FBI tells router users to reboot now to kill malware infecting 500k devices
arstechnica.com
arstechnica.com
At the very least there should be some kind of policy or standard that allows someone on the inside of the network to know if the password or software has been changed. If the FBI can tell from the outside, then how in the world are people still in the dark about this?
Yeah, definitely. Especially for infrastructure.
I realize the implications of this are significant.
I don't think the solution is "all bugs cost every company money for every product", but there's definitely more or less risk involved in some software and we are well past the point of negligence from router manufacturers - the vulnerabilities we see from them are absolutely absurd.
And even assuming we have a definition of 'infrastructure software' and a way to reliably enumerate a set of vulnerabilities, attribution of liability is even harder:
- Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review libraries.
- What happens if that library is openssl and almost all webservers on the internet are vulnerable?
- What happens if the library is used in an insecure way? For example, if you seed openssl or libressl with weak random numbers, it is possible to attack algorithms provided by the library.
- On the contrary, if the author of a library is liable, what's going to happen if I use a library of a company and build something vulnerable with it intentionally?
I dislike being so negative about it, but I wouldn't want to get sued for sticking an MIT license on a silly project 10 years ago someone necro'd and stuck into a router, so to say.
Most FOSS licenses come with 'without warranty' notice. Businesses, who use it, should know that.
There's no such thing as absolutely safe software.
And yes, organizations and versions of software would have to be recertified on a regular basis.
You would want software versions to be able to be certified quickly and through an automated process, but there is already some best practice in this space — it’s just unevenly distributed.
IMHO, we should have optimistic check: any public network device must have guarantee from the vendor to fix any remote vulnerability in 30 days after discovery by independent security organization(s), otherwise vendor liable for the damage done by his device.
Past event: https://www.aei.org/events/securing-the-internet-of-things-a...
Partial event video: https://www.youtube.com/watch?v=DrnFcLuqzd4
When it comes to SOHO routers it's not as hard as it should be, by a long shot. Tons of hardcoded creds and pretty surface vulns in them.
> - Is the distributor of the router liable for a vulnerability in a used library? Surely they could vet and review libraries.
Yes.
> - What happens if that library is openssl and almost all webservers on the internet are vulnerable?
Everyone deploying it is liable.
> - What happens if the library is used in an insecure way? For example, if you seed openssl or libressl with weak random numbers, it is possible to attack algorithms provided by the library.
The company doing so is liable.
> - On the contrary, if the author of a library is liable, what's going to happen if I use a library of a company and build something vulnerable with it intentionally?
You are liable.
As in, the person who produces the product is liable for what they put in the product.
But, as I said elsewhere, this is all off the cuff and relies on a way to properly classify software, which is extremely hard.
But yeah, to your points, none of those feel hard to deal with at all.
I'm not a lawyer. This is not an area I'm so familiar with. But we already have some controls for CC info, and extending those further would be hard but a good start. This situation is extremely out of hand, whether I have the solution today or not.
We don’t need hardware and software costs spirally out of control like healthcare because of the liability. If device makers would just support their products (bug fixes) for 10(?) years I think that would do it.
In programming, you have true and false, and generally things fall into one or the other category with no human input.
In law, you have concepts like "reasonable", and a whole lot of human input, by design.
So my expectation would be that if software vendors were to be held responsible for bugs in their products, the standard they would be expected to adhere to would be "reasonable expectation of proper functioning", with humans intepreting what "reasonable" means.
Change the phrase "software bug" to "engineering error". Then consider the liabilities involved with the manufacture of any real-world-might-kill-someone product. The lawyer's view starts to make a helluva lot more sense.
Millions of malicious people constantly attacking it with cheap equipment from a distance with little chance of being caught doing so?
For one thing, we would be much more conservative in how we wrote code. Libraries would be vetted, with insurance contracts attached to them. Programming languages would not allow for dynamic data, type coercion, or weak typing. In the 80s, rather than C rising to prominence, Ada would have. Haskell would be our generations Javascript, and XHTML would have won over HTML5 simple because guessing how rendering should work would open up a browser maker to high fines and lawsuits.
We'd have to rewrite our entire software stack from the ground up. It's not impossible, but we'd have to view it as a multi-decade transition like how the chemical industry was slowly forced to not use heavily polluting procedures.
There is tradition, but a lot of it military in origin, not civil: ARPA net, Grace Hopper, and the first bug, Turing and the Enigma. Stealworking as a military secret in comparison is thousands of years old. And so far, leaked DB content has per the official record not killed anyone ... perhaps a few astronauts but none of the people responsible in place to fix it, as would be the case in a family of incorporated electricians.
We need a code-code.
Manufacturers should be liable for the poor quality of the devices they make. Software vulnerabilities are a fact of life, because there is no driving force to be better. Strict liability would force the industry to be more like other engineering disciplines.
There is a line somewhere, and beyond that line is negligence. A developer exposing a potential vulnerability in an internal service that does not handle sensitive information is clearly not across that line, a company that creates routers that constantly have serious holes, that handle sensitive information, seems clearly on the other side.
Deciding exactly where that line exists is obviously complex.
>>> Everyone deploying it is liable.
> I've been shipping production software for years...
Have you ever shipped software which depends on openssl? If not, then pretend that you have. Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for because you deployed something using openssl?
> Since you believe that you are liable, can you give me a ballpark of how much money you think you personally should be sued for because you deployed something using openssl?
This is a really ridiculous question. I've already stated that these things are complicated - you're asking for a hard number?
Companies should take responsibility for their users data, which includes understanding the risk involved in third party libraries they use.
If they're concerned about fees, invest in the security of the project you're using.
But this is all based on some hypothetical, undefined 'law', so arguing about the specific mechanics is pointless.
> you're asking for a hard number?
No, I am not asking for a hard number, I specifically asked for a ballpark.
> invest in the security of the project you're using
I agree, but slapping fines of developers for using openssl to enhance security makes it a bit hard for anyone to afford putting any extra money towards security
> arguing about the specific mechanics is pointless
Agreed, my goal is not to flesh out the mechanics, it is to demonstrate the pitfalls of such a law. I'm only asking for a ballpark (again, not a hard number) so that you can personally understand why you and every other serious developer would be sued out of existence unless you propose obscenely small fines (which would make the whole idea useless, because then developers could easily afford to be negligent without getting too much of an increase in fines).
Yes, and it's a fake law that doesn't exist. How would I possibly answer this?
Off handedly, I'd say that the fine could really range depending on a lot of things. Was this an outdated version of OpenSSL that they just didn't patch? Was it a programmer error using the library? A 0day? All of these things would probably make a big different - charging companies for 0days in 3rd party code, in at least many cases, would not make sense.
> I agree, but slapping fines of developers for using openssl to enhance security makes it a bit hard for anyone to afford putting any extra money towards security
At some point if companies can't afford to keep users safe maybe they just shouldn't be companies. And if we're talking about router companies, they have the cash.
> why you and every other serious developer would be sued out of existence unless you propose obscenely small fines
I would imagine instead that companies would have insurance around these issues to cover developers, but again, the legal components of this are not something I'd want to get into since I'm not qualified to.
Well you've just made the workaround trivial. Open source the majority of everything under a separate org and then use that stuff from the product being shipped. Therefore any vulns are not their problem.
>And if we're talking about router companies, they have the cash
I don't think you understand how tiny the margins are in consumer networking gear. Lowest price dominates.
>the legal components of this are not something I'd want to get into since I'm not qualified to.
Suggesting they be liable is a legal component.
you mean like, say, routing all of the traffic from my system to the internet?
No commerce, no liability.
You nailed the problem here, though you don't seem to realize it. Yes, software is very complex. Maybe it should be made simpler instead of buggier.
Nobody has half a fucking clue where the libraries they're slapping together come from, nor how they're maintained, nor how they're vulnerable. It gets worse every day with trash like DockerHub, and has no relief in sight.
So yeah -- let the folks who won't adhere to proper engineering burn.
So you consider well-known and well-understood design limitations to be comparable to unknown defects?
At least users can apply workarounds in that condition. As it stands, there are no options for the owner of the device.
I think that there would probably need to be classifications of software.
Things like:
1) Is this infrastructure (routers, scada)
2) What level of user data is exposed to this software ? (unencrypted user data, credit card info, etc - we already do this to some extent)
3) What level of exposure exists? (NAT'd, routable, etc)
And then start imposing restrictions on software in those cases.
But this is very off-the-cuff, obviously it's far more complex than this. But someone needs to be responsible.
The problem is that this is entirely useless.
There are basically two classes of software company.
The first is the likes of Google or Mozilla. They, as a rule, do the right thing. All humans make mistakes but the mistakes are understandable and there isn't really much we can expect to incentivize them to do that they aren't already doing.
The second is Fly By Night IoT Device Corporation. They make garbage, it has a million vulnerabilities, but they're judgment proof. If you sue them they just file for bankruptcy. Many of them don't even exist within your jurisdiction and the ones that do are likely to have gone out of business by the time you get around to filing a lawsuit. You might as well pass a law imposing liability on raccoons for spilling garbage.
There is a much better solution to all of this. Fund a government agency to search for vulnerabilities in popular products and report the vulnerabilities to the developers. Then remove products from the market that have had known unpatched vulnerabilities for more than a limited amount of time, and require updates to be offered to any product sold in the past X number of years.
Because it's a lot easier to get a company to spend $5000 in developer time to fix their garbage than to get them not to avoid a twelve billion dollar lawsuit by filing for bankruptcy -- which only leaves all their customers in the lurch with hardware that will then never be patched.
Cisco hasn't owned Linksys in years and Linksys itself is tiny. This kind of liability absolutely could bankrupt them.
And they're one of the major players. There are companies making this kind of hardware with like twelve employees.
The barrier to entry is so low that even individuals commonly make one-offs from scratch for personal use.
I didn't say they did... I was providing two examples. I wouldn't call linksys tiny, either.
You're assuming a lot about the costs of this liability for a made up law with no defined penalty.
Maybe if companies building software can't afford to keep it safe... they shouldn't be companies? Is that so controversial?
But Cisco (i.e. Talos) are the ones finding the vulnerabilities in routers made by other companies in this case.
> Maybe if companies building software can't afford to keep it safe... they shouldn't be companies? Is that so controversial?
They still would be companies though. That's the point. If they expect to be out of business by then regardless, or they're outside of your jurisdiction, or they know they're judgment proof, it doesn't change their behavior.
It's like trying to address homelessness by allowing the victims of panhandling to sue the perpetrators. There is no blood to be had from that stone.
All you do is make the problem worse, because every company you destroy is a company which is no longer around to patch their installed base of devices. Meanwhile they're immediately replaced in the market by another company which is no better.
Regulation and liability only works against monopolies and other huge companies. When you actually have a competitive market like this, you need to use the carrot rather than the stick.
That's not true at all. Many industries that are very competitive and are full of small companies are effectively regulated.
>There is no blood to be had from that stone.
There's a simple fix to this problem. You require companies to carry insurance to cover the problems you're talking about. We do it with general contractors, doctors, tree removal companies etc...
The regulation says it's illegal to manufacturer, sale, or distribute non-licensed routers, and part of the requirement for licensing is insurance.
I'm not saying that this is necessarily the best course of action in this instance, but there are definitely time tested solutions for the problem you're describing.
There are many industries that are very competitive and full of small companies and have regulations, but what most commonly happens in those cases is that the regulations are rarely enforced which nobody much minds because the competition is preventing abusive practices regardless.
> There's a simple fix to this problem. You require companies to carry insurance to cover the problems you're talking about. We do it with general contractors, doctors, tree removal companies etc...
None of those things happen at scale. When a doctor makes a mistake, it affects one patient. A single security vulnerability can affect millions of people.
That's the problem with this. Typically what regulators try to do with risk is to find a deep pocket to stick it to that can absorb it with minimal consequences, but there isn't one here because the risk is large compared to the (inexpensive) cost of the device.
It's also a poor thing to try to insure because the main risk factor is code quality but insurance companies are generally not equipped to evaluate that. It doesn't help anybody to triple the price of every device just so the customer can still get pwned because once the insurance is covering it the developers lose the incentive the liability was supposed to be giving them to improve their security.
Again I don't think this is true at all. Some counter examples: restaurants, electricians, general contractors, engineering firms, beauty salons, and tanning salons.
>None of those things happen at scale. When a doctor makes a mistake, it affects one patient. A single security vulnerability can affect millions of people.
A single bridge failure can affect an entire city, and a large building collapse could cost billions in payouts--yet engineering and construction firms can and do buy insurance to cover these things.
Magnitude isn't a problem here, even insurance companies buy insurance from larger insurance companies.
>It's also a poor thing to try to insure because the main risk factor is code quality but insurance companies are generally not equipped to evaluate that.
Insurance companies are able to evaluate risk factors for every industry--they are better able to evaluate risk than anyone else, and it's not like they wouldn't hire domain experts.
There's nothing special about software in this regard--it's a complex system, but the insurance industry regularly insurances against damage resulting from far more complex systems than software--weather for instance.
I'm not sure if requiring router manufacturers to buy insurance would lead to a net benefit or not, but the problems you're creating have already been solved by other industries. There's nothing magic about software that makes it impossible to insure.
That said in extreme cases like e.g. airplanes I think it would be fair to consider it negligent when code is just brought into production without any kind of debugging or testing.
I guess the stakes decide when something is or isn't negligent.
Next time you get a prescription filled, ask yourself if you're willing to pay that much for a router.
For free software? No. No payment, no obligation.
For paid products? Yes. If you are selling a device, you should be liable for it, just like a car manufacturer would have liability if the brakes failed because they were improperly installed.
This is a tough problem. We want to punish negligence, not destroy lives because of honest mistakes.
It does not matter if you charge for your service or product, nor how much you charge, you can still be found criminally negligent or reckless if it kills people and your actions played an important role. There are very few exceptions to that.
In civil terms it's far more straight forward: if your free brakes kill people, you will be sued for it (almost guaranteed). From there they will attempt to prove that you were negligent regarding the quality of the free brakes you created.
You give away thousands of free chicken sandwiches, that without your knowledge happen to contain bacteria that causes food poisoning and ends up killing several people. You did a very poor, careless job at food prep (similar to the dangerously manufactured brakes). You're almost guaranteed to be pursued criminally and civilly for the deaths.
I'm not sure I agree that making the vendors liable in case of vulnerabilities is the right way. It should probably suffice to require vendors to define a guaranteed product support period, where they are obliged to provide security patches, and then hold them liable if they fail that.
15. Disclaimer of Warranty.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM “AS IS” WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION. 16. Limitation of Liability.
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
This program is distributed in the hope that it will be useful,
but WITHOUT ANY WARRANTY; without even the implied warranty of
MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
GNU General Public License for more details.I can imagine a lot of licensing hassle here. Worked for Technicolor in Edegem, not on routers / STBs but know the challenges. There are tons of libraries used by virtually every device in the field that no company will touch b/c of licensing hell.
Why should your router manufacturer be liable if I break your router?
Clearly in both cases the company failed to manufacture a secure enough product.
Neither will prevent a malicious party from breaking them.
Depends on the nature of the bug, certain kinds of security holes are well known and should come with liability. Examples: SQL injection, default passwords, no encryption of sensitive information on the wire, no permission checks.
Some of these kinds of bugs are so well known that I don't see how someone could argue against liability.
All bugs can be argued as being the result of negligence.
1. it is not trivial to produce
2. there could be vulnerabilities in the crypto implementation (like that never happens!)
3. there could be buffer overflow attacks that let the malware bypass the crypto
4. The server itself could be compromised into sending a correct certificate encoded malware
5. How are you going to audit all that?
A physical switch, on the other hand, is much easier to audit, and an attacker would need physical control of device to compromise it.
Samsung had to recall and repair dangerously defective hardware - why not Cisco? Does it matter whether the public risk is in the battery or router memory?
And, imo, it follows that free OSS organizations are not liable for vulnerabilities. No money, no consumers. I think it's fair that businesses should expect to do their due diligence before blindly reusing public domain IP...
If you ever wanted an example of how to stifle innovation, read the comment I'm replying to.
Battery fires can kill so even a handful is significant, but a security vulnerability that impacts thousands of routers has lower but wider impact. Some companies will be targeted for DDoS or using the routers to probe and infect the company infrastructure... some consumers will end up paying ransomware, or having their finances hacked, or personal info leakes, or bandwidth siphoned.
For some bugs, that count as negligence. Sw engineering as a field knows how to make much safer products than what is in these wormable boxes.
Router software is part of something you actually pay for, so there should be liability.
GDPR has shown that inconveniencing tech companies with legal consequences for their negligence can be a net boon to society. So yes, liability for software bugs. Hell, we probably need to start licensing programmers.
Default passwords are a vulnerability, and defective by design is not an excuse...
My Netgear router came with a secure unique password printed on a card, an internal-only admin panel, and UPnP disabled by default. It's not hard.
https://www.woodshopnews.com/.amp/news/table-saw-suit-nets-1...
This guy was given a table saw with the guard already removed, and was using it on the floor (a table saw should be used at table height, so that you can have a foot forward to prevent falling into the blade). He was apparently not using push-sticks.
Somehow, the table saw manufacturer was found 65% liable in the case, because technology exists to reduce the likelihood of injury when flesh contacts the blade. Specifically, SawStop, which I believe senses capacitance and fires an aluminum block into the blade.
Here's a rather biased and snarky rundown of the whole thing that links some important bits of the backstory:
https://www.bob-easton.com/blog/is-it-your-table-saw-or-the-...
Oh, did I mention the members have many more ridiculous patents than gass? They've sued each other over patents on worksite radios before. https://insight.rpxcorp.com/litigation_documents/3919186
They are also multi billion dollar conglomerates, often in countries with little respect for IP, so I imagine one reason he patented so much was to protect himself.
They are also a lobbying org, and he misses all the things they did, yet points out what sawstop did.
PTI has done a great job of lobbying here, unfortunately.
I am generally not a fan of the CPSC (what they did on magnets was beyond the pale), but here he also missed the biggest point they made: the cost of table saw injuries, to the government and insurers, is greater than the value of the table saw market!
I could go on. He seems like a mostly reasonable person (moreso than most on this issue), but yeah.
There really are two sides to that part. Neither side is deserving of adoration, honestly.
The court case is much simpler. For defective design liability in a lot of states, it's enough to show a feasible alternative design that would not have impacted function or price in a serious way. Most of the argument was about the latter.
> The cost of table saw injuries, to the government and insurers, is greater than the value of the table saw market!
...making it seem like the manufacturers are just taking the profits and dumping the externalities.
https://www.homag.com/en/products/cutting/
This stuff is now very cheap. They are talking about the jobsite and home market, and if you compare that to what these videos show, yeah it's wildly unsafe
I wager that "security" is something fairly far from their mind when they craft this software, which I consider especially negligent for any company that is dealing in networked devices.
It's no surprise that routers from competing manufacturers are vulnerable, since it's all the same under the hood. The companies that sell the finished product have zero insight into how secure the software is.
Could you provide any sort of source for this extraordinary claim of yours?
Do you have a QA department? What do they do? If you're like most software companies, they do testing. This is not QA, though, it's QV. The role of QA is to assure that the quality of your product is high. By the time you're testing it, the product is "done" - all of the defects are already there in the product. There is now nothing you can do to affect the quality of the product - all you can do is test and measure the overall quality of the product.
I mean, your tests will find problems, and you can fix those problems. But, if you keep track of how many problems you find, and how much test effort was involved to find those problems, you can plot a weibull regression and make a prediction about how many defects you haven't found yet. On any project I've been on where we ran this analysis, it was obvious that testing was finding almost none of the problems - barely skimming the surface. And, when you ran this analysis you could predict how many defects you will find if you spend X days testing, and on any project where I've seen this analysis run, those predictions have been highly accurate.
Really good automated tests can help with this, because they can do huge amounts of test effort "for free", but really QA should be about the process you follow when you write software - making sure you have a repeatable process, and then figuring out how to improve it. Almost no one does this.
I was doing a pen test on a router whose manufacturer decided it would be an OK idea to use GET requests to launch their ping diagnostic tool on their router's unauthenticated QA web interface.
this ping diagnostic tool was triggered by doing GET http://192.168.1.1/diagnostic/trace&ip=X.X.X.X
The IP address in the URL parameter would get plugged directly into a "ping" command line command, so you could obtain command injection by going GET http://192.168.1.1/diagnostic/trace&ip=X.X.X.X&&telnetd
You could exploit this from literally any website on the internet, and since it's a GET request and we don't care about what it returns, CORS won't save your router. I think that counts as a javascript one-liner, but you get the idea how fucking awful some of these routers are.
[1] https://twitter.com/natashenka/status/861748397409058816
[2] https://bugs.chromium.org/p/project-zero/issues/detail?id=12...
https://nakedsecurity.sophos.com/2013/10/11/anatomy-of-an-ex...
There’s plenty of precedent
I think lack of safety features that meet our current common knowledge of the potential failure scenarios should be enough to shut down a company
We can refuse to enable commerce that jeopardizes or personal safety (literal or ephemeral data theft)
Capitalists are just humans. They can be culturally pressured and shunned. Such behavior has been a hallmark of human society since they began
Physics is a vacuum of such rules. Human society has always had them
It isn’t clear how that would work with software. Would FOSS authors be held liable? That would mean the end of open source.
Because there is no law that says so?
Most the world has been led to believe that computers are unpredictable machines with feelings that break randomly.
Because then they'd all exit the router business. Nobody wants to expose themselves to unlimited liability.
Sometimes the router companies are cover ops like TCP 32764
The core message here that everyone should reboot their router is simple enough to survive on Twitter and be understood, whereas specific instructions about which devices are bad will likely be screwed up.
https://arstechnica.com/information-technology/2018/05/fbi-s...
That's, uh, "reassuring".
In the long term, you want a fix for your router, or you want a new router.
Mine is similar to one of the affected units, enough so that it's likely vulnerable. I'm looking at replacing it.
I don't think we are so far from the day that "high risk" will mean anyone who opposes the government.
> Mine is similar to one of the affected units, enough so that it's likely vulnerable. I'm looking at replacing it.
That's probably wise.
- the continued militarization of police
- classifying 66% of houses as constitution-free border crossings
- holding citizens for years without charges or trial
- a for-profit prison system that engages in de facto forced labor
- criminalizing mental health issues and withholding psychiatric care from insured people.
For the record, these things have all been going on for multiple presidential administrations, and have enjoyed bipartisan support.
You're going many steps beyond simple exaggeration and pushing into extreme hyperbolic territory.
> classifying 66% of houses as constitution-free border crossings
You're inventing that, such a thing has not been classified by the US Government. If the government - local, state or federal - wants to search your residence in NYC or Los Angeles, they still need a warrant or equivalent court approval. If you were right, that wouldn't be the case.
> holding citizens for years without charges or trial
Show me the specific figures you have on how many times that has occurred in relation to the total number of people that have been arrested over a relevant time frame. It's extraordinarily rare in fact. Using events with very few instances to argue a premise of widespread occurrence, is an immense logic fail.
> a for-profit prison system that engages in de facto forced labor
The government prison complex (the supposedly non-profit oriented mass incarceration machine) is and has been dramatically worse. Over 95% of all people that have been put into prison in the last 40 years, during the war on drugs and mass incarceration phase, have gone into government prisons. During the epic Reagan and Clinton prison boom, the private prison industry had a single digit share of the prison inmates.
And now the incarceration rate is rapidly declining and has been for a decade. We're also pursuing the end of mass incarceration policies, with wide bi-partisan support. And we're also pursuing the end of the war on drugs, via legalization and decriminalization policies all over the US. If I were to use your argumentation approach, that means the expansion of private prisons is causing all of those things and is a good thing: as the private prisons have expanded their market share the last decade, all of those good things have finally started to happen.
> criminalizing mental health issues and withholding psychiatric care from insured people
What share of the population has suffered from the criminalization of which mental health issues? How many insured people are being kept from psychiatric care? Being vague doesn't support your topline premise, it detracts from it.
You've made an extraordinary claim and you didn't support it with much of anything.
That's like saying liver cancer is better than pancreatic cancer - true but not comforting.
In one case they went to court to get an OK from a judge to use the malware and seized domain(s) to then activity remove it from people's computers. They asked a judge because while they can seize a botnet, actually altering people's computers might be seen as bad so it seems they went about it the right way.
If they were going to be all evil I doubt they'd be talking about rebooting routers and such ;)
Also, chances are courts would deny them such orders on the grounds that it would be easier for about everyone involved if the FBI just asked the router’s owner to restore its firmware (why would the FBI need a court order against foo because bar hacked its modem?)
Correction: according to the original report a reset will mitigate the stage 2 and 3 attack only
Source: https://blog.talosintelligence.com/2018/05/VPNFilter.html?m=...
If the vendor really, really wants to update the firmware, have the write-enable switch be a physical one, not a software switch.
When firmware can't fully trust itself (and it cant), the correct option is to deffer ultimate judgement and control to the physical owner.
It's not clear how stage 1 installs. Is it into the (hidden) base Linux install in rc.local or whatever, does it get into the bios/firmware of the computer.
[..] to counter Russian-engineered malware that has infected hundreds of thousands devices.
I'm interested in the evidence for this attribution. Both ars and dailybeast [0] are pointing to Russia, but the only specific hints are that it's targeting Ukraine (which might also have to do with the prevalence of vulnerable devices there, we don't know that), and that it shares code with the BlackEnergy bot builder toolkit[1], which apparently can be bought on the black market for a decade already.
Neither of the original articles [2,3] mention Russia or any of the Russian APTs, so I'm genuinly interested in better attribution data.
[0] https://amp.thedailybeast.com/exclusive-fbi-seizes-control-o...
[1] https://community.rsa.com/thread/186012
[2] https://blog.talosintelligence.com/2018/05/VPNFilter.html
[3] https://www.symantec.com/blogs/threat-intelligence/vpnfilter...
BlackEnergy is a toolkit that has been used for years by various criminal outfits. In the summer of 2014, we noted that certain samples of BlackEnergy malware began targeting Ukranian government organizations for information harvesting. These samples were identified as being the work of one group, referred to in this document as “Quedagh”, which has a history of targeting political organizations.
The only way I see how anybody could conclude from "APT uses a black market toolkit" to "Anybody using this toolkit is that APT" is: clickbait.
[0] https://www.us-cert.gov/sites/default/files/publications/AR-...
[1] https://www.f-secure.com/documents/996508/1030745/blackenerg...
Antivirus provider Symantec issued its own advisory Wednesday that identified the targeted devices as:
Linksys E1200
Linksys E2500
Linksys WRVS4400N
Netgear DGN2200
Netgear R6400
Netgear R7000
Netgear R8000
Netgear WNR1000
Netgear WNR2000
QNAP TS251
QNAP TS439 Pro
TP-Link R600VPN
- Mikrotik RouterOS for Cloud Core Routers: Versions 1016, 1036, and 1072
I don't recall what article I read a day or two ago, but I don't believe it mentioned the specific models.
"Your devices are safe if the port 80 is firewalled, or if you have upgraded to v6.38.5 or newer."
From what I understand, alternative firmwares like Tomato & OpenWRT are not inherently safe from VPNFilter, but it seems to me the rate at which they are maintained make them less easy targets (?). So this new flaw made me think now is a good time to replace my crappy router and its unmaintained vendor firmware with something more solid running Tomato/OpenWRT. Disagreements?
But I’ve found a lot of Ubiquiti hardware to be extremely high quality given how cheap it is. At my office, we installed seven new 802.11ac Ubiquiti access points for as much as it would have cost to add one more 802.11n to our Cisco system (apart from wanting 802.11ac, we also decided to decommission the Cisco because the controller would periodically crash every two months or so).
To get the number of 10GbE interfaces and performance the EdgeRouter Infinity has (for $1600) in a Cisco would cost multiple times the price there too.
I don’t know if I’d trust it for service-provider infrastructure, but we’ve replaced a lot of enterprise Cisco stuff in our office networks with Ubiquiti and only had a good experience.
WTF? Angst!?
It takes minutes to install and configure OpenWRT on supported hardware. You upload the OpenWRT firmware like any manufacturer-provided firmware update, and after it's beeen flashed the router reboots into OpenWRT. The added time cost compared to learning and configuring any other router OS is negligible.
EDIT: oops, thanks
Why does EU (for example) authorities not warning their citizens ?
It's possible that the models affected by this particular attack aren't sold in other places, or perhaps they are, but are actually still different (enough). Or they are just not widely used.
I say this because govt. organisations have often issued warnings and recommendations like this in similar circumstances, e.g. a while ago some modem-routers widely used in this country were attacked, and a warning very much like this has been issued.
Maybe the FBI works closer to manufacturers or victims? I’ve had a freind who got some Wordpress he managed sites infected. He was able to trace it back to a professor in Turkey and call the FBI. The FBI came and interviewed him.
[1]https://www.interpol.int/News-and-media/News/2015/N2015-038
https://forum.lede-project.org/t/cert-advisory-vpnfilter-des...
A comment on another forum suggests OpenWRT/LEDE is not affected due to file system layout differences:
https://nakedsecurity.sophos.com/2018/05/23/vpnfilter-is-a-m...
This is insane.
I thought what'd a very basic monitoring & release for a self driving car would look like:
Below could be measured as A/B experiment - (control 1% on old release, experiment 1% on new release).
1. Number of miles driven 2. Number of user intervention. 3. Score rating (assuming users give a rating for their comfort after reach ride). 4. Number of rides completed. 5. Average/median speed driven 6. Average/median G change (like too much breaking would cause a change in G-force user is enforced to). 7. Average/median time-to-destination etc.
The data is already available and collected, what's missing is a way that's plug&play for these companies to push the data and necessary dimensions and integrate them into their roll outs.
You can find such metrics for almost all internet-connected device.
Make a dashboard out of this, give a way to slice data, give visualization tools and a way to query it out, and this is a winner.
Excuse my ignorance but I'm not not going to ask these types of questions.
EDIT: After reading a bit - it seems the control is somehow "transferred" to the FBI rather than the malicious actor - any other external agent controlling my software and hardware should be considered a malicious actor from a defensive standpoint, right?
Also, I don't buy the "FBI is better" argument, because I'm a skeptic.
EDIT 2: Moved the 'Why should I trust the FBI?' question to the end of my opening paragraph because I just want to know more about how a layman should approach verification of this vulnerability other than just "trust the powers that be"
The best I can come up with is a false sense of security, which given they actually expect you to also patch and upgrade and proffer advice to patch and upgrade, is a bit weak. Basically, I cannot construct a scenario where there is a significant, could-not-be-found-by-white-hat reason they'd do this, to secure some advantage.
I.E. Occams razor works for you, in this case.
According to ArsTech in this article (https://arstechnica.com/information-technology/2018/05/hacke...) the VPNFilter exploit can survive a reboot - so how can a simple reboot disinfect if the only delta is the owner of [one of] the second stage callback IP addresses? I haven't seen any mechanics explained that would actually disinfect the router.
I appreciate your response with actual critical thinking tips and not just flippancy - I don't know where else to have these types of discussions.
As I understand it, from reading around: The FBI took over an "initiator" headend which bootstraps a simpler infection into the actual threat/attack code.
The low level infection can't be removed simply, that demands new code from the maker or an OpenWRT type source. The FBI took over the domain namer behind a service which acts as the sign-in site. The attack mode code is not in your firmware, it has to be re-downloaded. If you block the initiator login, you aren't "clean" but you cannot complete download of attack code to mount the DDOS
If you reboot, the low level infection tries to sign in, and is blocked, and so can't get the second/third stage downloads.
Thanks for this insightful response. I know a lot of readers would just tell me to do my own research but this was really enlightening.
Back in the day, cable TV was crypted, and people had to have cable TV decoder cards with a key to fit a slot in the receiver. So, in the UK, somebody worked out how to decode the keypair, and you could buy a keycard in the pub for like GBP50, instead of paying the cable company GBP100/mo. But the cards, they have a fixed life. They don't last forever, you have to keep coming back for more.
The real fix is obviously to fix the crypto, but there are a million receivers out there. Nobody has time to go round each one. So what the cops did, is find where the faked out keycards are being printed and shut down the print house, so imagine... if you then get the city electric company to power cycle every house, when its receiver reboots, it needs a new keycard, but they can't get one any more, 'cept from the cable company. Fixed? No, but you cut the problem off at the knees.
Oh wait: we all wanted those sweet stolen keycards. I gotta think of a better metaphor :-)
Because this is their job. And you'll probably need to reboot your router anyway in the near future so why now do it now just in case?
>Could the FBI put their own malicious code on the router, via this supposed exploit?
Sure. So could space aliens.
Your second point is not clear to me. Space aliens aren't an extant authority on our planet (afaik)
You can find independent corroboration of this this malware with little effort. And if your gear is compromised, it's most likely doing something you don't want. So "jumping" is the smart move here unless you just want to be contrary.
The second point is: if you're assuming a conspiracy based on zero evidence, why not go big?
"The FBI is advising users of consumer-grade routers and network-attached storage devices to reboot them as soon as possible"
Granted I don't know many specifics here but that's why I'm employing the elenctic method.
So don't. No one is forcing you to reboot your router. No one who cares about this issue cares about your personal Jason Bourne fantasies.
Reboot. Don't reboot. For the rest of the world, your decision makes zero difference.
because skeptic
It's just like English. Close enough.
I have no personal fantasies; I want to understand the truth and that's my only motive.
It allows people to see the IP addresses of printers, routers, etc.... at scale.
So if a hacker finds a vulnerability, they can really quantify the amount of devices they can attack.
Which led to this repo: https://github.com/robimarko/routeros-GPL
I sold most of my Ubiquiti gear and bought a Netgate 2440 a couple years ago, put Debian on it with Shorewall and auto updates, and haven't looked back.
"CITRON EXPOSES UBIQUITI NETWORKS"
"Looking at Citron’s track record, Barron reports that, on average, companies that Left writes about see their value drop by ten per cent in a year. “And some drop as much as 95 per cent,” he writes. But that’s of little consolation to those who followed Citron’s advice and shorted NVIDIA, Motorola or Mobileye."
Ubiquity makes solid networking hardware for prosumers and small businesses that costs considerably less.
I use a peplink, which doesn’t target the “consumer” market. Is that better? Seems impossible to know.
Itd be painful to setup initially, but once setup should be rock solid.
So things like this hack would be exposed.
But then Google keeps them up to date. But the other is Google has now found Shellshock, Heartbleed, Meltdown, Cloudbleed, Spectre among several other big ones and just invest far more in security than anyone else.
They find these problems before anyone. Plus they write them up and highly recommend a few of their blog posts.
A great one is their write up on the Broadpwn vulnerability.