Live data from Hacker News

FBI tells router users to reboot now to kill malware infecting 500k devices

arstechnica.com

221–230 of 299 posts

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#222
post #97

Earlier quoted context omitted.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

This is going to be really, really hard without turning into a mess. Software is complex, and bad software even more so, and an integrated hardware/software system is even worse. Even finding the vulnerabilities is hard already, because lots of systems are snowflakes and each needs to be analyzed individually, and usually in individual ways. And even assuming we have a definition of 'infrastructure software' and a wa…

When an aircraft crashes and the NTSB gets involved to investigate, does the aircraft manufacturer get sued? I don't know. Why can't we set up something like the NTSB for critical infrastructure stuff at least? I can see how setting it up for consumer stuff would suck. But purpose of the org would be to make stuff safer and develop best practices, not assign blame. I'm probably naive, as I don't know all the good and bad details of how NTSB investigations work. But I figure that's a good place as any to find inspiration for something that could work?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#223

Earlier quoted context omitted.

>>>> - What happens if that library is openssl and almost all webservers on the internet are vulnerable? >>> Everyone deploying it is liable. > I've been shipping production software for years... Have you ever shipped software which depends on openssl? If not, then pretend that you have. Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for bec…

Yes, I have. > Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for because you deployed something using openssl? This is a really ridiculous question. I've already stated that these things are complicated - you're asking for a hard number? Companies should take responsibility for their users data, which includes understanding the risk involve…

>> can you give me a ballpark

> you're asking for a hard number?

No, I am not asking for a hard number, I specifically asked for a ballpark.

> invest in the security of the project you're using

I agree, but slapping fines of developers for using openssl to enhance security makes it a bit hard for anyone to afford putting any extra money towards security

> arguing about the specific mechanics is pointless

Agreed, my goal is not to flesh out the mechanics, it is to demonstrate the pitfalls of such a law. I'm only asking for a ballpark (again, not a hard number) so that you can personally understand why you and every other serious developer would be sued out of existence unless you propose obscenely small fines (which would make the whole idea useless, because then developers could easily afford to be negligent without getting too much of an increase in fines).

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#224

Asus is not affected by this but it I still updated the firmware because it was affected by multiple other vulnerabilities... I wonder if computing we'll become secure before I die...

I was wondering about this so that is good to know, thanks. My Asus router was also updated for multiple other vulnerabilities. I really think Asus has been doing a great job with pushing regular updates.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#225

Earlier quoted context omitted.

If the exploit wasn't put there intentionally, then we're talking about a bug in the software. Do you really want liability for software bugs? The consequences of that would be substantial. Imagine if Apache or PHP were liable for their bugs used on websites across the internet. The projects would shutdown immediately.. no one could fund the potential liability.

> Do you really want liability for software bugs? Yeah, definitely. Especially for infrastructure. I realize the implications of this are significant. I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are abs…

Yes. But now you are liable. How many bugs have you fixed that were created by you?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#226

Earlier quoted context omitted.

Yes, I have. > Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for because you deployed something using openssl? This is a really ridiculous question. I've already stated that these things are complicated - you're asking for a hard number? Companies should take responsibility for their users data, which includes understanding the risk involve…

>> can you give me a ballpark > you're asking for a hard number? No, I am not asking for a hard number, I specifically asked for a ballpark. > invest in the security of the project you're using I agree, but slapping fines of developers for using openssl to enhance security makes it a bit hard for anyone to afford putting any extra money towards security > arguing about the specific mechanics is pointless Agreed, my g…

> No, I am not asking for a hard number, I specifically asked for a ballpark.

Yes, and it's a fake law that doesn't exist. How would I possibly answer this?

Off handedly, I'd say that the fine could really range depending on a lot of things. Was this an outdated version of OpenSSL that they just didn't patch? Was it a programmer error using the library? A 0day? All of these things would probably make a big different - charging companies for 0days in 3rd party code, in at least many cases, would not make sense.

> I agree, but slapping fines of developers for using openssl to enhance security makes it a bit hard for anyone to afford putting any extra money towards security

At some point if companies can't afford to keep users safe maybe they just shouldn't be companies. And if we're talking about router companies, they have the cash.

> why you and every other serious developer would be sued out of existence unless you propose obscenely small fines

I would imagine instead that companies would have insurance around these issues to cover developers, but again, the legal components of this are not something I'd want to get into since I'm not qualified to.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#227
post #5

Earlier quoted context omitted.

A factory reset, according to Cisco, will fix it. Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...

It's really too bad that nobody makes hardware with the obvious solution - put the firmware in ROM. Then it cannot be altered by malware. If the vendor really, really wants to update the firmware, have the write-enable switch be a physical one, not a software switch.

You really want vendor to patch vulnerabilities in firmware without pushing any buttons.

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#228

Earlier quoted context omitted.

Cisco is a Fly By Night IOT Corporation? Linksys?

> Cisco is a Fly By Night IOT Corporation? Linksys? Cisco hasn't owned Linksys in years and Linksys itself is tiny. This kind of liability absolutely could bankrupt them. And they're one of the major players. There are companies making this kind of hardware with like twelve employees. The barrier to entry is so low that even individuals commonly make one-offs from scratch for personal use.

> Cisco hasn't owned Linksys in years

I didn't say they did... I was providing two examples. I wouldn't call linksys tiny, either.

You're assuming a lot about the costs of this liability for a made up law with no defined penalty.

Maybe if companies building software can't afford to keep it safe... they shouldn't be companies? Is that so controversial?

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#229

Just calling out the good guys at Microtik. They patched their router a year before being notified by Cisco.

Is this posted somewhere? I read the CERT release, TFA, and the MT forums and can't see any reference to a known fixed version. Thanks.

https://forum.mikrotik.com/viewtopic.php?t=134776

Re: FBI tells router users to reboot now to kill malware infecting 500k devices

#230

Earlier quoted context omitted.

It's really too bad that nobody makes hardware with the obvious solution - put the firmware in ROM. Then it cannot be altered by malware. If the vendor really, really wants to update the firmware, have the write-enable switch be a physical one, not a software switch.

You really want vendor to patch vulnerabilities in firmware without pushing any buttons.

So you want the ability to remotely update to protect against the malware being installed via remote update?
Post reply on HN