<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Your Cisco phone is listening to you: 29C3 talk on breaking Cisco&#160;phones</title>
	<atom:link href="http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html/feed" rel="self" type="application/rss+xml" />
	<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html</link>
	<description>Brain candy for Happy Mutants</description>
	<lastBuildDate>Fri, 24 May 2013 12:50:00 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.4.1</generator>
	<item>
		<title>By: bellebouche</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617424</link>
		<dc:creator>bellebouche</dc:creator>
		<pubDate>Sun, 30 Dec 2012 09:56:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617424</guid>
		<description>Wry smiles all round when the slides that detailed the Cisco TAC responsiveness to their own bugs came up. Fancy that!


Schadenfreude all round and I trust one or two people there will be butthurt after xmas</description>
		<content:encoded><![CDATA[<p>Wry smiles all round when the slides that detailed the Cisco TAC responsiveness to their own bugs came up. Fancy that!</p>
<p>Schadenfreude all round and I trust one or two people there will be butthurt after xmas</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fuzzyfuzzyfungus</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617406</link>
		<dc:creator>fuzzyfuzzyfungus</dc:creator>
		<pubDate>Sun, 30 Dec 2012 05:40:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617406</guid>
		<description>It was. However, the default user account(which isn&#039;t privileged; but which is enough to launch their privilege escalation exploit) is identical across all phones, so obtaining a password that would work reliably during an automated attack wasn&#039;t terribly difficult.

(And, in an ironic touch, the file checksumming security system prevents tampering with /etc/passwd, so even an alert operator cannot disable the account or change its password, the phone will just detect the tampering and revert the file...)</description>
		<content:encoded><![CDATA[<p>It was. However, the default user account(which isn&#8217;t privileged; but which is enough to launch their privilege escalation exploit) is identical across all phones, so obtaining a password that would work reliably during an automated attack wasn&#8217;t terribly difficult.</p>
<p>(And, in an ironic touch, the file checksumming security system prevents tampering with /etc/passwd, so even an alert operator cannot disable the account or change its password, the phone will just detect the tampering and revert the file&#8230;)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Sean Aubin</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617379</link>
		<dc:creator>Sean Aubin</dc:creator>
		<pubDate>Sun, 30 Dec 2012 02:11:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617379</guid>
		<description>One thing that I was a little unclear on, why wasn&#039;t the console which gave them access password protected?</description>
		<content:encoded><![CDATA[<p>One thing that I was a little unclear on, why wasn&#8217;t the console which gave them access password protected?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: asuffield</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617339</link>
		<dc:creator>asuffield</dc:creator>
		<pubDate>Sat, 29 Dec 2012 23:51:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617339</guid>
		<description>If the competition was Polycom then it&#039;s not hard to beat in any evaluation. Sad reality is that standards are low in this market, and this is driven by customers being primarily interested in price - what corporate purchasers want is a cheap, bad phone that covers all the things on their &quot;essential features&quot; list. I know a lot of engineers who would love to build better endpoints. Nobody would buy them.

(My opinions here are my own and not those of my employer, Cisco Systems. I don&#039;t work in a part of the company that does phones.)</description>
		<content:encoded><![CDATA[<p>If the competition was Polycom then it&#8217;s not hard to beat in any evaluation. Sad reality is that standards are low in this market, and this is driven by customers being primarily interested in price &#8211; what corporate purchasers want is a cheap, bad phone that covers all the things on their &#8220;essential features&#8221; list. I know a lot of engineers who would love to build better endpoints. Nobody would buy them.</p>
<p>(My opinions here are my own and not those of my employer, Cisco Systems. I don&#8217;t work in a part of the company that does phones.)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Brad Ackerman</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617336</link>
		<dc:creator>Brad Ackerman</dc:creator>
		<pubDate>Sat, 29 Dec 2012 23:36:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617336</guid>
		<description>&quot;Nobody ever got fired for buying Cisco&quot;. Do Cisco phones get bought because they beat the competition in a real evaluation, or because the CxO said &quot;I met with the Cisco sales rep and he had a really swank suit; give them all our money&quot;?</description>
		<content:encoded><![CDATA[<p>&#8220;Nobody ever got fired for buying Cisco&#8221;. Do Cisco phones get bought because they beat the competition in a real evaluation, or because the CxO said &#8220;I met with the Cisco sales rep and he had a really swank suit; give them all our money&#8221;?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: fuzzyfuzzyfungus</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617299</link>
		<dc:creator>fuzzyfuzzyfungus</dc:creator>
		<pubDate>Sat, 29 Dec 2012 21:49:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617299</guid>
		<description>Just remember, this is the expensive, classy, &#039;enterprise&#039;, secure product... Odds are good that the goods don&#039;t exactly improve elsewhere in the market.</description>
		<content:encoded><![CDATA[<p>Just remember, this is the expensive, classy, &#8216;enterprise&#8217;, secure product&#8230; Odds are good that the goods don&#8217;t exactly improve elsewhere in the market.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Aaron Swain</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617288</link>
		<dc:creator>Aaron Swain</dc:creator>
		<pubDate>Sat, 29 Dec 2012 21:15:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617288</guid>
		<description>Equal parts entertaining and disturbing</description>
		<content:encoded><![CDATA[<p>Equal parts entertaining and disturbing</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: PAPPP</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617282</link>
		<dc:creator>PAPPP</dc:creator>
		<pubDate>Sat, 29 Dec 2012 20:57:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617282</guid>
		<description>The official mirrors/torrents for videos of all the talks for the 29C3 sessions as they get processed and uploaded are here: https://events.ccc.de/congress/2012/wiki/Documentation#Official_mirrors
They were running a live-stream during the conference, but it was at inconvenient times for the U.S. and some of the things I wanted to watch overlapped, so I just waited for the good copies to go up and am watching now. The Chaos Communication Congress talks tend to be some of the best tech presentations that make it to the &#039;net, I&#039;ve never managed to come up with an excuse to end up in Germany for it, but I have ended up watching most of the sessions online after the fact each year. </description>
		<content:encoded><![CDATA[<p>The official mirrors/torrents for videos of all the talks for the 29C3 sessions as they get processed and uploaded are here: https://events.ccc.de/congress/2012/wiki/Documentation#Official_mirrors<br />
They were running a live-stream during the conference, but it was at inconvenient times for the U.S. and some of the things I wanted to watch overlapped, so I just waited for the good copies to go up and am watching now. The Chaos Communication Congress talks tend to be some of the best tech presentations that make it to the &#8216;net, I&#8217;ve never managed to come up with an excuse to end up in Germany for it, but I have ended up watching most of the sessions online after the fact each year. </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: kai rupert</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617271</link>
		<dc:creator>kai rupert</dc:creator>
		<pubDate>Sat, 29 Dec 2012 20:32:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617271</guid>
		<description>this time the CCC is in Hambug, not in Berlin </description>
		<content:encoded><![CDATA[<p>this time the CCC is in Hambug, not in Berlin </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: René Walter</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617264</link>
		<dc:creator>René Walter</dc:creator>
		<pubDate>Sat, 29 Dec 2012 20:13:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617264</guid>
		<description>Yep, it&#039;s in Hamburg this year. Also: Here&#039;s the YT-Channel for all 29c3-Talks in english Language:  http://www.youtube.com/user/CCCen/videos (and here are the german ones: http://www.youtube.com/user/CCCdeVideos/videos)</description>
		<content:encoded><![CDATA[<p>Yep, it&#8217;s in Hamburg this year. Also: Here&#8217;s the YT-Channel for all 29c3-Talks in english Language:  <a href="http://www.youtube.com/user/CCCen/videos" rel="nofollow">http://www.youtube.com/user/CCCen/videos</a> (and here are the german ones: <a href="http://www.youtube.com/user/CCCdeVideos/videos" rel="nofollow">http://www.youtube.com/user/CCCdeVideos/videos</a>)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jan-Bernd Vstn</title>
		<link>http://boingboing.net/2012/12/29/your-cisco-phone-is-listening.html#comment-1617258</link>
		<dc:creator>Jan-Bernd Vstn</dc:creator>
		<pubDate>Sat, 29 Dec 2012 20:08:00 +0000</pubDate>
		<guid isPermaLink="false">http://boingboing.net/?p=203159#comment-1617258</guid>
		<description>29c3 is in Hamburg not Berlin </description>
		<content:encoded><![CDATA[<p>29c3 is in Hamburg not Berlin </p>
]]></content:encoded>
	</item>
</channel>
</rss>
