Live data from Hacker News

The Harmless Pi-Hole Bug

kiyell.com

1–10 of 48 posts

Re: The Harmless Pi-Hole Bug

#2
This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug.

This is just generating CVE numbers for the sake of it.

Re: The Harmless Pi-Hole Bug

#4
post #2

This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.

If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect.

As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone else’s.

Re: The Harmless Pi-Hole Bug

#5
post #2

This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.

Not exactly that, someone can change the unit used to display the temperature for authenticated users.

Re: The Harmless Pi-Hole Bug

#6
post #4
post #2

This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.

If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…

So you are happy to have 1 million cves to look for per year per product?

Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.

Re: The Harmless Pi-Hole Bug

#7
post #6
post #4

Earlier quoted context omitted.

If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…

So you are happy to have 1 million cves to look for per year per product? Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.

>So you are happy to have 1 million cves to look for per year per product?

Trying to ignore the extreme hyperbole here...

I want me or my team to see every security-related flaw affecting the products in our network, yes. That's literally our job.

A CVE like this takes maybe 2 minutes for a junior on the team to mark as no risk.

Re: The Harmless Pi-Hole Bug

#8
post #2

This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.

Now we just sit back and wait for the side channel attack where someone figures out how to use temperature changes to exfil data.

Re: The Harmless Pi-Hole Bug

#9
post #2

This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.

Yeah this is generating CVE numbers for resume clout.

Re: The Harmless Pi-Hole Bug

#10
post #7
post #6

Earlier quoted context omitted.

So you are happy to have 1 million cves to look for per year per product? Unless there’s a minimum standard it becomes noise, and the real CVEs are lost.

> So you are happy to have 1 million cves to look for per year per product? Trying to ignore the extreme hyperbole here... I want me or my team to see every security-related flaw affecting the products in our network, yes. That's literally our job. A CVE like this takes maybe 2 minutes for a junior on the team to mark as no risk.

I agree with ziddoap here. Not reviewing these minor bugs are exactly how we end up with sophisticated attacks using simple bugs that leave us arm chair experts commenting "How did they even think of this?!?!"

Because the people that do conduct sophisticated attacks are studying every knock and cranny for these types of things. If they can find it once, they can automate it and find more. And then they move on to the next piece of their puzzle of "what can I do from here?"

Post reply on HN