Live data from Hacker News

Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

twitter.com

271–280 of 322 posts

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#271
post #223

Earlier quoted context omitted.

Engineer Alice is the only person incompetent at their job in this conversation. If " irrepressibly existential sigh " is how you argue security with your bosses then maybe you're not senior enough to be in meetings like these. The Manager and QA Engineers here depend on the expertise of the engineers. If the engineers fail to communicate key details of the situation, then that's on them. Sure, the boss is still at f…

If you answer with the existential sigh, you’ve had at least 20 conversations with a similar outcome before. Nobody arrives at a new company that jaded.

I see your point and I suspect that that's what the author meant.

At the same time, I know lots of, well, arrogant nerds who get into "existential sigh" mode as soon as someone with less technical skill than them says something stupid. That's more how I read it.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#272

Here is the original vulnerability report: https://www.redteam-pentesting.de/en/advisories/rt-sa-2019-0...

... which has

    -A kurl
in the proof of concept.

I also note the timeline

* 2019-01-22 Firmware 1.4.2.20 released by vendor

...

* 2019-02-07 Incomplete mitigation of vulnerability identified

...

* 2019-03-25 Vendor requests postponed disclosure

So this is apparently a bad fix that Cisco has known about since February, and asked for an extension in order to fix again.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#274

Earlier quoted context omitted.

Yes. I don’t think there is even a PE licensing path for software, so even with a CS degree you could never become a licensed engineer. You have to work under a PE for 5 years, then take the PE exam, then CE credits. I have an MSEE, but can’t put engineer in my title. Though Ing. sounds kind of cool.

There actually was a PE for Software Engineering, but it is being discontinued, because almost no one took it. https://ncees.org/ncees-discontinuing-pe-software-engineerin...

Wow, didn’t know they had one. I wonder how they handle the licensing as there would be no one to complete the 5 year understudy; chicken and the egg.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#275
post #186

Earlier quoted context omitted.

Quitting assumes the possibility of finding a job around the corner and not having people that depend on you.

You might be surprised, but if you move to Europe, it is actually so! Move to Berlin of Frankfurt. There is always work for Software Developer here, it is hard not to get one and you get spammed by recruiters all the time. You don't have to take shit from management, you can just go elsewhere. Everything is also very near.

I live in Germany, now try to convince the family to move along.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#276
post #82

Earlier quoted context omitted.

Rubbish. They are incredibly useful for debugging.

They would be a lot more useful if they were more straighforward and honest. Just give me "Chrome 68" instead of "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.106 Safari/537.36"

firefox has a sane user agent. mine is:

>Mozilla/5.0 (X11; Linux x86_64; rv:65.0) Gecko/20100101 Firefox/65.0

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#277
post #213

Earlier quoted context omitted.

On HN its always big bad management who is the cause of every security problem or shoddy piece of engineering. If only that pesky management would screw off then we could do things "properly". You'd be suprieed at how many incompetent engineers there are out there. If "engineer" Alice in your story was actually competent they would never agree to implement the proposed "fix". Its not a fix. To pass it off as one woul…

If you're a company the size of Cisco, and you have two widely publicised vulnerabilities like this, then this sort of failure is _always_ management's responsibility. That responsibility might come in the form of "big bad management" chasing the cheapest possible "fix" against the advice of the the hero engineers, but it can take other shapes too. It might be poor oversight and QA processes, or a failure to hire and…

> That responsibility might come in the form of "big bad management" chasing the cheapest possible "fix" against the advice of the the hero engineers

This is the narrative that always shows up in HN. Big bad management vs the hero engineer. It makes us feel good about ourselves while also absolving us of all responsibility. Its a bullshit narrative.

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#279

Earlier quoted context omitted.

I've come to the conclusion recently that we're all just barbers, bloodletting and burring holes. Until we have proper certifiable and reproducible competency, we'll never become surgeons.

Don't you need a license to be a barber?

In modern times yes, here's some interesting reading on the guilds licensing originated from - https://en.wikipedia.org/wiki/Worshipful_Company_of_Barbers

Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent

#280

Earlier quoted context omitted.

Some time ago I went through the list of all the major router manufacturers and rated them on 1) security, and 2) long term usability, and 3) culture. My conclusion was that I would buy my infrastructure from Allied Telesis. It's pretty much a Japanese version of Cisco, but it's still healthy. Ubiquity was number 2. I refrain from buying from them only because of their glossy UI. Mikrotik was on that list. Until I sa…

https://threatpost.com/hardware-vendor-offers-backdoor-every... At least Allied Telesis documents their backdoors :)

Oh god...
Post reply on HN