Live data from Hacker News

Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

wired.com

11–20 of 121 posts

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#11
post #7
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.

Yeah, because illegitimate / spoofed certificates will never happen...

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#12
post #7
post #6

It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.

You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.

Many https sites use RC4, I wouldn't be so sure.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#13
The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#14

The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...

It would appear that the "party of reasonable size" here is China or Russia, not a corporation.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#15

The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...

It would appear that the "party of reasonable size" here is China or Russia, not a corporation.

I'm not sure that matters. Any powerful entity wrapped in secrecy is suspect, whether they're a nation state or a corporation. We, the users, are always the victims - dependant on the infrastructure or services that have been compromised.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#16

The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...

Now? The code was introduced in 2008.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#17
I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#18
post #12
post #7

Earlier quoted context omitted.

You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.

Many https sites use RC4, I wouldn't be so sure.

Then use a browser that rejects RC4 (like latest Chrome).

Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors

#19

I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.

And a good one. They were definitely deliberate, but the other details are not public.
Post reply on HN