3 ms·
Cisco has gone through in depth code review for many of their products, as they are often the vendor of choice for security critical applications. Look at the d
by StudentStuff 8y ago
Cisco has gone through in depth code review for many of their products, as they are often the vendor of choice for security critical applications. Look at the desk phones in the upper echelons of the federal gov't and note how the "secure" systems are all Cisco with metal cages on the back to prevent signal leakage/sidechannel attacks.
That being said, Cisco is a bag of dicks when it comes to their support contracts, pricing, and any of their consumer rubbish.
Juniper and other 2nd tier hardware vendors are a bigger threat than Cisco IMO, their gear is much more common, and much more vulnerable (JunOS is a pile of security vulns). None of them take proper software development seriously, and the audits they've undergone are often just to rubber stamp their products.
Frankly, none of these companies should be rolling their own "firmware", as they've proven that they won't reliably update as upstream (usually OpenWRT or Debian) push out security critical updates. Downgrading them to a role whereby their secret sauce is just an extra APT repo/extra metapackage from opkg is more than sufficient for what these companies need, while preventing them from accidentally or purposefully blocking updates.
- pleasecalllater 8y agoYea, an in depth code review. Like the last Cisco router bug fixed by banning access if user-agent contains 'curl'?
- raxxorrax 8y agoWow, that is an amazing idea. That could keep out all those filthy hackers!
- StudentStuff 8y agoI referenced this in my prior comment, calling out their consumer rubbish which they don't bother to maintain.