Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

51–60 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#51

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

> "Responsible" disclosure is paradoxically named because actually it is completely irresponsible.

It's only paradoxical if you've never considered the inherent conflicts present in everything before.

The "responsible" in "responsible disclosure" relates to the researchers responsibility to the producer, not the companies responsibility to their customers. The philosophical implication is that the product does what it was designed to do, now you (the security researcher) is making it do something you don't think it should do, and so you should be responsible for how you get that out there. Otherwise you are damaging me, the corporation, and that's just irresponsible.

As software guys we probably consider security issues a design problem. The software has a defect, and it should be fixed. A breakdown in the responsibility of the corporation to their customer. "Responsible disclosure" considers it external to the software. My customers are perfectly happy, you have decided to tell them that they shouldn't be. You've made a product that destroys my product, you need to make sure you don't destroy my product before you release it.

The security researcher is not primarily responsible to the public, they are responsible to the corporation.

It's not a paradox, it's just a simple inversion of responsibility.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#52
post #48
post #42

Earlier quoted context omitted.

Yes but responsible disclosure should be "you have a week (or whatever) from my first email, then I go public".

what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? If the reason for responsible disclosure is to ensure that no members of the public is harmed as a result of said disclosure, should it not be a conversation between the security researcher and the company? The security researcher should have an approx. idea of how or what to do to…

If the vulnerability can't be fixed within the week, maybe the company should be SOL. This will incentivize companies to build their software better, as they'll know that any vulnerability that is hard to fix will mean consequences.

Maybe the mitigation is for the company to take its service down while it works on the problem. Again, a good incentive to avoid that in the first place. Also an incentive to not waste any time after a report comes in, to see and act on it immediately, etc.

At some point, we have to balance customer risk from disclosing immediately with companies sitting on vulnerabilities for months, vulnerabilities that may be actively exploited.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#54
post #4

> I asked ASUS if they offered bug bounties. They responded saying they do not, but they would instead put my name in their “hall of fame”. This is understandable since ASUS is just a small startup and likely does not have the capital to pay a bounty. :(

This makes me never want to buy another ASUS product again.

For me it's them lying about providing a way to unlock the bootloader of my soon to be 1000€ paperweight(2 android updates only) called an Asus zenfone 10.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#55
post #48
post #42

Earlier quoted context omitted.

Yes but responsible disclosure should be "you have a week (or whatever) from my first email, then I go public".

what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? If the reason for responsible disclosure is to ensure that no members of the public is harmed as a result of said disclosure, should it not be a conversation between the security researcher and the company? The security researcher should have an approx. idea of how or what to do to…

The security researcher should have an approx. idea of how or what to do to fix.

How is that in any way the responsibility of independent randos on the internet?

If you truly believe these issues should be fixed, the right answer would be to hold companies accountable for timely security patches, overseen and managed by a government department.

I'm not sure thats a good idea, but expecting random security researchers to somehow hold massive billion dollar Enterprises accountable is silly.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#56
post #36

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

The problem with a fair warning is that once I email you such a warning, I'll never be able to anonymously publish it no matter how much you ignore the report. Then the fair thing becomes I never go public I'm confident you'll call lawyers.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#57
post #36

Earlier quoted context omitted.

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

The problem with a fair warning is that once I email you such a warning, I'll never be able to anonymously publish it no matter how much you ignore the report. Then the fair thing becomes I never go public I'm confident you'll call lawyers.

Can't you just send it from anon email?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#58

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

> a disaster for the human race.

This is a prime example where a hyperbole completely obliterates the point one is trying to make.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#59

Obligatory "Scumbag Asus" video link: Invidious https://inv.nadeko.net/watch?v=cbGfc-JBxlY YouTube https://youtube.com/watch?v=cbGfc-JBxlY "ASUS emailed us last week (...) and asked if they could fly out to our office this week to meet with us about the issues and speak "openly." We told them we'd be down for it but that we'd have to record the conversation. They did say they wanted to speak openly, after all. They h…

So are there any "basically respectable" motherboard manufacturers? Or is there a similar story about each of the big players?

Asking for a friend who is thinking about building a new PC soon.

Post reply on HN