4 ms·
Meanwhile in Arch land (possibly other distros as well), the fwupd package (which I imagine to be a fairly common package to be installed among the user base) h
by DDiggler 2y ago
Meanwhile in Arch land (possibly other distros as well), the fwupd package (which I imagine to be a fairly common package to be installed among the user base) has been silently configured to depend on passim, which spins up an open web server on 0.0.0.0:27500[1] without any(!) explicit user consent whatsover. Passim then uses GnuTLS, which is famous for containing more holes than Swiss cheese [2][3].
Absolutely insane to me, and I would not be surprised if there's an xz type of exploit hidden somewhere in the chain.
[1]: https://github.com/fwupd/fwupd/issues/6721 https://github.com/fwupd/fwupd/issues/6721
[2]: https://news.ycombinator.com/item?id=7347500 https://news.ycombinator.com/item?id=7347500
[3]: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=gnutls https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=gnutls
- workethics 2y agoGood to know. I think this should probably be it's own post
- 1oooqooq 2y agohttps://news.ycombinator.com/item?id=40322408 https://news.ycombinator.com/item?id=40322408
- 1oooqooq 2y agowhy fish for fwupd? systemd-resolved which is everywhere, will open (at request) an LLMNR server (a.k.a. mDNS, nee microsoft netbios) on port 5355. With IoT everyone have access to your LAN, so now people are making sure linux also join the REDACTED party btw, fix for fwupmdg, since they have a low quality default conf file without commented out defaults: ``` # /etc/fwupd/fwupd.conf [fwupd] P2pPolicy=none ``` fix for resolved is commented out on /etc/systemd/resolved.conf `LLMNR=no`, and you probably also want `DNSStubListener=no`. heck here is a good default ``` # /etc/systemd/resolved.conf [Resolve] DNS=9.9.9.9#dns.quad9.net 149.112.112.112#dns.quad9.net 2620:fe::fe#dns.quad9.net 2620:fe::9#dns.quad9.net FallbackDNS=127.0.0.1 ::1 Domains=~. DNSOverTLS=yes LLMNR=no DNSStubListener=no ```
- hughsient 2y ago> since they have a low quality default conf file without commented out defaults Try `man fwupd.conf` for all the options.
- 1oooqooq 2y agolooking at the fwupmgr code. The client uses DBUS to ask the server how many bytes were download from your LAN peers (unless you connect your device directly to the internet, then i guess i will show how many bytes ssh probes downloaded from you, inflating their numbers and making them more aggressive on the server feature) https://github.com/hughsie/passim/blob/ae38c13da1a63fff8c8fa0b8e343ecb1cd417e5a/src/passim-cli.c#L292-L306 https://github.com/hughsie/passim/blob/ae38c13da1a63fff8c8fa... https://github.com/hughsie/passim/blob/ae38c13da1a63fff8c8fa0b8e343ecb1cd417e5a/src/passim-server.c#L1425 https://github.com/hughsie/passim/blob/ae38c13da1a63fff8c8fa... also, note the quaint code to tell how much carbon it saved earth. edit: interestingly, if you search for that data collection method name, both ddg and google only find the call from fwmgr side. the actual one, older, from passim code is not shown anywhere https://duckduckgo.com/?q="passim_client_get_download_saving" https://duckduckgo.com/?q="passim_client_get_download_saving... but it's there https://github.com/hughsie/passim/blob/ae38c13da1a63fff8c8fa0b8e343ecb1cd417e5a/libpassim/passim-client.c#L124 https://github.com/hughsie/passim/blob/ae38c13da1a63fff8c8fa...
- AceJohnny2 2y ago> mDNS, nee microsoft netbios veering offtopic: I always thought mDNS was an Apple thing, since Bonjour is the most extensive implementation of it (and Windows sucks at it. In fact the only way I found to get a full mDNS implementation on Windows a few years ago was to install Bonjour via an installer extracted from iTunes for Windows). The Wikipedia page for mDNS [1] doesn't have a lot of history information, saying just that the idea of mDNS was first proposed by Bill Woodcock & Bill Manning to the IETF in 2000, and neither seem obviously tied to Microsoft. Apple later published Bonjour in 2002, and mDNS only became an official rfc6762 in 2013! [1] https://en.wikipedia.org/wiki/Multicast_DNS https://en.wikipedia.org/wiki/Multicast_DNS
- 1oooqooq 2y ago