The InformationWeek -- Blogs
Welcome Guest. | Log In| Register | Membership Benefits

InformationWeek's Analytics Weblog

Topics:   Analytics

  • Email this page E-mail this page
  • Print this page Print this page
  • Bookmark and Share
  • icon

Buying Cisco? Beware Of Counterfeit Gear


Posted by Randy George, Jul 8, 2008 12:46 PM

Call me a little slow on the uptake, but I had no idea about how bad the counterfeit network hardware issue was until I became a victim myself. According to KPMG, almost 10% of gear out there is suspected to be counterfeit. That amounts to billions of dollars per year in bogus equipment floating around out there. Fake gear could be running in your data center now -- it was in mine.


Until recently, I would have had no problem buying Cisco gear from any source for deployment in my network. I mean, its Cisco, right? (Insert Jeopardy buzzer sound here). Boy, was I wrong, and I should have known better. If the price is too good to be true, then it probably is. I first became aware of the counterfeit gear issue after personally buying a bogus T1 WIC for a Cisco 2600 series router. After getting undressed by a Cisco partner for buying a bad WIC on eBay, I started to read up on the bogus gear issue. That's when I came across a news release by the Department of Justice and Homeland Security earlier this year regarding a bust of fake networking gear amounting to a street value of $76 million dollars.

Unfortunately for all of us, the problem isn't confined to eBay. Even Cisco authorized resellers are victims of sourcing stock through illegitimate channels. And the impact on our production networks is much more far reaching than having a serial interface buckle intermittently. And what of the security threat associated with fake Cisco gear? How difficult would it be to burn malware into the ROM of a fake router? I'm not an embedded hardware engineer, but in my opinion, if you're good enough to make a router or switch that looks and works like the real deal, then you're good enough to develop a back door into that equipment.

Thankfully, Cisco is all over this issue like a mosquito on an open wound. UsedCisco.com, a large, preowned equipment sales outfit not affiliated with Cisco, released a set of guidelines for minimizing your risk when buying used. At the top of the list of things to be wary of is sourcing parts from Chinese suppliers. According to Cisco, the bulk of fake gear is coming out of China, so you need to vet these suppliers carefully by looking at feedback and references where they exist. Simultaneously, check with Cisco and have them run your serial numbers against their private database. You also should be wary of the ridiculously low pricing on gear compared with market value. Lastly, get a warranty on used gear from your supplier. That shifts the risk away from you and back to the supplier.

Have you discovered that you've purchased fake gear? Reply to my blog and share your story with our readers. Let us know what led you to realize that you had bought a bogus piece of hardware.

« Microsoft Gets Off The Pot (Finally!) | Main | Hacking The Hypervisor »



Sign Up Now
For InformationWeek News Alerts




This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.




 
 

  1. Massive Parallelism Has a Name ... Extreme Scale Computing
  2. Intel Turbo Boost Technology Monitor: A Windows Gadget to Understand Dynamic Frequencies
  3. Two-Stage Input Parallel Pipeline: Part 2


Join The InformationWeek Group On LinkedIn


  1. Latest Windows Mobile 7 Rumors
  2. Android 2.1 With Multitouch Headed To Motorola Droid
  3. Google's Universal Translator
  4. Rating The Mobile Superbowl Ads


  1. Microsoft Fixes 26 Vulnerabilities In Windows, Office
  2. Intel Ships Itanium Server Processor
  3. Commerce Department Proposes One-Stop Climate Service
  4. Microsoft Denies Windows 7 Battery Bug
  5. Google Buzz Challenges Facebook, Twitter
  6. Android, iPhone Gain In Smartphone Market

 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  DECEMBER 2008
NOVEMBER 2008
OCTOBER 2008
SEPTEMBER 2008
AUGUST 2008
JULY 2008
JUNE 2008
MAY 2008
  APRIL 2008
MARCH 2008
FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007