https://www.tomshardware.com/news/cisco-backdoor-hardcoded-a...
Honestly you could probably do it without engineers knowing about it simply by cutting QA and red team budgets.
I'm not saying I think that's what happens at Cisco. Having worked at large companies that actively try to ship secure products, and having observed (as a paying end user) the general terrible-ness of networking hardware, that it is more plausible that they're just not being careful - I want to say incompetent by that is likely unfair to the majority of engineers there.
Of course nothing says that various gov. agencies in many countries aren't auditing the equipment themselves and making use of flaws without publicizing them.
And then there's leaving in five separate root logins in just in the first half of 2018. Like, come on.
Given the lack of subtlety and the wide spread existence of these same exploits/backdoors/bugs indicates there's a level of care that is missing in engineering of these devices that makes it plausible that this is by ignorance rather than malice.
1. US administration may change and might outlaw whatever unholy thing CIA is doing today; 2. CIA does it at a smaller scale, seeding smaller companies;
So it's okay? Fascinating.
https://medium.com/insurge-intelligence/how-the-cia-made-goo...