Lynn's actions at Black Hat weren't noble
It was a case of stolen intellectual property
Computerworld - I read the latest Security Manager's Journal, "Peers Say Cisco Ended Up Wearing the Black Hat," written by C.J. Kelly, and I was somewhat surprised by the gist of the comments. But I guess I shouldn't be. It's another case where the details of a situation take a back seat to the hype surrounding it.
The controversy surrounding Michael Lynn making a presentation at the Black Hat event has given most people the impression that the events involve someone who is trying to let the world know about some critical vulnerability that Cisco Systems Inc. was hiding from the world. The details aren't as noble as the reality.
According to published reports, Lynn, during the course of his work at Internet Security Systems Inc., discovered a vulnerability in the Internetworking Operating System from Cisco. The exploitation of the vulnerability would result in control of the router. Cisco created a fix for the problem and released it without describing the details. At the same time, Lynn submitted a presentation about the vulnerability to the Black Hat conference, which was reviewed internally at ISS and disclosed to Cisco. At some point prior to the presentation, after the approvals were given out, ISS and/or Cisco changed its mind and wanted Lynn to edit the presentation. Lynn didn't want to and resigned his position. Despite warnings, Lynn still made his presentation at Black Hat.
Immediately prior to Lynn giving the presentation, he stated that he would be "sued into oblivion." I can only assume that this was in reference to the fact that he was warned that, since he created the presentation during his employment at ISS, the presentation was the property of ISS. That didn't change when he resigned. As a matter of fact, it likely made it worse, since he didn't have any legal right to access the materials after he left.
The fact is that the Lynn incident became an issue primarily involving the protection of intellectual property and consistent application of human resource guidelines. The question of proper disclosure is secondary. Lynn wanted to make the point that Cisco wasn't telling how critical the new vulnerability could be and that similar vulnerabilities could exist in the system. There were other ways he could have done that.
I agree that Cisco and ISS giving approval for the presentation and then withdrawing it is bad. I would also give a person credit for quitting because of a personal belief. However, what Lynn did after that is what created all the problems.
It's



- Excel 2010 Cheat Sheet
- Register for this Computerworld Insider Cheat Sheet and gain access to hundreds of premium content articles, guides, product reviews and more.
- Overcome Top 7 Admin Challenges of Active Directory
- As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable,...
- Insiders Can Ruin Your Company. Take Action.
- Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in...
- Top Solutions and Tools to Prevent Devastating Malware
- Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring...
- X-Ray of the PCI Process-4 Proactive Steps
- This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into...
- Identity Governance: The Business Imperatives
- This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make... All Security White Papers
- Live Webcast
Playing Defense: Staying on Top of Your Disaster Recovery Game - When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing...
- Introduction to VMware vCenter Site Recovery Manager 5
- Traditional disaster recovery solutions are often too expensive, complex and unreliable to meet business requirements. As a result, IT departments are hesitant to...
- The Top Ten Secrets to Avoiding SAN Performance Problems
- Maintaining peak performance while simultaneously addressing the root cause of SAN errors is challenging. Learn the most common SAN problems and explore new...
- Deduplication Without Compromise
- Go inside Quantum's scalable, high-performance, multi-protocol new DXi deduplication appliances, designed to make backup much more effective. Discover how the new future-proof DXi6700...
- Director of Disk Products Discusses DXi6700
- Discover how the new DXi 6700 series of deduplication appliances provide investment protection and a future-proof feature set, all while delivering fast, scalable,...
- Playing Defense: Staying on Top of Your Disaster Recovery Game
- When it comes to disaster recovery, rapidly growing data volumes, distributed computing models, and new technologies all combine to present an ever-changing playing... All Security Webcasts