I don't see what the fuss is about. This is an effective mitigation, given that software can't just arbitrarily lie about its user agent.
I have to fix my sarcasm detection AI again because of this comment
Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
171–180 of 322 posts
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#172(in reference to : https://news.ycombinator.com/item?id=19318498#19329754)
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#173² https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#174Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#175Earlier quoted context omitted.
We don't need user agents for that. There's an easy way to tell whether a visitor wants a cleaner view of a page, without Javascript: Yes.
I have been having a shitty day and your comments in this article have honestly cheered me up a bit. Thank you!
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#176Earlier quoted context omitted.
You can always quit. Or force them to fire you for refusing to implement a non fix. In reality though I doubt this narrative even occurred. Some incompetent engineer likely proposed this fix thinking that it was actually a fix. Edit: I see I've been downvoted for this comment. If we were real engineers working on things like cars and bridges we'd actually be held accountable. Take some pride in your work people, this…
If there were actual accountability, software engineers would have a much better lever against management. For some software this is case. If you write safety critical software you can be held personally responsible for accidents. In those industries engineer pushback is much more effective.
System tick timer rolled over after 2^32 1ms clock ticks (a little over seven weeks) and the software mishandled it by rebooting and losing control of the process. It wasn't until QA got involved (it turned out they saw it on a long-term test) that we were cleared to actually fix it. It was a two-character change in an inline function!
In some places "cover it up, don't discuss it in email" is the natural response. It really depends on the management and the organisational culture. You can have management who support the engineering team, or you can have management who micromanage and overrule and end up turning a two-day hotfix cycle into ten months of "try soldering a resistor to every single pin on the PCB".
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#177Earlier quoted context omitted.
Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I sa…
https://threatpost.com/hardware-vendor-offers-backdoor-every... At least Allied Telesis documents their backdoors :)
I guess there is nothing good.. what is wrong with people :(
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#178Earlier quoted context omitted.
On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…
"Engineer" conveys image of middle class white-collar job with relatively high status, good education and responsibilities. That word now used for everyone doing programming related jobs inside office space for no good reason. I think the word "tehnician" should be used to describe most grey-collar ICT jobs, including most programmers. Their responsibility and scope of their work is limited. Many programming jobs are…
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#179Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
i'll raise you a case where a team of very well paid senior engineers/architects and PMs dismissed a remote execution vulnerability down to a very low "some next release" priority on the grounds that "notepad.exe doesn't seem to do any damage" - as you may have guessed the vulnerability PoC used notepad.exe . After seeing that with my own eyes, this Cisco curl is just "meh" for me :)
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#180This "fix" seriously hurts Cisco's credibility. How can you trust their products? Perhaps they are thinking that noone gives a damn anyway after no less than five backdoors² were found in their products in 2018 alone? Just incredible. ² https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...