Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

221–230 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#221
post #209
post #162

Earlier quoted context omitted.

You must live in a very nice, ideal world, where simply saying "no, that's not the right way to do it" will convince managers to ignore the pressures placed on them to, at times, value speed over correctness.

What they are saying is that this isn't just "the wrong way to do it". It doesn't actually fix the problem it's supposed to fix, therefore it's actually wrong to say it's a functioning patch.

Of course, but their boss doesn’t know that (or care about it), he just wants to see the fixed bug graph line approach the total bug graphline.

It’ll be totally explainable as engineer failure if something somehow doesn’t work.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#222
post #160

Earlier quoted context omitted.

Absolutely: Cisco made this happen, not Engineer Alice. If your boss asks you to do something within my ethical boundaries and you have 5 tired co-workers in favour of shipping it, eventually you'll break and say "fine". It doesn't make you responsible or the one that pulled the trigger.

The fact that this fix made it to prod tells you that something is deeply deeply broken with cisco’s processes that goes well beyond any individual’s responsibility.

Exactly. It's not like somebody just did this like in a three people startup. There are code reviews and quality management and many more, and this lousy "fix" has passed all those stages and instances. If nobody declined this, there's a serious problem within Cisco.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#223

Earlier quoted context omitted.

Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…

Engineer Alice is the only person incompetent at their job in this conversation. If " irrepressibly existential sigh " is how you argue security with your bosses then maybe you're not senior enough to be in meetings like these. The Manager and QA Engineers here depend on the expertise of the engineers. If the engineers fail to communicate key details of the situation, then that's on them. Sure, the boss is still at f…

If you answer with the existential sigh, you’ve had at least 20 conversations with a similar outcome before. Nobody arrives at a new company that jaded.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#224
post #145

Earlier quoted context omitted.

> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.

Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I sa…

disable winbox and use their webui?

also, while not perfect, what is so horrible about their winbox protocol?

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#225
post #145

Earlier quoted context omitted.

> I want my socially maladept neckbeards and terminal junkies back plz. the MBA types don't like these hacker types - personality clash and whatnots. But the MBA types control the company from above, and the hacker types don't like to do management work. The result is obvious.

Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I sa…

Can you elaborate on Mikrotik? I've only heard good things about them and am very satisfied with the one hAP I bought from them.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#226

Earlier quoted context omitted.

Yeah but it's not Reddit, it's HN. You have to know your audience, read the crowd. On Reddit it's 90% sarcasm so there's no fixing it. Here it's the reverse and people take things seriously without a tell. You just have to bury the tell in another joke or it will ruin the funny.

"given that software can't [ridiculous thing no one has ever claimed]" is plenty for a tell.

Just the fact that this “fix” exists tells you some people believe differently.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#227
post #3

I don't see what the fuss is about. This is an effective mitigation, given that software can't just arbitrarily lie about its user agent.

It does seem so obviously simple to sidestep that it makes me wonder if they pushed it because they had an active attack they believed it would mitigate. Were they concerned that the attack was already baked into some automated script in the wild and this could perhaps at least trip up the script long enough for them to engineer a real fix?

Scripted attacks can of course be modified too, but it still takes more than zero human effort to do it.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#228

Earlier quoted context omitted.

Rubbish. They are incredibly useful for debugging.

You're writing your websites wrong.

I've had to debug around a short-lived bug in the Firefox rendering engine that only showed up in the FF rendering engine before. The site itself? Standards-compliant; there was flexibility in the standard (ironically, for flexboxes ;) ) about performance constraints and our site just fell down Gecko's slowness tree and hit every branch on the way.

Given the engines are allowed to vary, this experience is inevitable from time to time. The user-agent is really valuable in helping us figure out when that's what we're seeing.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#229

Earlier quoted context omitted.

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

There are plenty of poor engineers, but this “fix” has to go through a process defined and enforced by managers. In a good process, multiple engineers would review the code, and if the office culture is good, then objections will be brought up and listened to, and if a fix is insufficient, management will understand and assign resources to make it right. None of those things depend on any one engineer or manager. The…

The only way, and I mean the only way, this gets blocked is because a manager (not a dev) assesses the risk of improper fixing to be higher than the reward of not doing a shit ton of work justifies.

A significant portion of that is making sure the manager is fully cognisant of what the quick fix means. Alice's job is to ensure that happens. The managers job is to advocate to his bosses that this has to be done and is a net win to do it properly.

It is as likely manager person failed in advocacy as it is she failed in information transfer, but there are plenty of gradients here.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#230
post #185

Earlier quoted context omitted.

Thankfully there are countries where Engineer is still a proper word, not something that you are allowed to call yourself after a 6 month bootcamp.

And most states in the US too. Just rarely enforced. Only a licensed PE can do business as an “Engineer”. (For example have a company with the word Engineer or Engineering in the name).

Protected term in Canada as well, but I don't know the last time anyone that was used against in any level of court. During my education there was a case study of some guy digging basements calling himself an engineer when he wasn't but that's about it.
Post reply on HN