Advertisement
Promo

Security threats Toolkit

Juniper defends hiring Cisco flaw researcher

Colin Barker ZDNet.co.uk

Published: 09 Nov 2005 16:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Juniper said on Wednesday it is standing by its decision to employ a security consultant who revealed "great holes" in the security of Cisco routers.

A spokeswoman for Juniper confirmed on Wednesday that it had hired Michael Lynn as a full-time employee but released no further details other than to state it was not the policy of the company to comment on the circumstances of an individual employee.

Juniper did comment on the subject of whether someone who had blown the whistle on Cisco's alleged cover-up of a security problem was a suitable employee for a network security.

"Juniper takes its responsibilities as a member of the global IT community very seriously," the spokeswoman said in a statement, "and as a company always operates within a very strict code of ethics. We are confident that all our employees will do the same."

Lynn was a security analyst with ISS until he resigned suddenly in July to give a security briefing at a Black Hat conference in Las Vegas, where he disclosed the existence of a flaw within Cisco's Infrastructure Operating System.

It was reported at the time that Lynn had outlined a method of attacking Cisco's Internetwork Operating System (IOS) to gain control over Cisco routers, which make up much of the infrastructure of the Internet. A widespread attack could badly impair the Internet's functioning, according to experts attending Black Hat.

When Lynn went public about the flaw, Cisco and ISS both sued him, although the parties have now settled.

Lynn told Wired  that he had gone public because "the worst thing is to keep this stuff secret".

The tale took another twist last week when Cisco finally released details, and patched, a second flaw identified by Lynn.

The scope of the second flaw explains why Cisco went through great lengths to keep it under wraps, said Johannes Ullrich, chief research officer at the SANS Institute Internet Storm Center, last week

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
59 out of 118 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

McKinnon lawyers seek judicial review

Lawyers seeking a judicial review for Nasa hacker Gary McKinnon lodged fresh evidence of his psychiatric state at the High Court on Thursday. Karen Todner, McKinnon's solicitor,... More

1 comment

Beware of keeping your head in the clo...

Information security professionals can look forward to a deepening appreciation for their skills as security continues to be recognised as an essential element for doing business in... More

1 comment

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters