Cisco Reviews Code After Juniper Breach; More Scrutiny Expected

Advertisement
By Reuters | Updated: 22 December 2015 11:32 IST
Networking equipment maker Cisco Systems Inc said on Monday it has launched a product review to look for tampering after rival Juniper Networks Inc's disclosure it found code in firewall software that made in vulnerable to cyber attacks.

Juniper warned customers on Thursday that it had uncovered "unauthorised code" in its firewall software, saying it could be exploited to allow an attacker to unscramble encrypted communications that travel through the security devices.

That prompted the code review by Cisco. Security experts said they expect other technology companies to conduct similar investigations after last week's unprecedented news from Juniper.

It was the first time a major technology firm discovered the addition of an unauthorised 'back door," or code that could be exploited to facilitate cyber attacks, according to security experts.

Advertisement

"I can't imagine there is a major vendor that isn't doing a major code audit now," said HD Moore, chief research officer with Rapid7 Inc .

Advertisement

Technology companies regularly audit their code for bugs, including "back doors" that attackers could leverage to launch cyber attacks on customer networks.

But Moore said that such reviews focus on "back doors" that are unintentionally created, not ones inserted without the manufacturer's knowledge.

Advertisement

"The challenge is that nobody has been looking for this in the past," said Moore, an expert in software vulnerabilities. "If you know you are looking for a malicious backdoor, you have a much better chance of finding something."

Cryptologist Bruce Schneier said that technology companies should have long been looking for unauthorised code, but that many ignored the problem since the reviews boost expenses.

Advertisement

"The fundamental problem is that the market doesn't reward the things we want like secure code. Nobody wants to pay for it," he said.

Cisco said on its blog that the testing will include code reviews by engineers with deep networking and cryptography experience as well as penetration testing, a process where technicians attempt to attack products to find bugs the way malicious hackers might seek to exploit them.

Meanwhile, the US Department of Homeland Security said it was investigating how the Juniper "back door" might impact government networks.

"As we routinely do when such vulnerabilities are brought to light, we are assessing the potential impact, if any, on federal networks, and will take any appropriate mitigation measures in close coordination with interagency partners," said agency spokesman S.Y. Lee.

© Thomson Reuters 2015

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: Cisco, Internet, Juniper
Advertisement

Related Stories

Popular Mobile Brands
  1. Amazon Great Indian Festival Sale: Deals on Smartphones, Laptops Teased
  2. Redmi 15 5G, Note 14 Pro Prices Dropped During Diwali With Xiaomi Sale
  3. Realme 15T With 50-Megapixel Selfie Camera Debuts in India: See Price
  4. Samsung Galaxy S25 FE Accessories Leaked Ahead of September 4 Launch
  5. Apple Rolls Out iOS 26 Beta 9 for iPhone Ahead of iPhone 17 Launch
  6. OpenAI Shares Plans to Better Protect Teenagers, Distressed Users
  7. From iPhone 17 to New Apple Watch Models: What to Expect from Apple Event
  8. Realme Watch 5 Design, Key Features Leaked Ahead of Debut
  1. Samsung Galaxy S25 FE Accessories Leaked Ahead of Galaxy Unpacked Launch Event on September 4
  2. Apple Rolls Out iOS 26 Beta 9 Update for iPhone With Bug Fixes Ahead of iPhone 17 Launch
  3. BCCI Says Crypto, Real Money Gaming Platforms Can’t Bid for Team India’s Title Sponsorship
  4. Scientists Discover Hidden Mantle Layer Beneath the Himalayas Challenging Century-Old Theory
  5. Astronomers Propose Rectangular Telescope to Hunt Earth-Like Planets
  6. Microsoft Testing Native Clipboard Sync Feature to Share Text Between Windows PCs, Android Devices
  7. Su From So OTT Release: When and Where to Watch This Kannada-Language Horror-Comedy Online
  8. Sennheiser Momentum 4 Wireless 80th Anniversary Edition Launched in India With Up to 60 Hour Battery Life
  9. Call of Duty Film Adaption Said to Be a 'Priority' at Paramount, Negotiations on to Acquire Rights
  10. Cannibal Solar Storm May Trigger Auroras as Powerful Geomagnetic Storm to Hit Earth Soon
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.