Cisco agreed to pay $8.6 million to settle claims that it sold security software with known vulnerabilities to the U.S. government and several states. This is the first time that a tech company has been forced to pay out for flawed security products under a federal whistleblower protection law.
The case dates back to 2008, when a Cisco subcontractor, James Glenn, discovered he could hack into the video surveillance software and access the systems running the devices. Airports, schools, hospitals, prisons, and other federal agencies used the software. Glenn said he contacted Cisco about the flaw, and shortly after was fired.
Later, in 2010, Glenn discovered the software still being used by Los Angeles International Airport. At that point he contacted local law enforcement and the F.B.I.
Cisco didn’t acknowledge the bugs until three years later. “In July 2013, we advised that customers should upgrade to a new version of the software, which addressed security features. All sales of the older versions of the software had ended by September 2014,” Mark Chandler, Cisco’s executive vice president of legal services and general counsel, wrote in a blog post about the settlement.
The company says the bugs weren’t exploited by hackers while the flawed software was being used.
“We are pleased to have resolved a 2011 dispute involving the architecture of a video security technology product we added to our portfolio through the Broadware acquisition in 2007,” a Cisco spokesperson wrote in an email to SDxCentral. “There was no allegation or evidence that any unauthorized access to customers’ video occurred as a result of the architecture.”
The settlement will be used to pay the whistleblower about $1.6 million and partially refund the U.S. federal government and 16 states for Cisco products purchased between 2008 and 2013. It’s essentially pocket change for the vendor — for comparison, Cisco CEO Chuck Robbins' house sold for $10.65 million last year — but it could have broader implications for other security vendors.
“It’s one of the risks of open software,” said Zeus Kerravala, principal analyst at ZK Research, adding that the push for open, interoperable software comes with inherent risk. “Everybody screams they want open and standards-based, but even for buyers understanding the risk is important. As soon as you open things, you open them up to the bad guys as well as the good guys.”
But, he added, if Cisco had addressed the security flaw back when the whistleblower first raised the issues “there might not have been any issue at all. The lesson for companies is if they are going to be using open software, as soon as something like this is reported they need to jump on it and make sure it’s fixed.”
Charles King, president and principal analyst at Pund-IT, said the settlement highlights changing attitudes in the tech industry.
“When ... James Glenn informed Cisco about the problems with in security software, his reward was losing his job,” King wrote in an email. “Cisco, meanwhile, acted as if nothing were wrong and continued selling the flawed software. Today, the situation has improved and vendors recognize the value that software ‘bug finders’ offer to themselves and their customers.”
It also reinforces the need for independent software analysis, King added. “That it took James Glenn a decade to receive justice for an act he made in good faith is a reminder of the way that all too many IT vendors once did business,” he said. “That things have evolved considerably since then is good news for the tech industry and the businesses and consumers that depend on its products and services.”
Comments