Former Cisco engineer pleads guilty to causing Webex account chaos
1–10 of 17 posts
Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#2Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#3Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#4Why did it take two weeks to recover from this? Aren't there protections in AWS from simply deleting VMs. Wouldn't AWS step in and help a company like Cisco if something horrible went wrong?
For this, in general, the answer is: (1) yes, IAM permissions, and (2) yes, if you configure them, and they often have a cost.
> Wouldn't AWS step in and help a company like Cisco if something horrible went wrong?
If Cisco asked, probably. But some things are inherently non-trivial to recover from once you've allowed them to happen. AWS can help, but they aren't magic.
Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#5Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#6I read this as incompetence on Cisco’s part.
Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#7Why did it take two weeks to recover from this? Aren't there protections in AWS from simply deleting VMs. Wouldn't AWS step in and help a company like Cisco if something horrible went wrong?
> Aren't there protections in AWS For this, in general, the answer is: (1) yes, IAM permissions, and (2) yes, if you configure them, and they often have a cost. > Wouldn't AWS step in and help a company like Cisco if something horrible went wrong? If Cisco asked, probably. But some things are inherently non-trivial to recover from once you've allowed them to happen. AWS can help, but they aren't magic.
Remove the user that is being terminated from the group and 'voila', it is safe.
Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#8Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#9What’s going on at Cisco where a departed engineer doesn’t have AWS credentials revoked for a whole 4 months? Hell, the person probably would have had access indefinitely if they had not had done something to make to make Cisco aware of the access.
At most companies IT handles logins and credentials for all internal systems. Things like email, vpn, internal sites, and chat. Usually this is all centralized, and when someone leaves IT revokes that user's access to everything.
I'm guessing what happened here was that the engineer got access to AWS manually. Maybe IT wasn't responsible for handling AWS credentials and it was expected that the person who gave him access would revoke it too. Alternatively, the person who gave him might not have gone through the company's regular policies.
Either way, the process in place for handling credentials here clearly didn't work and they got burned in it. Would love to see the internal postmortem here.
Re: Former Cisco engineer pleads guilty to causing Webex account chaos
#10When you login at Cisco WebEx, they warn you of criminal liability. However, if you report a security concern at Cisco they treat you like a criminal. Basically, as an employee at Cisco you take on all the liability but they won't protect you from their own negligence.