Earlier quoted context omitted.
It would appear that the "party of reasonable size" here is China or Russia, not a corporation.
Can you please explain how you reached that conclusion? What made you exclude US and UK?
Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
41–50 of 121 posts
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#42Earlier quoted context omitted.
Signal is open source. But you have to trust the OS it runs on...
And even if you trust the OS, you have no idea what is going on on the phone's baseband processor: https://en.m.wikipedia.org/wiki/Baseband_processor One has to assume that all are back-doored. Mobile phones are inherently not trustable. Same goes for all major firewall vendors. If you going to hack one of them as a nation state, then you're going to do all of them.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#43It's sad but events like this one make me turn away from Internet. I started using Signal because I don't want people seeing the messages I post. But in the end it's only trust that makes me think Signal is safe to use. A lot of people also trusted Juniper. But that trust is gone. And not only for Juniper. What about other brands? We don't know.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#44If you care about your security then you need to be able to inspect the code that protects your assets.
Distributed open source firewall vs propritary firewall with backdoors.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#45The honeymoon is over. The Internet is now a hostile environment. We cannot assume good conduct from any party of reasonable size and should assume deception from anything that isn't fully open source and vocal about it. It sucks to assume the worst...
That has always been the case. It's always been the case that if your adversary is a well funded government you need very careful security. We knew this from Echelon in the 1980s.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#46I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#47This also highlights why it would be better to use opensource firewalls such as Openbsd instead of proprietary ones! If you care about your security then you need to be able to inspect the code that protects your assets. Distributed open source firewall vs propritary firewall with backdoors.
Some of the very large security bugs found in open source software which were present in that code for years, indicate that this is not commonly done.
And that was just bugs as opposed to actual backdoors which would likely be harder to find if inserted competently.
So whilst in theory you are correct, I'm not so sure you are in practice.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#48This also highlights why it would be better to use opensource firewalls such as Openbsd instead of proprietary ones! If you care about your security then you need to be able to inspect the code that protects your assets. Distributed open source firewall vs propritary firewall with backdoors.
Given enough eyeballs backdoors can be easy to spot in source code, but eyeballs aren't an unlimited resource. In addition to open sourcing your software, the community that cares about the project needs enough funding or institutional support to actually review the code in question.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#49I'm confused. Are these accidental vulnerabilities or deliberate backdoors? If deliberate, why is there speculation about who might have installed this "secret code"? Do they have version control? Is there a specific human attached to the relevant commits? Serious question.
Would you take whatever your VCS claims as face value in this case? I wouldn't, which makes answering this very difficult, so I think it is to be expected that they don't have an answer yet.
Re: Secret Code Found in Juniper's Firewalls Shows Risk of Government Backdoors
#50I like CNN's take on the story: http://edition.cnn.com/2015/12/18/politics/juniper-networks-... Obviously it must be either Russia or China - NSA couldn't possibly be responsible ;)
It can't be NSA agents who caught intercepting network gear from Cisco Systems as it was being shipped to a customer (as revealed by snowden) it is highly unlikely they infected juniper networks as well.