http://edition.cnn.com/2015/12/18/politics/juniper-networks-...
Obviously it must be either Russia or China - NSA couldn't possibly be responsible ;)
21–30 of 121 posts
http://edition.cnn.com/2015/12/18/politics/juniper-networks-...
Obviously it must be either Russia or China - NSA couldn't possibly be responsible ;)
Earlier quoted context omitted.
You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.
Yeah, because illegitimate / spoofed certificates will never happen...
I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.
And a good one. They were definitely deliberate, but the other details are not public.
The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...
It would appear that the "party of reasonable size" here is China or Russia, not a corporation.
The problem goes much deeper. It could be any "larger" corporation or government or other entity having enough manpower. It could even be parts of a corporation or government entity.
However which way you put it, a program of which you don't have access to the source cannot be trusted.
The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...
It would appear that the "party of reasonable size" here is China or Russia, not a corporation.
The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...
We knew this from Echelon in the 1980s.
Earlier quoted context omitted.
Then use a browser that rejects RC4 (like latest Chrome).
[deleted]
(Also, since it's a stream cipher, it can't use the same key ever again, else you can xor those ciphertexts to get 2 xored plaintexts, which are much easier to crack.)
I'm looking at Juniper's news page [1] and its Twitter feed [2]...it doesn't give me a lot of confidence that this security breach or even its (apparently inadequate) patch doesn't even a news item or a Tweet. [1] http://newsroom.juniper.net/ [2] https://twitter.com/JuniperNetworks/with_replies
Was discussed yesterday on this thread https://news.ycombinator.com/item?id=10754917 which points to the proactive announcement Juniper made
Earlier quoted context omitted.
You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.
Yeah, because illegitimate / spoofed certificates will never happen...
It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.
You're still secure if you use https. If neither your computer nor the host you're connecting to has been tampered with, then you're safe irrespective of what's happening between.
While that used to be true, based upon recent history we, unfortunately, can't blindly trust HTTPS to always be "secure" 100% of the time anymore -- whether due to things like Heartbleed, fake certs signed by a root CA, protocol attacks, or some other vulnerability that hasn't even been discovered yet.