Skip to content

Comment on Cisco Systems pulled out of Russia: destroyed $23.42M worth of equipment

Comments

Why not ship them or sell them over seas instead of destroying them ?

Because you're not getting that hardware out of Russia through normal channels.

In the best of times, in the best of places, you'd be able to do that. Decommission the hardware in use, pack it all up, ship it wherever.

It is not the best of times in Russia and it was never the best of places.

In the best of times while operating in an adversarial market (to put it diplomatically), you have to know you're doing this well in advance and slowly phase out the equipment. Some of it is likely physically installed in the locations. And you have to do this while essentially receiving no new equipment. Which you could do by just faking shipments and manifests. But you're effectively smuggling at this point.

Now, with everything going on. You have to worry about Russia just sort of claiming your hardware/business/people and daring you to come get it. You get your people out and torch everything you can on your way out.

That assumes that Russian officials would let the items leave.

Bingo! AFAIK Russia has banned the sale or expatriation of western assets out of Russia.

They probably had special NSA implants inside of them and didn't want it getting out. [1]

[1] https://arstechnica.com/tech-policy/2014/05/photos-of-an-nsa...

It'd be really impressive if the NSA could intercept shipment a router manufactured in Russia or China, and then re-insert the shipment into the supply chain. Now I know why Cisco gear always takes forever to ship.

Tons of networking components contain microprocessors, microcontrollers and programmable logic with excess capacity for their role and could hide implants in software, firmware or even bitstreams without changing a single part of the hardware e.g. leaking encryption keys as jitter observable to a passive attacker, just waiting for backdoor command to e.g. drop or massively delay 90% of all traffic or even fry the hardware by overvolting or intentionally violating bus arbitration rules having multiple push-pull drivers active at the same time on a bus. You're only limited by the available time, physical access, hardware and the creativity of your paranoia. Should such implants exist it could be installed in a few minutes either through the whatever update process is supposed to patch the involved components or through, exposed test pads or even clipping suitable packages on the boards e.g. a serial flash chip. It's a scary paranoid idea.

There is no need to add imaginary Chinese spy chips to Supermicro mainboards the common AST2x000 BMC chips are already ideal spy chips by design and given the observed quality of the firmware e.g. there used to be an undocumented command available via the SSH management shell to drop into a root shell on the BMC and you could just download the plaintext password file required to log in via HTTP. While disclosing the password file via SSH is bad you can't even blame Supermicro for storing the plaintext passwords in the first place since IPMI BMCs have to store the plaintext passwords because they're required for the terrible challenge-response handshake mandated in the protocol which doesn't allow storing only a precomputed salted hash over the password. How many companies dispose of old servers without wiping the BMC passwords? How many of them reuse a single password over large parts of the server fleet? Some days I find it hard to attribute this to incompetence instead of malice. Now where have I left my tinfoil hat? sigh

manufactured in Russia or China
Servers, routers get “beacons” implanted at secret locations by NSA’s TAO team. (subtitle from the article in GP; emphasis mine)

Didn't make sense at first but now it does. Yeah, that would be impressive.

A few things.

1- That involves added costs that you may or may not recoup (read sibling comment about Russia "not allowing it" which doesn't seem out of hand). So if you don't want it in the current State's hands, and you can't reliably export them, destruction might be the right choice. 2- Part of the goal may be the headline. Either good press for Cisco or bad press for Russia, but visibility can be a goal as well.

I like the idea of scorched earth when you are forced to leave because of outside circumstances (war, politics, etc.). Burn it down!

But for serious, likely too risky to have the potential for anything that can fall into a sanctioned country’s hands. Just destroy it and write it off.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.