D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

Re: [LUG] [OT maybe] CVE-2016-5195 vs Amazon FireOS 5.6.2.0

 


On 24/07/18 08:52, Simon Waters wrote:
> I fear your joy at Amazon’s inability to roll out kernel fixes may be short lived 
> when you discover the network you want to use your shiny rooted Fire tablet on is 
> one big botnet playground....
> 
> In other news router firmware...
> 


I am guessing as these are consumer devices then a vast majority of
people would not really know about DirtyCow or even understand what
privilege escalation is, or the implications of this.

I sort of understand what this means,  In terms of a normal user, who is
say denied access to certain permissions who thanks to this but has
access to the ability to carry out tasks beyond what their normal user
would allow.

What it possibly needs is for people to understand this, and be able to
with the right level of confidence to challenge the vendors with the facts.

On a similar security note there still seems to be websites out there
sending password reminders in plain text,   so I then question how these
passwords are even stored.  I know this is a bad thing,  but most people
out there don't and just accept it,  they are users,  not techies, like
we are here,  therefore won't question this happening, and even if you
do question this,  you need to back 'this is a bad idea' to actually
making a proper argument and unless a lot of users do this, nothing will
change.


You keep mentioning problems with routers,   what exactly am I meant to
do about this,?  I check for updates, and have changed the login
password (standard move usually) but are you suggesting I keep buying a
new router then in 3 months by another one.   I don't understand this
enough to take affect it just seems like scaremongering unless there is
a proper explanation.

Paul


Paul Sutton
http://www.zleap.net
Friendi.ca :zleap@xxxxxxxxxxxxxxx

-- 
The Mailing List for the Devon & Cornwall LUG
https://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/listfaq