3 ms·
> The flaw can be exploited only by local attackers, and it also grants access to a low-privileged user account. In spite of this, Cisco has classified the issu
by bringtheaction 9y ago
> The flaw can be exploited only by local attackers, and it also grants access to a low-privileged user account. In spite of this, Cisco has classified the issue as "critical."
I find this reassuring. It is the opposite of downplaying security issues.
- Rotdhizon 9y agoCisco in the past few years has been good about handling security incidents, although it makes you wonder why they keep adding in hard coded password to their gear. Unless it's individual devs adding them in without documenting them or telling anyone else on the team about them.
- kossae 9y agoEven still.. something like that should not make it past review, unless that process is broken as well.
- ainiriand 9y agoI think they have some training in this particular matter now.
- collinf 9y agoI'm sure the executives take issues like this incredibly seriously. None of this stuff is insidious in nature, it's just what happens when people bypass processes. Engineer doesn't take the time for proper password management -> Password gets left in source -> Other engineer who does code review misses password -> this continues for several iterations -> product gets released. Unfortunately this definitely happens more often than you would want to think.
- paulie_a 9y ago> I'm sure the executives take issues like this incredibly seriously Considering Cisco's history of security issues they clearly don't take it seriously and it is unlikely that will change.
- Jach 9y agoCouldn't the same have been said about Microsoft say pre-Vista? Of course taking security seriously doesn't magically make you have competent staff and eliminate embarrassing vulns, Windows has still had its share post-Vista. A lot of "taking security seriously" can just turn into security theater cheerleading and focusing too much on certain processes (especially response over prevention[0]) without ever doing effective threat modeling. [0] You fixed a reported admin-attacking-admin XSS bug within the SLA, good job! You're also letting admins upload binary blobs you then parse, has anyone run a fuzzer on this to help uncover any potential code execution bugs? Does anyone even know what a fuzzer is? No? Carry on... Until something gets reported.
- user5994461 9y agoI don't think that's a fair comparison. The internet didn't exist when windows 2000 and XP were done.
- paulie_a 9y agoSarcasm, drunk or high?
- user5994461 9y agoNone of these. In the decade around the 2000's, we went from almost zero computer in the developed world, to virtually every household having one and they're all permanently connected through a high speed network. That's a new universe of unplanned threats and attack vectors. None of this was anticipated when operating systems were designed, a few years before release.
- mywacaday 9y agoI wonder given the prevalence of Cisco globally would it be worth a state getting an individual dev to insert the hard coded password or even an exploit broker given how much a zero day can sell for
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- Covzire 9y agoThe paranoid in me thinks that the low-privileged user account isn't as benign as some may think. If someone hard-coded a password on purpose they might have done so knowing of a vulnerability to escalate privileges. Then if it gets discovered, well, it was only a low-privilege account no big deal.
- criddell 9y agoI'll believe they are taking it seriously if they provide updates to customers without a current service contract. I genuinely hope they are.