4 ms·
Some commenters are decrying that this post fails to meet the bar for "responsible disclosure". Please stop using that phrase. "Responsible disclosure". It's w
by CiPHPerCoder 7y ago
Some commenters are decrying that this post fails to meet the bar for "responsible disclosure".
Please stop using that phrase. "Responsible disclosure". It's wrong and harmful, and the person who coined it agrees with me: https://adamcaudill.com/2015/11/19/responsible-disclosure-is-wrong/ https://adamcaudill.com/2015/11/19/responsible-disclosure-is...
You want "coordinated disclosure" instead.
Netgear doesn't do coordinated disclosure. They do non-disclosure. In the absence of a coordinated effort, full disclosure is the responsible thing to do.
- ryanlol 7y agoIt should be noted that it’s essentially never the people who find bugs arguing for “responsible disclosure”. It sure is easy to tell others what to do with their work product when you have zero stake in the game. There exists a really easy solution to the purported problem of full disclosure, vendors could just offer significant enough financial compensation for non-disclosure.
- RL_Quine 7y agoThat isn't what disclosing these sort of vulnerabilities is about. The core reason for just going full disclosure is that the vendor has absolutely not incentive to fix any sort of bug that is kept private. The customer is impacted, never the vendor.
- ryanlol 7y agoNah, disclosing these vulnerabilities is usually about CV-padding and publicity . There aren’t many people out there hunting bugs just to be nice.
- cipherboy 7y agoI happen to know one of the authors of this post (hey Tom!). He's actually a really nice, down to earth guy. Helped out with our college cyber defense programs and is a killer red teamer. Very patient in explaining how he got in and defaced your website, time and time again. Is this his best work? Nah, this is amateur hour on the part of Netgear. But am I glad it was him who found it? Definitely. Keep in mind, there really wasn't anything _to_ this vulnerability other than copying and pasting from one website (and a firmware zip) to another. They just added a little pretty formating and saved you the trouble of extracting the firmware.
- ryanlol 7y agoI don’t doubt that the authors of this post are wonderful people. I just don’t think that there are too many people in this space working for free, only motivated by a desire to help people. I certainly don’t think that there’s anything wrong with dropping bugs to pad your résumé. To the contrary, I think it’s fundamentally unreasonable to expect that more than a couple of people would do this work for purely selfless reasons.
- CiPHPerCoder 7y agoPeople who do this kind of work for purely selfless reasons and don't end up starving or homeless are probably very privileged.
- JshWright 7y agoI think the millions of people with Netgear equipment deployed have some "stake in the game". How does non-disclosure benefit them?
- CiPHPerCoder 7y ago'ryanlol is suggesting that if companies view "full disclosure" as a problem, the solution is (in my words) bribery. I don't think "benefiting the end users" is even present in that equation.
- throw0101a 7y ago> How does non-disclosure benefit them? And how does dumping the vulnerability without a fix help Netgear owners? They're all flapping in the wind right now. IMHO, the best scenario is coordinated disclosure. Full disclosure may be necessary to force a vendor to do something, but let us not pretend it is a good thing.
- JshWright 7y agoNo one (that I've seen in this thread) disagrees that coordinated disclosure is the best path. If the vendor doesn't want to coordinate, then dumping the vulnerability is the best course available.
- StavrosK 7y ago> And how does dumping the vulnerability without a fix help Netgear owners? It lets us know to buy another brand immediately and never buy Netgear again. > IMHO, the best scenario is coordinated disclosure The original post said that Netgear doesn't do coordinated disclosure, and subsequent posts were arguing whether non-disclosure or full disclosure were better. Nobody was disagreeing with what you said.
- swiley 7y agoNetgear making worthless routers isn’t really news.
- 7y ago
- zelon88 7y agoLet's take that avenue as a thought experiment... 1. Netgear buys the bug. 2. They keep shipping firmware with a private key. 3. Someone with malicious intent finds it. 4. Someone with malicious intent MITMs a Netgear network and does something bad. 5. Bad actor sells bug online. 6. Millions of Netgear devices continue operating with compromised certs. Instead, here's what happened/happens now... 1. Researcher tries to coordinate with the vendor, realizes NDAs are involved and the vendor intends to keep shipping their private key. 2. Researcher dumps details of private key on GH instead. 3. Mozilla and Google stop trusting the cert. 4. Now Netgear no longer gets to decide if they want to fix the problem. Browser vendors have fixed it for them. 5. Millions of otherwise insecure Netgear devices are protected by the browser instead. 6. Netgear rightfully gets bad press and hopefully the shaming makes them rethink their positions on NDAs in their bug-bounty program. 7. Future bug hunters submit bugs straight to a receptive Netgear, who has learned a valuable lesson about being a lazy hack.
- ryanlol 7y agoAh yes, it seems totally reasonable for netgear to not patch bugs they paid for.
- tialaramex 7y agoBecause this post is specifically a found private key for a certificate in the Web PKI it was not necessary to post that key in order to achieve all the positive consequences of public disclosure. The key only enables negative consequences. I could give some leeway to a grey hat who finds the data but doesn't understand what it is and posts it. "Hey, what's this blob of data?". But this poster clearly understands it's a private key for a certificate in the Web PKI. You can disclose the fact that you know a private key that isn't yours without revealing the key by various methods, but one that's very easy for non-experts is to create a bogus CSR. Just tell OpenSSL (or a tool that's actually good) that you have this private key and you want to request a certificate for it. Give bogus details, for example in the Common Name of the proposed certificate you can explain this is a Netgear key you found. You can now publish the CSR, it is inherently proof that you've got Netgear's private key but it does not contain that key and so black hats will need to do their own work, for which you are certainly not responsible, to get that key from a Netgear box if they want to. It would also make sense to tell the issuing CA, you should send them that CSR, although it's not terribly harmful to send them the actual private key and I guess if you're worried the CA's representatives don't "get it" this is a very blunt way to make your point. If the issuing CA doens't respond, tell m.d.s.policy both that you found this key and that the CA did not respond, and if necessary that can be escalated until the CA is distrusted (by Mozilla, and in my experience eventually everybody for reasons we'll not think too hard about here). In the case of Let's Encrypt the process is, like everything else, fully automated. Call the API (by running your client software of choice) and prove you know the private key for a certificate they issued and want it revoked, its status changes to revoked and the next batch of OCSP signatures will show revoked for that certificate.
- cipherboy 7y agoYeah, but remember how they found it? On Netgear's website! In their firmware images! It wasn't like they had to hack a router, get root, and exfil the keys. All of this data was already made public, by Netgear! They just put together a document with prettier forms for everyone else to see. Hell, they probably could've given you a shell one liner to grab it from Netgear and extract the keys yourself. :-) Edit: and the Comodo-issued cert is already revoked. I'm too lazy to pull the other cert but I'd bet that it's revoked too.
- m-p-3 7y agoAgreed, the key was already publicly available, and it was just a matter of time for someone with malicious intent to find it if that's not already the case. Exposing something already public to speed up the resolution and make sure the impact is kept to a minimum considering the circumstances.
- air7 7y agoWell, one can argue that every vulnerability is "already publicly available, and just a matter of time for someone with malicious intent to find it"
- dependenttypes 7y agoThis is correct, which is one of the reasons that I personally support full disclosure for everything.
- gdm85 7y agoI didn't know that Netgear already has proven to not be following coordinated disclosure; generally I think it's fair to give some time to the vendor. I like how Google Project Zero does it: give time, but don't extend indefinitely.