Live data from Hacker News

VirtualBox E1000 Guest-to-Host Escape

github.com

61–70 of 118 posts

Re: VirtualBox E1000 Guest-to-Host Escape

#61

This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

Oracle has a track record of being The Worst about anything.

Re: VirtualBox E1000 Guest-to-Host Escape

#62

This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

There are plenty of other big companies behaving similarly. HP comes to my mind also, but I cannot find the statistics which quantified worst maintainance practices.

Re: VirtualBox E1000 Guest-to-Host Escape

#63
post #52

FTA : >>> a browser opened a malicious website in the guest OS is exploited, a browser sandbox escape is made to gain full ring 3 access, an operating system vulnerability is exploited to pave a way to ring 0 from where there are anything you need to attack a hypervisor from the guest OS. I cracked several games in the end of the 80's but that was nowhere as hard as this seems to be. How do researchers find the time…

> I cracked several games in the end of the 80's but that was nowhere as hard as this seems to be.

There are are many reasons for this. One is that with a game, you already have full access to the program on your disc and can modify it at will, run it infinitely many times, have full access to how it's loaded and run, and analyze it separately. Plus "hacking a game" is not a security vulnerability, and the only person who loses if you add an RCE to your game is you, and possibly the publisher if you crack it.

Re: VirtualBox E1000 Guest-to-Host Escape

#64
post #62

Earlier quoted context omitted.

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

There are plenty of other big companies behaving similarly. HP comes to my mind also, but I cannot find the statistics which quantified worst maintainance practices.

Other companies may be behaving similarly, but Oracle is the perceived worst, and it says something.

Because, they plainly don't hide it and try to be nice, at least.

I also think that they're the worst in the industry.

Re: VirtualBox E1000 Guest-to-Host Escape

#65

The pricing of / evaluation of bug bounties seems to be a problem. Going begging to the vendor of course results in reduced value. Everything tends to be undervalued when there is only one buyer. Also purchase processes tend to be slow when there is only one buyer. It's almost as if there needs to be competition for the sale of the disclosure ... although that would have its own issues of course. Another idea is a pu…

[deleted]

Re: VirtualBox E1000 Guest-to-Host Escape

#66
post #23
post #3

Earlier quoted context omitted.

The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.

You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?

IMO the vendor should employ security researchers so their customers don't have to rely on outside volunteers to expose the bugs in the software they bought. The responsible disclosure talk often is just blame shifting.

Re: VirtualBox E1000 Guest-to-Host Escape

#67
post #3

Earlier quoted context omitted.

The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.

Especially the websites/branding of bugs, like Heartbleed, SHAttered, etc. It seems like researchers do this to propel their own fame, for probably financial motives. I imagine it's pretty lucrative to have been the "co-founder" of Heartbleed just like it is lucrative to be the co-founder of a well-known startup.

There is truth in that but I do think it makes them easier to refer to when you talk about them 5 years later, I still remember Heartbleed. If someone said to me “Hey, remember when CVE-2014-0160 happened?” I would be like what was that? So yeah, the awareness side of it helps

Re: VirtualBox E1000 Guest-to-Host Escape

#68

Earlier quoted context omitted.

Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?

Relevant discussion in another Oracle related post[0]. [0]: https://news.ycombinator.com/item?id=18389481

I do like that post because it summarizes how I feel about Oracle rather succinctly. For your typical FAANG company, the money is the means to the end. But for Oracle, the money is the end to the means.

Re: VirtualBox E1000 Guest-to-Host Escape

#69
post #51

I think the author brings up a good point about so-called "responsible disclosure" (a self-serving term by the vendors). I'm paraphrasing his 3 reasons for disclosing immediately: 1. It's unacceptable to wait half a year until a vulnerability is patched. 2. Bug bounties are riddled with tricks to delay you, shenanigans as to whether they'll pay you or not, and games to low ball the price. 3. It's arrogant to wait mon…

yep, all of that is equivalent to "security by obscurity". Hiding vulnerabilities longer is of no use, it just helps companies to be ready to answer customers, not to fix things in a better way.

Also it's really unfair to most vendors that don't have close ties with the creator of the security problem. E.g. in the case of Intel this turned out really bad for all other OSs except Windows and Linux. On the other hand it makes using products/software from entities who continue with this policy even more unattractive.

Re: VirtualBox E1000 Guest-to-Host Escape

#70

I think the author brings up a good point about so-called "responsible disclosure" (a self-serving term by the vendors). I'm paraphrasing his 3 reasons for disclosing immediately: 1. It's unacceptable to wait half a year until a vulnerability is patched. 2. Bug bounties are riddled with tricks to delay you, shenanigans as to whether they'll pay you or not, and games to low ball the price. 3. It's arrogant to wait mon…

The author's reasons are specific to Oracle. I believe other vendors have shown themselves to be worthy of the trust required to for such cooperative disclosure schemes to work.

As to your own more general arguments, they lead me to believe you're somewhat manichaean, and possibly a bit too eager to assign guilt and follow up with punishment.

Specifically, punishing users for "not demanding higher security" is a suggestion that can only be made when the metric ("high security") has become an objective by itself, completely divorced from real-world outcome that spawned it, namely to avoid people being harmed.

It's unclear if punishing users could reliably work as a proxy to get vendors to increase security. Thus, it is already assured that there will be some users that will be harmed by your idea with no positive effect possibly justifying that harm.

If, however, the mechanism works as envisioned by you, it would work just as well without helping it along: the very same effect will occur organically, whenever insecurity results in harm. And where it doesn't, nothing is lost. Quite the opposite: insecurity that does not result in harm is quite obviously something good.

It's a well-known failure mode of the human mind to so fully engage with some intermediate task that one forgets the initial motivation. Hence police officers arresting 6-year olds and soldiers "just following orders". Here, your suggestion is the result of fetishising one specific quality of software, namely security. Secure software, created in a process so beautiful it is a piece of art by itself, does not only shed its initial justification: Its pursuit suddenly legitimises actions specifically intended to injure those you once set out to protect.

Yeah, plus, you know: that mechanism assumes that fast disclosure harms users. So you're kinda contradicting all those other points about fast disclosure being helpful.

As to (5): You're not giving any reasons why early disclosure would result in more harm to the vendor, except for the very idea of responsible disclosure itself, namely lowering real-world harm by having a patch or other mitigation ready at the moment of disclosure. Here, you are falling into the same trap of being more interested in vengeance than justice, much like the first officer arriving at the crime scene putting another bullet in the victim to ensure that horrible criminal will face trial for murder, and not just assault.

Post reply on HN