by Readers

Letters to the editor: Undercurrents of Cisco vulnerabilities

Opinion
Sep 5, 20059 mins

Also, the new security landscape, employer control of mobile devices,IT staff shortage

Undercurrents of Cisco vulnerabilities 

As a vendor of security products that protect critical IT infrastructure, ION would like to comment on the recent situation regarding the exposure of security flaws in Cisco IOS. Cisco has gone to great lengths to ensure that its systems cannot be easily compromised, and for that it deserves a ton of credit. However, as we have seen time and time again, no software platform has achieved 100% security. And given the rich history of platform security flaws discovered, it is highly unlikely that the 100% secure computer platform will ever exist.

There is, however, an undercurrent to Cisco’s vulnerabilities:  It is the administration of these critical infrastructure devices, including their procedures, processes and tools.  Highly skilled technicians today perform most device administration anonymously, with little or no accountability.  Even the best-designed equipment can become vulnerable by poor or malicious administration. It’s important that when assessing the risk of using a particular device, both the design and the administration of that device must be considered together. 

Fortunately, the IT community has long favored a layered approach to security. In this way, systems and procedures can complement one another while compensating for each other’s weaknesses. Indeed, the primary cause of security vulnerabilities is not the weaknesses of the platforms, but the weaknesses in the (often well-meaning) people and processes responsible for design and administration of those platforms.

ION sees two distinct issues facing IT today regarding administration of critical infrastructure-open review of platform design and accountability in device administration. Without independent review, is it prudent to rely on a single vendor, such as Cisco, to furnish the majority of security components in the network? Given the rise in the use of outsourcing, how do we provide the necessary level of accountability in device administration while realizing outsourcing’s benefits?

As an industry, IT must continue to embrace the independent review process. Organizations such as Infragard have been founded to harness the power of open information exchange and peer review in the interest of identifying infrastructure security issues. It is imperative that the independence of these organizations be maintained. ISS, generally viewed as an independent source of information, was caught on the wrong side of this IOS issue when it sided with Cisco against its own researcher. Increasingly divided by special interest groups, our society views cozying up to powerful benefactors for what it is, as a result ISS may have forever damaged its reputation for independence in the process.

To be sure, our statements here are self-serving, since ION’s systems provide control and audit for the people and processes responsible for maintaining and supporting critical infrastructure. But we feel that our message is supported by common-sense principles. Accountability is required at both design and administrative levels when dealing with critical infrastructure. Those creating the technology must be subject to independent review, and those operating and managing that infrastructure must be subject to audit and control.   Openness does not come easy to either equipment manufacturers or those responsible for managing and protecting our networks. However, the public’s need to protect critical infrastructure, and the potential for serious disruption caused by vulnerable or mismanaged devices, makes the implementation of checks and balances absolutely necessary.

Accountability is a lynchpin of any well-run operation. Anonymity only creates an environment where bad practices or malicious activities can flourish. Consequently, current practices regarding device administration need to be treated as seriously as platform vulnerabilities.

Bill Whitney

Chief Technology Officer

ION Networks

South Plainfield, N.J.

The new threat

I have been part of the security landscape for more then 40 years in some capacity and the current challenges that we all face within technology risk and security has taken on a new dynamic. My early training prepared me for acting on perceived risk by “observing the risk,” “reporting the risk” and finally “neutralizing the risk.”  

The current threats to the computing environment and telecommunications have kept growing over the years, but the new reality has a distinctly new characteristic. Where crime will always be a high on the list within the threats, the threat of terrorism within the threat landscape and the growing possibilities is a threat that affects each of us. For instance, with a greater move to outsource programming and other services such as tax preparation, project management, call center help for credit cards, to overseas staff (non-US citizens), will this increase the threat? Let’s take this a step further: Let us suppose that there may be people in some parts of the world that may want to steal your information and misuse that information. Let us suppose that they work in a call center somewhere in Asia. What would the impact be if someone were “farming” the data not for the purpose of theft but for the purpose of committing a terrorist act? Would that be possible in light of the current threat landscape we face?

I agree with many of my colleagues within the industry that feel it is not enough to identify a problem, but to assess the impact and attempt to arrive at a reasonable dynamic solution. The current threats to our financial underpinnings by the terrorists may not be currently an issue, if you take the approach there is not evidence to support this assertion, not that we are aware as yet. At what point should we as a nation act, before or after?

Let’s look at some simple but effective solutions:

1. Taking technology security seriously — by all U.S. corporations. That means that it is time for Congress to become an active participant in protecting data; something even stronger than Sarbanes-Oxley will be required to meet the growing lapses.

2. Not allowing the outsourcing of programming and other services such as tax preparation and project management to any overseas operations (even if they are owned by U.S. entities, but have foreign nationals working in the environment). 

3. It would be a real achievement to have a “safe computing” environment, but it is not possible because it is not the technology, it is the abuse by users that cause the problem(s). We need an aggressive education program that really educates people, lawmakers and government officials to the real threats we face.

There is no “magic bullet,” though the three simple items above could begin to allow us all to think of technology security as a 360-degree problem that in today’s environment requires us all to think about the risk, impact and solutions. I do know this much: Outsourcing of services such as tax preparation, project management and call center help for credit cards to overseas staff is a really bad idea that in this terror environment could destroy the financial underpinnings of our country.

George B. Tselentis

Tampa, Fla.

A matter of trust

Regarding your Face-off on whether firms should strictly control employee use of mobile devices: Frankly, I have little respect for American management these days. And, if the contestants on “The Apprentice” represent our best and brightest, it looks like it’s only going to get worse.

Lighten up, people. Trust your employees. There will be occasional time-wasters, but most workers want to do a good job and will use technology to be more productive. Sometimes they will “play” with the technology, but this will only sharpen their grasp of it. If you drive the technology underground, your employees will use it anyway and you will not be able to address the legitimate security concerns.

Jack Durish

Mission Viejo, Calif.

Cause and effect

Regarding “IT staff shortage looming”: In a time when my stepson, with no discernable skills or experience (he’s never held a job for more than three months), can walk into a sales management position for Sprint, I have trouble as a highly skilled IT engineer staying employed for the same salary. The real reasons for the “coming IT job crunch” are simple to understand: low pay and impossible HR requirements.

How low? Here in Seattle a typical systems administrator opening is for $45,000 with extensive experience. That’s not great in an area where a basic house costs over $250,000 — in the cheap areas.

As for requirements, I’ve seen SOX remediation advertisements asking for three to five years’ experience, in a field a year old! Or how about the Active Directory architect positions in 2002 that wanted five or more years deploying AD in a Fortune 500 environment?  The reality is IT professionals remain generalists while the job requirements are being written for specialties that are thin to nonexistent, and certainly not cost effective to obtain.

Randy Grein

Bellevue, Wash.

Selling rocket science

Regarding Mark Gibbs’ BackSpin column “Selling rocket science”: I awakened my 8-year-old daughter that July 26 morning and had her watch the NASA channel with me. I was telling her things that were happening in between the comments of the NASA channel speaker. She seemed quite impressed with the amount of speed the shuttle reached before leaving the atmosphere and wanted to know how fast that was in relation to Dad’s driving. She is already very interested in science and technology and I will do everything in my power to see she learns everything she wants to.

As an IT manager at a law office, I point out to potential clients the technology we use. Most of them walk the main floor and ask what the orange cabling is coming out of the walls and into the back of the computers.  This opens up a quick tour of our gigabit Ethernet network, which was converted from fiber OC-3 ATM network. Explaining why we need this high-speed network is the next step, showing them the images of all the documents we scan and the time- and money-saving techniques we use in recalling and searching these documents. Then we sign them up.

I think in small part (and maybe in a big way) the technology we use sells our legal services, just as a viewing of the shuttle launch encourages the dreams of a little girl.

Ken Henderson

Litigation IT manager

Law Offices of W.R. Ramsey

Valencia, Calif.