This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
VirtualBox E1000 Guest-to-Host Escape
61–70 of 118 posts
Re: VirtualBox E1000 Guest-to-Host Escape
#62This [1] gives a little more background. The same security researcher found another vulnerability in VirtualBox earlier this year, and didn't have a great experience with Oracle: “We reported this vulnerability to Oracle, the latest update from them is that they are still looking into it, while in fact the latest version of Oracle VirtualBox version 5.2.18 has silently introduced a patch without giving credit or ment…
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
Re: VirtualBox E1000 Guest-to-Host Escape
#63FTA : >>> a browser opened a malicious website in the guest OS is exploited, a browser sandbox escape is made to gain full ring 3 access, an operating system vulnerability is exploited to pave a way to ring 0 from where there are anything you need to attack a hypervisor from the guest OS. I cracked several games in the end of the 80's but that was nowhere as hard as this seems to be. How do researchers find the time…
There are are many reasons for this. One is that with a game, you already have full access to the program on your disc and can modify it at will, run it infinitely many times, have full access to how it's loaded and run, and analyze it separately. Plus "hacking a game" is not a security vulnerability, and the only person who loses if you add an RCE to your game is you, and possibly the publisher if you crack it.
Re: VirtualBox E1000 Guest-to-Host Escape
#64Earlier quoted context omitted.
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
There are plenty of other big companies behaving similarly. HP comes to my mind also, but I cannot find the statistics which quantified worst maintainance practices.
Because, they plainly don't hide it and try to be nice, at least.
I also think that they're the worst in the industry.
Re: VirtualBox E1000 Guest-to-Host Escape
#65The pricing of / evaluation of bug bounties seems to be a problem. Going begging to the vendor of course results in reduced value. Everything tends to be undervalued when there is only one buyer. Also purchase processes tend to be slow when there is only one buyer. It's almost as if there needs to be competition for the sale of the disclosure ... although that would have its own issues of course. Another idea is a pu…
Re: VirtualBox E1000 Guest-to-Host Escape
#66Earlier quoted context omitted.
The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.
You don't think there is a place for giving vendors time to fix the exploit before handing it over to everyone who can use it maliciously?
Re: VirtualBox E1000 Guest-to-Host Escape
#67Earlier quoted context omitted.
The author has a number of great points, with an overarching theme that how we handle security bugs is ridiculous.
Especially the websites/branding of bugs, like Heartbleed, SHAttered, etc. It seems like researchers do this to propel their own fame, for probably financial motives. I imagine it's pretty lucrative to have been the "co-founder" of Heartbleed just like it is lucrative to be the co-founder of a well-known startup.
Re: VirtualBox E1000 Guest-to-Host Escape
#68Earlier quoted context omitted.
Does Oracle have a track record of being The Worst about this or should I have assumed as such given my preconceived notions of them being the classic villain in the tech world?
Relevant discussion in another Oracle related post[0]. [0]: https://news.ycombinator.com/item?id=18389481
Re: VirtualBox E1000 Guest-to-Host Escape
#69I think the author brings up a good point about so-called "responsible disclosure" (a self-serving term by the vendors). I'm paraphrasing his 3 reasons for disclosing immediately: 1. It's unacceptable to wait half a year until a vulnerability is patched. 2. Bug bounties are riddled with tricks to delay you, shenanigans as to whether they'll pay you or not, and games to low ball the price. 3. It's arrogant to wait mon…
yep, all of that is equivalent to "security by obscurity". Hiding vulnerabilities longer is of no use, it just helps companies to be ready to answer customers, not to fix things in a better way.
Re: VirtualBox E1000 Guest-to-Host Escape
#70I think the author brings up a good point about so-called "responsible disclosure" (a self-serving term by the vendors). I'm paraphrasing his 3 reasons for disclosing immediately: 1. It's unacceptable to wait half a year until a vulnerability is patched. 2. Bug bounties are riddled with tricks to delay you, shenanigans as to whether they'll pay you or not, and games to low ball the price. 3. It's arrogant to wait mon…
As to your own more general arguments, they lead me to believe you're somewhat manichaean, and possibly a bit too eager to assign guilt and follow up with punishment.
Specifically, punishing users for "not demanding higher security" is a suggestion that can only be made when the metric ("high security") has become an objective by itself, completely divorced from real-world outcome that spawned it, namely to avoid people being harmed.
It's unclear if punishing users could reliably work as a proxy to get vendors to increase security. Thus, it is already assured that there will be some users that will be harmed by your idea with no positive effect possibly justifying that harm.
If, however, the mechanism works as envisioned by you, it would work just as well without helping it along: the very same effect will occur organically, whenever insecurity results in harm. And where it doesn't, nothing is lost. Quite the opposite: insecurity that does not result in harm is quite obviously something good.
It's a well-known failure mode of the human mind to so fully engage with some intermediate task that one forgets the initial motivation. Hence police officers arresting 6-year olds and soldiers "just following orders". Here, your suggestion is the result of fetishising one specific quality of software, namely security. Secure software, created in a process so beautiful it is a piece of art by itself, does not only shed its initial justification: Its pursuit suddenly legitimises actions specifically intended to injure those you once set out to protect.
Yeah, plus, you know: that mechanism assumes that fast disclosure harms users. So you're kinda contradicting all those other points about fast disclosure being helpful.
As to (5): You're not giving any reasons why early disclosure would result in more harm to the vendor, except for the very idea of responsible disclosure itself, namely lowering real-world harm by having a patch or other mitigation ready at the moment of disclosure. Here, you are falling into the same trap of being more interested in vengeance than justice, much like the first officer arriving at the crime scene putting another bullet in the victim to ensure that horrible criminal will face trial for murder, and not just assault.