Cisco plans to acquire cybersecurity firm Duo Security for $2.35B
cnbc.com
cnbc.com
Lots of good tech in A2 in general - Deepfield acquired by Nokia, SkySpecs, Trove, FarmLogs (a YC startup), LLamasoft (my employer!), IBM is here, Toyota, Hyundai, a rapidly increasing number of medtech companies, and plenty of boutique consulting. It makes for a healthy life - a strong tech scene drives wages up, yet the cost of living is still fairly low (downtown A2 is very expensive already, but you can live in the nearby areas for considerably less). There were four companies from A2 in the who's hiring page the other day. Take a look! :)
haha edit - i didn't scroll down. you guys rock! - https://github.com/MadeInA2/madeina2
A big part of the August 7th primary will be about building more housing. Taylor wants more, Eaton wants to freeze Ann Arbor in amber so that no one else can move in and change the town.
Cisco Press Release: https://newsroom.cisco.com/press-release-content?type=webcon...
Letter sent by Duo CEO to customers: https://pastebin.com/AdTMYzzH
I'm thrilled that Duo will be joining an amazing business filled with a deep bench of security talent and wonderful customers. It's a really strong fit with what Duo has already built and with where both teams are going, now together.
I guess I should mention I was founder / CEO of OpenDNS, was acquired by Cisco, previously led the Cisco Security business, and am still an executive at Cisco. So maybe a bit biased, but still factually on the mark. ;-)
Spoken like a true Cisco executive. You could have just said "I'm supportive but it's out of my hands."
Or perhaps, no reply at all.
I'm not responsible for the buildings or teams in SJC15 and the OP knows that. The people who work with me at Cisco know that when I say I'll help, I do.
Caveating your offer of support three or four times signals hostility not helpfulness.
Any rational actor reading that statement would assume you’d forward their message onto HR without a real response. And make note of the complainer in question.
If you can’t be concrete with your words, why even bother?
"I'll see if I can give you some pointers of how to make some progress on that ask"
probably means
"I'm not the god damn office facilities manager, and I'm not spending my limited time and social capital to quarterback your request for you, but I'll see if I can figure out who in god's name in this 70,000+ person company you should talk to, and tips for how you might convince them to change their budget to give you free snacks".
The same can be said for people who know David outside of Cisco too. I know David from SHDH, EveryDNS, & OpenDNS. He's a man of his word.
/s
It's been a long time since my negative experience and I should probably update my prejudices. Cheers.
I hope you read this,the reason why Cisco chooses to aquire rather than compete is the same reason those companies would do better without Cisco. I am glad for the founders who get aquired but at least the John Chambers era aquisitions did not fare well.
The reputation of Cisco's internal engineering culture used to be pretty grim. I never understood why any PM or lead would actually build something from a Cisco internal MRD, rather than jumping ship, building it privately, and selling it back to Cisco. I know of more than one person that did literally exactly that, successfully.
But post-Sourcefire I think it's a different scene there; they have some very large, long-lived teams with coherent cultures now. I assume in the post-Sourcefire Cisco game plan, Duo stays Duo.
Not overly surprisingly if so. Meraki, and in some ways OpenDNS, have stayed mostly their own with varying degrees of integration.
Talos is a good example: it was created from merging Cisco SIO and SourceFire VRT, but I would wager it's 80% VRT [in terms of culture]. They also have so many researchers now that it probably has sub-cultures. Even a single remote office can have its own culture.
On the other hand I don't like how the acquisition's leadership gets to absorb other BU's which are targeting similar market space because there is a lot of time and effort that gets invested into integrating teams working culture and style. Also the incoming teams fight to keep their product portfolios alive which leads to sub-optimal decisions.
They provide all the resources you need, are very ethical and help your newly acquired team do your best. If your team (business unit as they call it) doesn't cut it after a few years, they start maneuvering those resources elsewhere. But they've always given every acquisition a fair chance to have their own story. See: Meraki, Insieme, Webex.
Cisco probably doesn't care if a few of their startup acquisitions don't work out.
ps - congrats to Duo!
If Cisco paid 2 billion dollars for this, my mind is really blown. I'm struggling to figure out how they ended up at 2 billion because I don't see it in anything material -- perhaps the patents or a play against Okta for recurring revenue from smaller companies which might not have Cisco gear?
Expressing skepticism of their stewardship of a security company is perfectly reasonable.
I personally and professionally will never want to touch their products.
Does anybody have an explanation, or is this claim in fact entirely hollow and a real world MITM would work just fine but they're pretending to believe real users would do stuff like verify their IP address in a phone message?
> Duo Push technology employs asymmetric encryption to sign and verify communications between Duo's servers and a smartphone running the Duo Push app
I'm thinking this is saying something like they sign the contents of the push notification with a key that the app knows and that the man in the middle wouldn't have. So, they're not just relying on the provider of the push notification service.
[1]: https://searchsecurity.techtarget.com/answer/Do-two-factor-a...
FIDO tokens break this attack because the token is talking to the victim's web browser, and that's not visiting the real site so it doesn't work. If Mallory lets the victim's browser talk to the real site, sign in works but Mallory is cut out of the loop.
It's a Confused Deputy problem. Push 2FA assumes that if you confirm that you're trying to sign in at 9:14 and there's an attempted sign in at 9:14 then that's one event, but unlike U2F the only thing connecting the two is the timing, which Mallory can choose.
You present an obvious problem that has been solved securely many times over many products and act as if a group of IAM and 2fa professionals ignored or just hadn't thought of it before...
I assume what Duo is referring to, though, is that they send through the IP address that your push request is coming from.
So if a user is observant and knows their public IP, they should see the difference.
You insist this "has been solved securely many times over" but it famously hasn't, which is why I asked if Duo had some secret sauce. They evidently don't.
People keep building things that are very clever but don't actually respond to the threats in the real world, MITM is a real world threat, and one Duo shouldn't be pretending they're defending against with this Push technology.
This is another solid proof that one doesn't have to be in the Bay to build Unicorn, amazing companies or have fantastic exit.
We have been successfully offering on-premise solution to local financial institutes here in Nepal and we are working on launching our SaaS offering (it's currently in beta with few users). If you are interested for beta access, drop me a message at sakshyam[at]seknox.com
Disclosure: I am founder of this startup.
good on them, since their product is largely uncompetitive today. (they had their moment but it has passed)