Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

141–150 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#141
post #117

Earlier quoted context omitted.

The browser is allowing remote code to talk with 127.0.0.1

Right... And that's only blocked in the host asks for it via CORS, or Same-Origin policies. Because otherwise you break any combination of apps. It's up to the server on the localhost not to blindly trust. And has been since the beginning.

Might have been there since the beginning, but doesn't make it less surprising or bad. That's a _ridiculously_ bad thing to allow. Any website to talk with just about ANY port on your local machine. Incredible.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#142
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

You already put your tens of thousands of users at risk. The people putting bugs in the software, not the ones discovering them.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#143

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Or we could just have regulation or at least the same product liability for software as everything else.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#144

A few of the drivers they install (or want to install) are also on Microsoft's vulnerable actively exploited driver blacklist. So that's fun, they have no intention of fixing it because they do not support "third party software". I'm also pretty sure their installer doesn't work without unencrypted HTTP traffic being let through. Plus they keep offering bloatware as "updates" to you. On top of it all, the software th…

I thought it was revealing that the driver blacklist (sipolicy.p7b) was not updated for several years until Will Dormann happened to notice it in 2022.

https://www.csoonline.com/article/573965/how-to-update-your-...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#145
post #35

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

The problem is just one of legislation of liability. Car manufacturers are ordered to recall and fix their cars, but software/hardware companies face just too little pressure. I think customers should be able to get full refund for broken devices (with unfixed CVE for example).

The devices and core functionality (including security updates, which are fixes to broken core functionality) must survive the manufacturer and should not require ongoing payments of any type*. (new updates being created? maybe, access to corrections to basic behavior? Bug / security fixes should remain free.)

Re: One-Click RCE in Asus's Preinstalled Driver Software

#146
post #36

Earlier quoted context omitted.

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…

I disagree. The vast majority of script kiddies don't know about the zero day.

Instead of just one bad actor using that vulnerability on Andrew select targets, your proposal will have a few tens of thousands bots performing drive by attacks on millions of victims.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#147
post #36

Earlier quoted context omitted.

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

You already put your tens of thousands of users at risk. The people putting bugs in the software, not the ones discovering them.

Please enlighten me on how you've managed to never write any bugs.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#148
post #119

Earlier quoted context omitted.

According to the post above, if you earned enough reputation then you might be given that one-hour window for fixing before disclosing. The issue isn't so much about whether or not there should be a "private" window but how long it lasts, especially when the editor is a multi-billion company

Let’s not forget the end users in this scenario, who will not be able to react to this as quickly as a billion dollar company regardless of how well they notify their customers.

Absolutely, which is yet another reason why this abstraction from the conditions of creation of anything tech-related is something that should be eliminated

Re: One-Click RCE in Asus's Preinstalled Driver Software

#149

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

What about damage control? I would argue your "anonymous, immediate disclosure" to the public (filled with bad actors) would be rubbing salt in the wound (allow more people to exploit the vulnerability before it's fixed). That's why nobody publishes writeups before the vuln is fixed. Even if corporations don't fix vulns in time, I can only see harm being done from not privately reporting them.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#150
post #87

Earlier quoted context omitted.

> You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day. Which is again, a problem created by the companies themselves. The way this should work is that the researcher discloses to the company, and the company reaches out to and informs their customers immediately . Then they fix it. But instead companies refuse to tell t…

Why should it work that way? Disclosing the vuln before fixing it seems like a surefire way for my mum to lose her life's savings. Why do you hate my mum so much?

Why not turn this around?

Why do the companies that make the software hate your mom so much they push out release after release of shit? We're all fine with these developers crapping on the floor as long as we give them 30 days to clean up their steaming pile.

If instead every release was capable of instantly ruining someone's life, maybe we'd be more capable of releasing secure software and judging what software is secure.

Post reply on HN