Live data from Hacker News

Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

cnbc.com

51–60 of 66 posts

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#51
post #28

I really hope that Duo survives this. Cisco isn't necessarily known for handling acquisitions well...or software...but who knows. Maybe it's the shot in the arm that many companies will need to move to token based auth. Lot's of enterprise IT departments take Cisco's word as divine. I have had some bad experiences with Cisco the company, but the devices have always been really good even if they lag behind some of the…

Cisco is essentially composed of nothing but acquisitions. That is what Cisco does. The reputation of Cisco's internal engineering culture used to be pretty grim. I never understood why any PM or lead would actually build something from a Cisco internal MRD, rather than jumping ship, building it privately, and selling it back to Cisco. I know of more than one person that did literally exactly that, successfully. But…

The culture didn't shift much post-Sourcefire, it just melded a bit. Everything they acquire becomes a little Cisco-y, depending on how big it was. Duo will become "Cisco-y Duo". But it may be more Cisco or Duo depending on the strength of the culture.

Talos is a good example: it was created from merging Cisco SIO and SourceFire VRT, but I would wager it's 80% VRT [in terms of culture]. They also have so many researchers now that it probably has sub-cultures. Even a single remote office can have its own culture.

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#52
post #20

I really hope that Duo survives this. Cisco isn't necessarily known for handling acquisitions well...or software...but who knows. Maybe it's the shot in the arm that many companies will need to move to token based auth. Lot's of enterprise IT departments take Cisco's word as divine. I have had some bad experiences with Cisco the company, but the devices have always been really good even if they lag behind some of the…

The acquisition track record for the Cisco Security business is pretty incredible. Like HBS Case Study good. Sourcefire, ThreatGrid, OpenDNS, Lancope, CloudLock, Observable. Great products and teams brought to scale and maintained. Even IronPort 10+ years later has done fantastically well. I'm thrilled that Duo will be joining an amazing business filled with a deep bench of security talent and wonderful customers. It…

Wow, that's really cool. OpenDNS is/was awesome. I think Cisco also does some great work in the security research space.

It's been a long time since my negative experience and I should probably update my prejudices. Cheers.

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#53
post #46
post #17

Earlier quoted context omitted.

Duo Beyond was a very smart move on their part, taking Google's enterprise security architecture and turning it into a third-party turnkey solution for enterprise customers. They did it before Cloudflare, too. I bet that is a big part of the reason why Cisco is paying so much now.

There isn't anything particularly innovative about Duo Beyond. Inspect the Docker containers and you'll see they simply rebranded simplesamlphp and wrote a custom ngx_http_auth_request_module handler for NGINX for their authenticated reverse proxy product. If Cisco paid 2 billion dollars for this, my mind is really blown. I'm struggling to figure out how they ended up at 2 billion because I don't see it in anything m…

Cisco didnt pay $2B for simplesamlphp, they paid it for "Duo Security provides cloud-based tools to prevent security breaches on devices." :)

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#54
post #44

Earlier quoted context omitted.

> Feel free to ping me and I'll see if I can give you some pointers of how to make some progress on that ask Spoken like a true Cisco executive. You could have just said "I'm supportive but it's out of my hands." Or perhaps, no reply at all.

I take that as a compliment. I really like working with almost every single one of my peers. I'm not responsible for the buildings or teams in SJC15 and the OP knows that. The people who work with me at Cisco know that when I say I'll help, I do.

> The people who work with me at Cisco know that when I say I'll help, I do.

The same can be said for people who know David outside of Cisco too. I know David from SHDH, EveryDNS, & OpenDNS. He's a man of his word.

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#55
post #45

Earlier quoted context omitted.

I know some of the Duo folks and they are serious security nerds and I don't think they would make this up. That said, I don't have any knowledge of the implementation. I did find this[1]: > Duo Push technology employs asymmetric encryption to sign and verify communications between Duo's servers and a smartphone running the Duo Push app I'm thinking this is saying something like they sign the contents of the push not…

Yeah, this doesn't help with a MITM because what happens is the victim is at Mallory's site thinking it's their real sign on site, Mallory is taking to their real sign on service. The victim types in real credentials, and says OK let's use Duo Push... Mallory now has their credentials and does Duo Push. The push is securely sent to the victim's phone, and they press OK because they really are trying to sign in. Mallo…

Why would Duo Push allow Mallory's site to initiate a Duo Push for RealSite.com without either a shared secret or certificate validation?

You present an obvious problem that has been solved securely many times over many products and act as if a group of IAM and 2fa professionals ignored or just hadn't thought of it before...

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#56
post #20

I really hope that Duo survives this. Cisco isn't necessarily known for handling acquisitions well...or software...but who knows. Maybe it's the shot in the arm that many companies will need to move to token based auth. Lot's of enterprise IT departments take Cisco's word as divine. I have had some bad experiences with Cisco the company, but the devices have always been really good even if they lag behind some of the…

The acquisition track record for the Cisco Security business is pretty incredible. Like HBS Case Study good. Sourcefire, ThreatGrid, OpenDNS, Lancope, CloudLock, Observable. Great products and teams brought to scale and maintained. Even IronPort 10+ years later has done fantastically well. I'm thrilled that Duo will be joining an amazing business filled with a deep bench of security talent and wonderful customers. It…

OpenDNS was pretty good until Cisco bought it, made the interface worse arbitrarily, and started increasing the cost without providing anything new worth having. The second we heard it was acquired I turned to my boss and said we ought to be looking for an alternative.

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#57

Are they a cybersecurity company? I thought they were more about IAM. I realize this is the CNBC headline, but I am curious if Duo does something I was unaware of, like rev. engineering, pen. testing, etc. ps - congrats to Duo!

I've never been clear about the connection to the core business but Duo Labs does a lot of vulnerability research / reverse engineering. https://duo.com/labs

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#58
post #31
post #9

Considering Cisco's history you will probably be able to use default credentials. I no longer would trust duo.

Trying to understand the downvotes to this comment. Cisco's been caught on multiple occasions including backdoors in their products. Expressing skepticism of their stewardship of a security company is perfectly reasonable.

[deleted]

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#59

Earlier quoted context omitted.

Yeah, this doesn't help with a MITM because what happens is the victim is at Mallory's site thinking it's their real sign on site, Mallory is taking to their real sign on service. The victim types in real credentials, and says OK let's use Duo Push... Mallory now has their credentials and does Duo Push. The push is securely sent to the victim's phone, and they press OK because they really are trying to sign in. Mallo…

Why would Duo Push allow Mallory's site to initiate a Duo Push for RealSite.com without either a shared secret or certificate validation? You present an obvious problem that has been solved securely many times over many products and act as if a group of IAM and 2fa professionals ignored or just hadn't thought of it before...

Because mallory.com (who's impersonating valery.com by ripping off the site design, and has a valid certificate for mallory.com) is running a full-up copy of Chrome in a VM, and is clicking the signin link just like a user would do.

I assume what Duo is referring to, though, is that they send through the IP address that your push request is coming from.

So if a user is observant and knows their public IP, they should see the difference.

Re: Cisco plans to acquire cybersecurity firm Duo Security for $2.35B

#60

Are they a cybersecurity company? I thought they were more about IAM. I realize this is the CNBC headline, but I am curious if Duo does something I was unaware of, like rev. engineering, pen. testing, etc. ps - congrats to Duo!

They are increasingly adding features that check the health and security of endpoints. So not unlike some MDM.
Post reply on HN