nanog mailing list archives
Re: Cisco cover up
From: James Baldwin <jbaldwin () antinode net>
Date: Wed, 27 Jul 2005 16:56:01 -0400
On Jul 27, 2005, at 4:48 PM, J. Oquendo wrote:
On Wed, 27 Jul 2005, Dan Hollis wrote:This is looking like a complete PR disaster for cisco. They would have been better off allowing the talk to take place, and actually fixing the holes rather than wasting money on a small army of razorblade- equippedcensors.Complete PR disaster? Maybe they're still working on the fix and didn't want those on the blackhat scene to have a glimpse of how they intended onfixing things. I wonder if this has exploit_foo_bar has anything to dowith their code being stolen earlier this year was it, or late last year.Maybe for the geeks in you, it may be a PR disaster, but I doubt their stock price will come down much. Oddly I wonder if those in gov arewatching closely to those who are running around shorting Cisco stock. Orshould that be: "sh0rt1ng c1sc0 st0ck!@$"
Cisco had initially approved this talk. My understanding is that this has been fixed and no current IOS images were vulnerable to the techniques he was describing. ISS, Lynn, and Cisco had been working together for months on this issue before the talk.
This had _nothing_ to do with the source code that was stolen. I have dealt with Lynn professionally on many occasions and he has shown himself to have more than a fair share of integrity. It is uncalled for to take to disparate events and place them together in a way which smudges the name of a respected researcher.
Current thread:
- Cisco cover up J. Oquendo (Jul 27)
- Re: Cisco cover up James Baldwin (Jul 27)
- Re: Cisco cover up Stephen J. Wilcox (Jul 28)
- Re: Cisco cover up Randy Bush (Jul 28)
- Re: Cisco cover up Stephen J. Wilcox (Jul 28)
- Re: Cisco cover up Mark Owen (Jul 28)
- Re: Cisco cover up Mikael Abrahamsson (Jul 28)
- Re: Cisco cover up james edwards (Jul 28)
- RE: Cisco cover up Robert Crowe (Jul 28)
- RE: Cisco cover up James Edwards (Jul 28)
- Re: Cisco cover up Mikael Abrahamsson (Jul 28)
- Re: Cisco cover up Stephen Sprunk (Jul 28)
- Re: Cisco cover up James Baldwin (Jul 27)
- Re: Cisco cover up Chris Adams (Jul 28)
- <Possible follow-ups>
- RE: Cisco cover up Olsen, Jason (Jul 27)