Hacker News new | ask | show | jobs
by kyrra 3566 days ago
From my time in Cisco, they take security VERY seriously. There was the story about Cisco devices being intercepted by the NSA in-transit to high-profile targets[0]. This was really bad press, especially since a lot of people assume that Cisco was complacent in the practice (there was no evidence as such, this was very likely the NSA intercepting the package in-route to the target). Many hardware companies (Cisco included) are trying to do verified-boot approaches where they can detect if the firmware or hardware is not genuine, there-by defeating these package intercept cases.

If you are a high-profile target, no matter what vendor or software you use, Five Eyes will do whatever is needed to infiltrate your network. Cisco is a large target just due to their volumes compared to most other solutions (you are more likely to see news of Cisco attacked due to volume of sales). But with that, Cisco will also dedicate resources to trying to defeat this type of attack.

[0] http://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa-...

1 comments

Is this true: "The NSA has been sitting on a zero day exploit to remotely grab VPN keys from Cisco firewalls for FOURTEEN years." [0]

0. https://twitter.com/musalbas/status/777834235273027584

There is a separate thread here on HN about this[0], though most of the discussion is around the original editorialized title for the article.

If you read the "Exploitation and Public Announcements" section of the Cisco publication, it meantions the source was another CVE from a month ago[1].

[0] https://news.ycombinator.com/item?id=12540692

[1] http://blogs.cisco.com/security/shadow-brokers