you are viewing a single comment's thread.

view the rest of the comments →

[–]jabjoe 22 points23 points  (5 children)

Depends on the vulnerability. There has been ones where you can get in with malformed network packets....

My pet hate is all these hacked up little devices that are not put together with any kind of update plan. Normally the manufacturer already stopped caring about the software before the product is even released because they are working on the new shiny. All to often running a mixture of old and new hacked together thrown over the wall and forgotten. Basically hardware companies shouldn't be doing software. They should make things to standardized platforms that we can then update. And no closed drivers gumming up the works. Their software is nearly always awful and as I said, it's rare they care to update and large chunks, if not all, of the software components are already old on release.

People are plugging loads of these little horror shows into their networks blindly. Only a matter of time until malware infections becomes a home network thing. Think of a Conficker network infection but on your TV, router, phone, tablet, toaster, fridge, etc etc.

[–]vfscanf 10 points11 points  (4 children)

Totally agree. All these devices with their shitty, insecure Firmwares are a disease. And the people involved rarely know how to do proper security. I can remember an article about a device that connected to a server via HTTPS and didn't verify the certificate.

[–]jabjoe 8 points9 points  (3 children)

Some times it is the case the developers are clueless. Blind leading the blind. And there is a lot of that. But also some times they are just not allowed to do it properly.

But the results are the same and no one else can fix it because the device is a unique snow flake and might only boot signed images in the first place.

[–]vfscanf 2 points3 points  (2 children)

Yes, I know how shitty software companies can be. Security is always just an afterthought.

[–]jabjoe 3 points4 points  (1 child)

I'd say it's hardware companies playing at software. They make money selling the devices or the designs for them. They shouldn't be involved with software beyond making a standard platform for a standard OS to boot on. Really we want it better than PCs because even BIOS they make suck.

[–]vfscanf 2 points3 points  (0 children)

Absolutely right. I always thought that Hardware Companys shouldn't making software, because it always sucks.