Advertisement
Promo

Security threats Toolkit

Security exploits: Who's to blame?

Joris Evers and Marguerite Reardon CNET News

Published: 06 Sep 2005 16:40 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

...that's the best approach. I do feel that it is happening less and that vendors are realizing that we don't want to work against them, but with them."

Cisco contends it doesn't have any beef with Lynn's discoveries, but instead the company is unhappy about the way he went about distributing the information to the public.

"This incident violated aspects of normal protocol for dealing with security flaws," said Bob Gleicoff, CTO for Cisco's Security Technology Group. "And we are real sticklers for protocol."

But it seems that there have been several instances where Cisco has had similar problems in its dealings with researchers.

Early in 2004, Paul Watson discovered a flaw in the TCP/IP protocol that could be exploited on a number of networking products, including Cisco's routers. Watson said he initially emailed two of Cisco's engineers, who responded promptly. They were helpful and even contributed some thoughts and ideas to his research, he said.

But once the issue was identified as a serious security risk by the legal team at Cisco, the tone of the communication changed, Watson said. Cisco still wanted information from Watson, but no longer responded to his queries. Watson provided Cisco with several possible methods to correct the problem.

Frustrated by the lack of communication with Cisco, Watson decided to present his research at the CanSecWest Security Conference in April 2004. In a scenario similar to that at Black Hat, Cisco and the US Department of Homeland Security asked the conference organiser to pull the talk. The request was denied.

The impending talk spurred the company into action. Fixes were released a few days before the conference. However, Cisco not only provided patches, it also patented a fix for the flaw. This raised fears that Cisco might charge for the fix, which also affected other vendors, although Cisco did not.

"I was shocked," Watson said in an e-mail. "It really broke my trust in them." Cisco, like other software makers, wants security researchers to report flaws privately and have time to patch before disclosure, but Cisco took advantage of this period to apply for a patent, he said.

Playing it smart
A similar situation played out about a year later. Cisco tried to patent a fix to a flaw in ICMP that was discovered by Fernando Gont. The researcher outsmarted Cisco by documenting his discovery and the fix, and also by sharing the information privately with the open source community and the Internet Engineering Task Force, a standards organization.

Mary Ann Davidson, chief security officer at Oracle, sees...

For more, click here...

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
272 out of 513 people found this useful


Company/Topic Alerts

Create a new alert from the list below:












Video icon

Video

Sentry Posts Blog

Official Organizations Losing Data

How does this article from earlier today make you feel? How many more government, health service, or military officials are going to lose pen drives, DVDs, USB hard disks and even entire... More

2 comments

Twitter hack was DNS redirect

Twitter has said an attack on Thursday which took the site offline for many users was the result of a DNS redirect. A group calling itself the Iranian Cyber Army redirected users... More

1 comment

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Win a BlackBerry with Vlingo voice recognition

Win a BlackBerry with Vlingo voice recognition

What is ZDNet UK's usual tagline?

Competition closes - 14 Jan 2010


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters