Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

81–90 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#81

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Business idea. Maybe this already exists. A disclosure aggregator/middle man which: - protects the privacy of folks submitting - vets security vulns. Everything they disclose is exploitable. - publishes disclosures publicly at a fixed cadence. - allows companies to pay to subscribe to an "early feed" of disclosures which impact them. This money is used to reward those submitting disclosures, pay the bills, and take s…

Isn't that basically HackerOne?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#82
post #54

Earlier quoted context omitted.

This makes me never want to buy another ASUS product again.

For me it's them lying about providing a way to unlock the bootloader of my soon to be 1000€ paperweight(2 android updates only) called an Asus zenfone 10.

Out of curiosity, what got you to spend 1000 Euros on a Zenphone 10 phone when Samsung S23 was net superior and cheaper and provides like 5 years of updates? It's not like previous phones from Asus had a better track record. I kept waring people to stay away form the Zenphone yet the online community kept overhyping it for some reason as the second coming of Christ or something.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#83

Earlier quoted context omitted.

Increasing the chance of a bad actor actually doing something with a vulnerability seems bad, actually. You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day.

> You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day. Which is again, a problem created by the companies themselves. The way this should work is that the researcher discloses to the company, and the company reaches out to and informs their customers immediately . Then they fix it. But instead companies refuse to tell t…

You are shopping at a store along with some other customers. When entering the store, you notice that an employee of the store has left a large knife outside, under a trashcan. A shady character is wandering around the store, looking for someone to steal from, but hasn't figured out the right angle of attack yet. At some point, you (ever the responsible citizen) stand up on a table in the store and yell "Hey! Just wanted to let everyone know that there is a large, scary looking knife under the trash can outside. You have been warned." You then climb down from the table and leave the store. Knives are dangerous, after all. Immediately after your announcement the shady character goes and grabs the knife, which they then use to stab a customer on their way out of the store and steal their stuff. Unfortunately the customer didn't hear your announcement about the impending danger because they were in the toilet at the time.

Whew, thank god for public disclosure with no prior warning to the people who would've been best equipped to retrieve their knife.

---

This was clearly not the best way to handle the situation.

Sure, you didn't know that the thief was unaware of the knife before your announcement, but he sure as shit was aware afterwards. You not knowing what they know is not a good reason to indiscriminately yell to no one in particular.

I did not make the argument that obscurity is security. The knife being under a trashcan is a risk and should be addressed by management. But that doesn't mean non-obscurity automatically improves security.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#84
A few of the drivers they install (or want to install) are also on Microsoft's vulnerable actively exploited driver blacklist. So that's fun, they have no intention of fixing it because they do not support "third party software". I'm also pretty sure their installer doesn't work without unencrypted HTTP traffic being let through. Plus they keep offering bloatware as "updates" to you.

On top of it all, the software they offer is slow and buggy on brand-new hardware.

But most of those issues also exist with AMD's or Gigabyte's drivers, most hardware vendors seem trashy like that. Like, if you install Samsung Magician (for their SSDs) then that even asks you if you're in the EEA (because of the privacy laws I suspect), it's absolutely crazy.

Microsoft should make it *significantly* harder to ship drivers outside of Windows Update and they should forbid any telemetry/analytics without consent.

I find Linux's hardware support model significantly nicer, although some rarer things do not work OOB, there's none of this bullshit.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#85
post #48
post #42

Earlier quoted context omitted.

Yes but responsible disclosure should be "you have a week (or whatever) from my first email, then I go public".

what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? If the reason for responsible disclosure is to ensure that no members of the public is harmed as a result of said disclosure, should it not be a conversation between the security researcher and the company? The security researcher should have an approx. idea of how or what to do to…

> what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem?

A week is an example and not a definitive value dictated by law, statute, or regulation.

When you report the vulnerability you give the developer a timeline of your plans, and if they can't make the deadline they can come back to you and request more time.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#86

Earlier quoted context omitted.

I mean, to be a bit more reasonable, there's a middle ground here. Maybe disclosing a massive RCE Vulnerability in software used by a lot of companies on 25th of December is not a good Idea. And perhaps an Open Source Dev with a security@project mail deserves a tad more help and patience than a megacorp with a record of shitty security management. And if you are a company that takes security serious and is responsive…

You are right about open source developers who do this on the side, as a hobby, and even if they don't are usually underpaid and understaffed. They do deserve more time and a different approach. But corporations making big bucks from their software need to be able to fix things quickly. They took money for their software, so it is their responsibility. If they cannot react on a public holiday, tough luck. Just look a…

> But corporations making big bucks from their software need to be able to fix things quickly. They took money for their software, so it is their responsibility. If they cannot react on a public holiday, tough luck.

Because it is not corporations who are reacting on public holidays, but developer human beings.

It is not corporations that are reacting to install patches on a Friday, but us sysadmins who are human beings.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#87

Earlier quoted context omitted.

Increasing the chance of a bad actor actually doing something with a vulnerability seems bad, actually. You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day.

> You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day. Which is again, a problem created by the companies themselves. The way this should work is that the researcher discloses to the company, and the company reaches out to and informs their customers immediately . Then they fix it. But instead companies refuse to tell t…

Why should it work that way? Disclosing the vuln before fixing it seems like a surefire way for my mum to lose her life's savings. Why do you hate my mum so much?

Re: One-Click RCE in Asus's Preinstalled Driver Software

#88
post #54

Earlier quoted context omitted.

For me it's them lying about providing a way to unlock the bootloader of my soon to be 1000€ paperweight(2 android updates only) called an Asus zenfone 10.

Out of curiosity, what got you to spend 1000 Euros on a Zenphone 10 phone when Samsung S23 was net superior and cheaper and provides like 5 years of updates? It's not like previous phones from Asus had a better track record. I kept waring people to stay away form the Zenphone yet the online community kept overhyping it for some reason as the second coming of Christ or something.

Zenfone is smaller and has a headphone jack. It's the superior phone

Re: One-Click RCE in Asus's Preinstalled Driver Software

#90
post #48

Earlier quoted context omitted.

what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? If the reason for responsible disclosure is to ensure that no members of the public is harmed as a result of said disclosure, should it not be a conversation between the security researcher and the company? The security researcher should have an approx. idea of how or what to do to…

> what if the vulnerability cannot be easily fixed within the week, even if the company stops all work and focus completely on the problem? A week is an example and not a definitive value dictated by law, statute, or regulation. When you report the vulnerability you give the developer a timeline of your plans, and if they can't make the deadline they can come back to you and request more time.

this is what i presume happens today. You have a date for which disclosure will happen, and the company can request for more time.

And this is exactly what the parent poster is against - because it is possible to continuously extend this date.

Post reply on HN