Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

221–230 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#221
post #220

Earlier quoted context omitted.

Asrock (sub-brand of Asus but seemingly independent in the product and dev side) has been fine for me over the ~10 years I've bought their mobos. There was the thing a few months ago with X870 mobos that were apparently frying CPUs, but I think that was not sufficiently proven to be their fault? That said, in their X670 / B650 they have the same setting as what this article is about, and it could be equally as broken…

Asus and AsRock are separate since 2010.

Its new owner since 2010 is still part of the Asus group, but sure it's technically a different company from Asus proper.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#222
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

> Asus is just a small startup I'm not sure where they got that from, Asus have been making motherboards and other pc parts since at least the 90s...

It's Poe's Law in action

Re: One-Click RCE in Asus's Preinstalled Driver Software

#223

Earlier quoted context omitted.

I think ASUS' turnaround time on this was quite good, I don't see the problem here. ASUS didn't deny the bug, didn't threaten to prosecute anyone for reverse engineering their software, and quickly patched their software. I have no doubt that before the days of responsible disclosure, this process would've taken months and might have involved the police. Normal people don't care about vulnerabilities. They use phones…

"Stores are not permitted to sell products with known vulnerabilities under new cybersecurity regulations." Do stores have to patch known vulnerabilities before releasing the product to customers or can customers install the patch?

Stores don’t have the capability to do this. These aren’t car dealerships we’re talking about here, more like Walmart or Best Buy. It would take a recall/RMA or online firmware updates, both of which already exist and are widely used.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#224

Earlier quoted context omitted.

You already put your tens of thousands of users at risk. The people putting bugs in the software, not the ones discovering them.

Please enlighten me on how you've managed to never write any bugs.

Didn't say that. But I can't blame the ones publicising the bugs we put in there.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#225
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

You made the software, you have your paid customers, you are responsible for security of your customers. If you have an RCE that's your problem and you gotta fix it.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#226
post #165

Earlier quoted context omitted.

I think ASUS' turnaround time on this was quite good, I don't see the problem here. ASUS didn't deny the bug, didn't threaten to prosecute anyone for reverse engineering their software, and quickly patched their software. I have no doubt that before the days of responsible disclosure, this process would've taken months and might have involved the police. Normal people don't care about vulnerabilities. They use phones…

> Stores are not permitted to sell products with known vulnerabilities under new cybersecurity regulations. What are the specifics on that? Like does the vulnerability need to be public or is it enough if just the vendor knows about it? Does everyone need to stop selling it right away if new vulnerability is discovered or do they some time patch it? I'm pretty sure software like Windows almost definitely has some unf…

Probably refering to CRA - Cyber Resilience Act

https://schjodt.com/news/the-cyber-resilience-act-enters-int...

https://digital-strategy.ec.europa.eu/en/policies/cyber-resi...

https://ec.europa.eu/commission/presscorner/detail/en/qanda_...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#227
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

> Asus is just a small startup I'm not sure where they got that from, Asus have been making motherboards and other pc parts since at least the 90s...

It's sarcasm

Re: One-Click RCE in Asus's Preinstalled Driver Software

#228

Earlier quoted context omitted.

Just a few days ago people were talking about this on the kicad discord. A chinese team made an open hardware x86_64 motherboard and published it not too long ago. Then they were essentially wiped off the face of the planet. That was the day I learned you literally cannot develop a computer motherboard without Intel's permission. Turns out Intel is no different than the likes of Nintendo.

Yes, if you want to go that route, you'll be better off going with RISC-V.

I absolutely want to go with RISC-V longer-term, but it seems we're still a few years away from RISC-V boards being a pragmatic choice for the average workstation, unless I've missed some recent development.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#229

Earlier quoted context omitted.

Yep. People keep pushing this false dichotomy that it's either company-directed 'responsible disclosure', or it's "release full working POC and complete writeup publicly, immediately", and there's no middle ground. Yes, limited disclosure will make people start hunting for the vuln, but it's still more than enough time for me to revoke an API key, lock down an internet-facing service, turn off my Alexa (no, I don't/w…

Knowing a half-truth is as bad as knowing nothing. Half the time I will do useless mitigations because actually I would have been unaffected. The other half I will do the wrong thing because of incomplete reporting.

> Knowing a half-truth is as bad as knowing nothing.

This is assuming the perfect user who even understands the bug and the full impact. Everyone is working with half-truths already, in which case by your logic they may as well know nothing.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#230
post #206

Earlier quoted context omitted.

It is virtually the same size[1] as the era equivalent S23. I don't think a headphone jack which you can get via a super cheap USB-C adaptor, makes the justification for a 1000 Euro paperweight. [1] https://www.gsmarena.com/size-compare-3d.php3?idPhone1=12380...

I bought several of those adapters. The issues are these: 0. They don't work on all models. Not product lines, e.g. not "all Pixel phones" or so, no, reviews mention "works with Pixel 3 but not Pixel 3a". You need to either waste a bunch of resources sending various ones back and forth, or scour listings until you find one where a review mentioned it works with the model you have. It turns out that all the ones I ord…

I went the pure DAP + wired IEMS, couple with smartphone and Bluetooth only when I need to call. Overall, less distraction as well.
Post reply on HN