Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

201–210 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#201

Earlier quoted context omitted.

Is that true? I thought you could pay for a H1 service that basically had professionals triaging the vulnerabilities and only pass on the correct ones?

Our company pays for one of these third party triage services for H1. The quality is seriously lacking. They have dismissed many valid findings.

Ah thank you for the info!

From what I understood, the service is also (very) expensive. Wild.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#202
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

[flagged]

Re: One-Click RCE in Asus's Preinstalled Driver Software

#203

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

I think ASUS' turnaround time on this was quite good, I don't see the problem here. ASUS didn't deny the bug, didn't threaten to prosecute anyone for reverse engineering their software, and quickly patched their software. I have no doubt that before the days of responsible disclosure, this process would've taken months and might have involved the police. Normal people don't care about vulnerabilities. They use phones…

"Stores are not permitted to sell products with known vulnerabilities under new cybersecurity regulations."

Do stores have to patch known vulnerabilities before releasing the product to customers or can customers install the patch?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#204
post #152

Earlier quoted context omitted.

Well, not sure DJB posts here, but he has kept it to a minimum. And this is mostly BS too. People don't write bug free software, they write features. Other industries had to license professional engineers to keep this kind of crap from being a regular issue.

"Licensed professional engineers" are a software-development myth. If all our software was as simple as a bridge, then we could have that. A bridge is 5 sheets of plans, 10 pages of founding checks, 30 pages of calculations, 100 pages of material specs. You can read all those in a day. Check the calculations in a week. Next bridge will be almost the same. Now tell me about any software where the spec is that short an…

> We always build something new and bespoke, with extremely high complexity compared to any kind of building or infrastructure.

Maybe this is part of the problem?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#205
I have a similar model motherboard from ASUS in my desktop I had custom built a few years ago, and I've mostly just been annoyed that I have to have Windows installed to be able to even update the BIOS at all given that the previous one I had (which I think was also from them?) would just let me do it over ethernet if I booted directly into the BIOS setup menu. Now I have much larger concerns in addition to the risk of not updating as frequently seeming much larger...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#206
post #88

Earlier quoted context omitted.

Zenfone is smaller and has a headphone jack. It's the superior phone

It is virtually the same size[1] as the era equivalent S23. I don't think a headphone jack which you can get via a super cheap USB-C adaptor, makes the justification for a 1000 Euro paperweight. [1] https://www.gsmarena.com/size-compare-3d.php3?idPhone1=12380...

I bought several of those adapters. The issues are these:

0. They don't work on all models. Not product lines, e.g. not "all Pixel phones" or so, no, reviews mention "works with Pixel 3 but not Pixel 3a". You need to either waste a bunch of resources sending various ones back and forth, or scour listings until you find one where a review mentioned it works with the model you have. It turns out that all the ones I ordered work on the two USB-C phones I have by now (one from work, one privately) but...

1. The quality of the mic conversion is so bad that people cannot understand what I'm saying. It's described as though I'm speaking while holding the phone under water. Plugging the headphones into my work laptop makes it clear that the mic itself is not the problem, nor the meeting software or my WiFi or anything

2. Loose contacts in most of the converters, if not from the start then after a handful of uses. The headphone cable itself somehow doesn't have that problem, so I don't think that's a me problem (many reviews also mentioned it)

3. You can't charge at the same time. I've tried wireless charging but that makes the device overheat. There are adapter models that will let you also plug in a power cable, but I didn't buy one for some reason. Probably all of them had bad reviews about all of the aforementioned problems and I didn't find a single one that sounded like it was worth a try

4. You need to plug it in at the right time. One of the converters needed to be plugged in before joining the meeting. Another one after. The OS or meeting software (not sure) wouldn't route the audio correctly otherwise

And cheap phones manage to include headphone jacks somehow. It's just a status symbol when manufacturers exclude it from more expensive models, it doesn't seem to serve any purpose as the Zenphone 10 shows by having it and also being great on all other fronts -- except one.

> a 1000 Euro paperweight

It's actually 700€.

It does everything I want. After searching a few days for what models are small, have a headphone jack, and are capable of running Android 14 or so, I was so happy to find that the Zenphone 10 checked all boxes. Then I found out why it didn't initially show up: Asus was the manufacturer that I had previously excluded because you can't root the device. It's not your device: the manufacturer maintains control over what you can and cannot do with it. You can't make full-system backups, for example, because access to your apps' data folders isn't part of what they allow you. The device was easily worth the 700€ because it sounded like I could finally stop wasting my time on choosing which compromise I wanted to make (huge size, no jack, or old chipset were the main options). Finding out there was a dealbreaker after all felt like an ice bath. I just won't buy something where I can't access my own data and make a fricking backup

Re: One-Click RCE in Asus's Preinstalled Driver Software

#207
post #185

I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup[1] and likely does not have the capital to pay a bounty. [1]: https://companiesmarketcap.com/asus/marketcap/

alternatively, sarcasm.com ;)

I'm surprised to find that this is just a random person's blog. Was very prepared for an ad page, scalped domain, or some corporation trying to make money out of it. On the sadder side, it doesn't seem like this person makes any use of the domain's name at all; they could have had firstlast.cctld for their blog and given this to someone who wants to put a sarcastic joke on it. But better this than ad farms so I don't blame them for keeping it!

Re: One-Click RCE in Asus's Preinstalled Driver Software

#208

Earlier quoted context omitted.

And when its an OS company and the test suites take a week to run (really) ? Dev time + test time + upload to cdn , is often longer than a week.

You know, airlines also had a ton of excuses for not making air travel so safe, it's expensive, takes a while, do you know how long these things take, etc. Still, they did it, because we decided safety is important to us.

Airlines also get to control how equipment is used and have clear controlled deployments. Os vendors do not.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#209
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

Because there is an information disparity I could profit from instead of doing free work for you. Even if that disparity is just "posting the vuln to my blog" to get e-famous.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#210

A few of the drivers they install (or want to install) are also on Microsoft's vulnerable actively exploited driver blacklist. So that's fun, they have no intention of fixing it because they do not support "third party software". I'm also pretty sure their installer doesn't work without unencrypted HTTP traffic being let through. Plus they keep offering bloatware as "updates" to you. On top of it all, the software th…

> Microsoft should make it significantly harder to ship drivers outside of Windows Update

No. No no no no no no no NO! That just centralises even more control to MS.

What we really need is for more people to develop open-source Windows drivers for existing hardware, or encourage the use of Linux.

Post reply on HN