Results 1 to 5 of 5

Thread: How should Cisco have dealt with their security flaw?

  1. #1
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Posts
    14,283
    Thanks
    293
    Thanked
    841 times in 476 posts

    How should Cisco have dealt with their security flaw?

    So what is the best way to deal with security issues? Being open with the problem will increase awareness and (hopefully) result in all customers updating and patching as necessary. For those bugs that nobody but the programmers know about, quietly rolling out a fix in the next update might be wise. So what if a security researcher wants to make a presentation about a security flaw in your routers that you'd rather he didn't make? What Lynn did may have been a little naughty, after all he did quit his job to enable him to make the presentation, but similarly the 'cover up' attempt has resulted in more hackers attempting to map out the exploit. The most dangerous problem here being that the people that know most about the exploit are good at hacking. One bad apple could cause a lot of trouble.
    http://www.hexus.net/content/news/ne...lld19JRD0xNDI5
    Last edited by Steve; 01-08-2005 at 11:58 AM.
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  2. #2
    Hexus.net Troll Dougal's Avatar
    Join Date
    Jun 2005
    Location
    In your eyeball.
    Posts
    2,750
    Thanks
    0
    Thanked
    0 times in 0 posts
    I'd have thought that Cisco would have made their people sign a non disclosure agreement. Waved that in his face first.

    Normal NDA give 12months after the person has left before they can do/say anything.

    Then got the guy to show them it, then fix the ruddy problem. If its such a big flaw and the net relies on the vulnerable routers then Ciscos reb would have gone higher (if poss) for fixing it!
    Quote Originally Posted by Errr...me
    I MSN offline people
    6014 3DMk 05

  3. #3
    HEXUS webmaster Steve's Avatar
    Join Date
    Nov 2003
    Posts
    14,283
    Thanks
    293
    Thanked
    841 times in 476 posts
    Indeed as far as I know the flaw remains exploitable only locally, but perhaps Cisco feared somebody would find a way of exploiting it remotely?
    PHP Code:
    $s = new signature();
    $s->sarcasm()->intellect()->font('Courier New')->display(); 

  4. #4
    Hexus.net Troll Dougal's Avatar
    Join Date
    Jun 2005
    Location
    In your eyeball.
    Posts
    2,750
    Thanks
    0
    Thanked
    0 times in 0 posts
    But they still have a major security hole to repair, they didn't do themselves any favours by doing all this stuff. They should have stopped it at the source of the problem.

    It may have taken a week or two to repair the exploit and another couple of weeks to deploy it.

    But how much warning did they get? We got a few days (IIRC).
    Quote Originally Posted by Errr...me
    I MSN offline people
    6014 3DMk 05

  5. #5
    Hexus.net Troll Dougal's Avatar
    Join Date
    Jun 2005
    Location
    In your eyeball.
    Posts
    2,750
    Thanks
    0
    Thanked
    0 times in 0 posts
    http://www.wired.com/news/privacy/0,...w=wn_tophead_1

    Just read this on Wired.

    Damn good and it looks like the reason it was publicised was because of ISS wanting to get back at Cisco.
    Quote Originally Posted by Errr...me
    I MSN offline people
    6014 3DMk 05

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Firefox suffers first 'extremely critical' security hole
    By XA04 in forum General Discussion
    Replies: 18
    Last Post: 12-05-2005, 12:13 PM
  2. Have you done all of your windows updates ?
    By Moby-Dick in forum General Discussion
    Replies: 33
    Last Post: 05-05-2004, 01:23 PM
  3. 'Critical' flaw found in Windows
    By Basher in forum General Discussion
    Replies: 8
    Last Post: 25-07-2003, 04:49 AM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •