Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…
One-Click RCE in Asus's Preinstalled Driver Software
241–250 of 253 posts
Re: One-Click RCE in Asus's Preinstalled Driver Software
#242Earlier quoted context omitted.
I believe it's okay to let customers install the patch. The regulation itself can be found here: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML Basically, the manufacturer has to issue a patch, and the distributor has to ensure that the patch is available before selling the vulnerable devices. Without secure software, the product is essentially CE-incompliant, which means it practically isn't allowed to be sold.…
This sounds like another bureaucratic nightmare. Who is going to track this?
Re: One-Click RCE in Asus's Preinstalled Driver Software
#243Earlier quoted context omitted.
This sounds like another bureaucratic nightmare. Who is going to track this?
You know, vendors could just do the right thing and invest into security so that they don't ship vulnerable stuff from the start...
Re: One-Click RCE in Asus's Preinstalled Driver Software
#244Earlier quoted context omitted.
You know, vendors could just do the right thing and invest into security so that they don't ship vulnerable stuff from the start...
I'll pass the message on, if you kindly sign this contract to never have a car accident for the rest of your life. Just do the right thing and invest in your driving skills.
Well your analogy just proves my point, LOL.
The EU mandates that you take driving school lessons and pass an appropriate examination. Some countries go even further and demand regular medical checkups (Italy does so for senior citizens, if you're 80+ it's once every two years). And if you manage to get in the spotlight for too many or too egregious violations, your license gets suspended to permanently revoked, in addition to some serious fines and the requirement to undergo further evaluation or even therapy (e.g. if you're facing substance addiction issues).
Use that analogy on software/firmware for appliances, and then you get:
- an initial independent certification requirement before introduction into the market - and no, CE doesn't count: all that "CE" signifies is that you as the manufacturer/importer believe your product is conforming to regulations. For many products (IIRC, everything but medical products and devices containing radio transmitters), that's it, you don't even have to go to a third party like the TÜV for a formal audit.
- obligations if you manage to stand out with security issues, including a temporary order to not sell any more units until they are reworked
- getting permanently booted off the market if your violations are too serious.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#245The cynical me imagines juicy telemetry to sell to advertisers.
The realist me imagines time gains by not needing to go through Microsoft's driver update validation process (like companies keep linux drivers out-of-tree to not cleanup their code).
It's probably both.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#246Earlier quoted context omitted.
> Stores are not permitted to sell products with known vulnerabilities under new cybersecurity regulations. What are the specifics on that? Like does the vulnerability need to be public or is it enough if just the vendor knows about it? Does everyone need to stop selling it right away if new vulnerability is discovered or do they some time patch it? I'm pretty sure software like Windows almost definitely has some unf…
The full legal text doesn't fit in a HN comment, but I believe this is the meat of the description: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=OJ:... Note that in the legal text above there is language stating what requirements from the annexes applies to what hard/software. As far as I know (I haven't read the text fully) selling stuff is fine if the end user can update their software. There is no clea…
The "including the possibility to reset the product to its original state" is interesting one, would that prevent manufacturers from not allowing user to downgrade to original version (via eFuses)? 5.3.3.1 on those guidelines does say "initial or newest version", but that doesn't really sound like original state.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#247Earlier quoted context omitted.
Strange wording. You are the one that put tens of thousands of your users at risk. Not the one who discovers the problem.
If you forget your shop's door open after hours, and someone starts shouting "HEY GUYS! THIS DOOR IS OPEN! LOOK!", I have a hard time putting 100% of the blame on you.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#248Earlier quoted context omitted.
I believe it's okay to let customers install the patch. The regulation itself can be found here: https://eur-lex.europa.eu/legal-content/EN/TXT/HTML Basically, the manufacturer has to issue a patch, and the distributor has to ensure that the patch is available before selling the vulnerable devices. Without secure software, the product is essentially CE-incompliant, which means it practically isn't allowed to be sold.…
This sounds like another bureaucratic nightmare. Who is going to track this?
Re: One-Click RCE in Asus's Preinstalled Driver Software
#249A few of the drivers they install (or want to install) are also on Microsoft's vulnerable actively exploited driver blacklist. So that's fun, they have no intention of fixing it because they do not support "third party software". I'm also pretty sure their installer doesn't work without unencrypted HTTP traffic being let through. Plus they keep offering bloatware as "updates" to you. On top of it all, the software th…
> Microsoft should make it significantly harder to ship drivers outside of Windows Update No. No no no no no no no NO! That just centralises even more control to MS. What we really need is for more people to develop open-source Windows drivers for existing hardware, or encourage the use of Linux.
Re: One-Click RCE in Asus's Preinstalled Driver Software
#250Earlier quoted context omitted.
This sounds like another bureaucratic nightmare. Who is going to track this?
Grocery stores everywhere have the ability to pull recalled products off their shelves pretty quickly. I did it fairly regularly at my first job as a shelf-stocker for a small local store in rural MO. Somehow we made it work, so clearly someone figured out how to deal with that "bureaucratic nightmare". I see no reason why hardware products that are on a list due to known issues would be any different.
An immediate sales stop and recall is certainly appropriate when food endangers people's health, I'm not sure it is the right decision in this case. You could give manufacturers some time to fix it, and only then stopping the sales. This way they would still be incentivised to quickly make a fix, but avoid the potentially huge economic downside, which will lead to higher barriers of entry and probably further consolidation, hurting consumers in a different way. Remember that regulation always benefits the incumbents.