Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

71–80 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#72
post #14

Earlier quoted context omitted.

Did you not see the PoC video?

Seems I was wrong. I am utterly surprised at the lack of security in modern browsers. Yes, that backend is misconfigured, but why this request is even allowed to take place in the first place is utterly mindblowing to me.

What would you suggest the browser did? All it’s does is sends the correct origin - as it would be - downloads.asus.badsite(.)com

Re: One-Click RCE in Asus's Preinstalled Driver Software

#73
post #36

Earlier quoted context omitted.

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…

Increasing the chance of a bad actor actually doing something with a vulnerability seems bad, actually. You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#74
post #36

Earlier quoted context omitted.

I make software. If you discover a vulnerability, why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing? I get that companies sit on vulnerabilities, but isn't fair warning... fair?

> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…

You're making an assumption that doesn't match reality - vulnerability discovery doesn't work like some efficient market. Yes, intelligence agencies and sophisticated criminal groups might find 0-days, but they typically target selectively, not deploying exploits universally.

The real threat comes from the vast number of opportunistic attackers who lack the skills to discover vulnerabilities themselves but are perfectly capable of weaponizing public disclosures and proof-of-concepts. These bottom-feeders represent a much larger attack surface that only materializes after public disclosure.

Responsible disclosure gives vendors time to patch before this larger wave of attackers gets access to the vulnerability information. It's not about protecting company reputation - it's about minimizing the window of mass exploitation.

Timing the disclosure to match the fix release is actually the most practical approach for everyone involved. It eliminates the difficult choice customers would otherwise face - either disrupt their service entirely or knowingly remain vulnerable.

Most organizations simply can't afford the downtime from abruptly cutting off a service, nor can they accept the risk of continuing with a known vulnerability. Providing the fix simultaneously with disclosure allows for orderly patch deployment without service interruption.

This coordinated approach minimizes disruption while still addressing the security issue - a balanced solution that protects both the security and continuity needs of end users.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#75
post #65
post #52

Earlier quoted context omitted.

If the vulnerability can't be fixed within the week, maybe the company should be SOL. This will incentivize companies to build their software better, as they'll know that any vulnerability that is hard to fix will mean consequences. Maybe the mitigation is for the company to take its service down while it works on the problem. Again, a good incentive to avoid that in the first place. Also an incentive to not waste an…

I hear what you're saying and I agree, but it's perhaps too black and white. Let's take one of the most disastrous bugs in recent history: meltdown. Speculative execution attacks inside the CPU. This required (in Paul Turners words): putting a warehouse of trampolines around an overly energetic 7-year old. This, understandably took a lot of time, both for microcode and OS vendors.. it took even longer to fix it in si…

> waiting for CERT by itself (after you have a validated fix) is 2 weeks

If the industry practice would be few days to disclosure just maybe those practices might change or maybe there would be a (extra paid) option to skip the line for urgent stuff.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#76

Earlier quoted context omitted.

"Responsible" disclosure is paradoxically named because actually it is completely irresponsible. The vast majority of corporations handle disclosures badly in that they do not fix in time (i.e. a week), do not attribute properly, do not inform their users and do not learn from their mistakes. Irresponsibly delayed limited disclosure reinforces those behaviors. The actually responsible thing to do is to disclose immed…

> "Responsible" disclosure is paradoxically named because actually it is completely irresponsible. It's only paradoxical if you've never considered the inherent conflicts present in everything before. The "responsible" in "responsible disclosure" relates to the researchers responsibility to the producer, not the companies responsibility to their customers. The philosophical implication is that the product does what i…

> The security researcher is not primarily responsible to the public, they are responsible to the corporation.

Unless the researcher works for the corporation on an in-house security team, what’s your reasoning for this?

Why are they more responsible to the corporation they don’t work for than for to the people they’re protecting (depending on the personal motivations of the individual security researcher I guess).

Re: One-Click RCE in Asus's Preinstalled Driver Software

#77
post #67

Earlier quoted context omitted.

Seems I was wrong. I am utterly surprised at the lack of security in modern browsers. Yes, that backend is misconfigured, but why this request is even allowed to take place in the first place is utterly mindblowing to me.

Where did the browser go wrong, here? They followed all security practices. The browser isn't what is running the payload. Unless, you're suggesting that nobody should be able to download programs, unless blessed by some large company?

The browser is allowing remote code to talk with 127.0.0.1

Re: One-Click RCE in Asus's Preinstalled Driver Software

#78
post #23

Earlier quoted context omitted.

Citing CGPGrey: Solutions that are the first thing you can think of are terrible and ineffective. Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes. You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.

> You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot. I don't think you can fathom the amount of people that have phones with roughly 3 years of no android updates as their primary device with which they use all the digital services they use, Banking, Texting, Doomscrolling, Porn, ... Users, especially the most likely to be exploited ar…

I’m not sure that’s a great example as they would be vulnerable to many responsibly disclosed and previously fixed issues anyway since they never update.

In fact they would be just as vulnerable to any new responsibly disclosed issues as they would if they were immediately “irresponsibly” disclosed because again, they never update anyway.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#79

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Business idea. Maybe this already exists. A disclosure aggregator/middle man which:

- protects the privacy of folks submitting

- vets security vulns. Everything they disclose is exploitable.

- publishes disclosures publicly at a fixed cadence.

- allows companies to pay to subscribe to an "early feed" of disclosures which impact them. This money is used to reward those submitting disclosures, pay the bills, and take some profit.

A bug bounty marketplace, if you will. That is slightly hostile to corporations. Would that be legal, or extortion?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#80

Earlier quoted context omitted.

> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…

Increasing the chance of a bad actor actually doing something with a vulnerability seems bad, actually. You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day.

> You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day.

Which is again, a problem created by the companies themselves. The way this should work is that the researcher discloses to the company, and the company reaches out to and informs their customers immediately. Then they fix it.

But instead companies refuse to tell their customers when they're at risk, and make it out to be the researchers that are endangering people, when those researchers don't wait on an arbitrary, open-ended future date.

> Increasing the chance of a bad actor actually doing something with a vulnerability seems bad, actually.

Unless you know who knows what already, this is unprovable supposition (it could already be being exploited in the wild), and the arguments about whether POC code is good or bad is well tread, and covers this question.

You are just making the argument that obscurity is security, and it's not.

Post reply on HN