Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

151–160 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#151

Earlier quoted context omitted.

You suggest it was just one lone engineer being incompetent. Then you respond to downvotes with the non-sequitur "take some pride in your work" - are you suggesting pride is a fix for incompetence? What?

There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).

It's easy to opine and judge from on high when it's not your nuts in the vice.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#152

Earlier quoted context omitted.

I honestly envy the sort of person who can post something like this. Not liking nodejs is fine, but to extrapolate from "I don't like nodejs" to "Thousands of engineers at companies like Google are wrong and I am right" must require such a level of myopic, ignorant self-belief that is completely alien to me. I just find myself respecting other people's work too much, even if I don't like it.

> Thousands of engineers at companies like Google That's an appeal to authority. It's also worth noting that nodejs is not a Google project and it is barely used internally at all. Only for small toy projects. Google uses python for scripting, or java for real servers.

That's an appeal to authority.

It is, but it's also shorthand for "people who are likely to be good based on the fact they've been through a rigorous hiring process designed to filter out the worst engineers". Sometimes, maybe, you should let the principle of charity win over the rigorous rhetorical logic you can use to dismiss an argument because it broke The Rules you learned on LessWrong.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#153

Earlier quoted context omitted.

I honestly envy the sort of person who can post something like this. Not liking nodejs is fine, but to extrapolate from "I don't like nodejs" to "Thousands of engineers at companies like Google are wrong and I am right" must require such a level of myopic, ignorant self-belief that is completely alien to me. I just find myself respecting other people's work too much, even if I don't like it.

I might be inclined to believe you, but node's ecosystem really is a trainwreck

NPM is a trainwreck in many respects, and nodejs is terrible in many ways, but that doesn't mean developers can't use them both productively. It requires effort. You can't just push responsibility for what your app is doing under the hood to the ecosystem of library code you pull in.

However, this is true for literally every language we code in.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#154
post #131

Earlier quoted context omitted.

You live in a nice world, because usually the actual power (and duty) of a dev team member is to advise, not to agree or refuse.

So whose fault is the cancerous heap of flaming dogshit that is nodejs, then? Some manager managed it into existence? No, it's the brainchild of an engineer. Somebody actually thought nodejs was a good idea. Face it, there are lots of really bad engineers out there.

Would you please stop breaking the site guidelines and posting unsubstantive comments here?

https://news.ycombinator.com/newsguidelines.html

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#155
post #40
post #8

Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.

>how a team of well-paid comfortable engineers got together and decided this patch was a good idea Test-driven development

Only if you are really bad at it. Really, really bad.

It's completely unrelated to any development methodology, this is someone unaware of basic HTTP protocol semantics.

So just bad development, period.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#156
post #8

Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

In similar situations I

1. Explain that the 'hack' does not actually fix the problem. This is absolutely the engineers responsibility. In your example Alice does not say that. This has always been sufficient.

2. I make a habit of sending emails or keeping minutes confirming such meetings and the details of who said what.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#157
post #146

Earlier quoted context omitted.

So when I check desktop site in chrome I'm hacking?

Of course! So is right clicking and selecting inspect element to modify the page!

I would call it hacking.. you sometimes run into those websites with 50 different opacity bits for all their web app things, and you don’t want to deal with all that rubbish so you set a “opacity: 1 !important” and the whole website looks off but it’s finally useable. I’d call that a hack.

Or also when you run into those websites designed on a $2000 screen that thinks it’s tres moderne to use 808080 text, so you “hack” it into readable text.

I think those are all happy little hacks :-)

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#158

Earlier quoted context omitted.

I like the original more without your embellishment. The addition sounds like every attempt at follow up humor on reddit.

Yeah but it's not Reddit, it's HN. You have to know your audience, read the crowd. On Reddit it's 90% sarcasm so there's no fixing it. Here it's the reverse and people take things seriously without a tell. You just have to bury the tell in another joke or it will ruin the funny.

If you can’t discern the joke, the joke isn’t for you to begin with; so it doesn’t matter.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#159
post #145

Cisco is crumbling under its own weight. This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents. It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunc…

> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.

Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture.

My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy.

Ubiquity was number 2. I refrain from buying from them only because of their glossy UI.

Mikrotik was on that list. Until I saw how horrible their winbox protocol was. And their implementation of SMB.. I must assume there are still plenty of unknown RCEs there.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#160

Earlier quoted context omitted.

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

You live in a nice world, because usually the actual power (and duty) of a dev team member is to advise, not to agree or refuse.

Absolutely: Cisco made this happen, not Engineer Alice. If your boss asks you to do something within my ethical boundaries and you have 5 tired co-workers in favour of shipping it, eventually you'll break and say "fine". It doesn't make you responsible or the one that pulled the trigger.
Post reply on HN