Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

111–120 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#111

Earlier quoted context omitted.

A better analogy would be if you see a bunch of people walking around in faulty stab vests, and you tell them that the vests are faulty before they are recalled and replaced by the company. In which case, telling everyone those vests are actually not going to stop a knife, is a very good thing to do. > I did not make the argument that obscurity is security... But that doesn't mean non-obscurity automatically improves…

Sure, we can run with your analogy. So you make everyone aware that the stab vests are faulty. One of the people you make aware of this fact is a thief with a knife, who previously wasn't gonna take the risk on robbing anyone, since he only had a knife (not a gun) and everyone was wearing stab proof vests. But now he knows, so he goes for it and stabs someone. You are partially responsible for this outcome in this hy…

> But now he knows, so he goes for it and stabs someone.

Except his old knife he already had with him isn't made for exploiting the flaw in the vest, so it doesn't work. He needs to go home and build a new one, and the people in the mall can go home before he comes back, now that they know their vests are flawed. Otherwise, someone who comes in and is aware of the flaw when the users are not, can stab everyone, and they'd have no clue they were vulnerable.

In real-world terms, the kind of mass-exploitation that people use to fear monger about disclosure already happens everyday, and most people don't notice. The script kid installing a monero miner on your server should not be driving the conversation, it should be the IC spook recording a journalist/ dissident/ etc.

> Just that, in the world afterwards, you must take responsibility for everyone knowing, including people who did not know before and abuse that knowledge.

This is just a generalized argument for censorship of knowledge. Yes, humans can use knowledge to do bad things. No, that does not justify hiding information. No, that does not make librarians/ researchers/ teachers responsible for the actions of those that learn from them.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#112

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

It's such a loaded term that I refuse to use it. "vendor-coordinated disclosure" is a much better term, imho

(and in the world of FOSS you might have "maintainer-coordinated" too)

Re: One-Click RCE in Asus's Preinstalled Driver Software

#113

Earlier quoted context omitted.

It is virtually the same size[1] as the era equivalent S23. I don't think a headphone jack which you can get via a super cheap USB-C adaptor, makes the justification for a 1000 Euro paperweight. [1] https://www.gsmarena.com/size-compare-3d.php3?idPhone1=12380...

The problem I found about the adaptors is that you can't charge your phone and listen to music at the same time. I have an older car with an old stereo where the only external input is via jack. Worked perfectly fine with my old phone. When I got a new Samsung, I went through the hassle of trying several "combined usb-c charger and audio jack adaptor" only to eventually find out they can only work in on mode or the o…

> only to eventually find out they can only work in on mode or the other, not both at the same time.

I can't tell you how many times I've bought something small that should reasonably do two things at once, but can't. Literal e-waste garbage.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#114

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

> "Responsible" disclosure is paradoxically named because actually it is completely irresponsible. It's only paradoxical if you've never considered the inherent conflicts present in everything before. The "responsible" in "responsible disclosure" relates to the researchers responsibility to the producer, not the companies responsibility to their customers. The philosophical implication is that the product does what i…

[deleted]

Re: One-Click RCE in Asus's Preinstalled Driver Software

#115
post #62

Earlier quoted context omitted.

All the consumer brands are pozzed. My last build (i7-14700K) used an MSI board. Their secureboot is still broken. The BIOS setup is complete mess, and all the settings are reset after a BIOS update. I have to unplug and replug my USB keyboard after a poweroff, or it doesn't work. But I insisted on a board without RGB lights, and that limited the selection. Computers are over.

There really needs to be an open source project for a PC motherboard.

Just a few days ago people were talking about this on the kicad discord. A chinese team made an open hardware x86_64 motherboard and published it not too long ago. Then they were essentially wiped off the face of the planet.

That was the day I learned you literally cannot develop a computer motherboard without Intel's permission. Turns out Intel is no different than the likes of Nintendo.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#116
post #30
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

no bug bounty, onto black market of exploit it goes. that or full public disclosure.

I wonder how worried they would get if more people actually started selling exploits on the black market, instead of reporting and not getting a bug bounty. If you don’t offer a bug bounty program in the first place, my gut feeling is that they probably wouldn’t care in that case either. Either way, this is a super good reason to not do business with such a company.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#117
post #67

Earlier quoted context omitted.

Where did the browser go wrong, here? They followed all security practices. The browser isn't what is running the payload. Unless, you're suggesting that nobody should be able to download programs, unless blessed by some large company?

The browser is allowing remote code to talk with 127.0.0.1

Right... And that's only blocked in the host asks for it via CORS, or Same-Origin policies. Because otherwise you break any combination of apps. It's up to the server on the localhost not to blindly trust. And has been since the beginning.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#118

Earlier quoted context omitted.

The problem I found about the adaptors is that you can't charge your phone and listen to music at the same time. I have an older car with an old stereo where the only external input is via jack. Worked perfectly fine with my old phone. When I got a new Samsung, I went through the hassle of trying several "combined usb-c charger and audio jack adaptor" only to eventually find out they can only work in on mode or the o…

> only to eventually find out they can only work in on mode or the other, not both at the same time. I can't tell you how many times I've bought something small that should reasonably do two things at once, but can't. Literal e-waste garbage.

Isn't the 1000 Euro phone a bigger e waste?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#119
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

According to the post above, if you earned enough reputation then you might be given that one-hour window for fixing before disclosing. The issue isn't so much about whether or not there should be a "private" window but how long it lasts, especially when the editor is a multi-billion company

Re: One-Click RCE in Asus's Preinstalled Driver Software

#120
post #52
post #48

Earlier quoted context omitted.

what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? If the reason for responsible disclosure is to ensure that no members of the public is harmed as a result of said disclosure, should it not be a conversation between the security researcher and the company? The security researcher should have an approx. idea of how or what to do to…

If the vulnerability can't be fixed within the week, maybe the company should be SOL. This will incentivize companies to build their software better, as they'll know that any vulnerability that is hard to fix will mean consequences. Maybe the mitigation is for the company to take its service down while it works on the problem. Again, a good incentive to avoid that in the first place. Also an incentive to not waste an…

And when its an OS company and the test suites take a week to run (really) ?

Dev time + test time + upload to cdn , is often longer than a week.

Post reply on HN