Live data from Hacker News

A simple command allows the CIA to commandeer vulnerable Cisco switches

arstechnica.com

51–60 of 90 posts

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#51
post #50

> and organizations get unfairly accused. I understand people, but why organisations? Capitalist firms literally thrive on the exploitation of labour, disregard for the environment and otherwise reckless pursuit of profit.

Capitalist firms employ people, who support families. They may have relocated to a region where they can't find alternate work if the company folds.

Capitalist firms are owned by asshole billionaires, nice billionaires, pension funds, individual investors, and retirement funds. They're still owned by and made up of people.

Instead of inventing false accusations about them, debate them on their merits.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#53
post #32

Earlier quoted context omitted.

> why? how is someone who has been vetted by the IC as a trustworthy keeper of their secrets become less trustworthy? Because their loyalties may lie with their former employer. National security matters tend to take priority over private sector loyalty for many people, and I'd imagine especially so for former IC types since they tend to be extremely patriotic. I mean that as a compliment, not an insult. > what kind…

Again, I'm glad you're engaging. I'm not down voting you. > Because their loyalties may lie with their former employer. By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets. > Personal relationships... that relationship is probably going to supersede loyalty to any private sector employer Sure, anything could happen. In your example, Joe gets nothing except enormous ris…

>By that logic, Apple shouldn't hire any employees from Google, because they might reveal iOS secrets.

Apple and Google are on the same playing field though. They're fundamentally the same type of entity. An intelligence agency vs a pure private-sector company is not.

>Any employee that is involved in this would almost certainly speak to someone. This isn't like a National Security Letter; there's no force of law to compel silence. It would be a foolish move for Joe.

While certainly risky, I'm not saying Joe wouldn't be legally protected. His favor very well could be under the auspices of an official program. Heck, IANAL but it possibly could even be in the form of an NSL. As far as I'm aware they're the legal equivalents of blank slates and don't necessarily require informing the upper echelon of a company of their issuance, but I could be wrong on that. I know that it is at least customary to do so, however.

Either way, let's say the government wants to issue a NSL requesting a very specific, perhaps even temporary backdoor to a Bay Area company. The normal route would likely start a veritable war with that company's legal department, and runs a non-insignificant chance of being leaked by those who know about it.

Contrast that scenario to issuing the NSL directly to Joe, who they know in advance is solid. If Joe happens to be an engineer, mission accomplished. If he isn't technical, then maybe he just happens to bring a USB stick to the office one day and plugs it in.

If that sounds far-fetched, keep in mind that the NSA compromised Google's internal network during the course of their operations, so network exploitation against U.S. companies isn't even off the table.

>People that are so loyal to the CIA don't leave for a pure private sector company. They go to a contractor so they can stay in the ecosystem. People going to Cisco are (1) physically moving away from Northern Virginia, (2) losing access to secrets.

All good points, but it doesn't mean they're cutting ties and shunning their former life either.

>Again, I'm glad you're engaging. I'm not down voting you.

Thanks. :)

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#54
post #50

> and organizations get unfairly accused. I understand people, but why organisations? Capitalist firms literally thrive on the exploitation of labour, disregard for the environment and otherwise reckless pursuit of profit.

Capitalist firms employ people, who support families. They may have relocated to a region where they can't find alternate work if the company folds. Capitalist firms are owned by asshole billionaires, nice billionaires, pension funds, individual investors, and retirement funds. They're still owned by and made up of people. Instead of inventing false accusations about them, debate them on their merits.

>Capitalist firms employ people, who support families.

The feudal lord supports families by giving them a place to live while the workers pay tribute with the fruit of their labour. The idea that the workers ought to be grateful for being exploited is, in my opinion, silly. Capitalist firms pay for the labour-time, which includes the cost of (i) the worker staying in the work force (ii) the worker "recharging" with a moderate amount of sleep and entertainment (iii) the worker adding more to the workforce via reproduction, so the children are also paid for.

The worker is an expense, the family is an expense. The family is an expense because if it was not paid for, the workers could not work or the supply of workers becomes more scarce.

So yes, while the capitalist firm may employ people who provide for the family, so does the slave owner, for the purpose of future slaves. And as soon as the worker is not profitable, what happens to that support for the family? It disappears.

So the merits are thus: people are kept in servitude by virtue of their status of being a worker, with just enough income to pay to replenish the work force and stay motivated. That's the merits of the capitalist firm.

Edit: if the downvoters would like to ask questions or respond, it would be nice to know where I'm going wrong, thanks :)

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#55
post #8

Earlier quoted context omitted.

Disabling the service is a way to protect you from the vulnerability, but it is not a fix for the vulnerability. A fix for the vulnerability would allow you to continue using the service.

The article kind of makes it sound like telnet is somehow necessary and that disabling it hasn't been a best practice for years. Maybe there are still old devices that don't support SSH and you literally have no option, but really, what other reason is there to have telnet enabled?

Please, use an RPi attached to a serial port and SSH through it.

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#57
Headline is pretty click-baity.

It looks like a better version might be "Some older Cisco switches are vulnerable to a simple telnet-based exploit." And then buried deep in the body it could be noted that, while the CIA should probably be expected to be aware of any vulnerabilities, we actually know that they are aware of this one in particular due to some leaks.

(Whereas the existing headline suggests that ONLY the CIA can use this vulnerability, which was false even before the leak.)

But then, an article about how you shouldn't expose telnet to the public internet wouldn't be very newsworthy would it? :)

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#58
post #54

Earlier quoted context omitted.

Capitalist firms employ people, who support families. They may have relocated to a region where they can't find alternate work if the company folds. Capitalist firms are owned by asshole billionaires, nice billionaires, pension funds, individual investors, and retirement funds. They're still owned by and made up of people. Instead of inventing false accusations about them, debate them on their merits.

>Capitalist firms employ people, who support families. The feudal lord supports families by giving them a place to live while the workers pay tribute with the fruit of their labour. The idea that the workers ought to be grateful for being exploited is, in my opinion, silly. Capitalist firms pay for the labour-time, which includes the cost of (i) the worker staying in the work force (ii) the worker "recharging" with a…

You seem to not be a fan of capitalism. Do you live in China, Cuba, Vietnam, Laos or North Korea? If not, why not?

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#59
post #54

Earlier quoted context omitted.

>Capitalist firms employ people, who support families. The feudal lord supports families by giving them a place to live while the workers pay tribute with the fruit of their labour. The idea that the workers ought to be grateful for being exploited is, in my opinion, silly. Capitalist firms pay for the labour-time, which includes the cost of (i) the worker staying in the work force (ii) the worker "recharging" with a…

You seem to not be a fan of capitalism. Do you live in China, Cuba, Vietnam, Laos or North Korea? If not, why not?

>China, Cuba, Vietnam

These are capitalist countries, in which wage labour is the primary way by which workers sustain themselves; property is privately owned (and yes, the government can privately own property).

>North Korea

North Korea is an ethno-nationalist dictatorship run by a hereditary monarchy.

What's your point?

Re: A simple command allows the CIA to commandeer vulnerable Cisco switches

#60
It is one thing to try penetrate a system (solely for the purposes of,..&c.) that to all appearances seems impermeable to your meagre skills but once you know that these impregnable walls you face can and do become doors placed there by like-purposed if not necessarily like-minded individuals then what a filip! What more encouragement to keep you fuzzing just that little bit longer and who knows maybe you will stumble upon it! That sir, is the damage. Software can be patched. Trust cannot. (And this is what I sound like from my high horse apparently).
Post reply on HN