Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

151–160 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#151
post #110

Earlier quoted context omitted.

I think one point being made is that (in this example) you would've been much less careless about shipping the vulnerability, if you knew you'd be held accountable for it. With current practice, you can be as sloppy and reckless as you want, and when you create vulnerabilities because of that, you somehow almost push the "responsibility" onto the person who discovers it, and you aren't discouraged from recklessness.…

> you would've been much less careless about shipping the vulnerability, if you knew you'd be held accountable for it I have a problem with this framing. Sure, some vulnerabilities are the result of recklessness, and there’s clearly a problem to be solved when it comes to companies shipping obviously shoddy code. But many vulnerabilities happen despite great care being taken to ship quality code. It is unfortunately…

>What you’re describing is a scenario that would force developers to just stop making software, on top of putting significantly more people at risk.

Good. I work in code security/SBOM, the amount of shit software from entities that should otherwise be creating secure software should worry you.

Businesses care very little about security and far more about pushing the new feature fast. And why not, there is no real penalty for it.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#152

Earlier quoted context omitted.

You already put your tens of thousands of users at risk. The people putting bugs in the software, not the ones discovering them.

Please enlighten me on how you've managed to never write any bugs.

Well, not sure DJB posts here, but he has kept it to a minimum.

And this is mostly BS too. People don't write bug free software, they write features.

Other industries had to license professional engineers to keep this kind of crap from being a regular issue.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#153
post #129

Earlier quoted context omitted.

Strange wording. You are the one that put tens of thousands of your users at risk. Not the one who discovers the problem.

If you forget your shop's door open after hours, and someone starts shouting "HEY GUYS! THIS DOOR IS OPEN! LOOK!", I have a hard time putting 100% of the blame on you.

If I point out the bridge is cracking and you get angry about it, I'm blaming the idiots that engineered a crap bridge and didn't maintain it.

Maybe it's time we get professional standards if this is how we are going to behave?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#154
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

Fair warning through "responsible" disclosure was abused again and again and again. Why should I trust company no 1000 after 999 have mislead bug reporters, the public, their customers and the rest of the world about their own "just an hour"?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#155
I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup[1] and likely does not have the capital to pay a bounty.

[1]: https://companiesmarketcap.com/asus/marketcap/

Re: One-Click RCE in Asus's Preinstalled Driver Software

#156

Earlier quoted context omitted.

You are right about open source developers who do this on the side, as a hobby, and even if they don't are usually underpaid and understaffed. They do deserve more time and a different approach. But corporations making big bucks from their software need to be able to fix things quickly. They took money for their software, so it is their responsibility. If they cannot react on a public holiday, tough luck. Just look a…

> But corporations making big bucks from their software need to be able to fix things quickly. They took money for their software, so it is their responsibility. If they cannot react on a public holiday, tough luck. Because it is not corporations who are reacting on public holidays, but developer human beings. It is not corporations that are reacting to install patches on a Friday, but us sysadmins who are human bein…

Companies will act out of greed and use their customers and developers as "human shields" to get out of their responsibility. Your on-call duty should be paid by the hour just as any duty, doubling the pay on weekends, holidays and nights. "But the poor developers" is just the "we will hurt this poor innocent puppy"-defense. The evil ones are the ones inflicting the hurt, the greedy companies. Not the reporters.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#157
post #110

Earlier quoted context omitted.

I think one point being made is that (in this example) you would've been much less careless about shipping the vulnerability, if you knew you'd be held accountable for it. With current practice, you can be as sloppy and reckless as you want, and when you create vulnerabilities because of that, you somehow almost push the "responsibility" onto the person who discovers it, and you aren't discouraged from recklessness.…

> you would've been much less careless about shipping the vulnerability, if you knew you'd be held accountable for it I have a problem with this framing. Sure, some vulnerabilities are the result of recklessness, and there’s clearly a problem to be solved when it comes to companies shipping obviously shoddy code. But many vulnerabilities happen despite great care being taken to ship quality code. It is unfortunately…

> A sufficiently complex system will result in vulnerabilities even a careful person could not have predicted.

I think as a field we're actually reasonably good at quantifying most of these risks and applying practices to reduce the risk. Once in a blue moon you do have "didn't see that coming" cases but those cause a very minor part of the damage that people suffer because of sw vulnerabilities. Most harm is caused by classes of vulnerabilities that are boringly pedestrian.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#158
post #152

Earlier quoted context omitted.

Please enlighten me on how you've managed to never write any bugs.

Well, not sure DJB posts here, but he has kept it to a minimum. And this is mostly BS too. People don't write bug free software, they write features. Other industries had to license professional engineers to keep this kind of crap from being a regular issue.

"Licensed professional engineers" are a software-development myth.

If all our software was as simple as a bridge, then we could have that. A bridge is 5 sheets of plans, 10 pages of founding checks, 30 pages of calculations, 100 pages of material specs. You can read all those in a day. Check the calculations in a week. Next bridge will be almost the same.

Now tell me about any software where the spec is that short and simple. /bin/cat? /bin/true? Certainly not the GNU versions of those.

Software is different because we don't build 1000 almost-identical bridges with low complexity. We always build something new and bespoke, with extremely high complexity compared to any kind of building or infrastructure. Reproduction is automatic, so there will never be routine. Totally different kind of job, where a licensed professional will not help at all.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#159
post #35

Earlier quoted context omitted.

The problem is just one of legislation of liability. Car manufacturers are ordered to recall and fix their cars, but software/hardware companies face just too little pressure. I think customers should be able to get full refund for broken devices (with unfixed CVE for example).

The devices and core functionality (including security updates, which are fixes to broken core functionality) must survive the manufacturer and should not require ongoing payments of any type*. (new updates being created? maybe, access to corrections to basic behavior? Bug / security fixes should remain free.)

Yes. I would envision that it is at least 5 years of such updates fixes and another 5 years available for purchase capped at 20% of device price.

All manufacturers must pay an annual fee to an insurance scheme which covers the case of insolvency of manufacturers.

Post reply on HN