[HN Gopher] Dump these insecure phone adapters because we're not...
       ___________________________________________________________________
        
       Dump these insecure phone adapters because we're not fixing them,
       says Cisco
        
       Author : PeterCorless
       Score  : 21 points
       Date   : 2023-05-05 21:16 UTC (1 hours ago)
        
 (HTM) web link (www.theregister.com)
 (TXT) w3m dump (www.theregister.com)
        
       | numpad0 wrote:
       | Looks like a lineage from Linksys, which is a subsidiary known
       | for once-ubiquitous WRT54G. IP phones from Cisco proper are much
       | different, and I wouldn't be surprised if they didn't have build
       | environment for this one ready to go.
        
       | whoopdedo wrote:
       | Allows unsigned firmware to be uploaded, eh? Sounds like an
       | opportunity to flash the phone with our own open source firmware.
       | Even better if it fixes the remote exploit.
        
       | PeterCorless wrote:
       | Also see: Cisco SPA112 2-Port Phone Adapters Remote Command
       | Execution Vulnerability [Listed as "Critical" "No workarounds
       | available"]
       | 
       | https://sec.cloudapps.cisco.com/security/center/content/Cisc...
        
         | bombcar wrote:
         | https://www.cisco.com/c/en/us/support/unified-communications...
         | 
         | Interesting:
         | 
         | Release Date 29-AUG-2011
         | 
         | End-of-Sale Date 01-JUN-2020
         | 
         | End-of-Support Date 31-MAY-2025
        
       | SoftTalker wrote:
       | My work has completely changed over their telephony technology at
       | least three times in 10 years. My parents had the same bakelite
       | Western Electric phone on the kitchen wall for over three
       | decades. Our defintion of technological advancement seems to be
       | shorter-lived, throwaway stuff that compromises our privacy and
       | demands frequent replacement. And the pace of obsolescence seems
       | to be accelerating.
        
         | Analemma_ wrote:
         | Same here. And what's amazing is that it never fixes anything.
         | I've been in the software industry well over ten years, and
         | been at companies that had multiple meeting room overhauls, and
         | yet meetings regularly still start with the same crap about the
         | AV equipment not working: host not sure if they're presenting,
         | microphone feedback loops, etc. It's like we're running
         | completely in place.
        
         | kayodelycaon wrote:
         | I think a company needs a solution that's a bit more involved
         | than an analog phone screwed to a wall.
        
       | crazygringo wrote:
       | > _Security hole ranks... 0 out of 10 in patch availability_
       | 
       | Seems like this is because the product already had its software
       | maintenance "end-of-life" in June 2020 [1]. Though it was also
       | being sold up to that date, which seems bizarre that you could
       | buy a product that would be "end-of-life" the very next day.
       | Also, it continues to receive hardware support for another 5
       | years (through May 2025).
       | 
       | I understand that companies can't provide security updates
       | infinitely for old products, but I have a hard time seeing logic
       | for not providing updates when they're still under a hardware
       | support contract. Seems like something should either be supported
       | or not, not in an insecure in-between state.
       | 
       | [1] https://www.cisco.com/c/en/us/products/collateral/unified-
       | co...
        
         | Maxburn wrote:
         | I don't work with Cisco kit but it certainly seems like they
         | are hostile in the support realm. Even if you buy something
         | used and there are software patches available for it you can't
         | get them without a support contract for example. Stories like
         | this "something serious is wrong and Cisco says get rid of it"
         | seem fairly common as well. They must be damn amazing at what
         | they do because these support stories would have me looking
         | elsewhere.
        
       | bitwize wrote:
       | Things like this are why "signed, approved boot chain from power
       | on to end user application" for all digital devices is currently
       | in the "yes, it's happening, and here's why it's a good thing"
       | phase.
        
         | numpad0 wrote:
         | "Real" Cisco phones like those behind President Zelenskyy on
         | magazine covers take .cop.sgn files, and can deal with SSL-VPN,
         | encrypted media and/or signaling, IPv6, device certificates,
         | etc. those features with a guard on duty usually suffices. It's
         | available if you need it and are willing to pay for, and
         | freemium version is just coming later.
         | 
         | (They're EOL too and on eBay dirt cheap. I don't know if my
         | calls are actually encrypted but it can be fun to burn a
         | weekend trying to register it to FreePBX)
        
           | simfree wrote:
           | Cisco phones are rough even with CUCM as the central server.
           | They freeze randomly when connected to CUCM, to the point
           | that its a pastime to walk into an office and look at the
           | time and date shown onscreen on all the frozen Cisco phones.
           | 
           | Note that this freezing issue primarily affects phones made
           | in the last decade from Cisco.
        
       ___________________________________________________________________
       (page generated 2023-05-05 23:01 UTC)