Live data from Hacker News

A simple command allows the CIA to commandeer vulnerable Cisco switches

arstechnica.com

11–20 of 90 posts

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#11
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs.

2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around?

3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community.

4. Telnet options are pretty arcane. It seems like an easy bug to write. The modus operandi of U.S. backdoor attempts in the past matches a different model. U.S. backdoor attempts fit two models: backdoor dependent on secret key (Dual_EC RNG), and backdoor dependent on physical sabotage (interdiction). This is stuff available in the Snowden docs and related news reports.

It's a common HN meme that Cisco and Microsoft help the U.S. government spy, but there isn't credible evidence supporting it. They actively resist government espionage attempts.

Yahoo, RSA, et. al. deserve the negative attention, not companies that fight the good fight.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#12
post #5

Thank god only the CIA knows the "simple command".

It was probably that simple on purpose, knowing Cisco's ties to intelligence agencies.

What are those ties? Besides speculation and the fact they sell equipment to intelligence agencies (and everyone else).

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#13
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

They PUBLICLY resist government espionage attempts. we don't know for sure what they do in private.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#14

Earlier quoted context omitted.

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

They PUBLICLY resist government espionage attempts. we don't know for sure what they do in private.

Have they stopped beating their spouses yet?

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#16

Thank god only the CIA knows the "simple command".

It was previously thought there were only two kinds of vulnerability. Those that can only be exploited by nation states and those that anyone can exploit with a simple command. Perhaps this is a new hybrid exploit, the simple command that only nation states can run.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#17
post #15

So a couple of years after Snowden's revelations, we're again being told "use US tech, be the bitch of the powerful" . And - honest question - why and how exactly would that ever become a thing of the past?

Your best bet is open hardware and open source software.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#19
post #8

ArsTechnica article as of this posting: > Cisco Systems said that more than 300 models of switches it sells contain a critical vulnerability that allows the CIA to use a simple command to remotely execute malicious code that takes full control of the devices. There currently is no fix. Text on Cisco Support Site linked on ArsTechnica: > This vulnerability affects the following Cisco devices when running a vulnerable…

Disabling the service is a way to protect you from the vulnerability, but it is not a fix for the vulnerability. A fix for the vulnerability would allow you to continue using the service.

The article kind of makes it sound like telnet is somehow necessary and that disabling it hasn't been a best practice for years.

Maybe there are still old devices that don't support SSH and you literally have no option, but really, what other reason is there to have telnet enabled?

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#20

ArsTechnica article as of this posting: > Cisco Systems said that more than 300 models of switches it sells contain a critical vulnerability that allows the CIA to use a simple command to remotely execute malicious code that takes full control of the devices. There currently is no fix. Text on Cisco Support Site linked on ArsTechnica: > This vulnerability affects the following Cisco devices when running a vulnerable…

Heh, telnet. Reminds me of:

http://m.slashdot.org/story/80056

"(...) vulnerability in Solaris 10 and 11 telnet that allows anyone to remotely connect as any account, including root, without authentication. Remote access can be gained with nothing more than a telnet client. More information and a Snort signature can be found at riosec.com. Worse, this is almost identical to a bug in AIX and Linux rlogin from way back in 1994." February of 2007

Post reply on HN