I'm looking at Juniper's news page [1] and its Twitter feed [2]...it doesn't give me a lot of confidence that this security breach or even its (apparently inadequate) patch doesn't even a news item or a Tweet. [1] http://newsroom.juniper.net/ [2] https://twitter.com/JuniperNetworks/with_replies
Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
31–40 of 121 posts
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#32Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#33I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#34It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#35Wow that nation state is stupid. They embedded the backdoor password right into it. Clearly they should have embedded the hash of the password instead. Then it would be unbreakable and no other party would be able to use the backdoor. Hashing passwords is extremely basic security practice.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#36It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.
Signal is open source. But you have to trust the OS it runs on...
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#37It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.
Signal is open source. But you have to trust the OS it runs on...
One has to assume that all are back-doored. Mobile phones are inherently not trustable.
Same goes for all major firewall vendors. If you going to hack one of them as a nation state, then you're going to do all of them.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#38I hope the folks at Juniper are checking their toolchains, build machines and repositories for signs of similar attack. Of course, enough time has elapsed that they may need to establish a cleanroom for their code. Hoo boy.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#39I like CNN's take on the story: http://edition.cnn.com/2015/12/18/politics/juniper-networks-... Obviously it must be either Russia or China - NSA couldn't possibly be responsible ;)
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#40Don't gouvernements can check the source code? like for Windows?