Those links were the result of a few cursory Google searches. It wasn't intended as a comprehensive representation of Cisco's CIA ties, nor to imply that anyone mentioned was directly involved in backdoors. Rather, the point was that when a security-oriented organization employs ex-spooks, it increases the likelihood of spooky things happening. At the very minimum it fosters distrust.
>2. Why would the ex-CIA guy hurt his current employer to help his former? Don't people do it the other way around?
While I didn't mean to imply any specific individual, I'll address the underlying rationale: When someone's former employer is a powerful government spy agency built on secrets, the loyalty dynamic is a bit different than that of normal private sector job hopping.
Moreover, I'm sure the CIA isn't stupid and tends to maintain relationships—intentionally or not—with former employees that cross over to private sector work, especially high-level people since they're already trusted, reliable, and may be taking positions that later prove to be beneficial to CIA interests in the future.
>3. Good luck finding a single Fortune 500 company that doesn't employ someone that used to be in the Intelligence Community.
This is a fair point. Given the nature of Cisco's products, and combined with recent leaks detailing the pervasive nature of US offensive cyber efforts, it should raise more suspicion than normal when former IC people go to work for a company dealing with network hardware.
That said, I'm not sure how you'd quantify the number of former IC people Cisco hires versus a normal Fortune 500 company. For all I know it could even be lower than average.
>... and backdoor dependent on physical sabotage (interdiction) ...
This approach is far superior to baking vulnerabilities into entire product ranges (or even standards). It doesn't compromise the private sector in the process, beyond perhaps supply chain integrity. The flipside of course is that physical implants don't really scale well, but at least the blowback is relatively minimal when things go wrong. Not to mention it's just badass in a James Bond kind of way.
>It's a common HN meme that Cisco and Microsoft help the U.S. government spy, but there isn't credible evidence supporting it. They actively resist government espionage attempts.
While that's true, it's also possible a company can publicly say or do one thing—genuine or not—and actively do another because of either connections, or that they're being compelled against their will by NSLs. It's also possible to have factions or even individual employees within a company that are actively subverting security with the addition of backdoors, unbeknownst to management.