Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

Lynn's actions at Black Hat weren't noble

It was a case of stolen intellectual property

August 31, 2005 12:00 PM ET

Computerworld - I read the latest Security Manager's Journal, "Peers Say Cisco Ended Up Wearing the Black Hat," written by C.J. Kelly, and I was somewhat surprised by the gist of the comments. But I guess I shouldn't be. It's another case where the details of a situation take a back seat to the hype surrounding it.

The controversy surrounding Michael Lynn making a presentation at the Black Hat event has given most people the impression that the events involve someone who is trying to let the world know about some critical vulnerability that Cisco Systems Inc. was hiding from the world. The details aren't as noble as the reality.

According to published reports, Lynn, during the course of his work at Internet Security Systems Inc., discovered a vulnerability in the Internetworking Operating System from Cisco. The exploitation of the vulnerability would result in control of the router. Cisco created a fix for the problem and released it without describing the details. At the same time, Lynn submitted a presentation about the vulnerability to the Black Hat conference, which was reviewed internally at ISS and disclosed to Cisco. At some point prior to the presentation, after the approvals were given out, ISS and/or Cisco changed its mind and wanted Lynn to edit the presentation. Lynn didn't want to and resigned his position. Despite warnings, Lynn still made his presentation at Black Hat.

Immediately prior to Lynn giving the presentation, he stated that he would be "sued into oblivion." I can only assume that this was in reference to the fact that he was warned that, since he created the presentation during his employment at ISS, the presentation was the property of ISS. That didn't change when he resigned. As a matter of fact, it likely made it worse, since he didn't have any legal right to access the materials after he left.

The fact is that the Lynn incident became an issue primarily involving the protection of intellectual property and consistent application of human resource guidelines. The question of proper disclosure is secondary. Lynn wanted to make the point that Cisco wasn't telling how critical the new vulnerability could be and that similar vulnerabilities could exist in the system. There were other ways he could have done that.

I agree that Cisco and ISS giving approval for the presentation and then withdrawing it is bad. I would also give a person credit for quitting because of a personal belief. However, what Lynn did after that is what created all the problems.

It's



Jump to comments

Security

Additional Resources

WHITE PAPER
Approximately 60 percent of data migration projects overrun time or budget, while some fail completely. Download this white paper, "Enhancing Your Chance for Successful Data Migration," to learn the critical steps you need to take to execute a data migration project with minimum cost and risk to your business.
WHITE PAPER
Read the Gartner research note to learn why the TCO of a server-based computing deployment used to deliver all applications to users is around 50% lower than that of an unmanaged desktop deployment.
WHITE PAPER
Economic downturns have a tendency to accelerate emerging technologies, boost the adoption of effective solutions, and punish solutions that are not cost competitive or that are out of synch with industry trends. This IDC White Paper presents the results of an IDC survey of 330 companies in Western Europe, Asia/Pacific and the Americas that measures the receptiveness to Linux and takes into consideration changing views driven by the disruptive economic environment that businesses face today.

White Papers & Webcasts

Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...

Can Heuristic Technology Help Your Company Fight Viruses?
What is Heuristic Technology and how can it help safeguard your business against viruses? Learn more.  

Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.

Why Email Must Operate 24/7 and How to Make This Happen
Learn how to avoid an email outage by implementing a hosted email continuity solution.  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...