Live data from Hacker News

The Harmless Pi-Hole Bug

kiyell.com

41–48 of 48 posts

Re: The Harmless Pi-Hole Bug

#41
post #4

Earlier quoted context omitted.

If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…

> I can look at a CVE and determine for myself and my organization whether it something we need to care about. Except it doesn't work like this. A security scanner will include a CVE. People want no red flags on the security scanner. They don't care what the CVE is, they just want red mark go away. The attitude to accepting useless crap as a CVE is diluting what an important CVE actually is.

If that is your attitude to security scanning, you should not be in charge of anything more important than a speak and spell.

Re: The Harmless Pi-Hole Bug

#42
post #2

This stuff is why CVE numbers are meaningless. "Someone can see the temperature of your server if they can get into your home network" is barely a bug, let alone a security bug. This is just generating CVE numbers for the sake of it.

I disagree, that's pretty easy to turn into a occupancy sensor. I think people need to get away from the "is this piece of information sensitive" in isolation and start thinking about it more like leaking bits. Leaking bits is bad, you don't know how a clever person might leverage them

Re: The Harmless Pi-Hole Bug

#43
post #25

Earlier quoted context omitted.

Except this isn't a CVE anyone will encounter in the workplace because nobody in their right mind would run Pi-Hole on a Raspberry Pi in a professional setting. It's a waste of time. If you want to dedicate staff to reviewing useless garbage issues you do that, go and review every issue logged against other non-commercial software. The rest of us have a job to do.

> The rest of us have a job to do. I'm not sure why you are being hostile about it, but okay. Obviously you feel very strongly about the subject. You should engage with MITRE and encourage them to reconsider their current CVE inclusion decision tree.

If Daniel Steinberg struggles to make headway with them…

Re: The Harmless Pi-Hole Bug

#44

Earlier quoted context omitted.

> I can look at a CVE and determine for myself and my organization whether it something we need to care about. Except it doesn't work like this. A security scanner will include a CVE. People want no red flags on the security scanner. They don't care what the CVE is, they just want red mark go away. The attitude to accepting useless crap as a CVE is diluting what an important CVE actually is.

If that is your attitude to security scanning, you should not be in charge of anything more important than a speak and spell.

Seriously? Treating joke CVEs the same as true sev 1 issues is beyond silly and counter productive. There are very real limits to time, money and attention and pretending otherwise is foolish.

Re: The Harmless Pi-Hole Bug

#45
post #4

Earlier quoted context omitted.

If you don't assign CVE numbers to every security-related flaw, no matter how minor the flaw may be, you must come up with a way to draw the line on what flaws get CVEs and what ones don’t. That would be worse in pretty much every respect. As it is now, I can look at a CVE and determine for myself and my organization whether it something we need to care about. I’d rather that decision stay in my hands, not someone el…

> I can look at a CVE and determine for myself and my organization whether it something we need to care about. Except it doesn't work like this. A security scanner will include a CVE. People want no red flags on the security scanner. They don't care what the CVE is, they just want red mark go away. The attitude to accepting useless crap as a CVE is diluting what an important CVE actually is.

Are you speaking from your experience in vulnerability management? If anything, I’ve seen the opposite behavior (ignore everything except where the risk is critical).

CVSS has been around since the mid-2000s, so it isn’t as if there’s no way to discern critical vulnerabilities from informational ones.

Re: The Harmless Pi-Hole Bug

#46
post #44

Earlier quoted context omitted.

If that is your attitude to security scanning, you should not be in charge of anything more important than a speak and spell.

Seriously? Treating joke CVEs the same as true sev 1 issues is beyond silly and counter productive. There are very real limits to time, money and attention and pretending otherwise is foolish.

The person you’re replying to seems to agree with you.

Re: The Harmless Pi-Hole Bug

#47
post #28

Earlier quoted context omitted.

Yeah except Bob, your uncle, is working from home and therefore needs to care about his home network security.

I look forward to your explanation of how the temperature of Bob's Raspberry Pi poses a threat to his employer. I also wonder how the attacker got access to Bob's home network in the first place? If only he had the chance to focus on actual important security issues instead of constant notifications about useless noise like the temperature of his Pi-Hole.

>I look forward to your explanation of how the temperature of Bob's Raspberry Pi poses a threat to his employer.

Hmm, anything like this can be used as part of side channel if an attacker is able to influence the temperature of Bob's RPi.

Re: The Harmless Pi-Hole Bug

#48
post #28

Earlier quoted context omitted.

Yeah except Bob, your uncle, is working from home and therefore needs to care about his home network security.

I look forward to your explanation of how the temperature of Bob's Raspberry Pi poses a threat to his employer. I also wonder how the attacker got access to Bob's home network in the first place? If only he had the chance to focus on actual important security issues instead of constant notifications about useless noise like the temperature of his Pi-Hole.

Informational vulnerabilities are often nothing to worry about, until they are.
Post reply on HN