Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

21–30 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#21

Obligatory "Scumbag Asus" video link: Invidious https://inv.nadeko.net/watch?v=cbGfc-JBxlY YouTube https://youtube.com/watch?v=cbGfc-JBxlY "ASUS emailed us last week (...) and asked if they could fly out to our office this week to meet with us about the issues and speak "openly." We told them we'd be down for it but that we'd have to record the conversation. They did say they wanted to speak openly, after all. They h…

This makes me angry, so can anyone think of a legitimate steelman of their position?

Expect my view is consistent with reality, though: they’re chasing profits and getting away with it, so why go on the record and look bad if they can ignore & spend that time on marketing.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#23

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Citing CGPGrey: Solutions that are the first thing you can think of are terrible and ineffective.

Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes.

You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#25

Doesn't surprise me. Their software sucks and security wise they are repeat offenders considering the lack of prevention. https://www.techspot.com/news/95425-years-gigabyte-asus-moth... https://www.reddit.com/r/ASUS/comments/tg3u2n/removing_bloat... https://www.reddit.com/r/ASUS/comments/ojsq80/nahimic_servic...

Not even the first of firsts;

https://cve.mitre.org/data/board/archives/2016-06/msg00006.h...

(my old blog is long gone from tumblr, but I archived it:)

https://gist.github.com/indrora/2ae05811a2625a6c5e69c677db6e...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#26
post #19

>so I could see if anyone else had a domain with driverhub.asus.com.* registered. From looking at other websites certificate transparency logs, I could see that domains and subdomains would appear in the logs usually within a month. After a month of waiting I am happy to say that my test domain is the only website that fits the regex, meaning it is unlikely that this was being actively exploited prior to my reporting…

A wildcard certificate is only for a single label level, '*.example.com.' would not allow 'test.test.example.com.', but would allow 'test.example.com.'. If someone issued a wildcard for '*.asus.com.example.com.', then could present a webserver under 'driverhub.asus.com.example.com.' and be seen as valid.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#27
post #23

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Citing CGPGrey: Solutions that are the first thing you can think of are terrible and ineffective. Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes. You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.

> You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.

I don't think you can fathom the amount of people that have phones with roughly 3 years of no android updates as their primary device with which they use all the digital services they use, Banking, Texting, Doomscrolling, Porn, ...

Users, especially the most likely to be exploited are already vulnerable to so much shit and even when there's a literal finished fix available, these vendors do shit about it. Only when their bottomline is threatened because even my mom knows "Don't buy anything with ASUS on it, your bank account gets broken into if you do" will we see change.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#28

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors.

The actually responsible thing to do is to disclose immediately, fully and publically (and maybe anonymously to protect yourself). Only after the affected company has repeatedly demonstrated that they do react properly, they might earn the right for a very time-limited heads-up of say 5 work days or something.

That irresponsibly delayed limited disclosure is even called "responsible disclosure" is an instance of newspeak.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#29

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I mean, to be a bit more reasonable, there's a middle ground here. Maybe disclosing a massive RCE Vulnerability in software used by a lot of companies on 25th of December is not a good Idea. And perhaps an Open Source Dev with a security@project mail deserves a tad more help and patience than a megacorp with a record of shitty security management. And if you are a company that takes security serious and is responsive to security researchers inquiries they deserve at least the chance to fix it fast and before it becomes public.

It's just that there are some companies EVERYONE knows are shitty. ASUS is one of them.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#30
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

no bug bounty, onto black market of exploit it goes.

that or full public disclosure.

Post reply on HN