
Security researcher Richard Forno has posted slides detailing the Cisco router vulnerability that were to be presented in the ISS talk last week at the Black Hat show in Vegas. Looong story short, Cisco and ISS canceled the talk at the last minute, ISS researcher Michael Lynn gave it anyway, Lynn got fired by ISS, Cisco and ISS sued Lynn and Black Hat, all parties settled and agreed never to speak of it again. (Ed. – Even that long-story-short was long.)
Notice Forno was nowhere in that equation, so he posted the slides, but Cisco’s now-very-busy legal eagles threatened to drop a lawsuit on his head if he didn’t take them down, which he did.
But Forno got away with a few good last words: “Had the two companies involved … said nothing about this briefing, it’s quite likely that few if any people or news outlets would’ve given it more than a passing thought. But as a result of their heavy-handed tactics this week, both Cisco and ISS have ended up publicizing a serious vulnerability quite significantly and thusly re-ignited the discussion over how the Internet security community handles vulnerability disclosure and product updates.”
More info here.




