Hackers exploited 0-day, not 2018 bug, to mass-wipe My Book Live devices
arstechnica.com
arstechnica.com
It's pretty clear that there are no coding standards, sparse comments (literally just 1), lots of mixed tab/spacing, misspelled names, etc.
Furthermore, the fact that this got into production shows that either the code wasn't even reviewed prior to release and/or it wasn't reviewed carefully.
I think this goes to a much larger issue of devices in this so-called IoT world we live in now. So many of these devices are built by "hardware-first" companies, who oftentimes put very little budget, time or emphasis on the software side of things. As people's daily lives depend more and more on IoT devices, I think this should be more and more of a concern: it doesn't matter how good the hardware is and/or how cost efficient a company's hardware production capability is if you don't value the quality in the software that runs said hardware.
(Full Disclosure: I'm a full-time independent software developer who has worked on many IoT projects, working directly with hardware and device manufacturers)
This is a problem. I don't know the solution, except that companies should really commit to LTS support of things no matter the sales targets.
The EU and US could mandate that all products sold in the EU/US have their firmware source code, working toolchain as a virtual machine image and all relevant documentation (including SoC docs, BOM and schematics, as well as case and other parts' 3D specs and any digital certificates and private keys) be held in trust at the national public libraries. When the manufacturer ceases to support the device - including not fixing critical security bugs at 90 days post disclosure - the complete archive is released to the public as open source.
Additionally, the US and EU could mandate that any Internet connected device's firmware as well as its development process must pass an audit at certified organizations such as TÜV or UL. We're doing this for electrical and gas appliances already due to the risk these things pose to the general public, it's time to do the same for IT.
Products developed as open source can be exempted from the audit requirement to incentivize open source development.
If you want to enjoy the public protections of IP, the public needs to get a copy of source code and meaningful device access, upon whatever definition of un-patched software or device abandonment.
Obviously there's a lot to work out, but philosophically, I like the idea better than introducing new jurisdictions of regulatory power, especially when the relief sought should already be attainable under the public contract made in seeking government enforced IP protection.
Putting your code into escrow does not imply it's going to get audited or that it was developed under somewhat reasonable conditions (aka with code reviewing and testing).
We have seen way, way too much damage, to the tune of billions of dollars and everybody's personal data ending up in hacks "thanks" to shoddy software now, it's a matter of national security to create ad enforce regulations.
Maybe we can create exemptions for small companies and startups, but as soon as you hit 10k users in general population you should have at least basic security processes implemented.
It was glaringly obvious that software was not part of the company's core competency. Worse, was that software was treated as a nuisance and afterthought to the hardware. No idea how today's Western Digital compares, but I generally steer clear of the company's products that rely on any non-trivial software.
It doesn't help things that the skill sets are very transferrable. It's tough to find somebody willing to forego 20-30% of salary just because they enjoy embedded - after a while, people get fed up and move into better paid SE roles. So, embedded software departments are often short-handed. A former employer of mine lost a senior firmware engineer almost three years ago. As far as I know, they still haven't filled the position.
WD then takes the OEM POC firmware - slaps on their logos and ships it.
That is why I would trust NAS manufacturers like Synology or Thecus or QNAP more -personally I use Unraid.
Excluding straight vandalism, I can't really come up with another reason for the reported sequence of events. Presumably the first attacker wanted to build a botnet (which is actually something they can draw profit from), and a competitor wanted to prevent them from doing that.
Otherwise — again, excluding straight vandalism — what is the benefit of wiping the devices? Having your preexisting botnet target/scan and exploit these devices isn't free. What else could they have been trying to gain?
Alternatively, some misguided "white knight" idea. Maybe the factory reset turns off the "open to the internet" setting.
Realistically speaking, you are probably going to be able to hide ~$100-$250k of put earnings, especially if you have a trading history and it's not the only thing you trade.
That can be a considerable payout.
An expert's perspective can certainly be helpful, but if market prices are set by non-experts (or, experts in other fields) then it may just lead to consistently wrong answers per the tenets of keynesian economics.
I'm not disagreeing by the way. You are correct. And the stock traders probably made the correct guess about the company profits.
Does HN like Doge? I helped use it to send Jamaica to the Olympics in 2014...
The logs in the article show these devices being accessed from the internet.
There have been many people in this forum mentioning how their data is gone, and I'm doubting most of the people here are directly connecting their devices to the internet .. which makes me feel like there is something more going on.
Because they want to access their data from anywhere or at least like the idea of doing that and it's under their control, not the Google or Microsoft cloud.
WD has (had?) credibility in non tech circles so these would sell well.
[0]: https://www.zdnet.com/article/a-mysterious-grey-hat-is-patch...
If a user forgets their password or buys a used drive then they won’t know the password. It’s common in the hardware industry to be able to factory reset a device somehow.
Isn't this the reason for a hardware reset button?
Having this available over the internet is probably negligent.
I would think it would run a firmware function to do the resetting, and if not that, then some sort of sell script that is not callable by their web interface.
Due to all this stupidness, my weekend is going to be consumed by trying to find out if my Synology has something stupid in it (assuming I can even figure that out).
So my trust in "personal" network storage devices has been shattered. Hopefully Synology is not as dumb.
So I'm reading up on TrueNAS to see if that's the way for me to go.
Frankly, I love my Synology, but it at EOL (can't do the new version of DSM) but my needs are pretty simple, hence either straight Linux or TrueNAS seem to be my best options.
1) devices only I have write access to 2) devices others have access to 3) iot (which are basically users I've never met)
At least I can segregate me running a port scan from my laptop, to a family members phone running a portscan from some spyware game they downloaded.
I have a good idea how much I can trust my own devices, even if my phone's baseband OS is sending an unstoppable stream of location data and super cookies.
But this NAS/cloud connected storage thing is a bit of a oddball, since you're supposed to trust it with your data, but can't trust it with unfettered network access.
I have one of these at my parents house, I had them unplug it, once I read this, but I was always wary of turning on remote access, as in it would only be accessible from the LAN, I haven't had a chance to go back in and check if it was hit, but I'd like to think that without remote access turned on it wasn't vulnerable.
Is it not possible for some reason on these limited devices?
And yet, their stock price seems unaffected. It was slightly up, though just in the way it randomly fluctuates, on the day of the announcement.
On one hand, they own Sandisk. On the other, no one outside of the industry knows that.
Is this a vulnerability of all My Book drives or just ones that connect to a cloud / online service?
I have one of these but haven't plugged it in for a while. However, I don't remember using any online service with it. It just had a bunch of movies.
function get($urlPath, $queryParams=null, $ouputFormat='xml'){
// if(!authenticateAsOwner($queryParams))
// {
// header("HTTP/1.0 401 Unauthorized");
// return;
// }Forums are all but dead.
Comments alone have kept me from visiting the site for a while now.
Used to be one of the sites I'd check daily, now I don't even like to click through on articles like these.
(I suspect this will bite them in the ass in the court of public opinion, but we'll see.)
( It will be worst if they start writing more data on the empty drive ... )
And I dont seems to read any site that offer basic advice as disconnection, power down and dont touch it for now. No knowing what to do is casing panic.
HTTP POST /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php
for no reason whatsoever. function get($urlPath, $queryParams=null, $ouputFormat='xml'){
// if(!authenticateAsOwner($queryParams))
// {
// header("HTTP/1.0 401 Unauthorized");
// return;
// }
That if statement is checking for authentication before running the rest of the function. Just the if check is commented out.Assuming here the rest of that function would come below it, with a closing brace.
ie:
function get($urlPath, $queryParams=null, $ouputFormat='xml'){
// if(!authenticateAsOwner($queryParams))
// {
// header("HTTP/1.0 401 Unauthorized");
// return;
// }
do;
something;
here;
then;
} function get($urlPath, $queryParams=null, $ouputFormat='xml'){
// if(!authenticateAsOwner($queryParams))
// {
// header("HTTP/1.0 401 Unauthorized");
// return;
// }
The closing brace there corresponds to the if. The rest of the body of the function, and its closing brace, are outside the snippet included in the article.