8 ms·
There are X thousand redis servers exposed to the Internet too. This is hardly intel’s fault (having the ports exposed, not the vulnerability). And again, this
by yzmtf2008 8y ago
There are X thousand redis servers exposed to the Internet too. This is hardly intel’s fault (having the ports exposed, not the vulnerability).
And again, this is not the main point I’m arguing. What I’m saying is that supposedly “this is something that’s enabled by default on consumer devices” is verifiably wrong.
- achillean 8y agoIf you run Redis on a public interface without authentication then it will spit out a bunch of warnings and make you aware of the security implications. The changes antirez has made to Redis both in terms of secure defaults and notifying users of insecure settings has directly lead to a huge reduction in Internet-exposed Redis instances. And I was trying to address this point: > Even then, every setup I’ve seen have AMT (a separate Ethernet interface) behind a firewall and is only accessible via local network. In the past, manufacturers used that defense when a security researcher approached them about a problem and they justified the lack of patching by saying things like "nobody would put this on the Internet". There are simple things a manufacturer can do to encourage good security by the end-user (ex. showing a warning). I don't believe that blaming the end-user is a viable path to fixing the problem. This issue isn't specific to Intel but I would prefer it if the vendor implemented more security safeguards to prevent users from inadvertently increasing their attack surface.