URGENT security reminder

[quote=gbapk007 post_id=701400 time=1543885433 user_id=133857]
… noobs won’t and will be secured.
[/quote]
Noobs will scream when their router randomly restart (because it was just applying updates during their gameplay)

Noobs will sue mikrotik when the router breaks some config during update as they will wake up one day and device won’t work…



Right now, people are responsible for setting and updating their routers. If router gets hacked, it is usually user’s fault as some management interface was accessible from internet. Even vulnerable version wouldn’t be hacked, if routers were properly set up.

Therefore, Automatic updates will not really help because properly setup router is not vulnerable. In addition, automatic updates will put responsibility on Mikrotik’s shoulders. Any issue with upgrade will hit many people who will have no idea how to fix it.



Personally, I don’t think it is worth it. (it might be, if all updates were without single issue, but it is getting more common lately, that upgrade brings some issues which needs to be addressed by person)

Tools → Traffic Monitor :slight_smile: “If there’s no traffic for the last 5 minutes - it’s okay to upgrade” xD

= never :smiley:

But they will stop complaining about the feature missing! xD

How cute. We all know that there is only one way for this to be done correctly.

Implement telepathic sensing software in all routers. When there is a new upgrade available, check if all residents are asleep. If all residents are asleep, check if any of them are dreaming of possible ongoing downloads or important services that need to stay online.
If telepathic sensing detect nothing of concern, initiate internal reality simulation to predict the future. What would the future be like if the router upgraded right now? If customer would complain about the interruption, don’t upgrade. What would the future be like if the router DID NOT upgrade right now? If customer would complain about the lack of auto-upgrade, upgrade the router. If the customer would complain either way, then toture the simulated customer for a billion years and brick the router.

We are working on that for v7

I’d say that this is already done in v7 alpha as it’s the easy part. I bet that showstopper is implementation of letsencrypt certificate autoupdate.

I was talking about mind reading and future prediction, but ok

Me too.

This appeared on my radar screen THIS AM with the moniker of UFO … NORAD sent 3 F18 jets to try and intercept but failed to catch the phantom OS.

blip
Screenshot 2018-12-06 at 15.22.50.png

Teasing us :slight_smile: wish we could have an alpha/beta for Christmas to play with

Sent from my SM-A520W using Tapatalk

This sums up how I think ROS 7 is communicated! :slight_smile:

No, major misunderstanding :smiley:

Not “it will be fixed in v7”, but “It can only be fixed in v7”.

So sorry but I could not just contain myself :wink: Not that I’m missing V7 I just follow the forum :slight_smile:

This was posted february 2015 by normis

http://forum.mikrotik.com/t/routeros-v7-0-beta1-when/84572/1

V7 are not at alpha167

So V7beta1 should be the next after alpha 999
An v7 Release-candidate men be out after beta 999
:mrgreen:


Looking for the beta to be announced:

Normis, is it public FTP? Is it in ipv4 address space? xD

Sure it is: 127.0.0.1 :stuck_out_tongue:

I like this site better
ftp://[::1]

good advertisement


https://www.heise.de/security/meldung/MikroTik-Hunderttausende-Router-schuerfen-heimlich-Kryptogeld-4243857.html