Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

241–250 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#241
post #210

Earlier quoted context omitted.

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

The question here, is if it would stop 90% of the attacks, would it be a worthwile way to spend 5 minutes. And the answer to that question is almost invariably yes.

Well, no.

That's like stopping 90% of a flood. The other 10% does more than enough.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#242

Okay, so the fix is bad. Now, you have to wonder how this "fix" made it through code review, QA, release... You can blame the engineer. Perhaps they were rushed, inexperienced, or both, but this is a failure on all levels.

Many people would've seen and signed off on this fix, not just one engineer.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#243

Cisco is crumbling under its own weight. This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents. It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunc…

Culture matters. I want my socially maladapt terminal junkies back plz.

I know some fastidiously groomed VSCode front-end hipsters whose entire bodies involuntarily tense up if you suggest a lazy technical workaround to them. It's funny and makes me feel good about the future.

But I get you; I agree completely. You do need people who really care. They're just not as easy to stereotype any more (if they ever were.)

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#244

Earlier quoted context omitted.

Rubbish. They are incredibly useful for debugging.

You're writing your websites wrong.

If there’s a way to write them without the occasional browser-specific bug, I’d sure like to know what it is.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#245
post #107

Don't blame the manager, the PO, the CEO. This is ABSURD engineering incompetence. The fellow that did that _fix_ probably had no idea how to properly solve the issue.

Managers, POs, and CEOs are responsible for preventing this by:

- hiring people who'd know not to do it

- creating processes for more than one security expert to review security patches

- requiring the testing of patches against real-world workarounds

- allotting the time and budget necessary for all of the above

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#246

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

We can "No True Scotsman" this all day long.

It is bad management to hire incompetent engineers.

It is bad management to fire competent engineers that push back.

It is bad management to make employees feel as though they would be fired for standing up in any way to management.

Take away the rhetorical shortcuts, and responsibility still always falls at the feet of the ones that have the power to make the decision. As long as engineers are hierarchically bound to obey managers upon pain of sudden and unplanned unemployment, the managers are ultimately responsible for everything the company does. If the company does not have tenured engineers that have stop work authority, the managers are fully to blame. And if they do, management still might be partially at fault.

We have this headcanon where a competent engineer could stand up, sweep away the slide deck on screen with a wave of the hand, and offer ironclad mathematical proof that the quick fix is no fix at all, and that the long, painful, but correct fix is what is Right for the Company (tm). The manager would then do the slow clap and tell that engineer to fix it right this time. It is a fantasy that is a great comfort to those of us doing maintenance work on a massive crock of shit, making the payments on technical debt that we are expressly forbidden from making any attempts to retire. But it is a fantasy. A real manager would cut the engineer off in mid-proof and say that the quick fix is happening, and that would be the end of the story.

The only way for an engineer that is "at will" and without a contract to push back is by falling on their own sword. They can quit, at great cost to themselves, to create a very minor inconvenience to the company, who will end up doing what it wanted anyway.

Being in this situation myself, you're damned right I have no responsibility for the crap code that goes out, because I have almost no autonomy in the manner in which I do my job. I cannot work outside the scope of the maintenance tickets I am assigned. And my company rents me out by the hour to the customer, so it has negative incentive to allow me to build up infrastructural capital that would allow me to do the same work in less time. I will blame management all day long, and then a bit more on evenings and weekends.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#247

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

If you read the parent post and think "bad management" I don't think the message was clear.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#248
post #163

Earlier quoted context omitted.

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

"Engineer" conveys image of middle class white-collar job with relatively high status, good education and responsibilities. That word now used for everyone doing programming related jobs inside office space for no good reason. I think the word "tehnician" should be used to describe most grey-collar ICT jobs, including most programmers. Their responsibility and scope of their work is limited. Many programming jobs are…

And how many 'engineers' would tack on 1000x too much complexity to justify their 'engineering' effort?

software in many cases is more art than science.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#249

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

Yes, but this is software engineering. Where there is no such thing as malpractice, and where managers can not be prosecuted for criminal negligence even when their overriding of the engineers professional position gets dozens of people killed. In this delightful world, managers rule the roost and engineers do not have the ability to refuse to do anything.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#250

Earlier quoted context omitted.

But in the USA you can refer to yourself generically as a Software Engineer without any formal education.

Yes. I don’t think there is even a PE licensing path for software, so even with a CS degree you could never become a licensed engineer. You have to work under a PE for 5 years, then take the PE exam, then CE credits. I have an MSEE, but can’t put engineer in my title. Though Ing. sounds kind of cool.

There actually was a PE for Software Engineering, but it is being discontinued, because almost no one took it.

https://ncees.org/ncees-discontinuing-pe-software-engineerin...

Post reply on HN