Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

131–140 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#131
post #56
post #46

Earlier quoted context omitted.

Cloud Key, USG, Switch 8 POE, and two AP-Lites. The UniFi console makes management easy compared to the edge router UI. I also have one of those but it’s just sitting right now.

I'd be wary of any Ubiquiti network kit. I only trust their APs. The ERL for example is an awful router - it has had a firmware issue for years now where it causes persistent packet loss due to reordering incoming packets. I discovered these problems in my own testing, and there is a giant thread on the forums about it which I helped kick off. The ER-X is the only thing that seems to work properly. Their switches are…

Why didn’t you use PFsense from Netgate?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#132
post #121

Earlier quoted context omitted.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

The security levels of most electronics products connected to the Internet, be it IoT or routers, can only be described as criminal negligence. There is no financial incentive for the manufacturers to invest into proper security, and they typically just add some junk to the firmware they get from the SoC vendor and ship.

I'm not sure I agree that making the vendors liable in case of vulnerabilities is the right way. It should probably suffice to require vendors to define a guaranteed product support period, where they are obliged to provide security patches, and then hold them liable if they fail that.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#133
post #121

Earlier quoted context omitted.

> Do you really want liability for software bugs? For free software? No. No payment, no obligation. For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.

This doesn’t make sense. Why is liability tied to payment? If someone 3D prints brakes and they give them away for free, are they liable? This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.

If you install someone's free plastic brake pads, you're at fault for whatever happens - and if someone offers to give you something for free and you agree, they don't have to follow through. If you buy them, there's an implied contract that you will receive them. In that implied contract, our society has also inserted "and they won't kill you." The idea that every time a dollar changes hands an implied contract is made underlies US business law. Related to this idea is how rights holders will be offered money for photographs they're giving away for free - because the person who wants to use the image wants to be protected by the implied contract. In this system money is the magic spice that makes agreements real. (If someone gives you their car for free, the courts will sometimes let them take it back. Not so if they sell it for a dollar.)

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#134
post #119

Earlier quoted context omitted.

> Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them. > - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review…

I have a very hard time believing you’ve developed software that has been released. I’ve always done my very best to release robust and stable software, and I’ve still shipped bugs. Should I be sued out of existence? We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that wou…

It seems to me this is one of those situations where the programmer mindset does not properly interface with the lawyer mindset.

In programming, you have true and false, and generally things fall into one or the other category with no human input.

In law, you have concepts like "reasonable", and a whole lot of human input, by design.

So my expectation would be that if software vendors were to be held responsible for bugs in their products, the standard they would be expected to adhere to would be "reasonable expectation of proper functioning", with humans intepreting what "reasonable" means.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#136

Earlier quoted context omitted.

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

We don't need to criminalize everything.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#137
Feds take aim at potent VPNFilter malware allegedly unleashed by Russia.

[..] to counter Russian-engineered malware that has infected hundreds of thousands devices.

I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't know that), and that it shares code with the BlackEnergy bot builder toolkit[1], which apparently can be bought on the black market for a decade already.

Neither of the original articles [2,3] mention Russia or any of the Russian APTs, so I'm genuinly interested in better attribution data.

[0] https://amp.thedailybeast.com/exclusive-fbi-seizes-control-o...

[1] https://community.rsa.com/thread/186012

[2] https://blog.talosintelligence.com/2018/05/VPNFilter.html

[3] https://www.symantec.com/blogs/threat-intelligence/vpnfilter...

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#138

Earlier quoted context omitted.

No matter which component caused the bug, the device vendor that made the final product should always be responsible, unless it has a contract outsourcing the responsibility for a specific component to another entity. If the vendor simply used open source libraries, then it needs to review and take responsibility for the code, or hire a contractor to do so. This might also incentivize them to provide timely security…

If they were liable there is no profit margin. These products will never exist.

No, they still would. People do amazing things under constraints.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#139

Does anyone know why router manufacturers aren't financially responsible for the exploits that allow their devices to be hacked? At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?

Because the market doesn't demand it. If you truly care, speak with your money and buy a WiFi system from a vendor that provides software/security updates and patches. There are a few out there doing this, but it's not cheap.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#140
post #2

Headline is a bit incorrect - a reboot will interfere with the malware by restarting the it’s C&C process, which the FBI now controls. This does not eliminate the malware, but it will stop it’s data collection and makes it more difficult for an adversary to activate it on a large scale.

So when these devices reboot, the FBI is now going to have control of ~500,000 home routers? That's, uh, "reassuring".

I belive they've done this before.

In one case they went to court to get an OK from a judge to use the malware and seized domain(s) to then activity remove it from people's computers. They asked a judge because while they can seize a botnet, actually altering people's computers might be seen as bad so it seems they went about it the right way.

If they were going to be all evil I doubt they'd be talking about rebooting routers and such ;)

Post reply on HN