Earlier quoted context omitted.
I will never stoop so low as to telegraph my own joke.
In textualform, sarcasm and ignorance look the same. otoh, it can sometime be quite funny to see responses from people that take it seriously...
Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
111–120 of 322 posts
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#112Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…
You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one would be malpractice for a real Engineer.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#113I don't see what the fuss is about. This is an effective mitigation, given that software can't just arbitrarily lie about its user agent.
I think you should have added a /s tag... some people don't get jokes unless you hit them over the head with it.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#114Earlier quoted context omitted.
I've been Engineer Alice before (not with a security issue, but a pretty bad systems issue). In case anyone is ever in that situation, here are some more productive replacements for that existential sigh (in that they sometimes work). Choose the one most suited to manager's biases. The cliches are important: think of it as giving manager an easy way to explain it to their manager. > Yes, but that would only help with…
No! The answer is an unequivocal “No“, without any „but“s or anything like that. The fix does not fix the problem, it is not even a fix, just a wrong code change that sets out to do something but does not achieve it. Answering „yes“ is a lie here. This is different from a fix that fixes the problem in an ugly way, where „yes, but...“ is applicable.
I'm envisioning more of a middle-ground case, where the code is still obviously wrong but it's harder to cleanly demonstrate why.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#115Earlier quoted context omitted.
They help you figure out if a user agent wants a mobile view of a page without Javascript... which is pretty useful.
So instead of sending a user agent, send only the page ratio!!
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#116Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#117User agents shouldn't exist any more. They serve only to help unsuspecting users be fingerprinted.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#118Earlier quoted context omitted.
Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…
On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#119Earlier quoted context omitted.
I couldn't agree more. The joke construction was a bit weak though, when you miss a good part of the audience. Add something like, "I mean, could you imagine the chaos it would cause if IE told websites it was really Mozilla?" and you demonstrate mastery of the subject matter, which should be enough to let other experts know you were facetious rather than ignorant. Unless you have timing issues... or need the comedia…
I like the original more without your embellishment. The addition sounds like every attempt at follow up humor on reddit.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#120Earlier quoted context omitted.
No! The answer is an unequivocal “No“, without any „but“s or anything like that. The fix does not fix the problem, it is not even a fix, just a wrong code change that sets out to do something but does not achieve it. Answering „yes“ is a lie here. This is different from a fix that fixes the problem in an ugly way, where „yes, but...“ is applicable.
In this specific case (I have never encountered a proposal quite this bad), the correct answer is probably "Give me the proof of concept code and about ten minutes, and I'll give you a version that works despite the patch." You're right about that. "No" is likely to bog down the discussion with "but Bob says it will work", and it's better to skip to the end. I'm envisioning more of a middle-ground case, where the cod…
Cisco has a bad track record in that regard and software in general.
My employer has reached a settlement with Cisco after buying their "firepower" solution which has been plagued with basic software and usability bugs.