Congratulations to my neighbors at Duo! That's a crazy amount of money and I hope that many Ann Arborites pay it forward in the tech scene from which Duo came. Lots of good tech in A2 in general - Deepfield acquired by Nokia, SkySpecs, Trove, FarmLogs (a YC startup), LLamasoft (my employer!), IBM is here, Toyota, Hyundai, a rapidly increasing number of medtech companies, and plenty of boutique consulting. It makes fo…
Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
41–50 of 66 posts
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#42I really hope that Duo survives this. Cisco isn't necessarily known for handling acquisitions well...or software...but who knows. Maybe it's the shot in the arm that many companies will need to move to token based auth. Lot's of enterprise IT departments take Cisco's word as divine. I have had some bad experiences with Cisco the company, but the devices have always been really good even if they lag behind some of the…
Cisco is essentially composed of nothing but acquisitions. That is what Cisco does. The reputation of Cisco's internal engineering culture used to be pretty grim. I never understood why any PM or lead would actually build something from a Cisco internal MRD, rather than jumping ship, building it privately, and selling it back to Cisco. I know of more than one person that did literally exactly that, successfully. But…
Not overly surprisingly if so. Meraki, and in some ways OpenDNS, have stayed mostly their own with varying degrees of integration.
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#43Earlier quoted context omitted.
The acquisition track record for the Cisco Security business is pretty incredible. Like HBS Case Study good. Sourcefire, ThreatGrid, OpenDNS, Lancope, CloudLock, Observable. Great products and teams brought to scale and maintained. Even IronPort 10+ years later has done fantastically well. I'm thrilled that Duo will be joining an amazing business filled with a deep bench of security talent and wonderful customers. It…
Yo can we get some snacks in SJC15?
/s
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#44Earlier quoted context omitted.
I'm supportive. Feel free to ping me and I'll see if I can give you some pointers of how to make some progress on that ask.
> Feel free to ping me and I'll see if I can give you some pointers of how to make some progress on that ask Spoken like a true Cisco executive. You could have just said "I'm supportive but it's out of my hands." Or perhaps, no reply at all.
I'm not responsible for the buildings or teams in SJC15 and the OP knows that. The people who work with me at Cisco know that when I say I'll help, I do.
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#45Duo's "Duo Push" push based second factor says it "can protect against man-in-the-middle (MITM) attacks" but I don't see how this type of push system can do that. Does anybody have an explanation, or is this claim in fact entirely hollow and a real world MITM would work just fine but they're pretending to believe real users would do stuff like verify their IP address in a phone message?
> Duo Push technology employs asymmetric encryption to sign and verify communications between Duo's servers and a smartphone running the Duo Push app
I'm thinking this is saying something like they sign the contents of the push notification with a key that the app knows and that the man in the middle wouldn't have. So, they're not just relying on the provider of the push notification service.
[1]: https://searchsecurity.techtarget.com/answer/Do-two-factor-a...
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#46Earlier quoted context omitted.
Doesn't do identity, relies on external IAM. Look into Duo Beyond.
Duo Beyond was a very smart move on their part, taking Google's enterprise security architecture and turning it into a third-party turnkey solution for enterprise customers. They did it before Cloudflare, too. I bet that is a big part of the reason why Cisco is paying so much now.
If Cisco paid 2 billion dollars for this, my mind is really blown. I'm struggling to figure out how they ended up at 2 billion because I don't see it in anything material -- perhaps the patents or a play against Okta for recurring revenue from smaller companies which might not have Cisco gear?
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#47Duo's "Duo Push" push based second factor says it "can protect against man-in-the-middle (MITM) attacks" but I don't see how this type of push system can do that. Does anybody have an explanation, or is this claim in fact entirely hollow and a real world MITM would work just fine but they're pretending to believe real users would do stuff like verify their IP address in a phone message?
I know some of the Duo folks and they are serious security nerds and I don't think they would make this up. That said, I don't have any knowledge of the implementation. I did find this[1]: > Duo Push technology employs asymmetric encryption to sign and verify communications between Duo's servers and a smartphone running the Duo Push app I'm thinking this is saying something like they sign the contents of the push not…
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#48Earlier quoted context omitted.
> Feel free to ping me and I'll see if I can give you some pointers of how to make some progress on that ask Spoken like a true Cisco executive. You could have just said "I'm supportive but it's out of my hands." Or perhaps, no reply at all.
I take that as a compliment. I really like working with almost every single one of my peers. I'm not responsible for the buildings or teams in SJC15 and the OP knows that. The people who work with me at Cisco know that when I say I'll help, I do.
Caveating your offer of support three or four times signals hostility not helpfulness.
Any rational actor reading that statement would assume you’d forward their message onto HR without a real response. And make note of the complainer in question.
If you can’t be concrete with your words, why even bother?
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#49Duo's "Duo Push" push based second factor says it "can protect against man-in-the-middle (MITM) attacks" but I don't see how this type of push system can do that. Does anybody have an explanation, or is this claim in fact entirely hollow and a real world MITM would work just fine but they're pretending to believe real users would do stuff like verify their IP address in a phone message?
I know some of the Duo folks and they are serious security nerds and I don't think they would make this up. That said, I don't have any knowledge of the implementation. I did find this[1]: > Duo Push technology employs asymmetric encryption to sign and verify communications between Duo's servers and a smartphone running the Duo Push app I'm thinking this is saying something like they sign the contents of the push not…
FIDO tokens break this attack because the token is talking to the victim's web browser, and that's not visiting the real site so it doesn't work. If Mallory lets the victim's browser talk to the real site, sign in works but Mallory is cut out of the loop.
It's a Confused Deputy problem. Push 2FA assumes that if you confirm that you're trying to sign in at 9:14 and there's an attempted sign in at 9:14 then that's one event, but unlike U2F the only thing connecting the two is the timing, which Mallory can choose.
Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
#50Earlier quoted context omitted.
I take that as a compliment. I really like working with almost every single one of my peers. I'm not responsible for the buildings or teams in SJC15 and the OP knows that. The people who work with me at Cisco know that when I say I'll help, I do.
It wasn’t. Caveating your offer of support three or four times signals hostility not helpfulness. Any rational actor reading that statement would assume you’d forward their message onto HR without a real response. And make note of the complainer in question. If you can’t be concrete with your words, why even bother?
"I'll see if I can give you some pointers of how to make some progress on that ask"
probably means
"I'm not the god damn office facilities manager, and I'm not spending my limited time and social capital to quarterback your request for you, but I'll see if I can figure out who in god's name in this 70,000+ person company you should talk to, and tips for how you might convince them to change their budget to give you free snacks".