The InformationWeek -- Blogs
Microsoft

Topics:   Microsoft

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Cisco: Dare To Be Stupid


Posted by admin, Aug 1, 2005 02:37 PM

First things first: There is now a legal defense fund accepting contributions on behalf of ex-ISS researcher Mike Lynn, who now faces a possible FBI criminal investigation. You can PayPal donations to abaddon@IO.com. EFF will get any leftover funds.


If you're just tuning in to this freak show here's a quick summary:

The annual Black Hat computer-security conference has become a forum for experts to disclose vulnerabilities in tech products, often rankling the products' makers. But few companies go to the lengths that Cisco Systems Inc. did this week to suppress information about a flaw in its software that directs Internet traffic.

Cisco threatened legal action to stop the conference's organizers from allowing a 24-year-old researcher for a rival tech firm to discuss how he says hackers could seize control of Cisco's Internet routers, which dominate the market. Cisco also instructed workers to tear 20 pages outlining the presentation from the conference program and ordered 2,000 CDs containing the presentation destroyed.

Over the past four days, Cisco's management turned a molehill into Mount Everest, and they're still shoveling furiously. I admit I'm a fan of hyperbole, but stupidity on this scale defies exaggeration.

Lynne's presentation was an unlikely candidate for a Wall Street Journal feature until Cisco squeezed its "deal" out of the invertebrates who pass for executives at Internet Security Systems. Then, with each subsequent move -- harassing and threatening both Lynn and the Black Hat organizers; alleging that Lynn broke the law by following wiely accepted responsible disclosure procedures; and finally, slapping restraining orders on him and on several sites mirroring his presentation materials -- Cisco turned up the media spotlight again and again, systematically achieving the exact opposite of what it wanted.

You'd expect this kind of behavior from a record-industry executive, bless its shriveled little heart. You're getting it, unfortunately, from the executives at a company whose hardware touches most of the planet's Internet traffic.

Cisco's management may or may not care about the PR fallout -- that will pass in time, anyway. They certainly care, however, that hundreds of sites are mirroring Lynn's presentation by now, including many in jurisdictions where a U.S. court order is gonna leave 'em laughing until they wet their pants.

Or if a Web mirror is just too twentieth-century for you, there's always BitTorrent or anonymity-shielding equivalents such as I2P and TOR: all open-source, and all decentralized, headless, and utterly impossible to cleanse by court order.

Incidentally, Lynn settled Cisco's lawsuit against him late last week by agreeing not to comment any further and to return any related information to ISS. That was good news: Lynn followed his conscience well past the point where his own sense of self-preservation should have stopped him, and of course he's now unemployed (one of his slides during the Black Hat talk was apparently a copy of his resume)

Lynn accomplished his goal: Cisco won't have the luxury of sweeping a major security problem under the rug or playing it off as old news. The material in Lynn's presentation and his comments before settling with Cisco are enough to ensure that the company works with customers to patch the vulnerabilities and that its customers have the information they need to keep Cisco honest.

As for those vicious attack chickens at ISS, the future is likely to be short and ugly:

"A few years ago it was rumored that ISS would hold back on certain things because (they're in the business of) providing solutions," [Ali-Reza] Anghaie, [a senior security engineer with an aerospace firm, who was in the audience,] said. "But now you've got full public confirmation that they'll submit to the will of a Cisco or Microsoft, and that's not fair to their customers.... If they're willing to back down and leave an employee ... out to hang, well what are they going to do for customers?"

At this point, it's safe to say that ISS and its remaining customers, if there are any, deserve one another.

Finally: Will Cisco manage to change the subject before its customers think too long and hard about the implications of Lynn's research? I doubt it, although the payback is likely to be a far more drawn-out affair than Lynn's weekend trip to hell. Litigation is never a good thing, but in this case, a shareholder lawsuit might work wonders on the quality of Cisco's decision-making processes.

« Successful Outsourcing Is 80% Prep Work | Main | Are We Being Served? »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Sequential Programming: Like Eating Peas with a Straw.
  2. Biomolecular device using self-assembled DNA nanostructures?
  3. Coreinfo v2.0: A Simple Utility to Understand the Manycore Complexity in Windows


Join The InformationWeek Group On LinkedIn


                           


  1. More Reasons Why Linux Misses The Desktop
  2. Too Much Netbook For Too Litl?
  3. Motorola Explains Why Droid Doesn't Have Multi-Touch
  4. Sprint And T-Mobile Headed The Wrong Direction


  1. Hadoop Crunches Web-Sized Data
  2. Microsoft Acquires SourceGear's Teamprise Unit
  3. Gartner Downgrades SaaS Forecast
  4. Google To Acquire AdMob
  5. RIM Boosts BlackBerry Developer Tools
  6. Microsoft: Windows 7 Malware Threat 'Sensationalized'

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007