Guide to the TechWeb Network


The InformationWeek -- Blogs
InformationWeek's Analytics Weblog

Topics:   Analytics

  • Email this page E-mail this page
  • |  Print this page Print this page
  • |   Bookmark and Share

Buying Cisco? Beware Of Counterfeit Gear


Posted by Randy George, Jul 8, 2008 12:46 PM

Call me a little slow on the uptake, but I had no idea about how bad the counterfeit network hardware issue was until I became a victim myself. According to KPMG, almost 10% of gear out there is suspected to be counterfeit. That amounts to billions of dollars per year in bogus equipment floating around out there. Fake gear could be running in your data center now -- it was in mine.

Until recently, I would have had no problem buying Cisco gear from any source for deployment in my network. I mean, its Cisco, right? (Insert Jeopardy buzzer sound here). Boy, was I wrong, and I should have known better. If the price is too good to be true, then it probably is. I first became aware of the counterfeit gear issue after personally buying a bogus T1 WIC for a Cisco 2600 series router. After getting undressed by a Cisco partner for buying a bad WIC on eBay, I started to read up on the bogus gear issue. That's when I came across a news release by the Department of Justice and Homeland Security earlier this year regarding a bust of fake networking gear amounting to a street value of $76 million dollars.

Unfortunately for all of us, the problem isn't confined to eBay. Even Cisco authorized resellers are victims of sourcing stock through illegitimate channels. And the impact on our production networks is much more far reaching than having a serial interface buckle intermittently. And what of the security threat associated with fake Cisco gear? How difficult would it be to burn malware into the ROM of a fake router? I'm not an embedded hardware engineer, but in my opinion, if you're good enough to make a router or switch that looks and works like the real deal, then you're good enough to develop a back door into that equipment.

Thankfully, Cisco is all over this issue like a mosquito on an open wound. UsedCisco.com, a large, preowned equipment sales outfit not affiliated with Cisco, released a set of guidelines for minimizing your risk when buying used. At the top of the list of things to be wary of is sourcing parts from Chinese suppliers. According to Cisco, the bulk of fake gear is coming out of China, so you need to vet these suppliers carefully by looking at feedback and references where they exist. Simultaneously, check with Cisco and have them run your serial numbers against their private database. You also should be wary of the ridiculously low pricing on gear compared with market value. Lastly, get a warranty on used gear from your supplier. That shifts the risk away from you and back to the supplier.

Have you discovered that you've purchased fake gear? Reply to my blog and share your story with our readers. Let us know what led you to realize that you had bought a bogus piece of hardware.

« Microsoft Gets Off The Pot (Finally!) | Main | Hacking The Hypervisor »



Tomorrow's CIO: Do you have what it takes?
Find out at the 2008 InformationWeek 500 Conference
Sept. 14-16, St. Regis Resort, Monarch Beach, Calif.


Sign up now for the weekly InformationWeek Blog Newsletter.


This is a public forum. United Business Media and its affiliates are not responsible for and do not control what is posted herein. United Business Media makes no warranties or guarantees concerning any advice dispensed by its staff members or readers.

Community standards in this comment area do not permit hate language, excessive profanity, or other patently offensive language. Please be aware that all information posted to this comment area becomes the property of United Business Media LLC and may be edited and republished in print or electronic format as outlined in United Business Media's Terms of Service.

Important Note: This comment area is NOT intended for commercial messages or solicitations of business.






  1. Windows Vista: The OS About Nothing
  2. You Thought Vista Was Bad?
  3. Google Chrome: Browser Or Cloud Operating System?
  4. Apple Nixes 'Pull My Finger' App, Even Though It's A Gas
  5. Sarah Palin's Babygate And The Future Of Journalism


  1. Radical Desktops Deliver Power To The People. But What About IT?
  2. Need Disaster Recovery On The Cheap? Think Virtualization
  3. No Virtualizing Without A License
  4. Smart Stuff: The State Of Business Intelligence 2008
  5. Down To Business: Are Technology Leaders Focusing Too Much On The Small Stuff?
  6. Rolling Review Wrap-Up: Vendors' RFP Responses Make The Case For Switching

 
 

  Ars Technica
Boing Boing
Channel 9 Forums
CRN Blogs
Dr.Dobb's Portal: Blogs
Engadget
Gizmodo
GrokLaw
  Lifehacker
Schneier on Security
Slashdot
TechCrunch
Techdirt
Techmeme
Valleywag

  FEBRUARY 2008
JANUARY 2008
DECEMBER 2007
NOVEMBER 2007
OCTOBER 2007
SEPTEMBER 2007
AUGUST 2007
JULY 2007
  JUNE 2007
MAY 2007
APRIL 2007
MARCH 2007
FEBRUARY 2007
JANUARY 2007
DECEMBER 2006
NOVEMBER 2006