Live data from Hacker News

A simple command allows the CIA to commandeer vulnerable Cisco switches

arstechnica.com

31–40 of 90 posts

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#31
post #27
post #24

Earlier quoted context omitted.

The edit window just expired as I attempted to amend my original comment, so I'll amend it here: Those links were the result of a few cursory Google searches. It wasn't intended as a comprehensive representation of Cisco's CIA ties, nor to imply that anyone mentioned was directly involved in backdoors. Rather, the point was that when a security-oriented organization employs ex-spooks, it increases the likelihood of s…

> At the very minimum it fosters distrust. why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy? > CIA isn't stupid and tends to maintain relationships with former employees that cross over to private sector work what kind of "relationships" are you talking about here?

>why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy?

once any single person enters the IC, they have lost trust of anyone outside of the IC... simple - and answers your other question as well...

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#32
post #27
post #24

Earlier quoted context omitted.

The edit window just expired as I attempted to amend my original comment, so I'll amend it here: Those links were the result of a few cursory Google searches. It wasn't intended as a comprehensive representation of Cisco's CIA ties, nor to imply that anyone mentioned was directly involved in backdoors. Rather, the point was that when a security-oriented organization employs ex-spooks, it increases the likelihood of s…

> At the very minimum it fosters distrust. why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy? > CIA isn't stupid and tends to maintain relationships with former employees that cross over to private sector work what kind of "relationships" are you talking about here?

>why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy?

Because their loyalties may lie with their former employer. National security matters tend to take priority over private sector loyalty for many people, and I'd imagine especially so for former IC types since they tend to be extremely patriotic. I mean that as a compliment, not an insult.

>what kind of "relationships" are you talking about here?

Personal relationships. Say Joe retires for private sector work. He's good friends with Bill, who's a case officer. Later when some national security matter comes down the pipe requiring access at Company Y, Bill knows Joe who works there. Seeing that Bill and Joe have been through some shit together, that relationship is probably going to supersede loyalty to any private sector employer when there are underlying national security motivations involved.

It's not tinfoil hat conspiracy allegations, just basic human dynamics.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#34
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

>> "Why would the ex-CIA guy hurt his current employer to help his former?"

Once you're a made man in an intelligence service, you're in for life, regardless of whether or not your name appears on the official payroll.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#35
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

I'd like to know what a malformed command is. If the program accepts it, it accepts it. This sounds like more explicit disclosure of a designed feature (admin via telnet).

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#36
post #26
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

Cisco buying an In-Q-Tel-funded company is about the most banal observation you can make. In-Q-Tel is one of the more prominent investors in network and information security companies (IIRC, that's their founding charter!) and Cisco is the bizdev endgame strategy for most VC-funded security product companies. I doubt ThreatGrid is the only IQT company Cisco has bought. I am as certain they're not a CIA plant inside C…

>I am as certain they're not a CIA plant inside Cisco as I am of anything else in my perceived reality ...

Of course they aren't. All I'm saying is if you have a company that has a routine acquisition deal flow from the CIA's venture capital arm, that there's probably healthy working relationships there.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#37
post #26
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

Cisco buying an In-Q-Tel-funded company is about the most banal observation you can make. In-Q-Tel is one of the more prominent investors in network and information security companies (IIRC, that's their founding charter!) and Cisco is the bizdev endgame strategy for most VC-funded security product companies. I doubt ThreatGrid is the only IQT company Cisco has bought. I am as certain they're not a CIA plant inside C…

> I know several of their key people, one of whom has a framed Che poster. They're not the type. :)

Perhaps a bit OT, but you're dead wrong about Che. He was a mass murderer, and I'd treat someone with a framed picture of him with the same suspicion I'd reserve for someone with a Stalin or Hitler portrait.

http://www.therealcuba.com/?page_id=32

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#38
post #8

Earlier quoted context omitted.

Disabling the service is a way to protect you from the vulnerability, but it is not a fix for the vulnerability. A fix for the vulnerability would allow you to continue using the service.

The article kind of makes it sound like telnet is somehow necessary and that disabling it hasn't been a best practice for years. Maybe there are still old devices that don't support SSH and you literally have no option, but really, what other reason is there to have telnet enabled?

That's what I was thinking about. On the Cisco support site Telnet gets barely a mention. It is apparently not the flagship feature of these switches and whatnot. Okay maybe it's customary to leave it open but there's a lot of lazy practices that result in bad security, not just headline "vulnerabilities" that affect - gasp - 300+ models!

So, basically I think Ars Technica's sub-par quality strikes again, in that a tech site gets a fundamental understanding of technology wrong. If something isn't mission critical, can be turned off, and alleviates a vulnerability, then that's a way to fix it. Plain fucking English.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#39
post #24

Earlier quoted context omitted.

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

The edit window just expired as I attempted to amend my original comment, so I'll amend it here: Those links were the result of a few cursory Google searches. It wasn't intended as a comprehensive representation of Cisco's CIA ties, nor to imply that anyone mentioned was directly involved in backdoors. Rather, the point was that when a security-oriented organization employs ex-spooks, it increases the likelihood of s…

Thanks for a reasoned response. I admit I get emotional when people and organizations get unfairly accused.

> it should raise more suspicion than normal when former IC people go to work for a company dealing with network hardware.

Fair enough about the perception of former IC employees entering the private sector. For the most part, "former IC employee" only impacts an organization once something else newsworthy occurs. Cisco considered the risk to be low that the CIA would pay a former official to order Cisco employees to insert a backdoor without a single one reporting this outside their chain. Personally, I think it benefits companies to hire employees with a diversity of backgrounds.

> [backdoor] approach is far superior ... [they] just don't scale well ... it's just badass.

The lack of scalability is a feature if you ask me. It should be expensive and difficult enough to limit espionage to those target that matter. And it's more palatable to the people who these agencies ultimately report to.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#40
post #34

Earlier quoted context omitted.

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

>> "Why would the ex-CIA guy hurt his current employer to help his former?" Once you're a made man in an intelligence service, you're in for life, regardless of whether or not your name appears on the official payroll.

What movie did you get that from? It sounds really cool. Like a cross between Goodfellas and the Bourne Identity.
Post reply on HN