Earlier quoted context omitted.
This makes me never want to buy another ASUS product again.
For me it's them lying about providing a way to unlock the bootloader of my soon to be 1000€ paperweight(2 android updates only) called an Asus zenfone 10.
One-Click RCE in Asus's Preinstalled Driver Software
101–110 of 253 posts
Re: One-Click RCE in Asus's Preinstalled Driver Software
#102Earlier quoted context omitted.
Citing CGPGrey: Solutions that are the first thing you can think of are terrible and ineffective. Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes. You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.
> You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot. I don't think you can fathom the amount of people that have phones with roughly 3 years of no android updates as their primary device with which they use all the digital services they use, Banking, Texting, Doomscrolling, Porn, ... Users, especially the most likely to be exploited ar…
I do. I'm an embedded software developer in a team that cares about having our software up-to-date a lot.
> Users, especially the most likely to be exploited are already vulnerable to so much shit and even when there's a literal finished fix available, these vendors do shit about it. Only when their bottomline is threatened because even my mom knows "Don't buy anything with ASUS on it, your bank account gets broken into if you do" will we see change.
Yes individuals are quite exploitable. That's why I really like EU's new regulations Cyber Resiliency Act and new Radio Equipment Directive. When governments enforce reasonable disclosure and fixing timelines, then threaten your company's ability to sell things in a market alltogether, if you don't comply, it works wonders. Companies hate not being able to make money. So all the extra security policies and vulnerability tracking we have been experimenting with and secure-by-default languages are now the highest priority for us.
EU regulation makes sure that you're not going to be sold a router that's instantly hackable in a year. It will also force chip manufacturers to have meaningful maintenance windows like 5-10 years due to pressure from ODMs. That's why you're seeing all the smartphone manufacturers have extended support timelines, it is not pure market pressure. They didn't give fuck about it for more than 10 years. When EU came with a big stick though...
Spreading word-of-mouth knowledge works until a point. Having your entire product line being banned entering a market works almost every time.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#103Earlier quoted context omitted.
> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…
You're making an assumption that doesn't match reality - vulnerability discovery doesn't work like some efficient market. Yes, intelligence agencies and sophisticated criminal groups might find 0-days, but they typically target selectively, not deploying exploits universally. The real threat comes from the vast number of opportunistic attackers who lack the skills to discover vulnerabilities themselves but are perfec…
Re: One-Click RCE in Asus's Preinstalled Driver Software
#104Earlier quoted context omitted.
Yes but responsible disclosure should be "you have a week (or whatever) from my first email, then I go public".
what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? If the reason for responsible disclosure is to ensure that no members of the public is harmed as a result of said disclosure, should it not be a conversation between the security researcher and the company? The security researcher should have an approx. idea of how or what to do to…
> The security researcher should have an approx. idea of how or what to do to fix
Any expectation put on the security researcher beyond "maybe don't cause unnecessary shit storms with zero days" needs to be met with an offer of a fat contract.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#105Earlier quoted context omitted.
So are there any "basically respectable" motherboard manufacturers? Or is there a similar story about each of the big players? Asking for a friend who is thinking about building a new PC soon.
All the consumer brands are pozzed. My last build (i7-14700K) used an MSI board. Their secureboot is still broken. The BIOS setup is complete mess, and all the settings are reset after a BIOS update. I have to unplug and replug my USB keyboard after a poweroff, or it doesn't work. But I insisted on a board without RGB lights, and that limited the selection. Computers are over.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#106Earlier quoted context omitted.
> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…
You're making an assumption that doesn't match reality - vulnerability discovery doesn't work like some efficient market. Yes, intelligence agencies and sophisticated criminal groups might find 0-days, but they typically target selectively, not deploying exploits universally. The real threat comes from the vast number of opportunistic attackers who lack the skills to discover vulnerabilities themselves but are perfec…
> It eliminates the difficult choice customers would otherwise face - either disrupt their service entirely or knowingly remain vulnerable.
You decided they are better off not having to make that choice, so you make it for them whether they like it or not.
In fact, you made the worst choice for them, because you chose that they'd remain unknowingly vulnerable, so they can't even put in temporary mitigations or extra monitoring, or know to be on the lookout for anything strange.
> Most organizations simply can't afford the downtime from abruptly cutting off a service, nor can they accept the risk of continuing with a known vulnerability.
Now this is an interesting part, because the first half is true depending on the service, but bad (that's a BCDR or internet outage issue waiting to happen), and the second half is just wrong (show me a company that doesn't know and accept that they have past-SLA vulns unpatched, criticals included, and I'll show you a company that's lying either to themselves or their customers).
> This coordinated approach minimizes disruption while still addressing the security issue - a balanced solution that protects both the security and continuity needs of end users.
This is not a balanced approach, this is a lowest-common-denominator approach that favors service providers over service users. You don't know if it protects someone's security needs, because people have different security needs: a journalist being targeted by a state actor can have the same iphone as someone's retired grandma, or infotainment system, or home assistant, etc.
I've managed bug bounty and unpaid disclosure programs, professionally, and I know firsthand that it's the company's interests that responsible disclosure serves, first and foremost.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#107Earlier quoted context omitted.
"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…
> "Responsible" disclosure is paradoxically named because actually it is completely irresponsible. It's only paradoxical if you've never considered the inherent conflicts present in everything before. The "responsible" in "responsible disclosure" relates to the researchers responsibility to the producer, not the companies responsibility to their customers. The philosophical implication is that the product does what i…
Re: One-Click RCE in Asus's Preinstalled Driver Software
#108Earlier quoted context omitted.
Zenfone is smaller and has a headphone jack. It's the superior phone
It is virtually the same size[1] as the era equivalent S23. I don't think a headphone jack which you can get via a super cheap USB-C adaptor, makes the justification for a 1000 Euro paperweight. [1] https://www.gsmarena.com/size-compare-3d.php3?idPhone1=12380...
I have an older car with an old stereo where the only external input is via jack. Worked perfectly fine with my old phone. When I got a new Samsung, I went through the hassle of trying several "combined usb-c charger and audio jack adaptor" only to eventually find out they can only work in on mode or the other, not both at the same time. I ended up throwing away my old phone holder and spending even more money on one with built-in wireless charging so I could both listen to a damn music and charge my phone at the same time while driving.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#109Re: One-Click RCE in Asus's Preinstalled Driver Software
#110Earlier quoted context omitted.
"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…
I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?
With current practice, you can be as sloppy and reckless as you want, and when you create vulnerabilities because of that, you somehow almost push the "responsibility" onto the person who discovers it, and you aren't discouraged from recklessness.
Personally, I think we need to keep the good part of responsible disclosure, but also phase in real penalties for the parties responsible for creating vulnerabilities that are exploited.
(A separate matter is the responsibility of parties that exploit the vulnerabilities. Some of those may warrant stronger criminal-judicial or military responses than they appear to receive.)
Ideal is a societal culture of responsibility, but in the US in some ways we've been conditioning people to be antisocial for decades, including by elevating some of the most greedy and arrogant to role models.