Live data from Hacker News

A simple command allows the CIA to commandeer vulnerable Cisco switches

arstechnica.com

81–90 of 90 posts

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#81
post #78

Earlier quoted context omitted.

> Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not. Good point; my analogy fails. > NSA compromised Google's internal network News stories that used that phrasing were being inaccurate; the collection was of plaintext traffic between international Google datacenters. The Intercept explains it pretty wel…

> News stories that used that phrasing were being inaccurate; the collection was of plaintext traffic between international Google datacenters. A US intelligence agency targeting a portion of a US company's infrastructure that just happens to be international still constitutes a breach of trust. Whether that means they'd go as far as compromising an office network located in the United States is another matter, but I…

>I wish I could find the link.

Eric Grosse at 5th RISC-V Workshop, 2016:

https://www.youtube.com/watch?v=0knR6vXba7g

Slides: https://riscv.org/wp-content/uploads/2016/12/Tue1330-RISC-V-...

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#83
post #3

Critical vulnerabilities in Cisco products that the CIA can exploit? "Cisco vice president of services Mike Quinn, a former CIA operations officer, ..." [0] "... Cisco's recent acquisition of In-Q-Tel-backed security company ThreatGRID ..." [1] "After retiring with 30+ years of service from the Agency, I spent several years as adviser to Cisco System’s Chief Security Officer, and I found Cisco was doing great work; t…

1. The vulnerability was probably exploited before the CIA guy joined Cisco. The Vault 7 cache contains some seriously legacy docs. 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around? 3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community. 4. Telnet options are pretty arcane. It seems li…

> 2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around?

I don't think quitting your CIA job lets you off the hook for essentially giving away something they consider to be a secret. Or at least I'm sure the CIA would not look at you kindly for doing so.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#84
post #67
post #36

Earlier quoted context omitted.

> I am as certain they're not a CIA plant inside Cisco as I am of anything else in my perceived reality ... Of course they aren't. All I'm saying is if you have a company that has a routine acquisition deal flow from the CIA's venture capital arm, that there's probably healthy working relationships there.

By that logic, In-Q-Tel is a stroke of genius, because they've also built "healthy working relationships" with Network Appliance, IBM, Amazon, EMC, Microsoft, Intel, Oracle, Google, and Nokia. I think you just can't read anything into In-Q-Tel involvement with a company.

>By that logic, In-Q-Tel is a stroke of genius, because they've also built "healthy working relationships" with Network Appliance, IBM, Amazon, EMC, Microsoft, Intel, Oracle, Google, and Nokia.

Perhaps the plan with In-Q-Tel was partly to achieve pervasive private sector influence, and it was somewhat successful.

While I appreciate the conceited scare quotes there, I'm not saying that working relationships directly translate to backdoors, just that it translates to influence, and that can indirectly lead to bad things over time.

>I think you just can't read anything into In-Q-Tel involvement with a company.

As a thought experiment, say Open Whisper Systems took money from In-Q-Tel, or even acqui-hired a team from one of their portfolio companies. Right or wrong, people would very much read into it, and probably lose their minds in short order. Signal's user base would plummet overnight.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#85
post #84
post #67

Earlier quoted context omitted.

By that logic, In-Q-Tel is a stroke of genius, because they've also built "healthy working relationships" with Network Appliance, IBM, Amazon, EMC, Microsoft, Intel, Oracle, Google, and Nokia. I think you just can't read anything into In-Q-Tel involvement with a company.

> By that logic, In-Q-Tel is a stroke of genius, because they've also built "healthy working relationships" with Network Appliance, IBM, Amazon, EMC, Microsoft, Intel, Oracle, Google, and Nokia. Perhaps the plan with In-Q-Tel was partly to achieve pervasive private sector influence, and it was somewhat successful. While I appreciate the conceited scare quotes there, I'm not saying that working relationships directly…

Because people would write comments like the one you did upthread, deceptively implying they had an understanding of what In-Q-Tel was that they could reason from as if a first principle. That's the problem. You don't need In-Q-Tel to cause the kind of damage you're talking about; you have many other vectors for this kind of deception.

I'm not sticking up for In-Q-Tel. I wouldn't take money from IQT. But it is, for the most part, just what it says it is: an investment firm that funds things that the CIA believes will be helpful to its mission, which includes virtually all network security, database, networking, and RF technology.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#86
post #85
post #84

Earlier quoted context omitted.

> By that logic, In-Q-Tel is a stroke of genius, because they've also built "healthy working relationships" with Network Appliance, IBM, Amazon, EMC, Microsoft, Intel, Oracle, Google, and Nokia. Perhaps the plan with In-Q-Tel was partly to achieve pervasive private sector influence, and it was somewhat successful. While I appreciate the conceited scare quotes there, I'm not saying that working relationships directly…

Because people would write comments like the one you did upthread, deceptively implying they had an understanding of what In-Q-Tel was that they could reason from as if a first principle. That's the problem. You don't need In-Q-Tel to cause the kind of damage you're talking about; you have many other vectors for this kind of deception. I'm not sticking up for In-Q-Tel. I wouldn't take money from IQT. But it is, for t…

>Because people would write comments like the one you did upthread, deceptively implying ...

Wasn't my intention for that comment to be deceptive in its implication. After seeing how some of the replies were going, I did try to amend it in a more balanced fashion—then ended up having to move that further down the thread due to the edit window expiring.

Funny enough the original comment's karma continued to skyrocket while the more measured words teetered on the brink of downvote for some time. It was surprising, since usually HN is pretty good at punishing anything that even has the slightest perception of hyperbole.

That said, I think we can agree that the 2-hour edit window represents a grave threat to civil discourse, freedom of expression, also freedom itself, probably national security, and nothing less than the future of Hacker News. It must be extended. :)

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#87

Earlier quoted context omitted.

> I know several of their key people, one of whom has a framed Che poster. They're not the type. :) Perhaps a bit OT, but you're dead wrong about Che. He was a mass murderer, and I'd treat someone with a framed picture of him with the same suspicion I'd reserve for someone with a Stalin or Hitler portrait. http://www.therealcuba.com/?page_id=32

The point he was making is that Che isn't a widely admired figure in U.S. intelligence circles.

Which is funny, because they had a lot in common at one point (and possibly still now).

http://nsarchive.gwu.edu/NSAEBB/NSAEBB4/ciaguat2.html

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#88

Earlier quoted context omitted.

Scope of "this" ?

So, in about 1997 or so I inherited a network where we had a Cisco router connecting Silicon Valley to a remote office but didn't have the password, so I hired a Ccie to help unpack the network and reset the password to this device... So as we were working on the 3640, and we got the password out of it (which was "Feet4Monkey") he was telling me about how they (Cisco) was required to provide back-door access to the N…

The thing is guys, I started complaining in the eighties. It was published knowledge back then, just not widely published. Being looked at as a loon back then didn't bother me. Being looked at as a loon POST-Snowden - and not infrequently - has really shaken me. People are choosing an alternate reality with alternate facts 'cause rose-colored glasses are just so much more comfortable.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#89

Earlier quoted context omitted.

So, in about 1997 or so I inherited a network where we had a Cisco router connecting Silicon Valley to a remote office but didn't have the password, so I hired a Ccie to help unpack the network and reset the password to this device... So as we were working on the 3640, and we got the password out of it (which was "Feet4Monkey") he was telling me about how they (Cisco) was required to provide back-door access to the N…

The thing is guys, I started complaining in the eighties. It was published knowledge back then, just not widely published. Being looked at as a loon back then didn't bother me. Being looked at as a loon POST-Snowden - and not infrequently - has really shaken me. People are choosing an alternate reality with alternate facts 'cause rose-colored glasses are just so much more comfortable.

Yeah - I was following echelon since about 88 - the 97 insight was just final confirmation I needed.... I have been modding /r/conspiracy for years.

people think "oh conspiracy! so like 'bigfoot'?" -- uh, no government conspiracy/corruption/collusion...

I didnt need snowden to tell me a thing, but I am sure glad he told everyone else.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#90

Earlier quoted context omitted.

The thing is guys, I started complaining in the eighties. It was published knowledge back then, just not widely published. Being looked at as a loon back then didn't bother me. Being looked at as a loon POST-Snowden - and not infrequently - has really shaken me. People are choosing an alternate reality with alternate facts 'cause rose-colored glasses are just so much more comfortable.

Yeah - I was following echelon since about 88 - the 97 insight was just final confirmation I needed.... I have been modding /r/conspiracy for years. people think "oh conspiracy! so like 'bigfoot'?" -- uh, no government conspiracy/corruption/collusion... I didnt need snowden to tell me a thing, but I am sure glad he told everyone else.

[deleted]
Post reply on HN