@PostcardsFromParadise @nickpeers
Yes, thats true.
They’re claiming it’s to prevent money laundering.
You find the info in the gift card section of your Amazon account, where it will ask you to provide an ID.
@GossiTheDog
Wouldn’t the uptime rather suggest that they just plugged the cable back in?
Doesn’t seem to even had bothered patching the routers beforehand.
The routers could potentially be CEs and thus the responsibility of the service provider.
@just_one_bear @acdha
I don’t know your team budget but this is a next to impossible task, even with automation. When the issue exist in a layer beneath the admin layer as in this case you basically have to do a full pen test on every firmware release. Where do you stop? How about the code inside the TPM, CPU microcode?
If just a single person on earth did this and reported it back to Cisco this vulnerability would have been discovered long ago.
Hopefully we’ll manage to train some kind of AI model to assist in searching for vulnerabilities like these in the future but the task is still hard to solve.
Even harder will be getting the vendors to actually remediate the findings. There’s no automation for that process.