To Avoid NSA Interception, Cisco Will Ship To Decoy Addresses
An anonymous reader writes with this news snipped from The Register: Cisco will ship boxes to vacant addresses in a bid to foil the NSA, security chief John Stewart says. The dead drop shipments help to foil a Snowden-revealed operation whereby the NSA would intercept networking kit and install backdoors before boxen reached customers. The interception campaign was revealed last May. Speaking at a Cisco Live press panel in Melbourne today, Stewart says the Borg will ship to fake identities for its most sensitive customers, in the hope that the NSA's interceptions are targeted. 'We ship [boxes] to an address that has nothing to do with the customer, and then you have no idea who, ultimately, it is going to,' Stewart says.
"We ship [boxes] to an address that's has nothing to do with the customer,"
I know some other companies that seem to do this for about half my orders.
I would be happy to pay a little extra for this service for non-critical hardware. But if I were actually concerned the NSA would want to twist my knickers there's no way in hell I would: It's a huge red flag for them. Instead I would bribe someone at a different company to accept my shipment and forward it to me.
But let's be honest, if the NSA is interested enough in you to install extras on your hardware, they probably already know your favorite porn, your underwear size, and what you had for breakfast. I'm happy to see extra services appearing for privacy-loving individuals but I don't think this particular one will help.
If video games influenced behavior the Pac Man generation would be eating pills and running away from their problems.
box, pl. boxen
putting the 'B' in LGBTQ+
They will be cloudified using super secret double Rot13 encryption.
putting the 'B' in LGBTQ+
>> a bid to foil the NSA, security chief John Stewart says
Both John Stewarts are funny guys.
the actual plan is pretty secretive but crap like Smallco at Nowheresville is easy to catch. all the NSA has to do is take a spammers approach when sifting through UPS and FEDEX databases pertaining to Cisco. Using Sparse Orthogonal Bigrams or CRM114 with a combination of known customer addresses and contacts allows the NSA to quickly weed out any future attempt to subvert its practice.
what isnt more difficult to thwart is a conscious customer, and thats the NSA's real problem. A shipment from San Francisco to Dallas for example, that takes a detour to Boson, could be good reason for suspicion. anti-tamper systems like tip-n-tell, environmental dyes, tamper seals, or a combination of these sytems as well as the much maligned DRM signed firmware could make the NSA's efforts substantially more difficult. Finally, getting out of lock-in technology monocultures like dell-everything shops and cisco-anything shops is helpful. a moving target is, after all, harder to hit.
Good people go to bed earlier.
In what fucking language. Pretty sure boxes is the pl. of box. But you know with everyone out there making up new spellings left and right how am I supposed to keep up. (I mean really "rediculous"???? why that one pisses me off so much I'll never know)
Sorry, teleporters just kill you and then make a copy. A perfect, soul-less copy.
What?
You just lost you nerd cred, that's what. I sentence you to 5 hours of reading the jargon file.
SJW n. One who posts facts.
I still can't trust that mechanism. Cisco needs to offer tools to verify the devices are genuine.
Anytime the Cisco account manager stopped by or called.
What?
"Editors"
While admiring Cisco's efforts here, this seems hard. At least these criteria would need to be satisfied:
1) the order would have to come in over an actual secure channel and be handled on known-secure systems.
2) the payment could not be processed until the delivery was made. Once the payment is made, the delivery location is compromised for future orders.
3) the shipment would have to be to a location that does not appear on the MLS. The receiver would have to follow tracking and send a courier out to meet the delivery driver (a easy expense for the right customers).
Driving to a distributor for pickup also seems like a good idea, so long as #2 is adhered to, since it amplifies the required effort of an attack to intercept several palettes of gear.
What other attacks are there on such a secure-delivery system using a common carrier?
My God, it's Full of Source!
OUTSIDE_IP=$(dig +short my.ip @outsideip.net)
Geeklore, dude. If the plural of ox is oxen then the plural of box is boxen. Sheesh. Next you're going to tell me you don't know what borked is.
cat sig >
This strikes me as either silly (very James Bond), or an indication that Cisco doesn't even trust its own employees.
Otherwise, why wouldn't Cisco just hand deliver the items using its own employees.
Taking this cloak-and-dagger approach implies that if anyone at Cisco knows who's receiving the hardware, then it is at risk, meaning that Cisco is compromised and knows it.
Seriously, I would assume that NSA at least has a "mole" in the order processing/accounting/shipping dept. at Cisco. Unless Cisco pays a lot more than market to these rank-and-file employees or gives them benefits unheard of elsewhere, they aren't particularly hard to get to cooperate, I would guess.
by putting their stuff into the Cisco boxes in the factory. Wait, aren't they already doing that?
You see, the US Government is very keen about governing exports. They prohibit shipping many products into restricted countries and they actively police it in a serious manner. Anyone who's product gets found in a restricted country is in hot water. It doesn't matter if the product(s) was sold through an intermediary or 20 middle men, the manufacturer is 100% responsible for asserting, under penalty of law, that their products will not end up in a restricted country and that's that. The treasury department even publishes a monthly list of offenders they catch but I apologize as I cannot seem to find it on google.
To address this issue, many companies that have been caught are required by the US Treasury Dept to document every single end user of their product. Yes, every single unit that is sold must be documented as to where it's final resting place is. I doubt Cisco is under this kind of requirement (unless they've been caught in the past) but it seems this new policy is a huge risk for them in that area. If you were an Iranian supply store trying to procure Cisco equipment, this seems like a good way to do it without anyone knowing or being able to track it --- and that's a serious risk for Cisco.
The minute one of those units gets found in Iran (or any restricted country), all hell will break loose. Again, it doesn't really matter how it got there.....
Here is a good overview of the requirements and Here is a company that has a good policy summary that they live by. Smart on them.
Understand that this has nothing to do with NSA or espionage. This is just a basic requirement of doing business overseas and exporting products. Doesn't matter whether it's plastic dog poo, Intel CPU's, lab equipment, cranes, or other engineered equipment
So what is the pl. of "ox"? "Oxes"? I think not.
putting the 'B' in LGBTQ+
We had several Vaxen in our lab.
It's used to show who groks tek. Sales dept use "Vaxes". Users say Vaxen.
Now, get off my lawn. I just mowed it.
How can you call yourself a /. reader having not read The Jargon File?
Popisms.com - Connecting pop culture
Years ago, this was a common mistake by people trying to touch type to fast for their skill level that actually became sort of a fad when talking about computers. Your boxen or my boxen actually refered to our computer hardware. Its also the reason we have lulz insted of lols.its now considered plural for lol but it was really just people trying to keep up with chat in busy chat rooms- where the originsl shorthand started before texting.
Have you never read The Jargon File. It's required reading for any hacker.
Popisms.com - Connecting pop culture
Boxes is the plural of box only if you're talking about containers like cardboard or wooden boxes, etc.
If you're talking about computer gear that happens to come in a vaguely box-shaped chassis (like a computer or a network switch), the plural is boxen. See also "vaxen".
Keep up? The terminology is possibly older than you are.
Your use of "neckbeard" dates you, that was a hip term two years ago. I'm guessing you have a neckbeard fetish, there might be genre of porn just for you.
Mouse-> Mice
Louse -> Lice
House -> Hice
Platapouse -> Platapice
Faux -> Fauce
Fox -> Fice
Box -> Bice
Apparently it's foxen since anything that ends with "ox" it pluralized the same way
Does nothing if all hardware is compromised prior to shipping. Would they be allowed to tell you if it were? Would they even be aware if it was? Has the government ever looked at their code or received a report from them about potential security vulnerabilities as part of a disclosure required for a government contract or security certification? I'm guessing if they did, that report was sent directly to the NSA.
I'm trying to teach myself to set people on fire with my mind... Is it hot in here?
Just address the shipping label to "Iran Institute of Centrifugal Studies" C/O Mailboxes Etc.
If you trusted Cisco, you'd drive to a random store at a random time and buy a unit off the shelf.
However CISCO sell tech to the US government, and in turn are required to hand their code over to NSA we presume, and certainly have been deeply involved in NSA's cyber security stuff, so I think you have to consider their routers compromised.
http://www.nist.gov/itl/csd/nccoe-041513.cfm
"ROCKVILLE, Md. — In recognition of the critical need to protect private-sector intellectual property and other valuable business data from a growing number of cyber threats 11 major companies have formally established partnerships with the National Cybersecurity Center of Excellence (NCCoE). U.S. Senator Barbara Mikulski, U.S. Cyber Command Commander/National Security Agency (NSA) Director General KEITH B ALEXANDER, Maryland Governor Martin O’Malley, Montgomery County Chief Executive Isiah Leggett and Under Secretary of Commerce for Standards and Technology and NIST Director Patrick Gallagher joined the new partners for a signing ceremony today at the NCCOE’s facilities in Rockville, Md."
"At the ceremony, representatives from the new partner companies – CISCO SYSTEMS Inc., Hewlett-Packard, HyTrust Inc., Intel Corp., McAfee Inc., Microsoft Federal Civilian Services, RSA, Splunk Inc., Symantec Corp., Vanguard Integrity Professionals and Venafi Inc. – pledged to contribute hardware and software components and share best practices and personnel with the center."
I view it more as required reading for anyone who plans to spend time at MIT in the 1960s.
404 Not Found: No such file or resource as '.sig'
No, the plural of vixen is "threesome".
Good job NSA! Way to destroy not just any integrity we had left as a country, but also undermine trust in the products we sell as well.
Or just ship everything in boxes with tamper evident seals, then instruct the end user on inspection of said seals while informing them that anything with a broken seal will be replaced?
There was a 1950's-1960's british vacuum cleaner brand, named you know whawt, advertised with the tag line, "nothing sucks like a Vax".
If it's THAT sensitive, either have the customer pick it up from a Cisco-controlled location or have a Cisco employee hand-deliver it to the customer.
Use tamper-evident seals and use something like a "warrant canary"-like system so the delivery person can effectively tell the customer that to the best of his and Cisco's knowledge the shipment was not tampered with en route: The absence of a followup message from Cisco guaranteeing that the shipment and delivery were not intercepted would be treated as a message that it might have been intercepted.
Speaking of "canaries" I wouldn't be surprised to see specialty shipping companies or specialty-arms of big-name shipping companies use "canaries" to guarantee that their shipments were delivered to an authorized person and not tampered with en route.
Knowledge is how to play a game, intelligence is how to win, wisdom is knowing what game to play.
In what fucking language. Pretty sure boxes is the pl. of box. But you know with everyone out there making up new spellings left and right how am I supposed to keep up. (I mean really "rediculous"???? why that one pisses me off so much I'll never know)
Hand in your card and get the fuck out.
Yeah; methinks we're seeing the symptoms of a serious humo[u]r deficiency here. These things have a long history in the English-speaking world. Many of us are quite aware of the ridiculocities that can easily be found in the English language, and a lot of humo[u]rists have gotten audiences laughing by mocking some of the stupider things in our language. This especially applies to the irregular plurals, which of course are derived from plural forms that were once regular (and still are in German), but which became relics a millennium or so back when our ancestors settled on just the -[e]s as the plural marker, but stubbornly insisted on keeping a few hundred of the old plurals around to confuse children and foreigners.
Maybe we should collect a list of links to some of the humorous things that have been written on the topic, and refer people to the list when they post complaints like we've been seeing here. Anyone wanna take on the task?
Those who do study history are doomed to stand helplessly by while everyone else repeats it.
What?
"Editors"
While admiring Cisco's efforts here, this seems hard. At least these criteria would need to be satisfied:
1) the order would have to come in over an actual secure channel and be handled on known-secure systems.
2) the payment could not be processed until the delivery was made. Once the payment is made, the delivery location is compromised for future orders.
3) the shipment would have to be to a location that does not appear on the MLS. The receiver would have to follow tracking and send a courier out to meet the delivery driver (a easy expense for the right customers).
Driving to a distributor for pickup also seems like a good idea, so long as #2 is adhered to, since it amplifies the required effort of an attack to intercept several palettes of gear.
What other attacks are there on such a secure-delivery system using a common carrier?
The most obvious one: they will just intercept everything leaving Cisco and not heading to a reputable US company (scratch that, they probably target reputable us companies too). If they can intercept and MitM one box they can surely do it to a thousand. Why should they care if they don't even know where it's going, they can needlessly bug 1000 routers for every 1 that gets inside the right place and still have enough money in the budget to buy donuts on friday.
Where did you get criteria 2 and 3 from? It's pretty clear from the description that Cisco thinks the NSA will be thrown off the trail based on the premise that they are using a (From==Cisco && To==Iran) style filter to do these intercepts, and won't think to do ((From==Cisco && To==Pier 4, NYC) || (From==Pier 4, NYC && To==Iran)). The thinking is similar to bitcoin laundering services Underestimating the NSA in this regard is pretty sad, given that the leaks are only a fraction of their secretive doings.
Really... when was the last time any of us thought Cisco was the best choice for a project?
Actually it can be a great deal... I'm in the process of building up a campus network for a non-profit, that will eventually have some 25 switches (Core and access), and 3 or 4 routers. All of it Cisco. Why? Because Cisco's support policies are such that there is tons of perfectly serviceable EoL/EoS equipment available on the secondary market that suits our needs, and available for very little $$$.
...si hoc legere nimium eruditionis habes...
You give the TSA mouth breathers too much credit. This is a far more likely scenario:
TSA goon: Waht is this? It looks expensive. (puts device in their pocket)
or:
TSA goon: What is this? Whoops! (drops device on the floor on accident)
Time to offend someone
Then the answer is not to send the hardware to empty buildings, but to install a GPS tracking device in the shipping container, and see where it goes off-course. Bonus points if you can track it all the way to the NSA modification warehouse, but at least if you know where it got diverted, you can figure out *how* it gets diverted. I suspect the truck drivers are in on it, but without tracking data, that is just a theory.
We might as well start with Lewis Carrol
Or with this well-known one about the absurdities of English spelling:
A plan for the improvement of spelling in the English language
By Mark Twain
For example, in Year 1 that useless letter "c" would be dropped to be replased either by "k" or "s", and likewise "x" would no longer be part of the alphabet. The only kase in which "c" would be retained would be the "ch" formation, which will be dealt with later. Year 2 might reform "w" spelling, so that "which" and "one" would take the same konsonant, wile Year 3 might well abolish "y" replasing it with "i" and iear 4 might fiks the "g/j" anomali wonse and for all.
Generally, then, the improvement would kontinue iear bai iear with iear 5 doing awai with useless double konsonants, and iears 6-12 or so modifaiing vowlz and the rimeiniing voist and unvoist konsonants. Bai iear 15 or sou, it wud fainali bi posibl tu meik ius ov thi ridandant letez "c", "y" and "x"— bai now jast a memori in the maindz ov ould doderez —tu riplais "ch", "sh", and "th" rispektivili.
Fainali, xen, aafte sam 20 iers ov orxogrefkl riform, wi wud hev a lojikl, kohirnt speling in ius xrewawt xe Ingliy-spiking werld.
Those who do study history are doomed to stand helplessly by while everyone else repeats it.