mistakes are understandable and there isn't really much we can expect to incentivize them to do that they aren't already doing. The second is Fly By Night…

Cisco is a Fly By Night IOT Corporation? Linksys?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#217

Earlier quoted context omitted.

I've been shipping production software for years... I think you've misread my post if you think I said that every bug should lead to a lawsuit. It's right in the first part of my first post that we should not be holding every product equally liable for every bug. There is a line somewhere , and beyond that line is negligence. A developer exposing a potential vulnerability in an internal service that does not handle s…

>>>> - What happens if that library is openssl and almost all webservers on the internet are vulnerable? >>> Everyone deploying it is liable. > I've been shipping production software for years... Have you ever shipped software which depends on openssl? If not, then pretend that you have. Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for bec…

Yes, I have.

> Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for because you deployed something using openssl?

This is a really ridiculous question. I've already stated that these things are complicated - you're asking for a hard number?

Companies should take responsibility for their users data, which includes understanding the risk involved in third party libraries they use.

If they're concerned about fees, invest in the security of the project you're using.

But this is all based on some hypothetical, undefined 'law', so arguing about the specific mechanics is pointless.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#218

Earlier quoted context omitted.

I've been shipping production software for years... I think you've misread my post if you think I said that every bug should lead to a lawsuit. It's right in the first part of my first post that we should not be holding every product equally liable for every bug. There is a line somewhere , and beyond that line is negligence. A developer exposing a potential vulnerability in an internal service that does not handle s…

Why would routers be handling sensitive information? You're doing something seriously wrong. Perhaps you should be fined for not encrypting your communications?

wat

you mean like, say, routing all of the traffic from my system to the internet?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#219

Earlier quoted context omitted.

> Yeah, definitely. Especially for infrastructure. The problem is that this is entirely useless. There are basically two classes of software company. The first is the likes of Google or Mozilla. They, as a rule, do the right thing. All humans make mistakes but the mistakes are understandable and there isn't really much we can expect to incentivize them to do that they aren't already doing. The second is Fly By Night…

Cisco is a Fly By Night IOT Corporation? Linksys?

> Cisco is a Fly By Night IOT Corporation? Linksys?

Cisco hasn't owned Linksys in years and Linksys itself is tiny. This kind of liability absolutely could bankrupt them.

And they're one of the major players. There are companies making this kind of hardware with like twelve employees.

The barrier to entry is so low that even individuals commonly make one-offs from scratch for personal use.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#220
post #119

Earlier quoted context omitted.

> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…

I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…

Most routers are shit. Manufacturers slap together a version of linux, some crappy web ui, and ship it. It is unlikely to receive any updates or patches.

Manufacturers should be liable for the poor quality of the devices they make. Software vulnerabilities are a fact of life, because there is no driving force to be better. Strict liability would force the industry to be more like other engineering disciplines.

Post reply on HN