Live data from Hacker News

A simple command allows the CIA to commandeer vulnerable Cisco switches

arstechnica.com

41–50 of 90 posts

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#44
post #26

Earlier quoted context omitted.

Cisco buying an In-Q-Tel-funded company is about the most banal observation you can make. In-Q-Tel is one of the more prominent investors in network and information security companies (IIRC, that's their founding charter!) and Cisco is the bizdev endgame strategy for most VC-funded security product companies. I doubt ThreatGrid is the only IQT company Cisco has bought. I am as certain they're not a CIA plant inside C…

> I know several of their key people, one of whom has a framed Che poster. They're not the type. :) Perhaps a bit OT, but you're dead wrong about Che. He was a mass murderer, and I'd treat someone with a framed picture of him with the same suspicion I'd reserve for someone with a Stalin or Hitler portrait. http://www.therealcuba.com/?page_id=32

The point he was making is that Che isn't a widely admired figure in U.S. intelligence circles.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#46
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

I very much doubt that high-level employees are able to inject covert intrusion code without it raising a stink inside the company. If that were the goal then you would want an engineer, not a manager.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#47
post #32
post #27

Earlier quoted context omitted.

> At the very minimum it fosters distrust. why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy? > CIA isn't stupid and tends to maintain relationships with former employees that cross over to private sector work what kind of "relationships" are you talking about here?

> why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy? Because their loyalties may lie with their former employer. National security matters tend to take priority over private sector loyalty for many people, and I'd imagine especially so for former IC types since they tend to be extremely patriotic. I mean that as a compliment, not an insult. > what kind…

Again, I'm glad you're engaging. I'm not down voting you.

> Because their loyalties may lie with their former employer.

By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets.

> Personal relationships... that relationship is probably going to supersede loyalty to any private sector employer

Sure, anything could happen. In your example, Joe gets nothing except enormous risk of public humiliation and expensive litigation in exchange for the favor to Bill. Any employee that is involved in this would almost certainly speak to someone. This isn't like a National Security Letter; there's no force of law to compel silence. It would be a foolish move for Joe.

Then Bill gets a call on his gray phone from his boss. "Why is the CIA in the newspapers for attempted backdooring of Cisco products?" We don't hear about this stuff because it doesn't happen like this.

People that are so loyal to the CIA don't leave for a pure private sector company. They go to a contractor so they can stay in the ecosystem. People going to Cisco are (1) physically moving away from Northern Virginia, (2) losing access to secrets.

Besides, it doesn't sound very patriotic to insert backdoor that's not even protected by a secret (e.g. key escrowed Clipper Chip, P and Q in Dual_EC) that goes into hardware purchased by more Americans than anyone else in the world.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#48
post #34

Earlier quoted context omitted.

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

>> "Why would the ex-CIA guy hurt his current employer to help his former?" Once you're a made man in an intelligence service, you're in for life, regardless of whether or not your name appears on the official payroll.

Sounds legit.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#49
post #15

So a couple of years after Snowden's revelations, we're again being told "use US tech, be the bitch of the powerful" . And - honest question - why and how exactly would that ever become a thing of the past?

I think there were some foreign manufacturer 0days revealed in the Snowden docs.
Post reply on HN