Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

271–280 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#271

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

It makes no sense from a capital perspective. The software provider would need to hold risk capital (money in the back pocket) like a bank or insurance company, but in proportion to the revenues of the companies they sell the software to, not the software company itself.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#272

Earlier quoted context omitted.

Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent.

> Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent. So you consider well-known and well-understood design limitations to be comparable to unknown defects?

Should the manufacturers of locks exhibited in DEFCON's lockpick village be sued for negligence? Are they getting sued for it?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#273
post #149

Earlier quoted context omitted.

Absolutely. How many smartphones, Smart TVs, old routers, etc, are out there running insecure software? A shit ton. This is insane.

There is a _huge_ business opportunity for the entrepreneurial mind. Auto update of firmware with proper monitoring and health checks as the roll out continues.

Yes, technically; the reason it doesn't exist is that "proper monitoring" would highlight how atrocious everyone's development practices are. Oh, and this would accidentally plug all the holes "everyone" variously uses when they're found helpful... generally you want to attract military funding, not scare it away :D

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#274

Earlier quoted context omitted.

Ubiquiti is overpriced and Mikrotik is underpowered. There are good consumer routers that have 802.11ac for the price of a wired-only Ubiquiti router. If you're comfortable installing OpenWRT, it still offers more capabilities for a lower price than those "prosumer" brands that pretend to be real enterprise-grade stuff.

In my experience, a lot of the MikroTik hardware has been underpowered (struggling to get decent routing and IPSEC performance), so I’ll agree with you on that point. But I’ve found a lot of Ubiquiti hardware to be extremely high quality given how cheap it is. At my office, we installed seven new 802.11ac Ubiquiti access points for as much as it would have cost to add one more 802.11n to our Cisco system (apart from…

Pointing out that Ubiquiti equipment is cheaper than Cisco isn't saying much. With regards to the products that are actually relevant to this discussion—the stuff that's a reasonable alternative to typical consumer networking equipment—Ubiquiti definitely isn't the more affordable choice than the competition.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#275

Earlier quoted context omitted.

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

Since you cannot stop someone from using open source, the liability is on the user to verify the source. If the source is closed, guess what ...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#276

Earlier quoted context omitted.

And you really don't want malicious actors to push malware to vulnerable firmware without pushing any buttons. When firmware can't fully trust itself (and it cant), the correct option is to deffer ultimate judgement and control to the physical owner.

This wouldn't work with consumer hardware.

Why?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#277
post #91

Earlier quoted context omitted.

So, 100% of the US population, based on: - the continued militarization of police - classifying 66% of houses as constitution-free border crossings - holding citizens for years without charges or trial - a for-profit prison system that engages in de facto forced labor - criminalizing mental health issues and withholding psychiatric care from insured people. For the record, these things have all been going on for mult…

> 100% of the US population [has an adversarial relationship with the government] You're going many steps beyond simple exaggeration and pushing into extreme hyperbolic territory. > classifying 66% of houses as constitution-free border crossings You're inventing that, such a thing has not been classified by the US Government. If the government - local, state or federal - wants to search your residence in NYC or Los A…

At some level you imagine that your head will be safe, stuck so deep in the sand...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#278
post #148

Earlier quoted context omitted.

Another article mentioned an rc4 implementation that had been tied to a previous Russian State sponsored cyber attack. (Sorry, am mobile, don't have the link).

You are right. The not-quite-RC4 implementation is mentioned in the Talos post, and it is originating from BlackEnergy. Talos is referencing a US-CERT report of APT28/29[0], which links an F-Secure whitepaper on APTs using "crimeware"[1]: BlackEnergy is a toolkit that has been used for years by various criminal outfits. In the summer of 2014, we noted that certain samples of BlackEnergy malware began targeting Ukrani…

Clickbait is among the more innocent explanations. Reporters who dutifully parrot what the TLAs tell them get more opportunities to do so. Reporters who don't, in short order aren't writing this sort of article. This is such a basic situation, repeated hundreds of times, yet the resolutely naive will bitterly deny that it ever occurs.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#279
post #119

Earlier quoted context omitted.

> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…

I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…

Take the grand parent comment as written by a consumer, not a producer.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#280
post #241

Earlier quoted context omitted.

On the contrary, it's the legal perspective that's most worrying. If every software bug carries the potential for liability, there's no way your legal department will let you have a widely-visible bug tracker, or easily report bugs at all. It'd be much like copyright violations are treated today, where there's a formal process to raise the issue and everyone's specifically trained not to discuss them openly.

What makes software so special in engineering, aside from the amazingly terrible culture we've crafted around it? Change the phrase "software bug" to "engineering error". Then consider the liabilities involved with the manufacture of any real-world-might-kill-someone product. The lawyer's view starts to make a helluva lot more sense.

Other engineering disciplines are very conservative. Due to age, this doesn't compare well to software.

There is tradition, but a lot of it military in origin, not civil: ARPA net, Grace Hopper, and the first bug, Turing and the Enigma. Stealworking as a military secret in comparison is thousands of years old. And so far, leaked DB content has per the official record not killed anyone ... perhaps a few astronauts but none of the people responsible in place to fix it, as would be the case in a family of incorporated electricians.

We need a code-code.

Post reply on HN