Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

281–290 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#281

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

If management let this important security fix get executed and deployed without a competent engineer in the loop, that's a horrible mistake in itself, but it's far less likely than management choosing this alternative based on accurate information from engineers.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#282
post #90

Earlier quoted context omitted.

I couldn't agree more. The joke construction was a bit weak though, when you miss a good part of the audience. Add something like, "I mean, could you imagine the chaos it would cause if IE told websites it was really Mozilla?" and you demonstrate mastery of the subject matter, which should be enough to let other experts know you were facetious rather than ignorant. Unless you have timing issues... or need the comedia…

Sir, your assessment of this particular joke is excellent. We should start a joke approval committee to avoid further confusion.

Yes, very well, as first action of the Joke Approval Committee, I propose that this august body instantiate the Recursed Approval Subcommittee, whose role will be to instantiate the Recursed Approval Subcommittee.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#283
post #147
post #125

Earlier quoted context omitted.

> Therefore, we obviously need to patch echo (and all echo shell builtins) to refuse to output strings containing "GET", "POST", "HTTP", or "Host:". Unfortunately it is also possible to do this using file redirection or to write a new program that will make a TCP connection and send arbitrary data through it, making it necessary to do the same for all editors, compilers and interpreters. That sounds like a lot of wor…

Why stop there? The user can easily modify the kernel to disable such prevention measures for malicious usage. We must have a regulation to require a hardware level detection and prevention features of curl which all hardware vendors must follow.

But users have fingers, which can be used to disable or subvert said "features". Thus, those fingers are just gonna have to go. They're a security risk, and security risks are against the regulations.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#284

Earlier quoted context omitted.

Sir, your assessment of this particular joke is excellent. We should start a joke approval committee to avoid further confusion.

Yes, very well, as first action of the Joke Approval Committee, I propose that this august body instantiate the Recursed Approval Subcommittee, whose role will be to instantiate the Recursed Approval Subcommittee.

That's a perfect example you should post to JAC before. It would not pass, please never post this "joke" again.

Welcome on board :)

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#285

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

Stereotypes are valid first order approximations.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#286
post #185

Earlier quoted context omitted.

Thankfully there are countries where Engineer is still a proper word, not something that you are allowed to call yourself after a 6 month bootcamp.

And most states in the US too. Just rarely enforced. Only a licensed PE can do business as an “Engineer”. (For example have a company with the word Engineer or Engineering in the name).

I believe the city of Portland OR recently sued a Danish man for "practicing engineering without a license". They were upset at him for generating strong proof of shortened yellow light times at intersections with red light cameras. He had a degree (and I believe a certificate) from Europe, but it wasn't recognized by the Authorities.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#287
post #185
post #163

Earlier quoted context omitted.

"Engineer" conveys image of middle class white-collar job with relatively high status, good education and responsibilities. That word now used for everyone doing programming related jobs inside office space for no good reason. I think the word "tehnician" should be used to describe most grey-collar ICT jobs, including most programmers. Their responsibility and scope of their work is limited. Many programming jobs are…

Thankfully there are countries where Engineer is still a proper word, not something that you are allowed to call yourself after a 6 month bootcamp.

and we'll get the job done better and quicker than you ;)

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#288
post #173

This "fix" seriously hurts Cisco's credibility. How can you trust their products? Perhaps they are thinking that noone gives a damn anyway after no less than five backdoors² were found in their products in 2018 alone? Just incredible. ² https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...

Cisco is in the business of selling big, black, expensive boxes that have a lot of security badges and fancy icons. People who buy such boxes don't care if they actually work, they want a big box so that they can claim they "invested in security".

What would you buy instead of Cisco?

HP and Dell are the same thing. From experience a decade ago, the HP usually did not have the enterprise features they advertised.

The other minor brands are very hard to procure if you're not in the US or a primary English speaking country.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#289
post #7

Source says they also did some input sanitizing along with blocking curl, and they had to make a new PoC to get around that. If I'm reading that right then this isn't really an issue, nothing wrong with defense in depth. Edit: >The update adds several filters to handle single quotes in user input. However, these filters can be evaded by specially crafted inputs. By providing the following string for the certificate's…

The equivalent of a "pls dont hack" sign is not defense in depth. Good to know they at least half fixed the problem, I guess. But that's not enough, and they should be capable of testing this.

Can anything without a "please don't hack" sign considered defense in depth?

Probably not, hence an appropriate first patch.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#290

Cisco is crumbling under its own weight. This is a symptom of the rot in their management, and probably also a sign that they have hired too many incompetents. It probably also is a sign of the current age. After the recovery from the IT-bubble programming got really hot. Thus: Too many of the new programmers wants to be programmers because it pays well - not because they love their craft. So therefore we have a bunc…

Your first point is just blabber. Cisco is a large company and this is a $100 product that they don't really care much about. It's the type of product that is produced at the cheapest possible cost, by interns. The way this product has been developed and managed is completely intentional and not a sign of mismanagement. Come back in 3 and then 6 months and let's see what effect this has had on their revenue and market cap, and then you can start talking about mismanagement.

As a sign of the quality of the current median developer, I think you are spot on. But I don't know that it's worth griping about. That is the world in which we live ... so live in it. In fact, all the better for those of us (if I may dare to put myself in a more elite group) that are highly skilled ... we don't have to work on some me-too unimportant SOHO router, at correspondingly low me-too unimportant wages.

Post reply on HN