Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

161–170 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#161

Earlier quoted context omitted.

There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).

It's easy to opine and judge from on high when it's not your nuts in the vice.

Doesn't mean the point isn't valid though.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#162
post #84
post #77

Earlier quoted context omitted.

I've been Engineer Alice before (not with a security issue, but a pretty bad systems issue). In case anyone is ever in that situation, here are some more productive replacements for that existential sigh (in that they sometimes work). Choose the one most suited to manager's biases. The cliches are important: think of it as giving manager an easy way to explain it to their manager. > Yes, but that would only help with…

No! The answer is an unequivocal “No“, without any „but“s or anything like that. The fix does not fix the problem, it is not even a fix, just a wrong code change that sets out to do something but does not achieve it. Answering „yes“ is a lie here. This is different from a fix that fixes the problem in an ugly way, where „yes, but...“ is applicable.

You must live in a very nice, ideal world, where simply saying "no, that's not the right way to do it" will convince managers to ignore the pressures placed on them to, at times, value speed over correctness.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#163

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

"Engineer" conveys image of middle class white-collar job with relatively high status, good education and responsibilities. That word now used for everyone doing programming related jobs inside office space for no good reason.

I think the word "tehnician" should be used to describe most grey-collar ICT jobs, including most programmers. Their responsibility and scope of their work is limited. Many programming jobs are closer to blue collar factory level mechanic than engineer.

https://en.wikipedia.org/wiki/Grey-collar

https://en.wikipedia.org/wiki/Technician

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#164

Earlier quoted context omitted.

You suggest it was just one lone engineer being incompetent. Then you respond to downvotes with the non-sequitur "take some pride in your work" - are you suggesting pride is a fix for incompetence? What?

There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).

1) is obviously false, since an engineer could be competent and evil. Or competent and under duress - needing to keep their job to keep their visa, family health insurance, etc. Or competent but misled - "Implement the suggested fix to show how easy it is to work around" "OK, here it is" "Now work on something else", while it ships.

2) Why should you? Unless you're willing to be homeless and leave society, you're not going to find a way to live in a capitalist society which is pure idealism and no compromises, and you can't effect change in a system from without, only from within. Quit, and someone else will implement this fix - you feel good, which is worthless, and the fix ships, which is bad, and Cisco doesn't change, which is bad. Pick your battles and you could use this result in future - to build other people's trust in your recommendations, to widen the review process before future fixes are agreed upon, to have a proven record of the cost of doing things twice.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#165
post #145

Earlier quoted context omitted.

> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.

Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I sa…

https://threatpost.com/hardware-vendor-offers-backdoor-every...

At least Allied Telesis documents their backdoors :)

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#166
post #8

Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

Ironically, this is the change most likely to break things for customers that use curl for automation.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#167
post #147
post #125

Earlier quoted context omitted.

> Therefore, we obviously need to patch echo (and all echo shell builtins) to refuse to output strings containing "GET", "POST", "HTTP", or "Host:". Unfortunately it is also possible to do this using file redirection or to write a new program that will make a TCP connection and send arbitrary data through it, making it necessary to do the same for all editors, compilers and interpreters. That sounds like a lot of wor…

Why stop there? The user can easily modify the kernel to disable such prevention measures for malicious usage. We must have a regulation to require a hardware level detection and prevention features of curl which all hardware vendors must follow.

oh god stop some politician might see this and take you for being srs

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#168
post #146

Earlier quoted context omitted.

So when I check desktop site in chrome I'm hacking?

Of course! So is right clicking and selecting inspect element to modify the page!

That's why super secure websites block right-click events on their webpage. Makes them unhackable!

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#169
post #61

Earlier quoted context omitted.

Ah, but what about packets that aren't evil, just gullible and manipulated by some third party?

Then add a "tainted by evil" flag to the ipv7 spec, or better, just add a "pure" flag to future ip spec.

I think I'd almost prefer an "alignment" flag, so we don't mischaracterize all the Chaotic Neutral packets.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#170
post #90

Earlier quoted context omitted.

I will never stoop so low as to telegraph my own joke.

I couldn't agree more. The joke construction was a bit weak though, when you miss a good part of the audience. Add something like, "I mean, could you imagine the chaos it would cause if IE told websites it was really Mozilla?" and you demonstrate mastery of the subject matter, which should be enough to let other experts know you were facetious rather than ignorant. Unless you have timing issues... or need the comedia…

I don't find that as funny, I think making the sarcasm more obvious makes the joke less funny as well. I prefer to take my chances than to go overboard and neuter the joke.
Post reply on HN