Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

261–270 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#262

Cisco is crumbling under its own weight. This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents. It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunc…

Bwahaha, hired too many incompetents?

They have outsourced the fuck out of their projects to uh, questionable means.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#263

Earlier quoted context omitted.

I've come to the conclusion recently that we're all just barbers, bloodletting and burring holes. Until we have proper certifiable and reproducible competency, we'll never become surgeons.

And yet the US has consistently been in the vanguard of software development worldwide. Do we need surgeons? Do you need a four year postgraduate degree and three more years of apprenticeship before slinging together a web app? Certainly the industry has its problems, and some applications demand more rigor, but I don’t see this as much of a general solution.

The market didn't demand a high survival rate or efficacy for barbering either, but do you think that the (conscious or unconscious) that software engineers are some sort of magical wizards will last forever?

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#264

Earlier quoted context omitted.

There are two points. 1) Any engineer involved in implementing this "fix" is incompetent. 2) If you are not incompetent and management tries to force you to implement this "fix" then you should take pride in your work and refuse to do it, even if it means quitting your job (or forcing the company to fire you).

Let me know when pride is accepted as currency to pay bills or when insubordination due to personal pride is seen as a desirable quality in a candidate. At the very least, how much are you willing to pay a person for not implementing the fix you disagree with (including engaging in a legal contract to pay them if they lose their employment due to not implementing the fix). From my past experiences with others, moral…

Pleas tell me in what country is it an issue for a software developer to make money? I mean in this situation, if I were forced to implement such fix, I would do it, but would then quit the next month. Because if I were to stay, not only would I get worse professionally, but I would feel dirty for not doing my work properly. The companies that accept such fixes are more often than not like a factory and treat you as gear in a machine. And also have an ugly software which make good engineers quit.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#265

Okay, so the fix is bad. Now, you have to wonder how this "fix" made it through code review, QA, release... You can blame the engineer. Perhaps they were rushed, inexperienced, or both, but this is a failure on all levels.

How do you know it wasn't fixed by the offshore maintenance team with an offshore manager controlled by a VP wanting a quick promotion for doing things fast? That would be where I work the likely scenario.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#266

Earlier quoted context omitted.

Curl can, easily. Curl is not just a client to get a file and pipe it to other programs, it's a diagnostic tool, and it has all sorts of parameters to help it simmulate all kinds of interaction with a webserver, including the -A parameter to change the user-agent, this is why this 'fix' is so stupid.

I see, thank you for the explanation!

Well played, sir.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#267
post #162
post #84

Earlier quoted context omitted.

No! The answer is an unequivocal “No“, without any „but“s or anything like that. The fix does not fix the problem, it is not even a fix, just a wrong code change that sets out to do something but does not achieve it. Answering „yes“ is a lie here. This is different from a fix that fixes the problem in an ugly way, where „yes, but...“ is applicable.

You must live in a very nice, ideal world, where simply saying "no, that's not the right way to do it" will convince managers to ignore the pressures placed on them to, at times, value speed over correctness.

Apparently I do? Not sure what you want to hear here, but management does listen to me and my engineering peers. Sometimes things are a bit gray and fuzzy, but in this case here where they definitely are not, I am absolutely certain that there would be no overriding of our arguments.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#269

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

Big bad management gets to keep their jobs when they make bad product decisions, so let's call it a wash.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#270
post #186

Earlier quoted context omitted.

You can always quit. Or force them to fire you for refusing to implement a non fix. In reality though I doubt this narrative even occurred. Some incompetent engineer likely proposed this fix thinking that it was actually a fix. Edit: I see I've been downvoted for this comment. If we were real engineers working on things like cars and bridges we'd actually be held accountable. Take some pride in your work people, this…

Quitting assumes the possibility of finding a job around the corner and not having people that depend on you.

> Quitting assumes the possibility of finding a job around the corner and not having people that depend on you.

Quitting assumes the possibility of finding a job after spending 4 months doing leetcode 6 hours a day and not having people that depend on you.

Post reply on HN