Cisco coughs up baker’s dozen of vulnerabilities and other security nasties
theregister.co.uk
theregister.co.uk
Or as I learned in the last week with Cisco, it doesn't even matter if you have an account! You can't download software updates to the hardware they sold you unless you pay extra for a Service Contract!
Leaving security holes in the software? Well gosh, we're real sorry about that. How 'bout you cough up a nominal fee for each of those "Security Appliances" you bought so we can give you the privilege of fixing our mistakes. Thanks!
Ok, but that's bullshit, isn't it? Not all customers are going to be proactive/attentive enough to know their hardware is vulnerable. Cisco knows there is vulnerable gear in the wild, knows there is a fix, but withholds the fix until people come begging? Almost feels like the sort of thing that should be illegal (or at least on the losing end of a civil suit).
Of course Microsoft also released some free security updates beyond the date too.
Holy crap does anybody actually think that's remotely acceptable behavior? I get better support on discounted Chinese routers I've bought in back alleys - they at least put out their patches for free.
Please go on and let me know where I can open this case.
I am not sarcastic, I really need that fixed.
Most security-critical devices are moving in the direction of auto-updating. I'm not super into that, but I see the justification. You're telling me that Cisco is so far in the opposite direction that if I want to patch a device, I can't download the firmware myself, I have to open a service request saying, "I'd like the latest security patches", and then answer the question, "Why? What specifically are you worried about?"
That is not the setup of a company that cares about security.
Putting firmware patches behind any kind of account authentication is mind-boggling to me. I wouldn't have guessed that there's a hardware company that does that.
If untrusted code can patch the kernel after that, then it's already ten kinds of game over. Also, if this attacker can patch the kernel, then it can patch firmware, as they run at the same security context.
It always amazes me that we continually release software with these backdoors in them. What is the thought process that's going on? Do they think security by obscurity really works? They must or else they wouldn't keep doing this. Cisco isn't a small company, they have the people-power, processes, and money to not do this. It literally saves no time or money when you figure in the cost to fixing the issue. US government conspiracy theories aside, I'm guessing it's just lazy developers, incompetent managers, or potentially intentional maliciousness from foreign governments or competitors.
I suspect the kind of person who left in that backdoor would, after going through the course, simply make a slightly harder-to-find backdoor. (If anything, they might be more likely because they think they've taken into account THE vulnerability, when it is only a vulnerability).
Ross Anderson has a good reply to your statement in the 7th chapter of his book, 'Security Engineering'. [1]
I've seen the networking gear sales world.
A huge % of customers just buy Cisco ... just because. It's a matter of fact. So if you're Cisco, there's no incentive. "Nobody ever got fired for buying IBM" is as much "Nobody ever got fired for buying Cisco".
> Likely. Considering the three letter agencies get early access to these things from other vendors: https://arstechnica.com/information-technology/2013/06/nsa-g...
Though, it's worth noting that the NSA actually two roles: 1) ensuring the security of US Government communications systems and 2) conducting signals intelligence against other foreign communications systems. People focus so much on the former that they often forget the latter.
Given their defensive role, being "done" with these exploits may mean simply having patched/secured all their systems against them.
If you're like me, check this out: https://www.todayifoundout.com/index.php/2010/09/why-a-baker...