Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
FBI tells router users to reboot now to kill malware infecting 500k devices
271–280 of 299 posts
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#272Earlier quoted context omitted.
Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent.
> Just as a door being breakable by sufficient force doesn't necessarily mean that the manufacturer is negligent, the fact that some software isn't perfect (i.e. contains bugs) doesn't necessarily mean that the developers are negligent. So you consider well-known and well-understood design limitations to be comparable to unknown defects?
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#273Earlier quoted context omitted.
Absolutely. How many smartphones, Smart TVs, old routers, etc, are out there running insecure software? A shit ton. This is insane.
There is a _huge_ business opportunity for the entrepreneurial mind. Auto update of firmware with proper monitoring and health checks as the roll out continues.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#274Earlier quoted context omitted.
Ubiquiti is overpriced and Mikrotik is underpowered. There are good consumer routers that have 802.11ac for the price of a wired-only Ubiquiti router. If you're comfortable installing OpenWRT, it still offers more capabilities for a lower price than those "prosumer" brands that pretend to be real enterprise-grade stuff.
In my experience, a lot of the MikroTik hardware has been underpowered (struggling to get decent routing and IPSEC performance), so I’ll agree with you on that point. But I’ve found a lot of Ubiquiti hardware to be extremely high quality given how cheap it is. At my office, we installed seven new 802.11ac Ubiquiti access points for as much as it would have cost to add one more 802.11n to our Cisco system (apart from…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#275Earlier quoted context omitted.
If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.
> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#276Earlier quoted context omitted.
And you really don't want malicious actors to push malware to vulnerable firmware without pushing any buttons. When firmware can't fully trust itself (and it cant), the correct option is to deffer ultimate judgement and control to the physical owner.
This wouldn't work with consumer hardware.
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#277Earlier quoted context omitted.
So, 100% of the US population, based on: - the continued militarization of police - classifying 66% of houses as constitution-free border crossings - holding citizens for years without charges or trial - a for-profit prison system that engages in de facto forced labor - criminalizing mental health issues and withholding psychiatric care from insured people. For the record, these things have all been going on for mult…
> 100% of the US population [has an adversarial relationship with the government] You're going many steps beyond simple exaggeration and pushing into extreme hyperbolic territory. > classifying 66% of houses as constitution-free border crossings You're inventing that, such a thing has not been classified by the US Government. If the government - local, state or federal - wants to search your residence in NYC or Los A…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#278Earlier quoted context omitted.
Another article mentioned an rc4 implementation that had been tied to a previous Russian State sponsored cyber attack. (Sorry, am mobile, don't have the link).
You are right. The not-quite-RC4 implementation is mentioned in the Talos post, and it is originating from BlackEnergy. Talos is referencing a US-CERT report of APT28/29[0], which links an F-Secure whitepaper on APTs using "crimeware"[1]: BlackEnergy is a toolkit that has been used for years by various criminal outfits. In the summer of 2014, we noted that certain samples of BlackEnergy malware began targeting Ukrani…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#279Earlier quoted context omitted.
> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…
I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…
Re: FBI tells router users to reboot now to kill malware infecting 500k devices
#280Earlier quoted context omitted.
On the contrary, it's the legal perspective that's most worrying. If every software bug carries the potential for liability, there's no way your legal department will let you have a widely-visible bug tracker, or easily report bugs at all. It'd be much like copyright violations are treated today, where there's a formal process to raise the issue and everyone's specifically trained not to discuss them openly.
What makes software so special in engineering, aside from the amazingly terrible culture we've crafted around it? Change the phrase "software bug" to "engineering error". Then consider the liabilities involved with the manufacture of any real-world-might-kill-someone product. The lawyer's view starts to make a helluva lot more sense.
There is tradition, but a lot of it military in origin, not civil: ARPA net, Grace Hopper, and the first bug, Turing and the Enigma. Stealworking as a military secret in comparison is thousands of years old. And so far, leaked DB content has per the official record not killed anyone ... perhaps a few astronauts but none of the people responsible in place to fix it, as would be the case in a family of incorporated electricians.
We need a code-code.