@peichl: Great summary! I find myself in total agreement with your post. However, one point might be added:
emails should be sent EVERYTIME there is serious security issue.
(I am refering to the fact that winbox port vulnerability - end of april - was not emailed)
Doesn’t that contradict with the other point made?
there are people who examine security updates to see what exactly was fixed and quickly write exploits for them
to use the time window between release of the updates and installation by the majority of users
I hope you don’t mean to suggest “we better keep the updates secret so the hackers don’t know about them and don’t exploit the vulnerabilities”
because that is not going to work anymore. Especially when there is no auto-update mechanism that would install the update on the majority
of installations before it is analyzed.
Vulnerability confirmed but not fixed sent message, to close or deactivate certain services if those are not secured additional by filtering.
Vulnerability confirmed and fixed, sent message. Go public and publish in blog.
Vulnerability not confirmed send message to a small and closed group to have a look at it, if it is indeed a vulnerability ask advise to have temporary effective filtering/services.
If it is alredy public communicate that you are investigating it. Message this to all the known users.
I know very well that some people are never fully satisfied, but please also try and appreciate the progress in this regard.
MikroTik did send an email to everyone in March 30, MikroTik did use forum/socialmedia also. MikroTik did fix it within a few hours of finding out. There is a changelog now where one version contains more lines than all of the v4 versions had together. There is also a blog now.
The forum does contain also e-mail addresses and many you can combine it with a GDPR information message to inviste also subscribing to security bulletins/messages by creating a Mikrotik account.
I am hesitant when I look at the page.
Allow to use my account from netinstall and winbox I don’t see any explanation what this means.
Send me information about MikroTik news this should be clearer if you write Send me the MikroTik newsletter
Add a the line that account holders also receive security bulletins. If a GDPR is not yet sent that could be used to inform the current accounts that this is added.
If you want to limit by using accounts put a link close to the general newsletter line that also a security bulletin is available. In the confirmation of creating a account also include the link to the new blog of Mikrotik.
Yes it has certainly improved. It is not so long ago that MikroTik denied the existence of vulnerabilities.
I did get a mail, two I think, on my mikrotik.com registered address and the second time it was at a more suitable point in time.
You could consider using the mail address list of the forum (maybe after subtracting the addresses from the site) to send a
one-time mail summarizing the security situation and referring to methods to get uptodate information.
But of course then there still remains a large group of buyers who never registered on the site, never visited the forum,
and have their router out of sight and never updated. Those are going to be difficult to reach.
It could also be considered to add pointers to this information in other places, like product leaflets in the boxes, product
pages on the website, and other places that people who are not aware of issues could accidentally visit.
I understand there is always a balance between making people aware of sales-unfriendly issues like security and keeping
people informed well, but on the other hand a category of prospective users might actually appreciate it when they are well
informed about the necessary maintenance to keep their device safe.
Winbox vulnerability was solved so fast and updated version was released on the same day so we did send out e-mails about new, patched versions released and did not have separate Winbox vulnerability e-mail. That was discussed in forum (in future, similar information also will be discussed in the blog):
Subject:
MikroTik RouterOS 6.40.8 [bugfix] and 6.42.1 [current]
Part of the message:
We have released new RouterOS versions in bugfix and current channels.
…
!) winbox - fixed vulnerability that allowed to gain access to an unsecured router;
…
Another example that shows how important is to read changelog. That is why we have tried to upgrade it a little bit after few last releases in order to highlight major fixes and improvements.
And we are pleased that we find a listening ear at the side of Mikrotik and the improvements made. We are pushing to have more security and we are certainly see significant steps and that is beneficiary for both sides.
Communication has room to improve and RSS is something I used a long long time ago and Twitter…I believe I have account but just to claim the name. My twitter expierence is on the moment not good because 9 out 10 times I want to see a twitter message it shows that I am rate limited so I end up not seeing the twitter message. This probably due that I connect through a VPN service.
E-mail has is old but it aged very well and it gained security and encryption if you want and your can now even chat through it and if someone does not have the APP then it display in you e-mail program.
Back to security e-mails. If you are afraid that it takes long to get hundreds of thousands of e-mails out then you are right. You can also have a mailing service sent out the mails for you and you must allow in your DNS (SPF) that they can do it. If you do it yourself please use BCC when using lists.
I would actually use this as an example of a bad changelog entry. It was very unclear, an “unsecured router” could mean an empty / weak admin password. My router was perfectly secure - strong admin password, firewalls for everything except the winbox port. If there was a vulnerability in OpenSSH, would you see a Linux distribution with a changelog that said “ssh - fixed vulnerability that allowed access to an insecure server”? No. The blame would be squarely on OpenSSH itself, not the security of the whole system. There are quite a few examples of users on this forum who in fact did see this changelog entry and ignored upgrading because they thought their router wasn’t classified as “unsecured”. If winbox was never meant to be exposed to untrusted networks, this is not documented anywhere.
Going forward I’m sure we would all appreciate more candid statements regarding security vulnerabilities. Yes, it isn’t fun to admit that there’s a bug in that allows exploitation, but network admins deserve to know the full details in order to make informed decisions about how and when to upgrade.
re notifications
i have been on this forum some years - and hurried to sign up for email alerts/announcements.
however - during the years, i have received but a few for news letter announcements - cant say how many, but maybe for every third.
result is that i sign up again several times - well, to be sure
the only security annoncment was received was concerning gdpr policy 25th may
i was never introduced to any harmful intrusion, though.
i check dayly mikrotik.com for news - but would like to be timely updated, in case i should be absent, or missed it.
It would take certain time to reverse-engineer update and prepare new exploit. Maybe significant time.
I have no doubt that some fancy bears are following this forum and would love to get security bulletins into email. But I think timely alerting regular customers would outweight such risk. Customers will be aware of risks and perhaps will be able to patch known holes.
I would prefer to receive security alerts from vendor arriving sooner than Talos/F5/whatever “sky is falling” articles appear in their social media.