Earlier quoted context omitted.
There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).
It's easy to opine and judge from on high when it's not your nuts in the vice.
Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
161–170 of 322 posts
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#162Earlier quoted context omitted.
I've been Engineer Alice before (not with a security issue, but a pretty bad systems issue). In case anyone is ever in that situation, here are some more productive replacements for that existential sigh (in that they sometimes work). Choose the one most suited to manager's biases. The cliches are important: think of it as giving manager an easy way to explain it to their manager. > Yes, but that would only help with…
No! The answer is an unequivocal “No“, without any „but“s or anything like that. The fix does not fix the problem, it is not even a fix, just a wrong code change that sets out to do something but does not achieve it. Answering „yes“ is a lie here. This is different from a fix that fixes the problem in an ugly way, where „yes, but...“ is applicable.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#163Earlier quoted context omitted.
Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…
On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…
I think the word "tehnician" should be used to describe most grey-collar ICT jobs, including most programmers. Their responsibility and scope of their work is limited. Many programming jobs are closer to blue collar factory level mechanic than engineer.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#164Earlier quoted context omitted.
You suggest it was just one lone engineer being incompetent. Then you respond to downvotes with the non-sequitur "take some pride in your work" - are you suggesting pride is a fix for incompetence? What?
There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).
2) Why should you? Unless you're willing to be homeless and leave society, you're not going to find a way to live in a capitalist society which is pure idealism and no compromises, and you can't effect change in a system from without, only from within. Quit, and someone else will implement this fix - you feel good, which is worthless, and the fix ships, which is bad, and Cisco doesn't change, which is bad. Pick your battles and you could use this result in future - to build other people's trust in your recommendations, to widen the review process before future fixes are agreed upon, to have a proven record of the cost of doing things twice.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#165Earlier quoted context omitted.
> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.
Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I sa…
At least Allied Telesis documents their backdoors :)
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#166Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#167Earlier quoted context omitted.
> Therefore, we obviously need to patch echo (and all echo shell builtins) to refuse to output strings containing "GET", "POST", "HTTP", or "Host:". Unfortunately it is also possible to do this using file redirection or to write a new program that will make a TCP connection and send arbitrary data through it, making it necessary to do the same for all editors, compilers and interpreters. That sounds like a lot of wor…
Why stop there? The user can easily modify the kernel to disable such prevention measures for malicious usage. We must have a regulation to require a hardware level detection and prevention features of curl which all hardware vendors must follow.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#168Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#169Earlier quoted context omitted.
Ah, but what about packets that aren't evil, just gullible and manipulated by some third party?
Then add a "tainted by evil" flag to the ipv7 spec, or better, just add a "pure" flag to future ip spec.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#170Earlier quoted context omitted.
I will never stoop so low as to telegraph my own joke.
I couldn't agree more. The joke construction was a bit weak though, when you miss a good part of the audience. Add something like, "I mean, could you imagine the chaos it would cause if IE told websites it was really Mozilla?" and you demonstrate mastery of the subject matter, which should be enough to let other experts know you were facetious rather than ignorant. Unless you have timing issues... or need the comedia…