Headline makes it sound like the Cisco routers come with a CIA SSH key baked in.
A simple command allows the CIA to commandeer vulnerable Cisco switches
21–30 of 90 posts
Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#22ArsTechnica article as of this posting: > Cisco Systems said that more than 300 models of switches it sells contain a critical vulnerability that allows the CIA to use a simple command to remotely execute malicious code that takes full control of the devices. There currently is no fix. Text on Cisco Support Site linked on ArsTechnica: > This vulnerability affects the following Cisco devices when running a vulnerable…
Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#23Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#24Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…
1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…
Those links were the result of a few cursory Google searches. It wasn't intended as a comprehensive representation of Cisco's CIA ties, nor to imply that anyone mentioned was directly involved in backdoors. Rather, the point was that when a security-oriented organization employs ex-spooks, it increases the likelihood of spooky things happening. At the very minimum it fosters distrust.
>2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around?
While I didn't mean to imply any specific individual, I'll address the underlying rationale: When someone's former employer is a powerful government spy agency built on secrets, the loyalty dynamic is a bit different than that of normal private sector job hopping.
Moreover, I'm sure the CIA isn't stupid and tends to maintain relationships—intentionally or not—with former employees that cross over to private sector work, especially high-level people since they're already trusted, reliable, and may be taking positions that later prove to be beneficial to CIA interests in the future.
>3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community.
This is a fair point. Given the nature of Cisco's products, and combined with recent leaks detailing the pervasive nature of US offensive cyber efforts, it should raise more suspicion than normal when former IC people go to work for a company dealing with network hardware.
That said, I'm not sure how you'd quantify the number of former IC people Cisco hires versus a normal Fortune 500 company. For all I know it could even be lower than average.
>... and backdoor dependent on physical sabotage (interdiction) ...
This approach is far superior to baking vulnerabilities into entire product ranges (or even standards). It doesn't compromise the private sector in the process, beyond perhaps supply chain integrity. The flipside of course is that physical implants don't really scale well, but at least the blowback is relatively minimal when things go wrong. Not to mention it's just badass in a James Bond kind of way.
>It's a common HN meme that Cisco and Microsoft help the U.S. government spy, but there isn't credible evidence supporting it. They actively resist government espionage attempts.
While that's true, it's also possible a company can publicly say or do one thing—genuine or not—and actively do another because of either connections, or that they're being compelled against their will by NSLs. It's also possible to have factions or even individual employees within a company that are actively subverting security with the addition of backdoors, unbeknownst to management.
Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#25"We are shocked that the CIA has the ability to use the command that we left in our firmware for them..."
Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#26Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…
I doubt ThreatGrid is the only IQT company Cisco has bought. I am as certain they're not a CIA plant inside Cisco as I am of anything else in my perceived reality; I know several of their key people, one of whom has a framed Che poster. They're not the type. :)
You're going to drive yourself seriously crazy if you try to trace every IQT investment that's been acquired by any company and then game them out as "compromised by the CIA".
Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#27Earlier quoted context omitted.
1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…
The edit window just expired as I attempted to amend my original comment, so I'll amend it here: Those links were the result of a few cursory Google searches. It wasn't intended as a comprehensive representation of Cisco's CIA ties, nor to imply that anyone mentioned was directly involved in backdoors. Rather, the point was that when a security-oriented organization employs ex-spooks, it increases the likelihood of s…
why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy?
> CIA isn't stupid and tends to maintain relationships with former employees that cross over to private sector work
what kind of "relationships" are you talking about here?
Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#28Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#29Re: A simple command allows the CIA to commandeer vulnerable Cisco switches
#30Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…
1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…
This is actually a completely fair point...
Look at all the ex SS at FB.