问HN:当供应商对安全问题没有回应时该怎么办?
我对家中某个联网设备感到厌烦,决定调查它的固件。由于供应商声称该产品仍在积极支持中,并且没有达到生命周期终止(EOL),我的主要目标是找到一个已存在的CVE(公共漏洞披露)来报告,以便供应商需要发布更新的固件,最好还能带来其他改进。
最新的版本已经有好几年没有更新了,所以这并不难。我发现了一个过时的服务,它可以在局域网内未经身份验证访问,并且存在一个已知的漏洞,允许对设备进行任意文件读取。我还发现了另一个在局域网内未经身份验证的端点,通过一个简单的GET请求可以使设备瘫痪,恢复需要拆解和JTAG访问。没有跨域检查或任何类型的限制,因此恶意网站可以将该URL放在img标签或类似的地方,轻易地使访问者的设备瘫痪,而无需任何交互。
我在欧盟,所以我访问了他们的欧盟网站,首先被指示在他们的支持网站上创建一个工单。我尝试了多次,但总是以“未知错误”失败,并指示我“联系服务台”,却没有提供任何联系线索。我还发现了另一个表单,可以选择安全问题作为主题,但描述字段几乎不够长,只能写下“我发现了${product}的安全问题,请与我联系以获取更多细节。”三周后,我仍在等待回复。
接下来,我在他们的美国网站上提交了同样的安全问题表单,并很快得到了回复。由于该型号在美国并未销售,因此他们不会直接处理,但承诺将任何细节转发给他们的欧盟同事,因为我直接联系他们非常困难。我发送了问题的详细信息,但此后没有收到任何回复。我发了一封后续电子邮件询问状态更新,但到目前为止也没有得到回应。
我接下来该怎么办?是否有某个欧盟机构可以介入?如果我直接发布我发现的问题,会不会有麻烦?
查看原文
I got fed up with a certain internet-connected appliance at home, and decided to investigate its firmware. Since the vendor claims the product is still in active support and not EOL, my main goal was to find a pre-existing CVE it was vulnerable to and report that so the vendor would need to release an updated firmware, hopefully with other improvements too.<p>The latest build was years old, so that wasn't too hard. I found an outdated service that is reachable unauthenticated from LAN and has a known vulnerability that allows arbitrary file reads on the device. I also found another endpoint that is unauthenticated from LAN and with a single GET request essentially bricks the device, requiring disassembly and JTAG access to recover from. There are no cross-origin checks or restrictions of any kind, so a malicious site could put the URL in an img tag or similar and brick visitors' devices with no interaction.<p>I'm in the EU, so I went to their EU site where I was first instructed to create a ticket on their support site. I tried numerous times but it always failed with "an unknown error", instructing me to "contact the service desk" with no clues how to reach them. I also found another form where you could select security issue as the topic, but the description field was barely long enough to fit "I found security issues with ${product}, please contact me for more details." Three weeks later I'm still waiting.<p>Next I filed the same security issue form on their US site, and promptly got a reply. The exact model isn't sold in the US so they wouldn't handle it directly, but promised to forward any details to their EU counterpart since I had such a hard time reaching them directly. I sent the issue details and have not heard back since. I sent a follow-up email asking for a status update, but so far that has gone unanswered too.<p>What should I do next? Is there some EU entity that could step in? Can I get in trouble if I just publish what I found?