[HN Gopher] Illuminating the Security Issues Surrounding Lights-...
___________________________________________________________________
Illuminating the Security Issues Surrounding Lights-Out Server
Management (2013) [pdf]
Author : walterbell
Score : 10 points
Date : 2022-05-15 06:42 UTC (1 days ago)
(HTM) web link (www.usenix.org)
(TXT) w3m dump (www.usenix.org)
| comboy wrote:
| IDRAC still uses non-ssl connection for fetching upgrades by
| default. They all seem so bad on many levels regarding security
| without even diving deep.
|
| I hope safe virtualization (where host can't access guest stuff)
| become a standard for hardware, but it still feels backward.
| yjftsjthsd-h wrote:
| Any chance the updates are signed (w/ PGP or such)? There are
| ways to make non-ssl safe-ish, and I can kind of accept not
| wanting a system that depends on an accurate clock and current
| root certs.
| pixl97 wrote:
| Imagine the current scenario.
|
| Version 1: Secure, currently in use.
|
| Version 2: Insecure. Known RCE.
|
| Version 3: Secure.
|
| Version 2 in this case is a signed update that is valid from
| the vendor, but adds a remote exploit that the attacker
| performing the MITM can then exploit.
| yjftsjthsd-h wrote:
| Fair point; I suppose I should have said saf _er_ ; GPG
| gives you authenticity with lower requirements, but is
| generally inferior to HTTPS.
___________________________________________________________________
(page generated 2022-05-16 23:01 UTC)