Showing posts with label cisco. Show all posts
Showing posts with label cisco. Show all posts

Sunday, December 29, 2013

NSA reportedly planted spyware on electronics equipment - Dell, Samsung & More

Based on internal NSA documents, Der Spiegel reveals that the spy agency planted backdoors to access computers, hard drives, routers, and other devices from companies such as Cisco, Dell, Western Digital, Seagate, Maxtor and Samsung.

CNET - A new report from Der Spiegel, based on internal National Security Agency documents, reveals more details about how the spy agency gains access to computers and other electronic devices to plant backdoors and other spyware.
The Office of Tailored Access Operations, or TAO, is described as a "squad of digital plumbers" that deals with hard targets -- systems that are not easy to infiltrate. TAO has reportedly been responsible for accessing the protected networks of heads of state worldwide, works with the CIA and FBI to undertake "sensitive missions," and has penetrated the security of undersea fiber-optic cables. TAO also intercepts deliveries of electronic equipment to plant spyware to gain remote access to the systems once they are delivered and installed.
According to the report, the NSA has planted backdoors to access computers, hard drives, routers, and other devices from companies such as Cisco, Dell, Western Digital, Seagate, Maxtor, Samsung, and Huawei. The report describes a 50-page product catalog of tools and techniques that an NSA division called ANT, which stands for Advanced or Access Network Technology, uses to gain access to devices.
This follows a report that the security firm RSA intentionally allowed the NSA to create a backdoor into its encryption tokens.   Read More

Tuesday, August 23, 2011

Cisco and Abuses of Human Rights in China: Part 1

This is the first in a two-part series explaining the background around the EFF call to action over Cisco assisting the Chinese government in abusing human rights. This article outlines the background of the issue and the first of our two demands to Cisco: intervening on behalf of dissident writer Du Daobin. Our next post will outline specifically how Cisco and other similar networking companies can pledge to uphold human rights.

If you have not done so, we urge you to sign our petition to Cisco. And if you’ve already signed, please continue to spread the word.

Understanding Du v. Cisco

What responsibility do corporations have to consider human rights when making business deals? Are companies that build and market equipment for the purpose of surveilling and censoring pro-democracy activists in authoritarian regimes culpable when those activists are imprisoned or tortured? Do companies bear a special responsibility if they customize products to improve the efficacy of tracking dissidents and choking free speech? What if the companies train government agents in using the technology to ferret out activists?

Two cases — one in the United States District Court of Maryland and another in the Northern District of California — are attempting to create legal precedent around these issues of corporate social responsibility. In Du v. Cisco, three named plaintiffs – Chinese citizens Du Daobin, Zhou Yuanzhi, and Liu Xianbin – are joining 10 unnamed "John Doe" plaintiffs in suing the American company Cisco Systems for their role in assisting the Chinese Communist Party (CCP) in violating human rights. The complaint against Cisco alleges that the plaintiffs in the case:
Have been and are being subjected to grave violations of some of the most universally recognized standards of international law, including prohibitions against torture, cruel, inhuman or other degrading treatment or punishment, arbitrary arrest and prolonged detention, and forced labor, for exercising their rights of freedom of speech, association, and assembly, at the hands of the Defendants through Chinese officials.
The complaint makes several accusations against Cisco Systems, including:
  • That Cisco Systems "aggressively sought contracts to provide substantial assistance in helping the Chinese government implement the Golden Shield Project"
  • That Cisco knew its services and products would be used by Chinese law enforcement, prisons, forced labor camps and also to police Internet usage
  • That Cisco employees themselves customized or trained others to customize the equipment they sold to China to meet the unique goals of the Golden Shield Project, including targeting disfavored groups in China
  • That Cisco knew the Golden Shield Project would be used to commit human rights violations
To understand these issues, one must first understand China’s Golden Shield Project, often referred to in the West as the Great Firewall of China. According to the complaint as well as published articles on the topic,1 the system employs a series of techniques to monitor and track the Internet usage of people in China and prevent them from accessing a wide swath of online content. The surveillance aspects are extensive; the government is often able to not only track what sites an individual visits, but may also be pinpointing who that individual is, what messages that person posts, and even the content of her communications.       More

Friday, August 5, 2011

Web malware more than doubled in the second quarter

The rate of unique web malware more than doubled in the second quarter, from 105,536 unique encounters of web malware in March 2011 to 287,298 unique encounters in June 2011, according to Cisco’s latest quarterly threat report.

 

Infosecurity.Com - The average web malware encounter rate in the second quarter was 335 encounters per enterprise per month, with the highest peaks in March (455) and April (453), according to Cisco's second-quarter threat report.

From an encounter-per-seat perspective, companies with 5001 to 10,000 employees and companies with more than 25,000 employees experienced significantly higher malware encounters compared to other size segments.

Despite the increase in web malware encounters, the number of unique malware hosts and unique IP addresses remained relatively consistent between March 2011 and June 2011, the report noted.

Brute-force SQL login attempts increased significantly during the second quarter, coinciding with increased reports of SQL injection attacks and other brute force intrusions – resulting in an increase in data breaches throughout the period.      More