Live data from Hacker News

One-Click RCE in Asus's Preinstalled Driver Software

mrbruh.com

91–100 of 253 posts

Re: One-Click RCE in Asus's Preinstalled Driver Software

#91

Earlier quoted context omitted.

Business idea. Maybe this already exists. A disclosure aggregator/middle man which: - protects the privacy of folks submitting - vets security vulns. Everything they disclose is exploitable. - publishes disclosures publicly at a fixed cadence. - allows companies to pay to subscribe to an "early feed" of disclosures which impact them. This money is used to reward those submitting disclosures, pay the bills, and take s…

Isn't that basically HackerOne?

HackerOne, BugCrowd, et al don't appear to make any serious effort to vet reports themselves.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#92

Earlier quoted context omitted.

Business idea. Maybe this already exists. A disclosure aggregator/middle man which: - protects the privacy of folks submitting - vets security vulns. Everything they disclose is exploitable. - publishes disclosures publicly at a fixed cadence. - allows companies to pay to subscribe to an "early feed" of disclosures which impact them. This money is used to reward those submitting disclosures, pay the bills, and take s…

Isn't that basically HackerOne?

No, HackerOne gets paid by the companies, so they're heavily incentivized to work for their benefit.

I've had three really bad experiences with unskilled H1 triagers that the next vuln I find from a company that uses H1 will go instantly public. I'm never going to spend that much effort again, to get a triager that would actually bother to triage.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#93

Earlier quoted context omitted.

Business idea. Maybe this already exists. A disclosure aggregator/middle man which: - protects the privacy of folks submitting - vets security vulns. Everything they disclose is exploitable. - publishes disclosures publicly at a fixed cadence. - allows companies to pay to subscribe to an "early feed" of disclosures which impact them. This money is used to reward those submitting disclosures, pay the bills, and take s…

Isn't that basically HackerOne?

except there you spend several months walking an underpaid person in india who can barely use a shell though reproduction steps, get a confirm after all that work and the vendor still ignores you

Re: One-Click RCE in Asus's Preinstalled Driver Software

#94
post #88

Earlier quoted context omitted.

Out of curiosity, what got you to spend 1000 Euros on a Zenphone 10 phone when Samsung S23 was net superior and cheaper and provides like 5 years of updates? It's not like previous phones from Asus had a better track record. I kept waring people to stay away form the Zenphone yet the online community kept overhyping it for some reason as the second coming of Christ or something.

Zenfone is smaller and has a headphone jack. It's the superior phone

It is virtually the same size[1] as the era equivalent S23.

I don't think a headphone jack which you can get via a super cheap USB-C adaptor, makes the justification for a 1000 Euro paperweight.

[1] https://www.gsmarena.com/size-compare-3d.php3?idPhone1=12380...

Re: One-Click RCE in Asus's Preinstalled Driver Software

#95
post #23

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

Citing CGPGrey: Solutions that are the first thing you can think of are terrible and ineffective. Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes. You are also making legitimate, fixable in a month issues available for everyone which increases their chances to be exploited a lot.

> Good safety/security culture encourages players to not hide their problems. Corporations are greedy bastards. They'll do everything to hide their security mistakes.

This is why I despise the Linux CNA for working against the single system that tries to hold vendors accountable. Their behavior is infantile.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#96

Earlier quoted context omitted.

> You're effectively shifting responsibility to consumers, who are probably not going to see a CVE for one of the dozens of softwares they use every day. Which is again, a problem created by the companies themselves. The way this should work is that the researcher discloses to the company, and the company reaches out to and informs their customers immediately . Then they fix it. But instead companies refuse to tell t…

You are shopping at a store along with some other customers. When entering the store, you notice that an employee of the store has left a large knife outside, under a trashcan. A shady character is wandering around the store, looking for someone to steal from, but hasn't figured out the right angle of attack yet. At some point, you (ever the responsible citizen) stand up on a table in the store and yell "Hey! Just wa…

A better analogy would be if you see a bunch of people walking around in faulty stab vests, and you tell them that the vests are faulty before they are recalled and replaced by the company. In which case, telling everyone those vests are actually not going to stop a knife, is a very good thing to do.

> I did not make the argument that obscurity is security... But that doesn't mean non-obscurity automatically improves security.

... egad. Yes, having information doesn't mean people will do the right thing with it, but you're not everyone's mommy/god/guardian. People should have the choice themselves about what actions they want to take, and what's in their own best interests.

And obscuring the information that they need to make that choice, in the name of not making them less secure, is, ipso facto, asserting that the obscuring is keeping them more secure than they otherwise might be.

So yes, you absolutely are arguing for obscurity as security.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#97

Earlier quoted context omitted.

> why would you put my tens of thousands of users at risk, instead of emailing me and have the vulnerability fixed in an hour before disclosing You've got it backwards. The vuln exists, so the users are already at risk; you don't know who else knows about the vuln, besides the people who reported it. Disclosing as soon as known means your customers can decide for themselves what action they want to take. Maybe they w…

You're making an assumption that doesn't match reality - vulnerability discovery doesn't work like some efficient market. Yes, intelligence agencies and sophisticated criminal groups might find 0-days, but they typically target selectively, not deploying exploits universally. The real threat comes from the vast number of opportunistic attackers who lack the skills to discover vulnerabilities themselves but are perfec…

Let’s imagine you found how to steal funds from a bank, best is to let them know that you are concerned (as a customer) for the safety of your own funds.

If they do nothing after a reasonable amount of time, escalate to regulators or change bank. Then once they release information that some processes are changed: “thanks to XXX working at YYY for helping us during it”. You win, they win, clients win, everybody wins.

Unwanted public disclosure directly leads to public exploitation, there is nothing good at all about it.

For example, there is a RCE in Discord (totally statistically certain due to the rendering engine, just not public yet), and this is going to be exploited only if someone shares the technical details.

If you don’t disclose it, it’s not like someone else will discover it tomorrow. It’s possible, but not more likely than it was yesterday. If you disclose it, you make sure that everybody with malicious intent knows about it.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#98

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

As I keep saying, liability like in any other industry.

Most folks don't put up with faulty products unless by decision, like those 1 euro/dollar shops, so why should software get a pass.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#99

Earlier quoted context omitted.

You are shopping at a store along with some other customers. When entering the store, you notice that an employee of the store has left a large knife outside, under a trashcan. A shady character is wandering around the store, looking for someone to steal from, but hasn't figured out the right angle of attack yet. At some point, you (ever the responsible citizen) stand up on a table in the store and yell "Hey! Just wa…

A better analogy would be if you see a bunch of people walking around in faulty stab vests, and you tell them that the vests are faulty before they are recalled and replaced by the company. In which case, telling everyone those vests are actually not going to stop a knife, is a very good thing to do. > I did not make the argument that obscurity is security... But that doesn't mean non-obscurity automatically improves…

Sure, we can run with your analogy. So you make everyone aware that the stab vests are faulty. One of the people you make aware of this fact is a thief with a knife, who previously wasn't gonna take the risk on robbing anyone, since he only had a knife (not a gun) and everyone was wearing stab proof vests. But now he knows, so he goes for it and stabs someone. You are partially responsible for this outcome in this hypothetical scenario, as the thief didn't know beforehand about the defect and the only reason he ended up stabbing someone was due to this knowledge. Again, you not knowing whether or not the thief already knows does not excuse you if he did not and now does through your actions.

I'm arguing that unveiling the obscurity can lead to attacks that wouldn't have happened otherwise, and you are partially to blame for those if they happen (which is true). I am not saying it was "more secure" before the disclosure. Just that, in the world afterwards, you must take responsibility for everyone knowing, including people who did not know before and abuse that knowledge.

Re: One-Click RCE in Asus's Preinstalled Driver Software

#100

Responsible Disclosures and their consequences have been a disaster for the human race. Companies need to feel a lot more pain a lot more often in order for them to take the security of their customers a lot more serious. If you just give them month to fix an issue and spoon-feed them the solution it's just another ticket in their Backlog. But if every other security issue becomes enough news online that their CEOs a…

I think ASUS' turnaround time on this was quite good, I don't see the problem here. ASUS didn't deny the bug, didn't threaten to prosecute anyone for reverse engineering their software, and quickly patched their software. I have no doubt that before the days of responsible disclosure, this process would've taken months and might have involved the police.

Normal people don't care about vulnerabilities. They use phones that haven't received updates in three years to do their finances. If you spam the news with CVEs, people will just get tired of hearing about how every company sucks and become apathetic once there's a real threat.

The EU is working on a different solution. Stores are not permitted to sell products with known vulnerabilities under new cybersecurity regulations. That means if ASUS keeps fucking up, their motherboards become dead stock and stores won't want to sell their hardware anymore. That's not just computer hardware, but also smart fridges and smart washing machines. Discover a vulnerability in your dish washer and you may end up costing the dish washer industry millions in unusable stock if their vendors haven't bothered to add a way to update the firmware.

Post reply on HN