Misfortune Cookie
mis.fortunecook.ie
mis.fortunecook.ie
I'll go out on a limb and say that if this pattern continues, it may be the most significant legacy of heartbleed.
The only argument I can see would be consumer awareness, but that might be worse than anything else - just look at the mass hyperbole being thrown around right now about the alleged direct North Korean involvement in the Sony hacks, a contention which few people in the security world appear to take seriously. I guess find a way to get hotfixes out reliably?
I understand this worry, but I don't think executives will ever see sites like this... except when engineers say HOLY HANNAH WE NEED HOURS TO FIX THIS RIGHT NOW, and the executive says "I have a fixed budget, and this doesn't make me money."
Then this site is brought up. And the world is better.
Or just work to make developer<->management communications more effective.
To be slightly more fair: it's pretty easy to think "if solving this problem was really important, it would already have a budget, like how hurricanes get disaster relief". And so spending $100 on a logo helps people not dismiss the urgency.
This whole situation is not amazing. But an emergency isn't the time to start working on developer <-> management communication problems -- at that point, whatever gets the job done is great.
They have little substance beyond a flashy name, logo and website giving the most generic of bullet points about their exploit.
Do a Google search and you'll find dozens of news articles harping about the designer vulnerability alongside the name of the company that discovered it. What could be a legitimate exploit dealt with through the channels we've always addressed them through becomes a marketing vehicle for info sec charlatans.
Which is fine, because security work is extremely overfunded and we don't have globally critical infrastructure like OpenSSL developed by one or two dudes begging for donations.
Imagine:
"You have good reason for self-doubt." "Avoid heavy machinery today." "You will be eaten by pumas." "Learn from your mistakes; wear a condom."
I've always been afraid I would get the fortune I deserve...
Complete marketing cruft.
Misfortune Cookie is a critical vulnerability that allows an intruder to remotely take over an Internet router and use it to attack home and business networks.
<TLDR>"The affected software is the embedded web server RomPager from AllegroSoft."
"AllegroSoft issued a fixed version to address the Misfortune Cookie vulnerability in 2005 [...]" but it's complicated.
TR-069 is mentioned because it makes it sound cooler, and also uses the RomPager in certain implementations.</TLDR>
Yeah, Home Gateway security is almost as nonexistent as their release/update cycle. TR-069 is a blasphemy and an anathema in the first place[2].
This is an attempt to 'heartbleed'-ize a much broader issue. It is one of many, and they are known, and they never get patched.
Maybe make this into a crowd-type-movement to take back our routers, intending to put pressure on manufacturers to be more responsible with security and the intermediates for pushing the updates (since they've provided themselves the functionality to do that/TR-069/The Irony), but do not try to heartbleed-ize it, kinda comes off cheap.
In the meantime, for those that can (Hello Friends!), we already know the available patches:
* OpenWRT
* DD-WRT
* Tomato
It's tricky though, because you may have to spend $20/$60 for a new router.
EDIT: Also, dupe. https://news.ycombinator.com/item?id=8767193 Hrm.
[1] https://www.reddit.com/r/netsec/comments/2poyp6/misfortune_c... https://www.reddit.com/r/netsec/comments/2polm6/the_misfortu...
[2] "So my ISP can just flash my router with a new firmware, remotely, and then flash back the original, at any time? Or anyone with my ISP's private keys/credentials* , for that matter, but let's not open that can of worms. And you say that, despite this being active (and sometimes partly hidden and un-killable cough BTHomeHub cough) our routers are still running archaic software that hasn't received a 9-year-old patch? Then... ugh.. what is this used for, exactly? Why is it there?"
* Oh God I hope it is at least private keys and not 'admin:P@ssword1' :S
[0] http://www.dd-wrt.com/phpBB2/viewtopic.php?t=277217&sid=e88f...
Checkpoint marketing is experimenting with new marketing techniques. No way this peacock-style creation could've come directly from engineering. They really want some of the CNN coverage that Heartbleed enjoyed, except now it will have a discreet "Checkpoint" logo in the corner. Ain't that clever.
If Ubiquiti's EdgeRouter Lite ran an actual Debian release rather than a derivative with no obvious toolchain, I would have bought that. (If they change to that, I would recommend them.) I worked my way through the capabilities list of the PCengines mini-ITX devices (ALIX: underpowered; APU: a little expensive) and settled on AMD's successor to the APU, now called Athlon 5150/5350.
It's deployed and making me really happy now.
Sadly yet another case of overly rococo Web design getting in the way of basic readability.
It's amazing how much nicer the web can be without images and javascript. These tool-bags really want to "promote their brand," but they might consider creating a website that looks less like malware.
Still uncertain if this is to be taken seriously, because detailed information is lacking.
Their website has a special security check section but that link is (conveniently ?) broken...