Earlier quoted context omitted.
Cisco is in the business of selling big, black, expensive boxes that have a lot of security badges and fancy icons. People who buy such boxes don't care if they actually work, they want a big box so that they can claim they "invested in security".
What would you buy instead of Cisco? HP and Dell are the same thing. From experience a decade ago, the HP usually did not have the enterprise features they advertised. The other minor brands are very hard to procure if you're not in the US or a primary English speaking country.
Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
291–300 of 322 posts
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#292Earlier quoted context omitted.
What would you buy instead of Cisco? HP and Dell are the same thing. From experience a decade ago, the HP usually did not have the enterprise features they advertised. The other minor brands are very hard to procure if you're not in the US or a primary English speaking country.
Juniper? Extreme? The list is not very long, but doesn't contain just Cisco.
Pretty sure Extreme is still non-existent in Europe as of today.
For all the flaws of Cisco, well the only flaw is the price, they can deliver in any language anywhere in the world.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#293Earlier quoted context omitted.
Let me know when pride is accepted as currency to pay bills or when insubordination due to personal pride is seen as a desirable quality in a candidate. At the very least, how much are you willing to pay a person for not implementing the fix you disagree with (including engaging in a legal contract to pay them if they lose their employment due to not implementing the fix). From my past experiences with others, moral…
Pleas tell me in what country is it an issue for a software developer to make money? I mean in this situation, if I were forced to implement such fix, I would do it, but would then quit the next month. Because if I were to stay, not only would I get worse professionally, but I would feel dirty for not doing my work properly. The companies that accept such fixes are more often than not like a factory and treat you as…
One could suggest to such people to display enough financial discipline to save up a rainy day fund, but this is ignoring all the procedures in place designed specifically for depressing wages.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#294Earlier quoted context omitted.
Sir, your assessment of this particular joke is excellent. We should start a joke approval committee to avoid further confusion.
Yes, very well, as first action of the Joke Approval Committee, I propose that this august body instantiate the Recursed Approval Subcommittee, whose role will be to instantiate the Recursed Approval Subcommittee.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#295Earlier quoted context omitted.
The equivalent of a "pls dont hack" sign is not defense in depth. Good to know they at least half fixed the problem, I guess. But that's not enough, and they should be capable of testing this.
Can anything without a "please don't hack" sign considered defense in depth? Probably not, hence an appropriate first patch.
If you're fighting an active attack you can stall by filtering on some arbitrary parameter unrelated to the actual problem. For anything that's supposed to last more than an hour, it's worse than useless. It makes your system more complex for no security benefit. An idea like that should never make it into a product release.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#296Earlier quoted context omitted.
And yet the US has consistently been in the vanguard of software development worldwide. Do we need surgeons? Do you need a four year postgraduate degree and three more years of apprenticeship before slinging together a web app? Certainly the industry has its problems, and some applications demand more rigor, but I don’t see this as much of a general solution.
The market didn't demand a high survival rate or efficacy for barbering either, but do you think that the (conscious or unconscious) that software engineers are some sort of magical wizards will last forever?
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#297Earlier quoted context omitted.
If you answer with the existential sigh, you’ve had at least 20 conversations with a similar outcome before. Nobody arrives at a new company that jaded.
I see your point and I suspect that that's what the author meant. At the same time, I know lots of, well, arrogant nerds who get into "existential sigh" mode as soon as someone with less technical skill than them says something stupid. That's more how I read it.
I guess for me the word existential is a bit different. For an arrogant developer it would have been something like ‘long-suffering sigh’.
Unless, I guess, you feel you are so smart that your entire life is defined by interacting with morons :P
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#298Earlier quoted context omitted.
Then add a "tainted by evil" flag to the ipv7 spec, or better, just add a "pure" flag to future ip spec.
I think I'd almost prefer an "alignment" flag, so we don't mischaracterize all the Chaotic Neutral packets.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#299Of all the security post-mortems I’ve ever wanted to read, it’s sad I’ll probably never get to read this one and its tale of how a team of well-paid comfortable engineers got together and decided this patch was a good idea.
Having been involved in meetings where "stop ship" was the phrase of the day, I'd bet money that the following at least vaguely resembles a real conversation: Engineer Alice: We should really fix this properly. Manager: How sure are you that the proper fix won't break something else for $BIG_CUSTOMERS who are responsible for $OBSCENE percent of this product line's revenue? Engineer Bob: Uh, ten percent on a good day?…
The one where the "appeasement engineer" shows up to fulfill the guaranteed response time requirement.
Re: Cisco Fixes RV320/RV325 Vulnerability by Banning “curl” in User-Agent
#300I don't see what the fuss is about. This is an effective mitigation, given that software can't just arbitrarily lie about its user agent.