nanog mailing list archives

Re: IOS Rookit: the sky isn't falling (yet)


From: Valdis.Kletnieks () vt edu
Date: Tue, 27 May 2008 13:54:19 -0400

On Tue, 27 May 2008 10:47:08 PDT, goemon () anime net said:

What you want is cisco hardware that verifies firmware signatures in 
hardware.

Yes, but that requires new hardware.  Understanding the security risk in
accepting an unsigned MD5 signature from the same place that you accepted the
file from is a wetware issue.

Granted, at many shops hardware upgrades are easier than wetware upgrades. ;)


Attachment: _bin
Description:


Current thread: