The Fake Cisco
labs.f-secure.com
labs.f-secure.com
I've seen people say that you don't need a Chinese partner, I've done business in China, I needed a partner company, and I was only doing software.
You need to share your IP with your Chinese Partner company. Your Chinese partner company is partially owned by the Chinese Government. When you share your IP with your Chinese partner company they share it with their owner, the Chinese Government. The Chinese Government then shares your IP with all the other Chinese companies that could benefit.
The Chinese haven't needed to steal Commercial IP because western companies have been handing it over to them willingly.
Making fakes
I got to know people at my Chinese partner company, and a relative of one guy was in the business of helping western companies manufacture in China. I was lucky enough to get a tour of a few "high end brand" factories. The relative was quite open about the fact that they right down the road was another factory, which I also toured, that looked almost identical to the first, where they were making similar products, almost identical to the first. The only difference was the leather, and quality of the fabric, and the hardware, you can't make a knock-off handbag if you use the same quality materials. The relative did allude to the fact that the cost of the second factory was buried in the cost of the first.
Never China.
https://www.wsj.com/articles/how-china-systematically-pries-...
The rush into China 20+ years ago forced the less willing to follow, just to stay cost competitive. And it's not like the original flood of businesses went in agreeing to give up all their IP, or expecting to wed themselves to Chinese manufacturing. They all went in chasing gold--cheaper production, access to what was to become the world's largest market. And like every gold rush in history expectations were foiled and people ended up making compromises they wouldn't have otherwise made.
I remember a graduation party I attended in 2000. A friend's parents flew in from India, where they owned several textile factories. I asked the father some questions about the direction of Indian and Chinese manufacturing, which caused him to launch into a long lament about the speculative investments flowing into China. So many investments were flowing into China they were making garments below the cost of inputs, and that's with the already low cost of labor, and without government financial aid. It made it impossible for him to compete fairly in the global markets.
The Chinese government knew what it was doing. They deliberately hyped the prospect of the Chinese domestic market to no end, holding it out as bait, and American businesses bought it hook, line, and sinker. They situated not only their most crucial industrial assets in China, but sent boatloads of cash and, more importantly, expertise on top of it. It's hard to exaggerate the irrational exuberance that played out over two decades.
Slowly, but surely, these mistakes are becoming apparent--not that any American MBA would ever admit to a personal error in judgment, or that they're prepared to make an about-face. This notion that it will all be worth it some day as the Chinese market matures still holds sway.
Of course, the potential of the Chinese market was always there, and still is. The error in judgement was believing China was dumb enough to just hand it over to the West, and to do so without exacting a price. That price is turning out to be far larger, and the first-mover advantages far more meager, than if the integration of China into the global market had occurred more organically and gradually, without American industry falling over themselves clambering across the Pacific, easy targets for industrial exploitation. Japan seems to have done a better job of it, as have many other countries. It's mostly the Americans that look like idiots.
The management at these companies in general are pretty dumb.
There’s a reason why in an age where all of the things are being computerized, most computer companies perform very poorly. When I followed this industry segment closely, Macs made more profit than HP, Dell, Lenovo and Asus combined.
Edit: to clearify, this behavior is behind a flag and only happens in the chinese version of CS:GO
All I see are lots of "removed for partner depot" comments which are the kind of thing that shows up when code has been stripped down for public/semipublic sharing
>game/shared/bannedwords.cpp line 3
// Purpose: Implementation of China Government Censorship enforced on all user-generated strings
>engine/net_ws.cpp line 2971
// Set partner. Running in china?
"If you know they are going to steal from you, why do business over there?" I asked.
His reply: "I need this sale".
35 years later our industry is still having this conversation.
I used to put up with Cisco's "you need to pay for ongoing support (SmartNet contracts) to get any updates/firmware - including for bug fixes and firmware upates for the modem etc." even for my home equipment when I had my CCNA and was still drinking the Kool-Aid trying to keep one foot in the Cisco ecosystem. And you couldn't buy used off eBay because they wouldn't sell you that SmartNet contract on it to get the updates/firmware.
I had a Cisco 877W modem/router/WiFi for ages back when I had DSL and, not only was it outrageously overpriced (I think I paid like $1000 for it), I also needed to buy SmartNet for it to get the firmware for the modem part of it to work properly with my ISP even new out of the box (Annex N support if I remember correctly).
TBH even if Ubiquiti's EdgeRouter stuff was the same price as Cisco I'd still buy it these days if it was my money instead because it is soo liberating to just be able to go to the website and download the firmware updates free forever. My EdgeRouter Lite was not only like 1/8th the cost of an equivilent Cisco but it is still getting free updates without even needing to register a login with them 5 years after I bought it and I haven't had a single problem with it in that time...
With the recent news about removing Huawei from UK cell networks, it got me wondering...is there a feasible way to verify there aren't backdoors in infrastructure hardware like this other than manufacturers open sourcing (this doesn't mean open licensing) software, firmware, microcode, chip designs, board designs, and compilers so researchers can see what you did and verify production matches the source?
How would you defend your IP with it being so out-in-the-open? Competitors seeing your code probably wouldn't be so much of a problem, and it wouldn't be so much of a problem for large players in first world countries, but China has a reputation for knockoffs, and they wouldn't hesitate producing counterfeit hardware for domestic use.
So, step one: produce your hardware on your own.
In certain settings this should work non-destructively, but that might require something like lapped (grinding the backside after fabrication to thin out the substrate) non-stacked >=22 nm chips.
The only way I can think of is monitoring its traffic and looking into anything fishy from there. But even that isn't conclusive.
Maybe the backdoor listener is behind a complex port knocking sequence? There's really no way to tell.
Even open sourcing all that wouldn't necessarily be enough to verify the non-existence of a backdoor. IIRC, clever back doors are deliberately designed to look like unintentional 0-day security flaws.
But that's not sufficient since you can't reasonably verify if a particular piece of hardware has the design, microcode or firmware that it is supposed to have. For all you know there's a tricky modification there that's not in the documents you got. There is published research on nearly undetectable alterations of chips during manufacturing, altering its functionality; chips can lie about the firmware they have, etc.
One day he gets a call and is in the middle of debugging when he asks for a particular device's serial number. He copies it down, and looks at his desk. That device is sitting on his desk. Asks the customer to confirm, and even gets a snapshot of the physical label which matches what was said by firmware.
Double Runs where the manufacturing partner builds your devices twice (or more) and sells the remaining ones on the gray market exist. You can have genuine cisco products and still not have genuine cisco products.
Just by taking a look at PCB pictures it looks like the counterfeiter managed to get their hands on some scrap or older revision boards and even went through more hoops (like that "modchip" design) to make them boot. Seems so overkill for a switch that goes for 250$ used - am I missing something?
Which means if you buy an aftermarket Cisco device, you're pirating the software on it unless you go through Cisco's pricey relicensing process... which mostly makes it cost you as much as buying a brand new device anyways. Obviously, homelab folks and test lab folks don't care too much, and Cisco doesn't mind them, but enterprises can't use used Cisco hardware.
As such, counterfeit Cisco hardware makes sense: It's basically software piracy, but they have to provide hardware that'll trick it into running.
(I also feel like we should give a shoutout to HP/Aruba in this thread. No support contract needed, they straight-up warranty and support most of their network hardware for like 100 years.)
However, I think that ends at the EOL of the item. Usually when they stop manufacturing it.
It's the same reason optics are whitelisted (how bullshittish that might be). If you are a datacenter or L1 IXP, spending a couple of grand on licenses is nothing compared to the cost of running the rest of the infrastructure. Not to mention you need the support when shit really hit's the fan.
My experience with aruba's support has been lackluster, while both cisco and juniper offer excellent support in my experience. (at a cost ofcourse).
Depreciation is intended to be an allocation of the purchase price across the whole expected usefulness term of that asset, it reflects the notion that in this year you "used up" some portion of an asset that will last for more years, so it makes sense to allocate just a part of the total cost to this year's cost of doing business. The intended purpose of that asset is to serve your business, not to resell it, so the fact that nobody would would buy that asset does not matter.
Also counterfeit Cisco hardware seems to be a major issue for Cisco since at least nineties. It is the reason why there are hologram stickers on almost anything. Then there is the observation that a lot of Cisco hardware contain some kind of completely unnecessary FPGA/ASIC implementing some comparatively trivial functionality, I suspect that the whole reason for this is to make counterfeiting harder.
The secret sauce has nothing to do with router size, but rather port density, bandwidth, and feature scale. For instance, Cisco’s latest generation of routers, the Cisco 8000 series, gets you 10.8 Tbps in a 1 RU fixed form factor.
What larger routers do provide is hardware redundancy, which is important when it comes to minimizing downtime.
Another question is router vs. switch. And as for routers I'm still somewhat discontent with Cisco's marketing wrt. CEF which on “small-ish” Cisco platforms simply meant implementing routing logic in software in exactly same way as any OS with BSD derived IP stack instead of the original IOS braindead implementation.
And as for hardware redundancy: I have large amount of stories that somewhat discredit the idea of low level redundancy (ie. you remove the SPOF and replace it with another failure point in the fail over logic that is guaranteed to fail in ways that nobody understands). And two of these stories with largest impact involve Cisco hardware.
* Confidence in interoperability / drop in replacement
* Can use existing configuration(s) without rewriting
* Can benefit from existing knowledge, training, expertise and documentation
* Service, existing contracts, etc.
* Network architects / designers don't have to find new visio stencils (Ok joking... well, half joking).
TL:DR; I think most customers in Cisco are buying into the ecosystem, not the hardware.
I’m not following. Why wouldn’t a forged device function?
The platform is vulnerable because this is a condition that the designers intended to engineer against - it's vulnerable in the sense that Sony's PS2 platform turned out to be vulnerable to circumvention with modchips.
The security chip has a private key embedded in it in such a way that private key can be used to sign stuff, but cannot be extracted directly. The (publically downloadable) software contains matching public key, and on boot, verifies that the known public key matches the private key embedded in security chip. Even if counterfeiters can buy the same kind of security chip, they'd have no private key to program there. And this means counterfeit devices would be detected on boot.
To prevent the software check from being disabled altogether, the vendor adds Secure Boot which is supposed to detect software tampering. But as this article shows, it can be bypassed as well.
No thanks. It's 2020, there's no need to make this only a PDF.