Live data from Hacker News

A simple command allows the CIA to commandeer vulnerable Cisco switches

arstechnica.com

71–80 of 90 posts

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#71
post #66

Earlier quoted context omitted.

Anarchism - belief in the abolition of all government and the organization of society on a voluntary, cooperative basis without recourse to force or compulsion. Communism - a political theory derived from Karl Marx, advocating class war and leading to a society in which all property is publicly owned and each person works and is paid according to their abilities and needs. If there is no government, who distributes t…

That why it's the best system to support in Internet forums! You can just pick the parts from each that work for the argument you are making. Since they are polar opposites you have a lot of ground to pick ideals from. Thus winning the argument.

On what evidence do you proclaim that Communism works with a state? Or that there is wage labour? Can you find any quotation at all from Marx or Engels in support of the state? How do you explain the existence of anarcho-Communism if you believe Communism has a state?

There is no need to be snarky. You could have just come out and said the point, vacuous as it is.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#72

If you're exposing telnet to the public internet on anything you need to rethink whether you're competent to run internet infrastructure.

I doubt that many Cisco shops expose telnet to the public internet, but I bet plenty of them have it exposed on a "secure" internal network since they know that no outside attacker can possibly reach it.

99% that I know of have at least disabled telnet even on internal. SSH2 only. And/or access via secured bastion/console server to a login prompt via RS232 9600-8N1 connection.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#73
post #53

Earlier quoted context omitted.

Again, I'm glad you're engaging. I'm not down voting you. > Because their loyalties may lie with their former employer. By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets. > Personal relationships... that relationship is probably going to supersede loyalty to any private sector employer Sure, anything could happen. In your example, Joe gets nothing except enormous ris…

> By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets. Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not. > Any employee that is involved in this would almost certainly speak to someone. This isn't like a National Security Letter; there's no force of law t…

> Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not.

Good point; my analogy fails.

> NSA compromised Google's internal network

News stories that used that phrasing were being inaccurate; the collection was of plaintext traffic between international Google datacenters. The Intercept explains it pretty well.

> As far as I'm aware they're the legal equivalents of blank slates and don't necessarily require informing the upper echelon of a company of their issuance, but I could be wrong on that. I know that it is at least customary to do so, however.

The point I'm making is that it's rational for people not well-versed in the minutiae of foreign intelligence regulations to think that intelligence agencies can and do intrude however they please on private companies. In reality, its with great caveats and with a (perhaps insufficient) legal process that introduces friction. It is far more overt and less cloak-and-dagger than would ordinarily be desired. The most clandestine way possible to spy would be with the badass methods we talked about earlier.

> Either way, let's say the government wants to issue a NSL requesting a very specific, perhaps even temporary backdoor to a Bay Area company. The normal route would likely start a veritable war with that company's legal department, and runs a non-insignificant chance of being leaked by those who know about it.

NSLs aren't a magic spell that gives the government whatever it wants. They go through a company's legal department and are subject to limitations. Several companies have successfully defeated the gag order portions of their NSLs. Having an inside man wouldn't be particularly advantageous since the company lawyers must get involved (the U.S. hasn't yet prohibited a person's legal representative from viewing writs).

At the end of the day, the government has a monopoly on violence and can sent the Army to invade Cisco or anyone else it doesn't like. But due to the conscientious individuals that make up the government, and the public relations and legal risks that are involved, this is unlikely to happen. What I'm describing is a series of norms that are unlikely to be broken in the course of spying business. There are far cheaper, easier, and less risky ways to accomplish espionage than a covert, mass-distributed, plaintext backdoor.

I do wish that the credibility of U.S. companies was taken into account more often when espionage decisions are made. The terrible optics behind PRISM made it look like companies were volunteering information, when the government was coercing them through the NSL program.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#74
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

> It's a common HN meme that Cisco and Microsoft help the U.S. government spy, but there isn't credible evidence supporting it. They actively resist government espionage attempts.

Microsoft was the only company featured in slides about teamwork and collaboration.

https://www.theguardian.com/world/2013/jul/11/microsoft-nsa-...

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#75
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

You're right, there are some pretty arcane telnet options floating around out there, whose implementations are open to (mis)interpretation...

https://tools.ietf.org/html/rfc748

NWG/RFC# 748, M. Crispin, 1 April 1978

Telnet Randomly-Lose Option

1. Command name and code.

RANDOMLY-LOSE 256

2. Command meanings.

IAC WILL RANDOMLY-LOSE

The sender of this command REQUESTS permission to, or confirms that it will, randomly lose.

IAC WON'T RANDOMLY-LOSE

The sender of this command REFUSES to randomly lose.

IAC DO RANDOMLY-LOSE

The sender of this command REQUESTS that the receiver, or grants the receiver permission to, randomly lose.

IAC DON'T RANDOMLY-LOSE

The command sender DEMANDS that the receiver not randomly lose.

3. Default.

WON'T RANDOMLY-LOSE

DON'T RANDOMLY-LOSE

i.e., random lossage will not happen.

4. Motivation for the option.

Several hosts appear to provide random lossage, such as system crashes, lost data, incorrectly functioning programs, etc., as part of their services. These services are often undocumented and are in general quite confusing to the novice user. A general means is needed to allow the user to disable these features.

5. Description of the option.

The normal mode does not allow random lossage; therefore the system is not allowed to crash, mung user files, etc. If the server wants to provide random lossage, it must first ask for permission from the user by sending IAC WILL RANDOMLY-LOSE.

If the user wants to permit the server to randomly lose, it replys with IAC DO RANDOMLY-LOSE. Otherwise it sends IAC DONT RANDOMLY-LOSE, and the server is forbidden from randomly losing.

Alternatively, the user could request the server to randomly lose, by sending IAC DO RANDOMLY-LOSE, and the server will either reply with IAC WILL RANDOMLY-LOSE, meaning that it will then proceed to do some random lossage (garbaging disk files is recommended for an initial implementation). Or, it could send IAC WONT RANDOMLY-LOSE, meaning that it insists upon being reliable.

Since this is implemented as a TELNET option, it is expected that servers which do not implement this option will not randomly lose; ie, they will provide 100% reliable uptime.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#76
post #53

Earlier quoted context omitted.

> By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets. Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not. > Any employee that is involved in this would almost certainly speak to someone. This isn't like a National Security Letter; there's no force of law t…

> Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not. Good point; my analogy fails. > NSA compromised Google's internal network News stories that used that phrasing were being inaccurate; the collection was of plaintext traffic between international Google datacenters. The Intercept explains it pretty wel…

[deleted]

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#77
post #50

> and organizations get unfairly accused. I understand people, but why organisations? Capitalist firms literally thrive on the exploitation of labour, disregard for the environment and otherwise reckless pursuit of profit.

Please don't take HN threads on generic ideological tangents. It's tedious and leads to flamewars.

We detached this subthread from https://news.ycombinator.com/item?id=13926144 and marked it off-topic.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#78
post #53

Earlier quoted context omitted.

> By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets. Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not. > Any employee that is involved in this would almost certainly speak to someone. This isn't like a National Security Letter; there's no force of law t…

> Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not. Good point; my analogy fails. > NSA compromised Google's internal network News stories that used that phrasing were being inaccurate; the collection was of plaintext traffic between international Google datacenters. The Intercept explains it pretty wel…

>News stories that used that phrasing were being inaccurate; the collection was of plaintext traffic between international Google datacenters.

A US intelligence agency targeting a portion of a US company's infrastructure that just happens to be international still constitutes a breach of trust. Whether that means they'd go as far as compromising an office network located in the United States is another matter, but I seem to recall a talk given by a security chief at Google discussing their use of custom RISC-V silicon for security due to their threat model including nation-state actors, with explicit mention of Western intelligence agencies. I wish I could find the link.

>The point I'm making is that it's rational for people not well-versed in the minutiae of foreign intelligence regulations to think that intelligence agencies can and do intrude however they please on private companies.

The mental gymnastics[0] that the NSA already uses to legally justify domestic collection on US citizens doesn't really inspire confidence that the IC wouldn't stoop to similar antics when it came to private companies.

>Having an inside man wouldn't be particularly advantageous since the company lawyers must get involved ...

Must they? My point was that legally compelling an insider who's already on your side might serve as an interesting loophole. Especially if they're not required to inform counsel and have no intention of doing so. Like I said though, IANAL.

>... (the U.S. hasn't yet prohibited a person's legal representative from viewing writs).

It's worth noting that in the early days that wasn't so clear:

"CONAN: And they are roughly equivalent to subpoenas.

Mr. LICHTBLAU: Yes and no. There are differences - one of the key differences is that for a long time the recipient was not even allowed to tell you when they received such a letter.

CONAN: Even their own lawyer.

Mr. LICHTBLAU: There was debate about whether or not you could even get a lawyer." [1]

>I do wish that the credibility of U.S. companies was taken into account more often when espionage decisions are made. The terrible optics behind PRISM made it look like companies were volunteering information, when the government was coercing them through the NSL program.

Agreed.

[0] https://news.ycombinator.com/item?id=10605489

[1] http://www.npr.org/templates/transcript/transcript.php?story...

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#79

jesus christ you guys; I have been telling you about this since 1997

Scope of "this" ?

So, in about 1997 or so I inherited a network where we had a Cisco router connecting Silicon Valley to a remote office but didn't have the password, so I hired a Ccie to help unpack the network and reset the password to this device...

So as we were working on the 3640, and we got the password out of it (which was "Feet4Monkey") he was telling me about how they (Cisco) was required to provide back-door access to the NSA

Again this was in the late 90s, and everyone thought EChelon was bullshit....

The company he worked for had a logo and slogan: "get caught in our web"

Some telling stuff but everyone thought we were loons when we talked about the spying.

Then room 641A happened years later ....

Post reply on HN