jim_duffy
Managing Editor

Cisco: We embrace hackers

Analysis
Sep 11, 20072 mins

Cisco says it has “moved on” since the ugly spat with Michael Lynn, who at Black Hat 2005 revealed information related to hacking Cisco routers. 

In an article in Forbes.com, Mike Caudill, Cisco’s product security incident manager, is quoted as saying: “We’ve worked with independent researchers for years, and we welcome them contacting us,” he says.

But that isn’t how Lynn saw it. You’ll remember that after Lynn’s presentation, Cisco sent reps to literally cut all of Lynn’s pages out of the Black Hat proceedings and erase the session from the Black Hat CD. Then it slaps Lynn and conference organizer, Jeff Moss, with court orders and sends two FBI agents to collect the materials.

Lynn gave the presentation after he notified Cisco of the exploitable flaw in its routers but Cisco failed to inform its customers. Two years on, Cisco says it recognizes hackers have a role to play.

According to the Forbes article:

Cisco has a 24/7 hotline and a secure system that hackers can use to send encrypted messages to the company about sensitive vulnerabilities.

How useful are such alerts circulated by security experts prior to the official advisory from Cisco? Is Cisco better at responding to such security finds?

Go to Cisco Subnet for more Cisco news, blogs, discussion forums, security alerts, book giveaways, and more.

Recent Cisconet blog entries

Subscribe to Network World’s Cisco News Alert, which includes a weekly digest of all Cisco Subnet items