4 ms·
I wonder if 3 vulnerabilities in 3 days means this device has exceptionally bad firmware compared to other similar devices or is just suddenly getting a lot of
by michh 12y ago
I wonder if 3 vulnerabilities in 3 days means this device has exceptionally bad firmware compared to other similar devices or is just suddenly getting a lot of attention from skilled hackers.
Guessing by how frail software on these types of devices (routers, access points, home automation stuff, DSL modems, cable boxes, consumer NAS enclosures, etc etc) often feels, I fear it's the latter.
- lunixbochs 12y agoIt's the latter.
- pasbesoin 12y agoIn my stints doing QA, I've found that developers seldom look beyond the immediately presented problem/issue, even when that problem makes it apparent that further review and consideration is warranted if not demanded. [1] Further, all too often, minimum mitigations -- sometimes, the word "solution" cannot even be accurately applied to these -- are conceived and implemented. When you see repeated problems cropping up like this, based upon experience, I can express the opinion that the organization and/or the individuals involved are not really paying attention or respecting sufficiently the security aspects involved. Hopefully, the repeated bad press will begin to change this. But... those in the organization responsible for setting or sanctioning such initiative, are often all-to-well insulated from the immediate "real world". -- [1] P.S. I guess I should qualify this to say that I'm speaking of what I consider to be a typical "corporate" environment. Lots of politics and inertia and, all too often, "just do what you're told".
- xyzzy123 12y agoIt's bad; it's not exceptionally bad compared to similar devices though. So I agree with you. I do think embedded devices as a whole are getting a lot more attention lately - because they're so fun to hack. A consumer home router is often quite similar in terms of hardware to a Linux box from say 1995 (with differences due to Moore's law versus Kryder's law). 20 years as a rule of thumb is OK. Unfortunately the development practices you see tend to be 20 years out of date as well [shoddy, non-memory safe code, with no automated tests, talking to the network]. This is partly why hacking embedded devices is fun; it's like the 90's again! [I think every pentester has dreamed about the idea of being transported to 1995, knowing what they know now...]